System reinforcing method and device, related equipment, medium and product

By automatically obtaining and sending hardening configuration files and programs on the server side, the problem of low efficiency in traditional system hardening methods is solved, and efficient operating system security hardening is achieved.

CN120893049AInactive Publication Date: 2025-11-04CHINA MOBILE (SUZHOU) SOFTWARE TECH CO LTD +1
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202511353232.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-22
Publication Date
2025-11-04
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Traditional system hardening methods consume a lot of manpower and time, are inefficient, and cannot effectively solve security risks and software vulnerabilities within the operating system.

Method used

The server receives the hardening entry list from the client, automatically retrieves and sends the hardening configuration file and program, thereby achieving automatic hardening of the client's operating system.

Benefits of technology

It improves the efficiency of system hardening, reduces the consumption of manpower and time, and enhances the degree of automation in hardening.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120893049A_ABST
    Figure CN120893049A_ABST
Patent Text Reader

Abstract

The invention discloses a system reinforcement method and device, related equipment, a medium and a product. The method comprises the following steps: receiving a first message sent by a client; the first message comprises a reinforced entry table of an operating system of the client; the reinforced entry table is used for indicating at least one to-be-reinforced entry; sending a second message to the client; the second message comprises a reinforcement configuration file and a reinforcement program corresponding to each to-be-reinforced entry.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of computer, and in particular to a system reinforcement method and device, related equipment, medium and product. BACKGROUND

[0002] Traditional operating system security protection mainly relies on external deployment of security tools such as firewalls, intrusion detection systems, and antivirus software. These methods can resist external attacks to some extent, but cannot solve the security risks and software vulnerabilities inside the operating system. Therefore, it is necessary to update the system for targeted security reinforcement in a timely manner to effectively resist system risks.

[0003] However, with the rapid development of information systems, the functions of the operating system are constantly expanding and updating, and using the existing system reinforcement method requires a lot of manpower and time, and the efficiency is low. SUMMARY

[0004] The present application mainly provides a system reinforcement method, device, related equipment, medium and product.

[0005] The technical solution of the present application is as follows: A system reinforcement method applied to a server, the method comprising: receiving a first message sent by a client; the first message comprising a reinforcement item table of an operating system of the client; the reinforcement item table being used to indicate at least one to-be-reinforced item; sending a second message to the client; the second message comprising a reinforcement configuration file and a reinforcement program corresponding to each to-be-reinforced item.

[0006] In the above scheme, before receiving the first message sent by the client, the method comprises: constructing a security reinforcement information library of the operating system; the security reinforcement information library comprising security standard information of the operating system; generating a third message based on the security standard information; the third message being used to request the client to reinforce the operating system; sending the third message to the client.

[0007] In the above scheme, the security reinforcement information library further comprises a reinforcement policy library of the operating system; and after receiving the first message sent by the client, the method comprises: extracting a keyword of each to-be-reinforced item based on the reinforcement item table; cross-verifying the reinforcement policy library and each to-be-reinforced item based on the keyword to obtain a reinforcement policy corresponding to each to-be-reinforced item; the reinforcement policy comprising the reinforcement program and the reinforcement configuration file.

[0008] In the above solution, after the second message is sent to the client, the method further includes: receiving a fourth message sent by the client; the fourth message includes reinforcement operation log information; the reinforcement operation log information is used to indicate a reinforcement state of each of the to-be-reinforced items; the reinforcement state includes a completed state and an uncompleted state.

[0009] In the above solution, after the fourth message sent by the client is received, the method further includes: if the reinforcement operation log information indicates that the reinforcement state of a first to-be-reinforced item is the uncompleted state, updating a reinforcement program and a reinforcement configuration file corresponding to the first to-be-reinforced item to obtain updated reinforcement program and reinforcement configuration file of the first to-be-reinforced item; the first to-be-reinforced item is any to-be-reinforced item in the at least one to-be-reinforced item; sending a fifth message to the client; the fifth message includes the updated reinforcement program and the reinforcement configuration file of the first to-be-reinforced item.

[0010] A system reinforcement method applied to a client, the method comprising: sending a first message to a server; the first message includes a reinforcement item table of an operating system of the client; the reinforcement item table is used to indicate at least one to-be-reinforced item; receiving a second message sent by the server; the second message includes a reinforcement configuration file and a reinforcement program corresponding to each of the to-be-reinforced items.

[0011] In the above solution, before the first message is sent to the server, the method further includes: receiving a third message sent by the server; the third message is used to request the client to reinforce the operating system.

[0012] In the above solution, after the third message sent by the server is received, the method further includes: performing security detection on the operating system to obtain a detection result; the detection result includes at least one of the to-be-reinforced items; generating the reinforcement item table based on the detection result.

[0013] In the above solution, after the second message sent by the server is received, the method further includes: performing a reinforcement operation on each of the to-be-reinforced items based on the reinforcement program and the reinforcement configuration file, and generating reinforcement operation log information; the reinforcement operation log information is used to indicate a reinforcement state of each of the to-be-reinforced items; the reinforcement state includes a completed state and an uncompleted state. send a fourth message to the server; the fourth message comprises the hardened operation log information.

[0014] In the above solution, after sending the fourth message to the server, the following is included: If the hardened operation log information indicates that the hardened state of the first to-be-hardened item is an unfinished state, receive the fourth message sent by the server; the fourth message comprises the updated hardened program and hardened configuration file of the first to-be-hardened item. Perform a hardened operation on the first to-be-hardened item based on the updated hardened program and hardened configuration file of the first to-be-hardened item.

[0015] A system hardening apparatus applied to a server, the apparatus comprising: A first receiving unit configured to receive a first message sent by a client; the first message comprises a hardened item table of an operating system of the client; the hardened item table is used to indicate at least one to-be-hardened item. A first sending unit configured to send a second message to the client; the second message comprises a hardened configuration file and a hardened program corresponding to each to-be-hardened item.

[0016] A system hardening apparatus applied to a client, the apparatus comprising: A second sending unit configured to send a first message to a server; the first message comprises a hardened item table of an operating system of the client; the hardened item table is used to indicate at least one to-be-hardened item. A second receiving unit configured to receive a second message sent by the server; the second message comprises a hardened configuration file and a hardened program corresponding to each to-be-hardened item.

[0017] A server comprising a first communication interface and a first processor; wherein, The first communication interface is configured to receive a first message sent by a client; the first message comprises a hardened item table of an operating system of the client; the hardened item table is used to indicate at least one to-be-hardened item. Send a second message to the client; the second message comprises a hardened configuration file and a hardened program corresponding to each to-be-hardened item.

[0018] A client comprising a second communication interface and a second processor; wherein, The second communication interface is configured to send a first message to a server; the first message comprises a hardened item table of an operating system of the client; the hardened item table is used to indicate at least one to-be-hardened item. receive a second message sent by the server; the second message includes a reinforcement configuration file and a reinforcement program corresponding to each of the to-be-reinforced items.

[0019] A storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements the steps of any of the methods on the server side or the steps of any of the methods on the client side.

[0020] A computer program product comprising a computer program, wherein the computer program, when executed by a processor, implements the steps of any of the methods on the server side or the steps of any of the methods on the client side.

[0021] The application provides a system reinforcement method and device, related equipment, medium and product, receiving a first message sent by a client; the first message includes a reinforcement item table of an operating system of the client; the reinforcement item table is used to indicate at least one to-be-reinforced item; sending a second message to the client; the second message includes a reinforcement configuration file and a reinforcement program corresponding to each of the to-be-reinforced items. That is to say, the application receives a first message sent by a client through a server, the first message includes a reinforcement item table of an operating system of the client, the reinforcement item table is used to indicate at least one to-be-reinforced item, and a second message is sent to the client; the second message includes a reinforcement configuration file and a reinforcement program corresponding to each of the to-be-reinforced items, so as to realize that the server automatically obtains to-be-reinforced items of the client and sends the reinforcement configuration file and the reinforcement program of the to-be-reinforced items to the client, thereby solving the problem that a system reinforcement method in the related art needs to consume a large amount of manpower and time, and improving reinforcement efficiency. BRIEF DESCRIPTION OF DRAWINGS

[0022] Figure 1 A flowchart of an operating system reinforcement process in the related art; Figure 2 A flowchart of a system reinforcement method provided by an embodiment of the application; Figure 3 A storage data diagram of a security reinforcement item detection provided by an embodiment of the application; Figure 4 A structure diagram of a security reinforcement information base provided by an embodiment of the application; Figure 5 A flowchart of a reinforcement strategy matching provided by an embodiment of the application; Figure 6 A flowchart of another system reinforcement method provided by an embodiment of the application; Figure 7 A flowchart of a third system reinforcement method provided by an embodiment of the application; Figure 8A flowchart of a Linux operating system reinforcement process provided by an embodiment of the present application is shown in the figure; Figure 9 A structural diagram of a system reinforcement device provided by an embodiment of the present application is shown in the figure; Figure 10 A structural diagram of another system reinforcement device provided by an embodiment of the present application is shown in the figure; Figure 11 A structural diagram of a server provided by an embodiment of the present application is shown in the figure; Figure 12 A structural diagram of a client provided by an embodiment of the present application is shown in the figure. DETAILED DESCRIPTION

[0023] In order to make the purposes, technical solutions and advantages of the present application clearer, the technical solutions of the present application are further described in detail below in combination with the figures and embodiments, and the described embodiments should not be regarded as limiting the present application, and all other embodiments obtained by those skilled in the art without making creative efforts fall within the scope of protection of the present application.

[0024] In the following description, "some embodiments" are related to a subset of all possible embodiments, but it can be understood that "some embodiments" can be the same subset or different subsets of all possible embodiments, and can be combined with each other without conflict.

[0025] The terms "first / second / third" involved in the present application only distinguish similar objects and do not represent a specific order of the objects, and it can be understood that "first / second / third" can interchange specific order or sequence as allowed, so that the embodiments of the present application described herein can be implemented in an order other than that illustrated or described herein.

[0026] Reference Figure 1 As shown in the figure, the whole process of the existing reinforcement method includes the following parts: writing a reinforcement script H according to a standard A, uploading the script to a system to be reinforced , running the reinforcement script, checking the state after reinforcement, and modifying the reinforcement script, etc. A large amount of time and labor cost is required to face the system cluster scene.

[0027] An embodiment of the present application provides a system reinforcement method applied to a server, referring to Figure 2 shown in the figure, the method includes the following steps: Step S201: receiving a first message sent by a client.

[0028] The first message includes a reinforcement entry table of an operating system of the client; the reinforcement entry table is used to indicate at least one entry to be reinforced.

[0029] It can be understood that the server can be a cloud server providing cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, content delivery networks (CDN), and big data and artificial intelligence platforms, and other basic cloud computing services. The client can be a bare metal server (BMS). The operating system on the client includes but is not limited to a Linux operating system (OS), a Windows OS, and the embodiments of the present application take the Linux OS as an example for illustration. The server and the client can be connected by a remote encrypted secure communication protocol (SSH) or a graphical remote management protocol (VNC).

[0030] In actual application, a system state inspection module can be arranged in the client, which can perform operations such as security baseline scanning, intrusion detection, and security vulnerability scanning on the Linux OS, and output the detection results of each security hardening item in the operating system. The data storage format of the detection results is as shown in the following table: Figure 3 As shown in the table, when the detection result is OK, it means that the item in the OS meets the security requirements and does not need to be hardened; if the detection result is WARNING, it means that the item does not meet the security requirements and needs to be hardened. Each table and security hardening item has a specific identity (ID), which can be automatically accessed and filtered by program traversal of the ID number. The hardening item table sent by the client to the server is all the to-be-hardened items with a WARNING result.

[0031] The host module of the server can communicate with the client cluster, and the host module can receive the hardening item table sent by the client at regular intervals.

[0032] Step S202: sending a second message to the client.

[0033] The second message includes a hardening configuration file and a hardening program corresponding to each to-be-hardened item.

[0034] In actual application, the server can further include a security hardening information library, which can include security standard information and a hardening policy library. According to the security standard information, the server can send a hardening request to the client, requesting the client to harden the operating system; the hardening policy library can be used to generate a hardening configuration file and a hardening program corresponding to each to-be-hardened item.

[0035] From the above, the embodiment of the application receives the first message sent by the client through the server, the first message includes the hardened item table of the operating system of the client, the hardened item table is used to indicate at least one to-be-hardened item, and the second message is sent to the client; the second message includes the hardened configuration file and the hardened program corresponding to each to-be-hardened item, so as to realize that the server automatically acquires the to-be-hardened item of the client and sends the hardened configuration file and the hardened program of the to-be-hardened item to the client, and the problem that the system hardening method in the related art needs to consume a large amount of manpower and time is solved, and the hardening efficiency is improved.

[0036] In some embodiments of the application, before receiving the first message sent by the client, the method comprises: constructing a security hardening information database of the operating system; the security hardening information database includes security standard information of the operating system; generating a third message based on the security standard information; the third message is used to request the client to harden the operating system; sending the third message to the client.

[0037] In actual application, the server can generate security standard information according to the latest security standard, generate a hardened policy library according to the prior knowledge such as a vulnerability database, construct a security hardening information database (Database) of the operating system, and the host module of the server can send the third message to the client according to the security standard information. The security standard information can be dynamically updated, and the host module of the server can also send the third message to the client when the security standard information is updated.

[0038] In some embodiments of the application, the security hardening information database further includes a hardened policy library of the operating system; after receiving the first message sent by the client, the method comprises: extracting a keyword of each to-be-hardened item based on the hardened item table; cross-verification of the hardened policy library and each to-be-hardened item based on the keyword, to obtain a hardened policy corresponding to each to-be-hardened item; the hardened policy includes a hardened program and a hardened configuration file.

[0039] In actual application, the hardened policy library mainly includes a security hardening implementation library, a security hardening configuration rule library and a security hardening policy file, for reference Figure 4As shown, the security standard information is not shown in the figure, and the security reinforcement implementation library content mainly stores high-risk vulnerability patches and binary software packages (RPM format) from the upstream vulnerability database; there are also security reinforcement scripts written according to industry standards or manufacturer instruction manuals, and defense scripts written according to intrusion detection reinforcement instruction manuals, mainly including bash, python, C and other language formats. The security reinforcement configuration rule library mainly stores the reinforcement configuration files required in the implementation library reinforcement script, which is used for script mapping, mainly including Extensible Markup Language (XML) and JavaScript Object Notation (JSON) formats. The security reinforcement policy file saves the brief description and ID number of the patch and script in the implementation library, which is one-to-one mapped with the implementation library content, and the file format can be csv and xlsx.

[0040] The server can also include a keyword matching module that uses a fuzzy matching scheme of keyword strings to calculate the difference between two string sequences, with reference to Figure 5 As shown, the input of the keyword matching module is the reinforcement entry table and the security reinforcement policy file Two data sources, using a string fuzzy matching tool (such as Fuzzywuzzy) to cross-verify the similarity between individual records of the two data sources, obtaining a similarity confidence value When the similarity confidence value is greater than or equal to the confidence threshold V, it is considered that the matching is successful, and on the contrary. When the matching fails, the entries of the reinforcement policy file records in the security reinforcement information library can be iterated until the matching is successful, and the corresponding reinforcement policy of each to-be-reinforced entry is output according to the matched reinforcement policy file.

[0041] A matching algorithm that ignores word order can be used, as shown in formula 1: (Formula 1) Wherein, is the reinforcement entry table, is the security reinforcement policy file, i is the number of data in the reinforcement entry table, j is the number of data in the security reinforcement policy file, and the similarity confidence value The confidence threshold V can be set according to the actual situation, which is not limited in the present application. N can refer to any data in the reinforcement entry table, and P can refer to any data in the security reinforcement policy file. is the reinforcement policy, and n is less than or equal to i.

[0042] The reinforcement policy includes the corresponding reinforcement program and hardened configuration files The hardening program may include hardening program scripts, and the hardening program script language may include, but is not limited to, shell, python, and c.

[0043] In some embodiments of this application, after sending the second message to the client, the process includes: Receive a fourth message sent by the client; the fourth message includes reinforcement operation log information; the reinforcement operation log information is used to indicate the reinforcement status of each item to be reinforced; the reinforcement status includes a completed status and an incomplete status.

[0044] In practical applications, a log auditing module can be set up on the client side. This module is mainly responsible for recording log information during the hardening process and synchronously sending the log information to the server for risk auditing. The hardening operation log information can be understood as the log information generated during the hardening process. When there are one or more failure or alarm messages in the entire hardening log, the server needs to adjust the corresponding hardening program and hardening configuration file and send them to the client. The client then performs operating system security hardening operations based on the adjusted hardening program and hardening configuration file. The hardening status includes an incomplete status and a completed status. The incomplete status can be understood as hardening failure or alarm.

[0045] In some embodiments of this application, after receiving the fourth message sent by the client, the process includes: If the reinforcement operation log information indicates that the reinforcement status of the first item to be reinforced is incomplete, update the reinforcement program and reinforcement configuration file corresponding to the first item to be reinforced to obtain the updated reinforcement program and reinforcement configuration file of the first item to be reinforced; the first item to be reinforced is any one of at least one item to be reinforced. Send a fifth message to the client; the fifth message includes the updated hardening program and hardening configuration file for the first entry to be hardened.

[0046] In practical applications, the first item to be reinforced can be understood as the item in the reinforcement item table that has not been reinforced. The server updates the reinforcement strategy corresponding to the first item to be reinforced, obtains the updated reinforcement program and reinforcement configuration file for the first item to be reinforced, and sends them to the client. The client then performs reinforcement operations on the first item to be reinforced based on the updated reinforcement program and reinforcement configuration file. The server can also update the security reinforcement information database.

[0047] Embodiments of this application provide a system hardening method applied to a client-side application, as shown below. Figure 6 As shown, the method includes the following steps: Step S601: Send the first message to the server.

[0048] The first message includes a hardened item table of an operating system of the client; the hardened item table is used to indicate at least one to-be-hardened item.

[0049] In actual application, a system state inspection module can be arranged in the client, and the system state inspection module can perform operations such as security baseline scanning, intrusion detection and security vulnerability scanning on the Linux OS, and output a detection result of each security hardened item in the operating system. The data storage format of the detection result is as shown in the following table: Figure 3 As shown in the table, when the detection result is OK, it indicates that the item in the OS meets the security requirement and does not need to be hardened; if the detection result is WARNING, it indicates that the item does not meet the security requirement and needs to be hardened. Each table and security hardened item has a specific ID, and the ID number can be automatically accessed and filtered through a program. The hardened item table sent by the client to the server is all to-be-hardened items with a result of WARNING.

[0050] Step S602: receiving the second message sent by the server.

[0051] The second message includes a hardened configuration file and a hardened program corresponding to each to-be-hardened item.

[0052] In actual application, the host module of the server can communicate with the client cluster, and the host module can receive the hardened item table sent by the client at a regular time.

[0053] The server can further include a security hardening information library, which can include security standard information and a hardened policy library. According to the security standard information, the server can send a hardened request to the client, requesting the client to harden the operating system; the hardened policy library can be used to generate a hardened configuration file and a hardened program corresponding to each to-be-hardened item.

[0054] From the above content, it can be known that the embodiments of the present application receive the first message sent by the client through the server, the first message includes a hardened item table of an operating system of the client, the hardened item table is used to indicate at least one to-be-hardened item, and the second message is sent to the client; the second message includes a hardened configuration file and a hardened program corresponding to each to-be-hardened item, so as to realize that the server automatically acquires the to-be-hardened items of the client and sends the hardened configuration file and the hardened program of the to-be-hardened items to the client, and solve the problem that the system hardening method in the related art needs to consume a large amount of manpower and time, and improve the hardening efficiency.

[0055] In some embodiments of the present application, before the first message is sent to the server, the following steps are included: receiving a third message sent by the server; the third message is used to request the client to harden the operating system.

[0056] In practical applications, refer to Figure 7 As shown, the server can generate security standard information based on the latest security standards, generate a hardening strategy library based on prior knowledge such as vulnerability databases, and build a security hardening information database for the operating system. The host module of the server can send a third message to the client based on the security standard information. The security standard information can be updated dynamically. When the security standard information is updated, the host module of the server can also send a third message to the client.

[0057] In some embodiments of this application, after receiving the third message sent by the server, the process includes: The operating system is subjected to security testing, and the test results are obtained; the test results include at least one item that needs to be hardened. A reinforcement item list is generated based on the test results.

[0058] In practical applications, refer to Figure 7 As shown, a system status inspection module can be configured in the client. This module can perform security baseline scanning, intrusion detection, and security vulnerability scanning on the Linux OS, outputting the detection results for each security hardening item in the operating system. The data storage format for the detection results is as follows: Figure 3 As shown, when the detection result is normal (OK), it means that the entry in the OS meets the security requirements and does not need to be hardened; if the detection result is a warning (WARNING), it means that it does not meet the security requirements and the entry needs to be hardened. Each table and security hardening entry has a specific identifier (Identity, ID), which can be automatically accessed and filtered by traversing the ID numbers. The hardening entry table sent by the client to the server contains all entries that have a WARNING result and need to be hardened.

[0059] In some embodiments of this application, after receiving the second message sent by the server, the process includes: The reinforcement operation is performed on each item to be reinforced based on the reinforcement program and reinforcement configuration file, and reinforcement operation log information is generated. The reinforcement operation log information is used to indicate the reinforcement status of each item to be reinforced. The reinforcement status includes completed status and incomplete status. Send a fourth message to the server; the fourth message includes hardening operation log information.

[0060] In practical applications, refer to Figure 7 As shown, a log auditing module can be configured in the client. This module is mainly responsible for recording log information during the hardening process and synchronously sending the log information to the server for risk auditing. It can be understood as log information generated in the reinforcement process; when there is single or multiple failure or warning information in the entire reinforcement log, the server needs to adjust the corresponding reinforcement program and reinforcement configuration file and send it to the client, and the client performs the operating system security reinforcement operation according to the adjusted reinforcement program and reinforcement configuration file. The reinforcement state includes an unfinished state and a completed state, and the unfinished state can be understood as reinforcement failure or warning.

[0061] In some embodiments of the present application, after sending the fourth message to the server, the method comprises: If the reinforcement operation log information indicates that the reinforcement state of the first to-be-reinforced item is an unfinished state, the fourth message sent by the server is received; the fourth message includes the updated reinforcement program and reinforcement configuration file of the first to-be-reinforced item; Based on the updated reinforcement program and reinforcement configuration file of the first to-be-reinforced item, the reinforcement operation is performed on the first to-be-reinforced item.

[0062] In actual application, referring to Figure 7 As shown in the figure, the first to-be-reinforced item can be understood as an item in the reinforcement item table that has not completed reinforcement. The server updates the reinforcement strategy corresponding to the first to-be-reinforced item to obtain the updated reinforcement program and reinforcement configuration file of the first to-be-reinforced item, and sends them to the client. The client performs reinforcement operation on the first to-be-reinforced item according to the updated reinforcement program and reinforcement configuration file. The server can also update the security reinforcement information library. The reinforcement configuration file can include multiple configuration file parameters. When a certain configuration file parameter displays an error, the configuration file parameter and the reinforcement program corresponding to the configuration file parameter can be updated, and the configuration file parameter and the reinforcement program corresponding to the configuration file parameter are sent to the client. The client updates the reinforcement configuration file according to the configuration file parameter and performs reinforcement.

[0063] In a cloud service scenario, Linux is generally used as the operating system of servers and virtual machines, and is usually managed in the form of a cluster. The server performs automatic operation and maintenance of the cluster system through the installation of a C / S architecture platform management software (such as Prometheus), monitors the security state and configuration, such as whether the system security configuration is appropriate, whether security reinforcement is needed, whether the system has known security vulnerabilities, the CPU and I / O usage, etc. In a realizable scenario, referring to Figure 8 As shown in the figure, a Linux operating system host cluster security reinforcement management method can be realized in the following way: Step 1, the security or operation administrator of cloud service provider compiles system security state detection code and reinforcement scripts and configuration files based on but not limited to vulnerability database, security operating system level protection standard, security reinforcement and intrusion detection guidebook, and stores them into security reinforcement information base.

[0064] Step 2, the server receives and responds to the security reinforcement request of the client cluster, and sends reinforcement state detection code to each host of the cluster.

[0065] Step 3, the communication between the server and the client uses remote connection security protocol SSH or VNC graphical protocol connection, which can also include other security protocols.

[0066] Step 4, after receiving the reinforcement detection code, the client first closes Security-Enhanced Linux (SELinux), then automatically runs the detection code to generate a current system-specific security state detection report and a to-be-reinforced item data table. The data table format can be fixed or can be a table or tuple, etc.

[0067] Step 5, the security state detection report will be backed up on the server for administrators to review and audit. After extracting the keywords from the to-be-reinforced item data table, it will be automatically input into the string fuzzy matching tool package together with the security reinforcement policy file for cross verification. It should be noted that the keyword matching algorithm is not limited to Levenshtein Distance, algorithm, but also includes Convolutional Deep Structured Semantic Model (CDSSM), Bilateral Multi-Perspective Matching (BIMPM) and other deep model algorithms.

[0068] Step 6, the matched security reinforcement policy file is mapped to obtain the implementation and configuration rules of the current specific to-be-reinforced item. The implementation can be a script file, including patch file, high version software package, Linux Security Modules (LSM) security framework and firewall configuration rules, etc.

[0069] Step 7, the client receives the implementation and configuration rules and starts one-key reinforcement. The system business is required to maintain smooth operation during the reinforcement process. The operation records generated during the entire reinforcement process are saved in a specific directory, such as the log file in / var.

[0070] Step 8, after reinforcement is completed, the server receives the log file for reinforcement risk audit, if all shows success, the whole process is ended, if some or several fail, the reinforcement strategy and security reinforcement information base content need to be updated in time, and then start from step 2 until the reinforcement task is completed.

[0071] Step 9, after the current batch of Linux host and virtual machine completes reinforcement, the upstream database and industry standard release need to be pulled in time, and the update iteration of the operating system also affects the security reinforcement baseline and content. Therefore, the security reinforcement information base needs to be updated in time according to these guidelines to better perform security protection, and the replacement cost of the system or information base is greatly reduced.

[0072] Based on the same inventive concept as the foregoing, Figure 9 A structural schematic diagram of a system reinforcement device provided by an embodiment of the present application is applied to a server, and the device comprises: The first receiving unit 901 is configured to receive a first message sent by a client; the first message comprises a reinforcement item table of an operating system of the client; the reinforcement item table is used to indicate at least one to-be-reinforced item; The first sending unit 902 is configured to send a second message to the client; the second message comprises a reinforcement configuration file and a reinforcement program corresponding to each to-be-reinforced item.

[0073] In some embodiments of the present application, the device further comprises a first processing unit configured to construct a security reinforcement information base of the operating system; the security reinforcement information base comprises security standard information of the operating system; generate a third message based on the security standard information; the third message is used to request the client to reinforce the operating system; The first sending unit 902 sends the third message to the client.

[0074] In some embodiments of the present application, the security reinforcement information base further comprises a reinforcement strategy base of the operating system; the first processing unit is configured to extract a keyword of each to-be-reinforced item based on the reinforcement item table; cross-verify the reinforcement strategy base and each to-be-reinforced item based on the keyword to obtain a reinforcement strategy corresponding to each to-be-reinforced item; the reinforcement strategy comprises the reinforcement program and the reinforcement configuration file.

[0075] In some embodiments of the present application, the first receiving unit 901 is configured to receive a fourth message sent by the client; the fourth message comprises reinforcement operation log information; the reinforcement operation log information is used to indicate a reinforcement state of each to-be-reinforced item; the reinforcement state comprises a completed state and an incomplete state.

[0076] In some embodiments of the present application, the first processing unit is configured to, if the reinforcement operation log information indicates that the reinforcement state of the first to-be-reinforced item is in an unfinished state, update the reinforcement program and the reinforcement configuration file corresponding to the first to-be-reinforced item to obtain the updated reinforcement program and the reinforcement configuration file of the first to-be-reinforced item; the first to-be-reinforced item is any to-be-reinforced item in the at least one to-be-reinforced item. The first sending unit 902 is configured to send the fifth message to the client; the fifth message includes the updated reinforcement program and the reinforcement configuration file of the first to-be-reinforced item.

[0077] Based on the same inventive concept as described above, Figure 10 A structural diagram of a system reinforcement device is provided for the embodiments of the present application, which is applied to a client, and the device includes: The second sending unit 1001 is configured to send the first message to the server; the first message includes the reinforcement item table of the operating system of the client; the reinforcement item table is used to indicate the at least one to-be-reinforced item. The second receiving unit 1002 is configured to receive the second message sent by the server; the second message includes the reinforcement configuration file and the reinforcement program corresponding to each to-be-reinforced item.

[0078] In some embodiments of the present application, the second receiving unit 1002 is configured to receive the third message sent by the server; the third message is used to request the client to reinforce the operating system.

[0079] In some embodiments of the present application, the device further includes a second processing unit configured to perform security detection on the operating system to obtain a detection result; the detection result includes the at least one to-be-reinforced item. The reinforcement item table is generated based on the detection result.

[0080] In some embodiments of the present application, the second processing unit is configured to perform reinforcement operation on each to-be-reinforced item based on the reinforcement program and the reinforcement configuration file, and generate reinforcement operation log information; the reinforcement operation log information is used to indicate the reinforcement state of each to-be-reinforced item; the reinforcement state includes a completed state and an unfinished state. The second sending unit 1001 is configured to send the fourth message to the server; the fourth message includes the reinforcement operation log information.

[0081] In some embodiments of the present application, the second processing unit is configured to, if the reinforcement operation log information indicates that the reinforcement state of the first to-be-reinforced item is in an unfinished state, receive the fourth message sent by the server; the fourth message includes the updated reinforcement program and the reinforcement configuration file of the first to-be-reinforced item. The reinforcement operation is performed on the first to-be-reinforced item based on the updated reinforcement program and the reinforcement configuration file of the first to-be-reinforced item.

[0082] Based on the hardware implementation of the above program module, and in order to implement the method of the server side of the embodiment of the application, the embodiment of the application further provides a server, as shown in the figure, the server 1100 includes: Figure 11 The first communication interface 1101 can interact with the client; The first processor 1102 is connected with the first communication interface 1101 to realize the information interaction with the client, and is used to run the computer program to execute the method provided by one or more technical solutions of the server side described above; the first memory 1103 stores the computer program.

[0083] Specifically, the first communication interface 1101 is configured to receive a first message sent by a client; the first message includes a hardened item table of an operating system of the client; the hardened item table is used to indicate at least one hardened item; The second message includes a hardened configuration file and a hardened program corresponding to each hardened item.

[0084] In some embodiments of the application, the first processor 1102 is configured to build a security hardening information base of the operating system; the security hardening information base includes security standard information of the operating system; Generate a third message based on the security standard information; the third message is used to request the client to harden the operating system; The first communication interface 1101 sends the third message to the client.

[0085] In some embodiments of the application, the security hardening information base further includes a hardened policy base of the operating system; the first processor 1102 is configured to extract a keyword of each hardened item based on the hardened item table; Cross verify the hardened policy base and each hardened item based on the keyword to obtain a hardened policy corresponding to each hardened item; the hardened policy includes a hardened program and a hardened configuration file.

[0086] In some embodiments of the application, the first communication interface 1101 is configured to receive a fourth message sent by the client; the fourth message includes hardened operation log information; the hardened operation log information is used to indicate the hardened state of each hardened item; the hardened state includes a completed state and an incomplete state.

[0087] ​In some embodiments of the present application, the first processor 1102 is configured to, if the reinforcement operation log information indicates that the reinforcement state of the first to-be-reinforced item is an unfinished state, update the reinforcement program and the reinforcement configuration file corresponding to the first to-be-reinforced item to obtain the updated reinforcement program and the reinforcement configuration file of the first to-be-reinforced item; and the first to-be-reinforced item is any to-be-reinforced item in the at least one to-be-reinforced item. The first communication interface 1101 is configured to send a fifth message to the client; and the fifth message includes the updated reinforcement program and the reinforcement configuration file of the first to-be-reinforced item.

[0088] Of course, in actual applications, various components in the server 1100 are coupled together through the bus system 1104. It can be understood that the bus system 1104 is used to realize the connection and communication between the components. In addition to including a data bus, the bus system 1104 also includes a power bus, a control bus, and a state signal bus. However, in order to clearly illustrate the application, all buses are marked as the bus system 1104 in the Figure 11

[0089] The method disclosed in the above embodiments of the present application can be applied to the first processor 1102 or implemented by the first processor 1102. The first processor 1102 can be an integrated circuit chip with signal processing capability. In the implementation process, each step of the above method can be completed by integrated logic circuits of hardware in the first processor 1102 or instructions in the form of software. The first processor 1102 can be a general-purpose processor, a digital signal processor (DSP), or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, etc. The first processor 1102 can implement or execute the disclosed methods, steps, and logic block diagrams in the embodiments of the present application. The general-purpose processor can be a microprocessor or any conventional processor. In combination with the steps of the method disclosed in the embodiments of the present application, the hardware decoding processor can be directly embodied to execute the above-mentioned steps, or the combination of hardware and software modules in the decoding processor can be executed. The software module can be located in a storage medium, and the storage medium is located in the first memory 1103. The first processor 1102 reads the information in the first memory 1103 and combines the hardware to complete the steps of the above-mentioned method.

[0090] ​In an example embodiment, the server 1100 can be implemented by one or more Application Specific Integrated Circuits (ASICs), DSPs, Programmable Logic Devices (PLDs), Complex Programmable Logic Devices (CPLDs), Field-Programmable Gate Arrays (FPGAs), general-purpose processors, controllers, microcontrollers (MCUs), microprocessors (Microprocessors), or other electronic elements for executing the foregoing methods.

[0091] Based on the hardware implementation of the foregoing program modules, and in order to implement the method on the client side of the embodiments of the present application, the embodiments of the present application further provide a client, as shown in the figure, the client 1200 includes: Figure 12 a second communication interface 1201 capable of information interaction with the server; a second processor 1202 connected with the second communication interface 1201 to realize information interaction with the server, for running a computer program, executing the method provided by one or more technical solutions on the client side described above; a second memory 1203, on which a computer program is stored.

[0092] Specifically, the second communication interface 1201 is configured to send a first message to the server; the first message includes a hardened entry table of the operating system of the client; the hardened entry table is configured to indicate at least one entry to be hardened; receive the second message sent by the server; the second message includes a hardened configuration file and a hardened program corresponding to each entry to be hardened.

[0093] In some embodiments of the present application, the second communication interface 1201 is configured to receive a third message sent by the server; the third message is configured to request the client to harden the operating system.

[0094] In some embodiments of the present application, the second processor 1202 is configured to perform security detection on the operating system to obtain a detection result; the detection result includes at least one entry to be hardened; generate a hardened entry table based on the detection result.

[0095] ​In some embodiments of the present application, the second processor 1202 is configured to perform the reinforcement operation on each to-be-reinforced item based on the reinforcement program and the reinforcement configuration file, and generate reinforcement operation log information; the reinforcement operation log information is used to indicate the reinforcement state of each to-be-reinforced item; the reinforcement state includes a completed state and an uncompleted state. The second communication interface 1201 is configured to send a fourth message to the server; the fourth message includes the reinforcement operation log information.

[0096] In some embodiments of the present application, the second processor 1202 is configured to receive the fourth message sent by the server if the reinforcement operation log information indicates that the reinforcement state of the first to-be-reinforced item is the uncompleted state; the fourth message includes the updated reinforcement program and the reinforcement configuration file of the first to-be-reinforced item. The reinforcement operation is performed on the first to-be-reinforced item based on the updated reinforcement program and the reinforcement configuration file of the first to-be-reinforced item.

[0097] Of course, in actual applications, various components in the client 1200 are coupled together through the bus system 1204. It can be understood that the bus system 1204 is used to realize the connection and communication between these components. The bus system 1204 includes not only a data bus, but also a power bus, a control bus, and a status signal bus. However, for the purpose of clear illustration, all kinds of buses are marked as the bus system 1204 in the Figure 12

[0098] The method disclosed in the above embodiments of the present application can be applied to the second processor 1202 or implemented by the second processor 1202. The second processor 1202 can be an integrated circuit chip with signal processing capability. In the implementation process, each step of the above method can be completed by the integrated logic circuit of hardware or the instruction in the form of software in the second processor 1202. The second processor 1202 can be a general-purpose processor, a DSP, or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, etc. The second processor 1202 can implement or execute the disclosed methods, steps, and logic block diagrams in the embodiments of the present application. The general-purpose processor can be a microprocessor or any conventional processor, etc. In combination with the steps of the method disclosed in the embodiments of the present application, the hardware decoding processor can be directly embodied to execute the completion, or the combination of hardware and software modules in the decoding processor can be executed to complete. The software module can be located in the storage medium, and the storage medium is located in the second memory 1203. The second processor 1202 reads the information in the second memory 1203, and combines the hardware to complete the steps of the above method.

[0099] ​In an exemplary embodiment, the client 1200 can be implemented with one or more ASICs, DSPs, PLDs, CPLDs, FPGAs, general purpose processors, controllers, MCUs, Microprocessors, or other electronic elements for performing the aforementioned methods.

[0100] It can be understood that the memory (the first memory 1103 and the second memory 1203) of the embodiments of the present application can be a volatile memory or a non-volatile memory, and can also include both volatile and non-volatile memories. The non-volatile memory can be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), a ferromagnetic random access memory (FRAM), a flash memory, a magnetic surface memory, an optical disc, or a compact disc read-only memory (CD-ROM). The magnetic surface memory can be a disk memory or a tape memory. The volatile memory can be a random access memory (RAM) used as an external cache. By way of example but not limitation, many forms of RAM can be used, such as static random access memory (SRAM), synchronous static random access memory (SSRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), sync link dynamic random access memory (SLDRAM), and direct rambus random access memory (DRRAM).The memory described in the embodiments of the present application is intended to include, but not limited to, these and any other suitable types of memory.

[0101] Based on the foregoing embodiments, the embodiments of the present application provide a storage medium, which stores computer executable instructions configured to perform the following steps when executed by a processor Figure 2 or Figure 6 The corresponding embodiments provide a system reinforcement method.

[0102] Based on the foregoing embodiments, the embodiments of the present application also provide a computer program product, which comprises a computer program, and the computer program is executed by a processor to implement the following steps Figure 2 or Figure 6 The steps in the system reinforcement method provided by the corresponding embodiments.

[0103] It should be noted that the computer storage medium described above can be a ROM, a PROM, an EPROM, an EEPROM, an FRAM, a Flash Memory, a magnetic surface memory, an optical disc, or a CD-ROM memory; or can be various electronic devices including one or any combination of the above memories, such as a mobile phone, a computer, a tablet device, a personal digital assistant, etc.

[0104] It should be noted that in this document, the term "comprise", "include" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device that includes a series of elements not only includes those elements, but also includes other elements not explicitly listed, or further includes elements inherent to such a process, method, article or device. Without more limitations, the element defined by the statement "comprises a" does not exclude the presence of additional identical elements in the process, method, article or device that includes the element.

[0105] The serial numbers of the embodiments of the present application described above are only for description, and do not represent the advantages and disadvantages of the embodiments.

[0106] Through the description of the above embodiments, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be realized by means of software and necessary general hardware platforms, of course, they can also be realized by hardware, but in many cases the former is a better embodiment. Based on such understanding, the technical solutions of the present application can be embodied in the form of a software product, which is stored in a storage medium (such as a ROM / RAM, a magnetic disc, an optical disc), and includes a plurality of instructions for causing a first client (which can be a mobile phone, a computer, a server, an air conditioner, or a client, etc.) to execute the methods described in various embodiments of the present application.

[0107] The computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart block or blocks. Figure 1 one or more flow or blocks. Figure 1 one or more flow or blocks.

[0108] These computer program instructions can also be stored in a computer readable memory that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer readable memory produce an article of manufacture including instructions which implement the function specified in the flowchart block or blocks. Figure 1 one or more flow or blocks. Figure 1 one or more flow or blocks.

[0109] The computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart block or blocks. Figure 1 one or more flow or blocks. Figure 1 one or more flow or blocks.

[0110] The above merely provides the preferred embodiment of the present application, and is not intended to limit the patent scope of the present application, and any equivalent structure or equivalent flow transformation made by using the content of the present application specification and drawings, or directly or indirectly applied in other related technical fields, are also included in the patent protection scope of the present application.

Claims

1. A system hardening method, characterized in that, Applied to the server side, the method includes: The system receives a first message sent by a client; the first message includes a hardening entry table of the client's operating system; the hardening entry table is used to indicate at least one entry to be hardened. A second message is sent to the client; the second message includes the hardening configuration file and hardening program corresponding to each of the items to be hardened.

2. The method according to claim 1, characterized in that, Before receiving the first message sent by the client, the following is included: Construct a security hardening information database for the operating system; the security hardening information database includes security standard information for the operating system; A third message is generated based on the security standard information; the third message is used to request the client to harden the operating system. The third message is sent to the client.

3. The method according to claim 2, characterized in that, The security hardening information database also includes the operating system's hardening policy database; after receiving the first message sent by the client, the process includes: Extract keywords for each item to be reinforced from the reinforcement item list; Based on the keywords, the reinforcement strategy library is cross-validated with each item to be reinforced to obtain the reinforcement strategy corresponding to each item to be reinforced; the reinforcement strategy includes the reinforcement program and the reinforcement configuration file.

4. The method according to claim 1, characterized in that, After sending the second message to the client, the process includes: The system receives a fourth message sent by the client; the fourth message includes reinforcement operation log information; the reinforcement operation log information is used to indicate the reinforcement status of each item to be reinforced; the reinforcement status includes a completed status and an incomplete status.

5. The method according to claim 4, characterized in that, After receiving the fourth message sent by the client, the process includes: If the reinforcement operation log information indicates that the reinforcement status of the first item to be reinforced is incomplete, update the reinforcement program and reinforcement configuration file corresponding to the first item to be reinforced to obtain the updated reinforcement program and reinforcement configuration file of the first item to be reinforced; the first item to be reinforced is any one of at least one item to be reinforced. A fifth message is sent to the client; the fifth message includes the updated hardening program and hardening configuration file for the first entry to be hardened.

6. A system hardening method, characterized in that, Applied to a client, the method includes: Send a first message to the server; the first message includes a hardening entry table of the client's operating system; the hardening entry table is used to indicate at least one entry to be hardened; The server receives a second message; the second message includes a hardening configuration file and a hardening program corresponding to each item to be hardened.

7. The method according to claim 6, characterized in that, Before sending the first message to the server, the following steps are included: The client receives a third message sent by the server; the third message is used to request the client to harden the operating system.

8. The method according to claim 7, characterized in that, After receiving the third message sent by the server, the process includes: A security test is performed on the operating system to obtain a test result; the test result includes at least one of the items to be hardened. The reinforcement item list is generated based on the detection results.

9. The method according to claim 6, characterized in that, After receiving the second message sent by the server, the process includes: Based on the reinforcement program and the reinforcement configuration file, a reinforcement operation is performed on each of the items to be reinforced, and reinforcement operation log information is generated; the reinforcement operation log information is used to indicate the reinforcement status of each of the items to be reinforced; the reinforcement status includes a completed status and an incomplete status; A fourth message is sent to the server; the fourth message includes the hardening operation log information.

10. The method according to claim 9, characterized in that, After sending the fourth message to the server, the process includes: If the reinforcement operation log information indicates that the reinforcement status of the first item to be reinforced is incomplete, a fourth message sent by the server is received; the fourth message includes the updated reinforcement program and reinforcement configuration file of the first item to be reinforced. The reinforcement operation is performed on the first item to be reinforced based on the updated reinforcement program and reinforcement configuration file.

11. A system ruggedization device, characterized in that, Applied to the server side, the device includes: A first receiving unit is configured to receive a first message sent by a client; the first message includes a hardening entry table of the client's operating system; the hardening entry table is used to indicate at least one entry to be hardened; The first sending unit is used to send a second message to the client; the second message includes a reinforcement configuration file and a reinforcement program corresponding to each of the items to be reinforced.

12. A system ruggedization device, characterized in that, Applied to a client, the device includes: The second sending unit is used to send a first message to the server; the first message includes a hardening entry table of the client's operating system; the hardening entry table is used to indicate at least one entry to be hardened; The second receiving unit is used to receive a second message sent by the server; the second message includes a hardening configuration file and a hardening program corresponding to each item to be hardened.

13. A server, comprising a first communication interface and a first processor; wherein, The first communication interface is used to receive a first message sent by the client; the first message includes a hardening entry table of the client's operating system; the hardening entry table is used to indicate at least one entry to be hardened; A second message is sent to the client; the second message includes the hardening configuration file and hardening program corresponding to each of the items to be hardened.

14. A client, comprising a second communication interface and a second processor; wherein, The second communication interface is used to send a first message to the server; the first message includes a hardening entry table of the client's operating system; the hardening entry table is used to indicate at least one entry to be hardened; The server receives a second message; the second message includes a hardening configuration file and a hardening program corresponding to each item to be hardened.

15. A storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 5 or 6 to 10.

16. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 5 or 6 to 10.

Citation Information

Patent Citations

  • Method and device for reinforcing operating system

    CN104732149A

  • Security vulnerability reinforcing method and system

    CN106033512A

  • Software safety reinforcing method and device

    CN107423587A

  • Concentrated safety configuration patrolling and reinforcing method

    CN107835094A

  • VNF reinforcement method, related equipment and computer readable storage medium

    CN109150557A