Host weak password processing method and system, storage medium and program product

By combining a sharding weight algorithm and a dynamic weak password rule base with a tiered repair strategy, the problem of low efficiency in weak password detection and repair in massive host environments is solved, achieving efficient and secure weak password processing and improving network security.

CN120915518APending Publication Date: 2025-11-07CHINA YANGTZE POWER +2
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511070861.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-31
Publication Date
2025-11-07

AI Technical Summary

Technical Problem

In a massive host environment, existing technologies that rely on tools or manual methods to identify weak passwords are time-consuming, labor-intensive, inefficient, and prone to oversights. Furthermore, they fail to create an effective security loop, resulting in unsatisfactory weak password remediation outcomes.

Method used

The host account information set is fragmented using a fragmentation weighting algorithm. Combined with host asset and cracking server configuration data, distributed cracking is performed using a JTR cracking cluster. Combined with a dynamic weak password rule base and a hierarchical repair strategy, centralized offline cracking and automated repair are achieved.

Benefits of technology

It improved cracking efficiency, reduced false negatives, ensured the normal operation of the host, reduced security risks, formed a complete security closed loop, and improved the level of network security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120915518A_ABST
    Figure CN120915518A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of information security, and discloses a host weak password processing method and system, a storage medium and a program product. A server receives host account information through a fragmentation control engine, combines preset host asset information and JTR to crack cluster configuration, carries out fragmentation processing by using a fragmentation weight algorithm, and obtains a weak password of a host; and finally, the server control module determines a hierarchical repair strategy for repair based on the preset host asset information, so that centralized off-line distributed cracking of the server is realized, host resources are prevented from being occupied, and the cracking cannot be intercepted by a host firewall and the like. The dynamic fragmentation improves the cracking efficiency in a massive host environment; the hierarchical repair strategy avoids service interruption caused by one-time cutting, prevents safety operation personnel from being submerged by massive alarms, guarantees normal operation of a host, and improves the network safety level.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of information security technology, and in particular to a host weak password processing method and system, a storage medium and a program product. BACKGROUND

[0002] In the field of information security, weak password is one of the most common and high-risk vulnerabilities in network security, and is also the most easy and effective attack method. For example, attackers can easily obtain user accounts and steal sensitive information through brute force cracking (such as dictionary attack, exhaustive attack). According to user habit statistics, 76% of users use the same password on different platforms, and only 18% of users change their passwords regularly, and only 65% of users change their passwords after being asked. If weak passwords are not corrected in time, they are vulnerable to brute force cracking and social engineering attacks. Light server control causes data leakage, and heavy damage to security. At present, there are many ways to correct weak passwords, some of which prevent the generation of weak passwords from the source, and some of which scan weak passwords on hosts through security scanning tools. In a large number of host environments, it is time-consuming and laborious to manually check weak passwords on hosts, and the efficiency is low, and it is easy to miss. At present, the effect of enterprise weak password correction is not ideal. SUMMARY

[0003] Therefore, the present application provides a host weak password processing method and system, a storage medium and a program product to solve the problem of time-consuming and laborious manual checking of weak passwords on hosts in a large number of host environments, low efficiency and easy to miss.

[0004] In a first aspect, the present application provides a host weak password processing method for a server, the server being connected to a host, the server including a sharding control engine, a plurality of JTR cracking clusters and a server control module; the method comprising:

[0005] When the sharding control engine receives the first host account information set of the host, the preset host asset information set and the cracking server configuration data set of the plurality of JTR cracking clusters are obtained; based on the preset host asset information set and the cracking server configuration data set, the first host account information set is processed by using a sharding weight algorithm to obtain a plurality of second host account information sets; the plurality of second host account information sets are distributed to the plurality of JTR cracking clusters; when the plurality of JTR cracking clusters receives the cracking task sent by the sharding control engine, based on the cracking task, the weak password in the plurality of second host account information sets is cracked by using a preset dynamic weak password rule library to obtain a plurality of target weak passwords; when the server control module receives the plurality of target weak passwords, the hierarchical repair strategy is determined by using the preset host asset information set; the plurality of target weak passwords are repaired by using the hierarchical repair strategy to make the host run normally.

[0006] The host weak password processing method provided by the application can make the load of each JTR cracking cluster more balanced compared with the traditional equal fragmentation, avoids the problems of excessive tasks of part of nodes and idle resources of nodes, thereby improving the overall cracking efficiency, and can also adapt to the large-scale cracking demand under the environment of massive hosts. Further, the account information set after fragmentation is distributed to multiple JTR cracking clusters, so that the computing resources of multiple cracking clusters can be fully utilized to perform cracking work at the same time, compared with single machine cracking, the cracking time is greatly shortened, the cracking efficiency is improved, and the requirement of rapid cracking of a large number of weak passwords under the environment of massive hosts is met. Further, the JTR cracking cluster cracks according to the preset dynamic weak password rule library, can effectively identify more weak passwords, and reduce false negatives. Further, the server control module determines a hierarchical repair strategy in combination with the preset host asset information and performs repair processing on multiple target weak passwords, which can not only process weak password risks in time to reduce security risks, but also ensure the continuity of business, and finally realizes the purpose of guaranteeing the normal operation of hosts and improving the network security level. Therefore, by implementing the application, the server centralized offline distributed cracking is realized, the host resources are avoided, and the host firewall and the like are not intercepted; the dynamic fragmentation improves the cracking efficiency under the environment of massive hosts; and the hierarchical repair strategy avoids the business interruption caused by one-size-fits-all, prevents security operation personnel from being overwhelmed by massive alarms, guarantees the normal operation of hosts, and improves the network security level.

[0007] In an optional implementation, based on the preset host asset information set and the cracking server configuration data set, the first host account information set is processed by using the fragmentation weight algorithm to obtain a plurality of second host account information sets, including:

[0008] Based on the preset host asset information set and the cracking server configuration data set, the fragmentation size is obtained by processing through the fragmentation weight algorithm; and the first host account information set is dynamically fragmented by using the fragmentation size to obtain a plurality of second host account information sets.

[0009] When the first host account information set is dynamically fragmented by using the fragmentation weight algorithm, the host asset and the cracking server configuration data are comprehensively considered, the fragmentation can be dynamically adjusted according to the actual situation of the host and the cracking server, the load of each cracking node is balanced, the cracking efficiency is greatly improved, and the large-scale cracking demand under the environment of massive hosts can also be adapted.

[0010] In an optional implementation, the server further includes a data receiving module, and the host is integrated with a host agent program; the method further includes:

[0011] The third host account information set of the host collected by the host agent program is received by using the data receiving module; the third host account information set is decrypted and parsed to obtain the first host account information set; and the first host account information set is sent to the shard control engine.

[0012] The host weak password processing method provided by the application reduces the data volume and transmission bottleneck by collecting the third host account information set of the host through the host agent program. Further, the third host account information set after encryption is transmitted to the data receiving module to prevent data information leakage. Further, the third host account information set is decrypted and parsed to ensure the smooth progress of the subsequent fragmentation and cracking process, and to provide a high-quality data basis for efficient cracking.

[0013] In an optional embodiment, the method further comprises:

[0014] Obtaining a target password data set and a preset password rule library, the target password data set including a plurality of weak passwords and a plurality of non-weak passwords; performing word segmentation cutting on the target password data set by using an algorithm based on a statistical language model to obtain a plurality of first character sequences; based on the plurality of first character sequences and the preset password rule library, constructing an initial dynamic weak password rule library by using a dynamic threshold and a threat intelligence injection method; based on the initial dynamic weak password rule library, returning to the step of performing word segmentation cutting by using the algorithm based on the statistical language model, and iteratively repeating until a preset dynamic weak password rule library is obtained.

[0015] The host weak password processing method provided by the application solves the problem of missing low-frequency high-risk passwords by combining a dynamic threshold when constructing a preset dynamic weak password rule library from a multi-source target password data set. At the same time, by combining a threat intelligence injection method, the anti-0day leakage capability is improved. Further, through repeated iteration, the preset dynamic weak password rule library can be continuously effective, significantly reducing the weak password false negative rate and improving the accuracy of weak password identification.

[0016] In an optional embodiment, based on the plurality of first character sequences and the preset password rule library, the initial dynamic weak password rule library is constructed by using a dynamic threshold and a threat intelligence injection method, comprising:

[0017] The probability statistics and feature extraction are performed on the plurality of first character sequences, a plurality of probability values and a plurality of feature information sets of the plurality of first character sequences appearing in the target password data set are obtained, a plurality of target thresholds are obtained by dynamically adjusting a plurality of preset thresholds according to the plurality of probability values, the plurality of feature information sets and a preset threat level, the plurality of first character sequences are filtered and adjusted by using the plurality of target thresholds, a plurality of second character sequences are obtained, the plurality of second character sequences are combined by using a preset password rule library, a plurality of target character sequences are obtained, the plurality of target character sequences are combined by using the plurality of probability values, a plurality of initial dynamic weak passwords are obtained, the plurality of initial dynamic weak passwords are processed by using a hierarchical encryption mode, and a plurality of target dynamic weak passwords are obtained, and an initial dynamic weak password password rule library is generated according to the plurality of target dynamic weak passwords and real-time threat intelligence.

[0018] The host weak password processing method provided by the application can make the analysis of character sequences more accurate by performing probability statistics and feature extraction on a plurality of first character sequences, and avoid weak password missed reports caused by insufficient feature extraction. Further, by dynamically adjusting the threshold, the problem of missing low-frequency high-risk passwords is solved, and the sensitivity of the password library to new threats is improved. Further, by dynamically adjusting the target threshold, character sequences that do not meet the weak password features are filtered out, reducing the redundancy of the password library and improving the accuracy of subsequent cracking and reducing the false positive rate. Further, the filtered character sequences are combined and expanded in combination with the preset rules, which enriches the weak password samples and can cover more potential weak password forms, solving the missed report problem caused by the single traditional rule. Further, based on the probability of the appearance of the character sequence, the plurality of target character sequences are combined to ensure that the weak passwords recorded in the password library have actual attack value and improve the cracking efficiency. Further, hierarchical encryption is adopted to prevent the leakage of sensitive information of the password library itself, which meets the data security specification and solves the security problem of the password library storage. Further, by injecting real-time threat intelligence, the password library can quickly respond to new weak password threats, improve the anti-0day leakage capability, ensure the timeliness and comprehensiveness of the rule library, and provide strong dictionary support for subsequent weak password detection.

[0019] In an optional implementation, the method further comprises:

[0020] When the real-time host account information set of the host is received, the hash values of the plurality of target weak passwords are verified by using the server control module; when the hash values of the plurality of target weak passwords are not changed, the disposal level of the plurality of target weak passwords is upgraded, and a control instruction is sent to the host to make the host perform password modification or account locking operation based on the control instruction; when the hash values of the plurality of target weak passwords are changed, the steps of obtaining the preset host asset information set and the cracking server configuration data set of the plurality of JTR cracking clusters are returned based on the real-time host account information set, and the iteration is repeated until the host normally operates.

[0021] The host weak password processing method provided by the application realizes closed loop verification of weak password repair effect by checking hash values of multiple target weak passwords, and ensures that the weak password is effectively rectified.

[0022] In an alternative embodiment, the server further comprises a notification module; the method further comprises: sending alarm information by using the notification module according to the hierarchical repair strategy.

[0023] The host weak password processing method provided by the application sends alarm information by using the hierarchical repair strategy, ensures that the relevant person in charge can receive alarm information of the corresponding level in time, improves the timeliness and effectiveness of weak password rectification, and avoids the expansion of security risks caused by inadequate notification.

[0024] In a second aspect, the application provides a host weak password processing system, which comprises a host and a server, the host is integrated with a host agent program, and the server comprises a data receiving module, a fragmentation control engine, a plurality of JTR cracking clusters, a server control module and a notification module.

[0025] The host is configured to obtain a first host account information set by using the host agent program, encrypt the first host account information set to obtain a third host account information set, and send the third host account information set to the data receiving module; and the server is configured to execute the host weak password processing method of the first aspect or any of the corresponding embodiments thereof.

[0026] The host weak password processing system provided by the application integrates the functions of the host and the server, solves the problem of dispersion and poor cooperation of components in the prior art, and cannot form a complete and efficient weak password processing system, realizes automatic detection, repair and verification of weak passwords, effectively reduces the risk of weak password attacks, ensures normal operation of the host, and improves the level of network security.

[0027] In a third aspect, the application provides a computer readable storage medium, which stores computer instructions, and the computer instructions are used to make a computer execute the host weak password processing method of the first aspect or any of the corresponding embodiments thereof.

[0028] In a fourth aspect, the application provides a computer program product comprising computer instructions, and the computer instructions are used to make a computer execute the host weak password processing method of the first aspect or any of the corresponding embodiments thereof. BRIEF DESCRIPTION OF DRAWINGS

[0029] In order to more clearly illustrate the specific embodiments of the present application or the technical solutions in the prior art, the following will briefly introduce the drawings needed to be used in the specific embodiments or prior art description. Obviously, the drawings described below are some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor.

[0030] Figure 1 is a structural block diagram of a host weak password processing system according to an embodiment of the present application;

[0031] Figure 2 is a flowchart of a host weak password processing method according to an embodiment of the present application;

[0032] Figure 3 is a construction flowchart of a weak password password library according to an embodiment of the present application;

[0033] Figure 4 is a massive weak password closed loop processing device architecture diagram according to an embodiment of the present application;

[0034] Figure 5 is a massive weak password closed loop processing device flowchart according to an embodiment of the present application;

[0035] Figure 6 is a hardware structure schematic diagram of a computer device of an embodiment of the present application. DETAILED DESCRIPTION

[0036] In order to make the purpose, technical scheme and advantages of the embodiments of the present application more clear, the technical scheme in the embodiments of the present application will be described clearly and completely below in combination with the drawings in the embodiments of the present application. Obviously, the described embodiments are some of the embodiments of the present application, not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor are within the scope of protection of the present application.

[0037] At present, the detection, repair and verification of massive host layer weak passwords have not formed an effective security closed loop, and the following problems exist:

[0038] (1) Single dimension prevention: the user inputs the account password, and the server blocks the user login according to the weak password identification strategy specified by the system administrator. This scenario is powerless to the existing weak password.

[0039] (2) Remote cracking is easy to be blocked: some security scanning tools, such as Hydra, Ncrack, Openvas, Nessus, can crack the server password online, but the problem is that network layer brute force cracking is easy to be found and intercepted by host firewall and host protection software, resulting in failure to identify weak password.

[0040] (3)Local cracking, affecting the server's own business; if some security scanning tools are installed on the cracked host, local password cracking is performed, and more problems are brought:

[0041] a) Cracking is a computationally intensive task that occupies server CPU resources and has a huge impact on the server's own business.

[0042] b) It is difficult to issue a weak password policy for a large number of server resources.

[0043] c) Different operating systems require maintenance of different versions of cracking software.

[0044] (4) Low detection efficiency: when the host scale is greater than 10,000, the cracking time increases exponentially, and the detection of a large number of hosts is not recognized.

[0045] (5) Lack of closed-loop repair: only weak passwords are detected, but the weak passwords are not verified, and there is no effective forced rectification control measure, and the weak password recurrence rate is high.

[0046] (6) Mass alarm: hosts are not classified and graded, and in a large number of host environments, a large number of alarms can easily submerge the real high-risk hosts. Since the assets are not classified and graded, a one-size-fits-all solution can easily cause core business interruption.

[0047] (7) Business interruption risk: for the detected weak password, if the account is locked, it may cause core service paralysis.

[0048] According to the embodiment of the application, a host weak password processing method embodiment is provided. It should be noted that the steps shown in the flowchart of the drawing can be executed in a computer system such as a group of computer executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.

[0049] In this embodiment, a host weak password processing method is provided, which can be used in a server 12 as shown in Figure 1 The server 12 is connected with the host 11. Further, the server 12 includes a sharding control engine 122, a plurality of JTR cracking clusters 123 and a server control module 124.

[0050] Figure 2 is a flowchart of the host weak password processing method according to the embodiment of the application, as shown in Figure 2 The flowchart includes the following steps:

[0051] Step S201, when the first host account information set of the host is received by the fragmentation control engine, the preset host asset information set and the cracking server configuration data set of the plurality of JTR cracking clusters are acquired.

[0052] Wherein, the fragmentation control engine represents a kind of core component for realizing distributed cracking task balanced distribution of server.

[0053] Further, the preset host asset information set represents the host asset related information set stored in configuration management database (CMDB, a central storage for storing the information about IT assets, configuration items and their mutual relations) in advance, mainly used for classifying host, can include the asset level (high risk / medium risk / low risk) of host, the business type (such as database server, application server, test machine) to which it belongs, risk coefficient (high-risk host K=1.5, low-risk host K=0.8) etc.

[0054] Further, the first host account information set represents the collection of host account information (such as linux server's / etc / passwd and / etc / shadow account information).

[0055] Further, JTR cracking cluster represents the distributed cracking cluster based on open source cracking tool John the Ripper (JTR), which is composed of multiple computing nodes, responsible for weak password cracking of fragmented host account information, supports dictionary attack (based on pre-set or custom dictionary matching password), brute force cracking (exhaust all possible character combinations, suitable for complex password), rule attack (expanding dictionary possibilities through custom rules) and other cracking modes, for realizing centralized offline cracking on server, avoiding the problem of occupying resources or being intercepted by firewall in local cracking of host, while improving the cracking efficiency of mass host weak password through distributed deployment.

[0056] Further, the cracking server configuration data set represents the hardware performance and state information set of each computing node in JTR cracking cluster, which can include CPU core number, memory capacity, network delay (communication delay with target host), current load state of each node.

[0057] Specifically, when the first host account information set of host 11 is received by fragmentation control engine 122, the preset host asset information can be acquired by querying configuration management database (CMDB), and the corresponding preset host asset information set is formed.

[0058] Further, the fragmentation control engine 122 can monitor and collect the hardware and performance information of the plurality of JTR cracking clusters 123 in real time, and form the corresponding cracking server configuration data set.

[0059] Step S202, based on the preset host asset information set and the cracking server configuration data set, the first host account information set is processed by using the sharding weight algorithm to obtain a plurality of second host account information sets.

[0060] The sharding weight algorithm represents an algorithm for realizing efficient sharding of a mass host account information set. The core is to dynamically calculate the sharding size by combining the host asset risk level and the hardware performance index of the JTR cracking cluster, and realize the balanced distribution of the cracking task among the distributed nodes.

[0061] Specifically, the preset host asset information set determines the priority weight of the cracking task (such as the higher risk coefficient of the high-risk host), and the cracking server configuration data set (such as the number of CPU cores, memory, network delay) reflects the processing capacity of each JTR cracking node.

[0062] Therefore, when the first host account information set to be cracked is disassembled into a plurality of allocable second host account information sets by using the sharding weight algorithm, by comprehensively considering the preset host asset information set and the cracking server configuration data set, it can be ensured that the sharding result matches the performance of the cracking node, and the cracking demand of the high-risk host is preferentially met, avoiding the node load imbalance problem caused by traditional equal sharding, realizing the balanced distribution of the cracking task among the plurality of JTR cracking clusters 123, and improving the overall efficiency of the weak password cracking in the mass host environment.

[0063] Step S203, the plurality of second host account information sets are distributed to the plurality of JTR cracking clusters.

[0064] Specifically, the sharding control engine 122 can divide the plurality of second host account information sets into different Kafka Topics (such as dividing 100,000 hosts into 100 Topics according to the network segment), and each Topic corresponds to one or more JTR cracking clusters 123. Wherein, the Kafka Topic represents a logical container for classifying and storing messages in the Kafka distributed message queue.

[0065] For example, the Topic of the high-risk host network segment is distributed to a cluster composed of 20 high-performance cracking nodes, and the Topic of the low-risk host network segment is distributed to a cluster composed of 10 regular-performance cracking nodes, ensuring that the task distribution matches the processing capacity of the cluster.

[0066] In some optional real-time manners, the sharding control engine 122 can also formulate an allocation rule based on the obtained multiple second host account information sets in combination with the load status (such as the current number of idle nodes, the amount of tasks being processed) of each JTR cracking cluster. For example, the second host account information set with a larger sharding size is allocated to a JTR cracking cluster with a larger number of CPU cores, sufficient memory, and low network delay, and high-risk hosts (risk coefficient k = 1.5) are preferentially allocated to a cluster with better performance.

[0067] Further, while allocating the second host account information set, the sharding control engine 122 can also synchronize metadata corresponding to the host asset level (such as high-risk / medium-risk / low-risk), cracking priority, and the like to the corresponding JTR cracking cluster, so as to facilitate the JTR cracking cluster to adjust the cracking strategy (such as starting a priority queue for the sharding task of a high-risk host, and preferentially performing a dictionary attack and a rule attack) according to the metadata.

[0068] Step S204, when the multiple JTR cracking clusters receive the cracking task sent by the sharding control engine, the multiple second host account information sets are cracked by using a preset dynamic weak password rule library based on the cracking task, and multiple target weak passwords are obtained.

[0069] In the preset dynamic weak password rule library, the weak password is a password with poor security protection capability due to low complexity, strong regularity, and easy guess or cracking.

[0070] Specifically, the multiple JTR cracking clusters 123 can receive the cracking task allocated by the sharding control engine 122 through a Kafka message queue.

[0071] Further, after receiving the cracking task issued by the sharding control engine 122, the JTR cracking cluster 123 can first initialize the cracking task, such as loading a preset dynamic weak password rule library (containing a weak password sequence generated based on an N-gram algorithm, and threat intelligence passwords injected in real time) matched with the sharding, and enabling a corresponding cracking mode (such as preferentially enabling a dictionary attack + rule attack for a high-risk host, and enabling only a dictionary attack for a low-risk host) according to the host asset level (high-risk / medium-risk / low-risk).

[0072] Further, the JTR cracking cluster 123 can call a self-cracking module (such as a core cracking engine of John the Ripper), and match and verify the encrypted password hash (such as a shadow file hash of a Linux system) in the second host account information set with the weak password in the preset dynamic weak password rule library.

[0073] Further, for different encryption algorithms (such as MD5, SHA-256), different cracking algorithms can be called: for simple hash types, dictionary attack is preferred (matching high-frequency weak passwords in the rule library, such as “123456” “admin@123”); for complex hash types, rule attack is combined (expanding the dictionary based on the character sequence rules generated by the N-gram algorithm, such as “name pronunciation + birthday” combination); if necessary, brute force cracking is started (exhaustive character combination, for low-frequency but high-risk weak passwords).

[0074] Further, during the cracking process, the JTR cracking cluster 123 can record the matching successful passwords in real time, and combine the threat level tags (such as “dark web leaked password” “recently high-frequency attack password”) of the preset dynamic weak password rule library to perform secondary screening on the matching results, eliminate false positives (such as false matches caused by hash collision), and finally determine multiple target weak passwords, that is, the account information confirmed as weak passwords can include account name, corresponding host IP, risk level, etc.

[0075] Step S205, when the server control module receives multiple target weak passwords, determines a hierarchical repair strategy using a preset host asset information set.

[0076] Specifically, after the multiple JTR cracking clusters 123 complete cracking, the cracking results containing the target weak passwords can be fed back to the server control module 124 after being encrypted (such as by using the national standard SM4 encryption).

[0077] Further, when the server control module 124 receives the target weak password data (including account name, corresponding host IP, encrypted password hash, risk level tag, etc.) fed back by the multiple JTR cracking clusters 123, the corresponding host unique identifier, associated asset ID, and other key information can be extracted.

[0078] Further, the server control module 124 can query the preset host asset information set in the configuration management database (CMDB) through the host unique identifier or asset ID to obtain the asset level (high risk / medium risk / low risk) of the corresponding host, the business type (such as database server, application server, test machine) to which the host belongs, the contact information of the asset person in charge, and other information.

[0079] Further, based on the host asset level, the corresponding repair rule is matched from the preset strategy library:

[0080] (1) If the host 11 is a high-risk asset (such as a core asset such as a database), the strategy of “locking the account immediately and notifying the asset person in charge” is matched;

[0081] (2) If the host 11 is a medium-risk asset (such as an application server), the strategy of “forcing the user to modify the password next time they log in” is matched;

[0082] (3) If the host 11 is a low-risk asset (such as a test environment host), match the "only generate alarm record" policy.

[0083] Further, for the matched repair rule, the server control module 124 can also generate specific execution parameters, including:

[0084] (1) High-risk assets: Lock account instruction code (such as usermod -L <user>), the contact information of the asset owner (Enterprise WeChat ID, mobile phone number);

[0085] (2) Medium-risk assets: Trigger conditions for forced password change (such as "prompt password change window next time you log in"), notification channels (email address, OA work order number);

[0086] (3) Low-risk assets: Storage path of alarm records, associated log numbers, etc.

[0087] Further, the server control module 124 can integrate the matched repair strategy and execution parameters into an executable hierarchical repair strategy scheme.

[0088] Step S206, using the hierarchical repair strategy to repair the multiple target weak passwords to make the host run normally.

[0089] Specifically, the server control module 124 can parse the hierarchical repair strategy and generate corresponding execution instructions according to the host asset level:

[0090] (1) For high-risk assets (such as database servers): Generate account lock instructions (such as usermod -L <user>), and the contact information (Enterprise WeChat ID, mobile phone number) of the asset owner is extracted, and the alarm information content is prepared (such as "[urgent] Weak password exists in host xxx (database), account has been locked, please handle immediately").

[0091] (2) For medium-risk assets (such as application servers): generate a forced password change trigger instruction (such as configure the PAM module to force jump to the password change interface next time login), and associate the asset owner's email address and OA work order system interface.

[0092] (3) For low-risk assets (such as test machines): generate an alarm record instruction, and write weak password information (host IP, account name, detection time) to the local log system (such as ELK log library), no additional operation instruction is required.

[0093] Further, the server control module 124 can issue the generated execution instructions to the corresponding host 11, and make different hosts 11 execute corresponding repair operations:

[0094] (1) High-risk host: after receiving the account lock instruction, immediately execute the account lock operation to prohibit the account from logging in; at the same time, the server notification module 124 can also send alarm information to the asset owner through WeChat and SMS, to ensure that the owner is aware in real time.

[0095] (2) Medium-risk host: after receiving the forced password change instruction, configure system parameters to make the target account complete password modification next time login (otherwise it cannot log in); the server notification module 124 can also send a password change reminder through email, and generate a work order in the OA system to track the password change progress.

[0096] (3) Low-risk host: after receiving the alarm record instruction, only write weak password information to the local log, without other execution operations, without disturbing the running of the test environment.

[0097] In some optional embodiments, when the server control module 124 issues the generated execution instructions to the corresponding host 11, the generated instructions can be encrypted by the SM4 encryption algorithm to avoid tampering or leakage during transmission. Further, the encrypted instructions are issued to the target host through the exclusive communication channel between the host 11 and the server control module 124, to ensure that the instructions are only received and executed by the corresponding host.

[0098] In some optional embodiments, after the host 11 executes the repair operation, it can also feedback the execution result to the server control module. The server control module 124 can also compare the received execution result with the corresponding policy to confirm whether the repair operation is successful, and synchronize the result to the CMDB to update the asset security status.

[0099] Further, if a host fails to successfully execute the repair instruction (e.g., the instruction fails to be sent due to network interruption), the server control module 124 can also mark the host as "repair failure" and reissue the instruction after 10 minutes (with a maximum of 3 retries); if the failure occurs multiple times, the host is upgraded to a medium or high risk asset (according to the original level) to trigger a more stringent processing flow (e.g., manual intervention for troubleshooting).

[0100] The host weak password processing method provided by the embodiment can make the load of each JTR cracking cluster more balanced by using the fragmentation weight algorithm and considering host assets and cracking server configuration data for fragmentation, compared with traditional equal fragmentation, avoiding the problem of excessive task of part of nodes and idle resources of nodes, thereby improving the overall cracking efficiency and adapting to large-scale cracking demand in a massive host environment. Further, the account information set after fragmentation can be distributed to multiple JTR cracking clusters, so that the computing resources of multiple cracking clusters can be fully utilized for cracking work, compared with single machine cracking, the cracking time is greatly shortened, the cracking efficiency is improved, and the requirement for rapid cracking of a large number of weak passwords in a massive host environment is met. Further, the JTR cracking cluster cracks according to the preset dynamic weak password rule library, which can effectively identify more weak passwords and reduce false negatives. Further, the server control module determines a hierarchical repair strategy in combination with preset host asset information and performs repair processing on multiple target weak passwords, which can not only timely process weak password risks and reduce security risks, but also ensure business continuity, and ultimately achieve the purpose of guaranteeing normal operation of the host and improving the network security level. Therefore, by implementing the application, centralized offline distributed cracking of the server is realized, host resources are avoided, and the host firewall and the like are not intercepted; dynamic fragmentation improves the cracking efficiency in a massive host environment; the hierarchical repair strategy avoids business interruption caused by one-size-fits-all and prevents security operation personnel from being overwhelmed by massive alarms, thereby guaranteeing normal operation of the host and improving the network security level.

[0101] In some optional embodiments, the above step S202 includes:

[0102] In step S2021, the fragmentation size is obtained based on the preset host asset information set and the cracking server configuration data set through the fragmentation weight algorithm.

[0103] Specifically, the asset risk coefficient of each host (e.g., K=1.5 for a high-risk host and K=0.8 for a low-risk host) can be obtained from the preset host asset information set; the CPU core number, memory capacity, and network delay of each JTR cracking node from the cracking server configuration data set.

[0104] Further, the fragmentation size can be calculated by the following relationship:

[0105] Fragment size = K x (CPU core number x 0.6 + memory x 0.4) / network delay

[0106] In the formula, K represents an asset risk coefficient.

[0107] In step S2022, the first host account information set is dynamically fragmented by using the fragment size to obtain a plurality of second host account information sets.

[0108] Specifically, the first host account information set can be initially grouped according to a host network segment or an asset type (for example, divided according to a C-class network segment, and each network segment contains account information of a plurality of hosts), so as to ensure that the hosts corresponding to the same batch of data have similar network attributes or risk levels.

[0109] Further, according to the calculated fragment size, each batch of host account information is dynamically split. For example, a node with a fragment size of 3.36 can be allocated 300 pieces of host account information (assuming that a single piece of information corresponds to a fixed amount of data), and a node with a fragment size of 2.0 is allocated 200 pieces, so as to ensure that the data amount of each fragment matches the processing capacity of the cracking node.

[0110] Further, each second host account information set after splitting can also be marked with an associated host asset level (such as "high risk" and "low risk") and a corresponding JTR cracking node identifier, so as to facilitate accurate allocation to the corresponding cracking cluster in the subsequent step S203, and realize the double matching of "risk adaptation + performance adaptation".

[0111] The host weak password processing method provided in the embodiment can dynamically adjust the fragmentation by comprehensively considering the host asset and cracking server configuration data according to the actual situation of the host and the cracking server when the first host account information set is dynamically fragmented by using the fragmentation weight algorithm, so as to balance the load of each cracking node, greatly improve the cracking efficiency, and also adapt to large-scale cracking demand in a massive host environment.

[0112] In some optional embodiments, as shown in Figure 1 The server 12 further includes a data receiving module 121, and the host 11 is integrated with a host agent program. Further, before the above step S201, the method further includes:

[0113] In step a1, the data receiving module receives a third host account information set of the host collected by the host agent program.

[0114] Specifically, the lightweight host agent program Agent on the host 11 can be used to direct capture of the account information of the host itself, only extract the core data related to weak password detection (such as the account name in the / etc / passwd file of the Linux system and the encrypted password hash in the / etc / shadow file, avoiding full log capture), and form an initial account information set.

[0115] The host Agent is an agent program installed on the host 11, which can collect some basic information of the host.

[0116] Further, the host agent program Agent encrypts the initial account information set using the SM4 algorithm, and forms a corresponding third host account information set after reducing the data volume through the LZMA compression algorithm. Encryption can prevent sensitive information from being leaked during transmission, and compression can reduce the bandwidth occupation during transmission.

[0117] Further, the host agent program Agent can send the third host account information set to the data receiving module 121 of the server 12 through a dedicated encryption channel (such as TLS+SM4 double-layer encryption) with the server 12.

[0118] Further, the data receiving module 121 can continuously monitor the port (such as the preset 8080 port) and receive Agent data from the host in real time to ensure that the information is not lost.

[0119] Step a2, decrypt and analyze the third host account information set to obtain the first host account information set.

[0120] Specifically, after the data receiving module 121 receives the third host account information set, it can call the SM4 decryption algorithm to decrypt the received third host account information set and restore the compressed original account data.

[0121] Further, the data receiving module 121 can also process the decrypted data through the LZMA decompression algorithm to obtain the original account information (such as the original content of / etc / passwd and / etc / shadow) as the first host account information set.

[0122] In some optional embodiments, the decompressed data can also be checked and invalid data (such as format error or incomplete record) can be removed to form the final first host account information set. The check can include verifying the legality of Agent_ID and checking the field integrity.

[0123] Step a3, send the first host account information set to the shard control engine.

[0124] Specifically, the data receiving module 121 can send the obtained first host account information set to the corresponding shard control engine 122.

[0125] In some optional embodiments, the data receiving module 121 can temporarily store the obtained first host account information set in a buffer queue (such as a Redis cache) of the server, and sort the first host account information set according to the timestamp and the Agent_ID, so as to avoid data congestion.

[0126] Further, when the amount of data in the buffer queue reaches a preset threshold (such as 1000) or the interval time reaches a set value (such as 1 minute), the data receiving module 121 can automatically send the first host account information set to the shard control engine 122 in batches.

[0127] The host weak password processing method provided in the embodiment reduces the amount of data and the transmission bottleneck by collecting the third host account information set of the host through the host agent program. Further, the third host account information set is transmitted after encryption to the data receiving module, so as to prevent the leakage of data information. Further, the third host account information set is decrypted and parsed, so as to ensure the smooth progress of the subsequent fragmentation and cracking process, and provide a high-quality data basis for efficient cracking.

[0128] In some optional embodiments, the preset dynamic weak password rule library in the above step S204 can be obtained by the following steps:

[0129] Step b1, obtaining a target password data set and a preset password rule library.

[0130] The target password data set includes a plurality of weak passwords and a plurality of non-weak passwords.

[0131] Further, the preset password rule library represents a rule set containing common weak password generation logic and mode, which is constructed in advance and used to assist in generating and identifying weak passwords.

[0132] Specifically, the multi-source intelligence fusion technology can be used to extract passwords from dark web forums, enterprise leakage libraries, and host behavior logs in real time and form a corresponding initial password data set.

[0133] Further, the initial password data set is subjected to data cleaning and standardization processing to obtain a corresponding target password data set.

[0134] Step b2, using an algorithm based on a statistical language model to perform word segmentation on the target password data set to obtain a plurality of first character sequences.

[0135] The algorithm based on the statistical language model (N-gram algorithm) represents a statistical language model for predicting the probability of the next word or sequence in the text, and the core idea is to assume that the occurrence of the current word is only related to the previous N-1 words. In this embodiment, the N-gram algorithm is to analyze the composition rule of the password by modeling the occurrence probability of the character sequence in a large amount of password data, so as to extract the feature mode of the weak password.

[0136] Specifically, the N-gram algorithm is used and the segmentation granularity is set (such as 2-gram or 3-gram, that is, cutting according to 2 or 3 continuous characters as a unit).

[0137] Further, each password (including weak password and non-weak password) in the target password data set is segmented, for example, "zhang1990" is cut into "zh", "ha", "ng", "19", "90" and the like 2-gram character sequences, and "qwe123" is cut into "qw", "we", "e1", "12", "23" and the like sequences, and finally a plurality of first character sequences are obtained.

[0138] Step b3, based on the plurality of first character sequences and the preset password rule library, an initial dynamic weak password rule library is constructed by using a dynamic threshold and a threat intelligence injection method.

[0139] The common password library has a generation method based on a dictionary (such as a common weak password of a birthday date, a name pinyin, a telephone drawing, etc.), a pattern matching based generation (through some letters and numbers, symbol combinations and continuous keyboard characters, etc.), a rule based generation (such as a name, a date of birth, a telephone number) to generate a password, and the above rules are single and easy to cause weak password missed report.

[0140] In this embodiment, a dynamic threshold and threat intelligence injection are innovatively combined to construct a powerful password library dictionary. The dynamic threshold mechanism solves the problem of missing low-frequency high-risk passwords, and the threat intelligence real-time injection improves the problem of resisting 0day leakage. Closed loop verification ensures that the password library is continuously effective.

[0141] Specifically, the above step b3 includes:

[0142] Step b31, probability statistics and feature extraction are performed on the plurality of first character sequences to obtain a plurality of probability values and a plurality of feature information sets of the plurality of first character sequences in the target password data set.

[0143] Step b32, according to the plurality of probability values, the plurality of feature information sets and the preset threat level, a plurality of preset thresholds are dynamically adjusted to obtain a plurality of target thresholds.

[0144] Step b33, filtering and adjusting the plurality of first character sequences using a plurality of target thresholds to obtain a plurality of second character sequences.

[0145] Step b34, combining the plurality of second character sequences using a preset password rule library to obtain a plurality of target character sequences.

[0146] Step b35, combining the plurality of target character sequences using a plurality of probability values to obtain a plurality of initial dynamic weak passwords.

[0147] Step b36, processing the plurality of initial dynamic weak passwords using a hierarchical encryption method to obtain a plurality of target dynamic weak passwords.

[0148] Step b37, generating an initial dynamic weak password rule library according to the plurality of target dynamic weak passwords and real-time threat intelligence.

[0149] Specifically, the frequency of occurrence of each first character sequence in the target password data set is counted, and the probability value is calculated. For example, the probability of sequences such as "12”"34” appearing in weak passwords is much higher than that of non-weak passwords.

[0150] Further, the feature information of each first character sequence can include character type (pure number / letter / symbol, mixed type), length, position rule (such as whether located at the beginning / end of the password), etc. and form a plurality of corresponding feature information sets. For example, the features of "12” are "pure number, length 2, high frequency in the first two positions of the password".

[0151] Further, the probability value (high frequency sequence needs strict threshold), feature information and preset threat level of the first character sequence are combined, and a plurality of preset thresholds are dynamically adjusted. Among them, the preset threat level can be divided into "extremely high”, "high”, "medium” and "low”. For example, the threat level of the password sequence newly leaked in the dark web is "extremely high”.

[0152] Illustratively, for sequences with threat level "extremely high” and probability value >80% (such as the "password123” split sequence appearing in the recent attack), the threshold is lowered to ensure inclusion; for sequences with threat level "low” and probability value <5% (such as rare complex character combinations), the threshold is increased to filter, and finally the adaptive target threshold is obtained.

[0153] Further, according to the obtained target threshold, the first character sequence that meets the condition (such as probability value ≥ target threshold, feature consistent with weak password rule) can be retained, and the sequence that does not meet the condition can be removed, and a plurality of second character sequences corresponding thereto can be obtained.

[0154] Further, rules in the preset password rule library can be called (such as "number sequence + letter sequence" and "prefix + birthday") to perform combination expansion on the second character sequence. For example, "zh", "19", and "90" are combined into "zh1990", "19zh90", and the like, and multiple target character sequences conforming to the weak password rule are generated.

[0155] Further, according to the obtained multiple probability values, high-frequency sequences in the multiple target character sequences can be preferentially combined, such as "12" and "34" having high probability values, which are combined into "1234" and "3412", and corresponding multiple initial dynamic weak passwords (such as "123456" and "zh1990") are formed.

[0156] Further, the multiple initial dynamic weak passwords can be processed by using a hierarchical encryption mode. For example, AES-256 encryption storage can be used to prevent the leakage of the password library itself.

[0157] Further, the metadata (such as occurrence probability and threat level) can be processed by using a hash desensitization method (such as SHA-256 hash), and finally the multiple target dynamic weak passwords after encryption are obtained.

[0158] Further, the target dynamic weak passwords after encryption can be fused with real-time threat intelligence (such as the latest leaked passwords in the dark web and the dictionary used by new attack tools), new weak password sequences (such as special weak passwords for a certain vulnerability) are supplemented, and a corresponding initial dynamic weak password rule library is formed.

[0159] In step b4, based on the initial dynamic weak password rule library, the step of using a statistical language model-based algorithm for word segmentation and cutting is returned, and iteration is repeated until a preset dynamic weak password rule library is obtained.

[0160] Specifically, the initial dynamic weak password rule library can be applied to a weak password detection scene to verify the recognition accuracy (such as the false negative rate and the false positive rate).

[0161] Further, if the false negative rate is greater than 5%, step b2 is returned, the target password data set (supplemented with newly collected password data) is segmented and cut by using the N-gram algorithm, the construction process of step b3 is repeated, and the weak password recognition accuracy of the rule library is up to standard (such as the false negative rate being less than 1%) until a corresponding constructed preset dynamic weak password rule library is finally obtained.

[0162] The host weak password processing method provided by the embodiment makes the analysis of the character sequence more accurate through probability statistics and feature extraction on the plurality of first character sequences, and avoids weak password missed reports caused by insufficient feature extraction. Further, by dynamically adjusting the threshold, the low-frequency high-risk password omission problem is solved, and the sensitivity of the password library to new threats is improved. Further, by dynamically adjusting the target threshold, character sequences that do not meet the weak password features are filtered out, reducing the redundancy of the password library and improving the accuracy of subsequent cracking and reducing the false positive rate. Further, the filtered character sequences are combined and expanded in combination with the preset rules, which enriches the weak password samples and can cover more potential weak password forms, solving the missed report problem caused by the single traditional rule. Further, based on the appearance probability of the character sequence, a plurality of target character sequences are combined to ensure that the weak passwords collected in the password library have actual attack value and improve the cracking efficiency. Further, hierarchical encryption is used to prevent sensitive information leakage of the password library itself, which meets the data security specification and solves the security problem of the password library storage. Further, by injecting threat intelligence in real time, the password library can quickly respond to new weak password threats, improve the anti-0day leakage capability, and ensure the timeliness and comprehensiveness of the rule library. Further, through repeated iteration, the preset dynamic weak password rule library can be continuously effective, significantly reducing the weak password missed report rate and improving the accuracy of weak password identification.

[0163] In some optional embodiments, after the above step S206, the method further comprises:

[0164] Step c1, when receiving the real-time host account information set of the host, the hash values of the plurality of target weak passwords are verified by using the server control module.

[0165] Specifically, the host agent program in the host 11 can collect the current host account information (including the password hash value corresponding to the account) according to a preset period (such as periodic scanning), and form a real-time host account information set, and then transmit it to the server 12 through an encrypted channel.

[0166] Further, the server control module 124 can extract the historical hash values corresponding to the plurality of target weak passwords detected before from the storage system (such as the security log library associated with the CMDB).

[0167] Further, the server control module 124 can compare the password hash values in the real-time host account information set with the historical target weak password hash values one by one, verify whether the hash values have changed, and determine whether the target weak password has been modified.

[0168] Step c2, when the hash values of the plurality of target weak passwords are not changed, the handling level of the plurality of target weak passwords is upgraded, and a control instruction is sent to the host to make the host perform password modification or account locking operation based on the control instruction.

[0169] Specifically, if the real-time hash value is consistent with the historical hash value, it indicates that the target weak password is not modified, i.e., the corresponding target weak password is a recurrent weak password.

[0170] Further, the server control module 124 can automatically upgrade the handling level of the recurrent weak password and send a control instruction to the host 11, so that the host 11 performs password modification or account locking operation under the control of the control instruction.

[0171] In some optional embodiments, the server control module 12 can improve the handling level according to the original asset level and the handling policy:

[0172] (1) The original low-risk host (such as test machine, only alarm record): upgraded to medium-risk, the handling policy is adjusted to "forced password change", and the server issues passwd-e <user>Command (force the user to change the password next time they log in, otherwise they cannot log in).

[0173] (2) The original medium-risk host (such as an application server, forced to change the password next time they log in): upgrade to high-risk, adjust the disposal policy to "lock the account immediately", and send usermod-L to the server <user>Instructions (directly lock accounts, prohibit login), and through WeChat + SMS to inform the asset responsible person.

[0174] (3) The original high-risk host (such as the database, the account is locked): marked as "persistent high-risk risk", the disposal strategy is upgraded to "network interruption rectification", the service end links the network equipment to issue temporary network interruption instructions until the password modification is completed.

[0175] Further, the disposal level upgrade result can also be synchronized to the CMDB, the asset security state is updated (such as "unrectified - level upgrade"), and the upgrade alarm is pushed through the corresponding notification channel (SMS, WeChat, etc.), so that the responsible person knows.

[0176] Step c3, when the hash values of the multiple target weak passwords change, based on the real-time host account information set, return to the step of obtaining the preset host asset information set and the cracking server configuration data set of the multiple JTR cracking clusters, and iterate repeatedly until the host runs normally.

[0177] Specifically, if the real-time hash value is inconsistent with the historical hash value, it indicates that the target weak password has been modified, and at this time the weak password in the newly received real-time host account information needs to be cracked, that is, returning to step S201 and repeating steps S201 to S206 until the weak password in the newly received real-time host account information is successfully cracked.

[0178] Further, when the weak password in the newly received real-time host account information is successfully cracked, the host 11 can run normally.

[0179] The host weak password processing method provided in the embodiment realizes closed-loop verification of weak password repair effect by verifying the hash values of multiple target weak passwords, ensuring that the weak password is effectively rectified. Further, more stringent disposal measures are taken for the recurring weak password, effectively reducing the weak password recurrence rate, and forming a complete security closed loop.

[0180] In some optional embodiments, as shown in Figure 1 The server 12 also includes a notification module 125. Further, after step S205, the above-mentioned method also includes:

[0181] Step d1, according to the hierarchical repair strategy, the notification module is used to send alarm information.

[0182] Specifically, key information can be extracted from the tiered repair strategy, including the host IP address, account name, asset level (high-risk / medium-risk / low-risk) corresponding to the target weak password, repair measures (such as "account locked" or "forced password change required"), processing deadline (such as high-risk hosts requiring processing within 2 hours), and contact information of the asset manager (mobile phone number, WeChat ID, email address), etc.

[0183] Furthermore, the corresponding notification channels and alarm templates can be selected based on the host asset level:

[0184] (1) High-risk assets (such as core database servers): Match the "Emergency Alarm" channel, push in real time via WeChat and send via SMS in seconds. The template content is "[Emergency Alarm] Host IP: xxx, Account: xxx has a weak password and has been locked. Please contact the maintenance team to change the password within 2 hours. Otherwise, the network will be disconnected. Person in charge: xxx".

[0185] (2) Medium-risk assets (such as application servers): Match the "Important Alarm" channel and push it through WeChat and email. The template content is "[Important Alarm] Host IP: xxx, Account: xxx has a weak password. The system has set up a forced password change. Please change it as required when you log in next time. See the attached OA work order for details."

[0186] (3) Low-risk assets (such as test machines): Match the "General Alarm" channel and push the message only via email. The template content is "[General Alarm] Host IP: xxx, Account: xxx has a weak password. Please check and modify it as soon as possible. The record has been synchronized to the security log."

[0187] Furthermore, the notification module 125 can call the corresponding channel's API interface (such as the WeChat Work robot interface, SMS gateway, email server interface) and send alarm information according to the above template.

[0188] In some optional implementations, after successful transmission, the transmission time, reception status (such as "delivered" or "unread"), and message content hash value can be synchronized to the server-side log system (such as ELK) to form an immutable alarm record, which is convenient for subsequent auditing and tracing.

[0189] Furthermore, secondary reminders can be set for alarms that are not responded to in a timely manner: if a high-risk asset is not confirmed within 1 hour, a reminder will be sent again via SMS and WeChat; if a medium-risk asset is not processed within 24 hours, a follow-up work order will be generated through the OA system to ensure that the person in charge is aware of and processes the issue in a timely manner.

[0190] The host weak password processing method provided in the embodiment sends alarm information through a hierarchical repair strategy, ensures that the relevant person in charge can timely receive alarm information of the corresponding level, improves the timeliness and effectiveness of weak password rectification, and avoids the expansion of security risks caused by inadequate notification.

[0191] A host weak password processing system is provided in the embodiment, as shown in the figure, the host weak password processing system 1 comprises a host 11 and a server 12. Figure 1

[0192] The host 11 is integrated with a host agent program, and the server 12 comprises a data receiving module 121, a sharding control engine 122, a plurality of JTR cracking clusters 123, a server control module 124 and a notification module 125.

[0193] Optionally, the host 11 is configured to acquire a first host account information set by using the host agent program, perform encryption processing on the first host account information set to obtain a third host account information set, and send the third host account information set to the data receiving module 121.

[0194] The specific process can refer to the related description in the above step a1, and will not be described here again.

[0195] Optionally, the server 12 is configured to execute the host weak password processing method provided in the above embodiment of the application, and the specific process will not be described here again.

[0196] The host weak password processing system provided in the embodiment integrates the functions of the host and the server, solves the problem of poor collaboration and dispersion of components in the prior art, and cannot form a complete and efficient weak password processing system, realizes the automatic detection, repair and verification of weak passwords, effectively reduces the risk of weak password attacks, ensures the normal operation of the host, and improves the network security level.

[0197] In an example, a mass host weak password closed-loop processing device and method are provided. In the first step, a powerful password library dictionary is constructed by using an innovative combination of a dynamic threshold and threat intelligence injection based on an N-gram algorithm, to reduce weak password false positives. In the second step, host information is collected by a host agent Agent in a lightweight manner, and data is transmitted by using a national cryptographic SM4 encryption algorithm to prevent sensitive information leakage. In the third step, a dynamic sharding control engine is used for distributed cracking to improve cracking efficiency, which is particularly suitable for simultaneous cracking of mass hosts. In the fourth step, a hierarchical repair strategy is implemented in combination with CMDB asset weights to avoid business interruption caused by mass alarms and "one-size-fits-all" disposal measures. The scheme is particularly suitable for the automatic detection, repair and verification of weak passwords in a distributed environment with more than 100,000 hosts. The host weak password can be effectively rectified by the device, an effective security closed loop is formed, and the risk of weak password attacks is effectively reduced. ​

[0198] Further, the problem solved by the present example is how to solve the problem of weak password governance closed loop in a massive server environment. Before weak password governance, a powerful password library dictionary is constructed by innovative combination of dynamic threshold and threat intelligence injection based on N-gram algorithm to reduce false negatives; in the weak password detection stage, it does not rely on online cracking, and the host is not aware of the detection, and does not occupy the host resources; in the process of governing weak password, the core business will not be interrupted due to weak password rectification, and the security operation personnel will not be overwhelmed by massive weak password alarms. The core technology includes:

[0199] (1) Dynamic weak password rule library generation: common password library has a generation method based on dictionary (such as common weak password of birthday date, name pinyin, telephone drawing, etc.), pattern matching (combination of some letters and numbers, symbols and continuous keyboard characters, etc.), rule-based generation (such as name, birth date, telephone number) to generate password, and the above single rules are easy to cause weak password false negatives. The present application adopts multi-source intelligence fusion technology to extract passwords from dark web forums, enterprise leakage library and host behavior logs in real time, and constructs a password library based on N-gram algorithm, and constructs a powerful password library dictionary by innovative combination of dynamic threshold and threat intelligence injection. The dynamic threshold mechanism solves the problem of missing low-frequency high-risk passwords, and the real-time injection of threat intelligence improves the problem of anti-0day leakage, and the closed loop verification ensures the continuous effectiveness of the password library. As shown in Figure 3 , it is a weak password library construction flowchart.

[0200] Among them, Figure 3

[0201] a. Probability statistics and feature extraction: N-gram algorithm is used to statistically model multi-source password data, and the probability of character sequence in the password is analyzed.

[0202] b. Dynamic threshold filtering: the inclusion threshold is dynamically adjusted according to the probability weight and threat level of the password.

[0203] c. Password composition engine: combine rule engine and probability model to generate candidate weak password.

[0204] d. Secure encrypted storage: use layered encryption, use AES-256 to encrypt sensitive fields (such as original password) for storage. The metadata (such as password frequency) is processed by hash desensitization.

[0205] ​(2) Dynamic fragmentation control engine for distributed cracking: Unlike conventional single-machine cracking, in a massive server environment, use Kafka to split the password file according to the host and split it to different computing nodes, such as dividing 100 Kafka topics according to network segments for a massive server (100,000 servers) and distributing them to a 20-node cracking cluster. To address the problem of unbalanced nodes in traditional equal fragmentation, a fragmentation weight algorithm is used to balance the cracking host according to performance indicators such as CPU, memory, and network latency of the target host, thereby improving cracking efficiency, as shown in the following relationship:

[0206] Fragment size = K x (CPU core number x 0.6 + memory x 0.4) / network latency

[0207] (3) Hierarchical repair strategy based on CMDB drive: For traditional weak password rectification and notification, a single script is usually executed through automation tools such as Ansible, and there are no risk control measures during execution, which can easily cause core business interruption. The present example uses a hierarchical repair strategy based on CMDB drive, which divides massive servers into high-risk hosts, medium-risk hosts, and low-risk hosts according to CMDB information. Among them, high-risk hosts (such as online servers such as databases) are immediately locked and the responsible person is alerted by SMS as soon as weak passwords are found; medium-risk hosts (such as online application servers) are forced to change passwords the next time they log in; and low-risk hosts (such as test machines) only generate alert records. By classifying and grading different hosts, on the one hand, security operation personnel will not be overwhelmed by massive alert messages, and on the other hand, core business interruption is avoided. The CMDB-based weak password asset grading method is shown in Table 1:

[0208] Table 1: CMDB-based weak password asset grading

[0209] Asset level Repair strategy Notification method High risk (core assets such as database) Immediately lock the account and send a short message to the asset owner Enterprise WeChat + short message Medium risk (application server) Force the next login password Email + OA work order Low risk (test environment) Only alarm record No notification

[0210] Further, the massive host weak password closed-loop processing device provided by the present example is as shown in Figure 4 . First, a dynamic threshold and threat intelligence injection are combined to generate a dynamic weak password rule library based on the N-gram algorithm, reducing false negatives; second, host account information is collected through the host Agent proxy program and transmitted to the server through an encrypted channel (here, only the account information of the Agent is collected, and the data receiving module of the server receives this information. It can be understood that the data receiving module in Figure 4 is part of the server.); offline cracking is performed; third, a dynamic fragmentation control engine is used for distributed cracking during offline cracking; and fourth, the hosts that are cracked successfully are repaired according to different strategies.

[0211] Further, as shown in Figure 5 the processing flow of the mass host weak password closed-loop processing device specifically includes:

[0212] (1) Generate dynamic weak password rule base: adopt multi-source intelligence fusion, extract passwords from dark web forums, enterprise leakage library and host behavior logs in real time, and based on N-gram algorithm, adopt dynamic threshold and threat intelligence injection to build password library, as shown in the above Figure 3 This way can effectively find more common weak passwords and enrich the password library.

[0213] (2) Data collection: in the mass server environment, the host agent program Agent directionally captures the account information on the host, such as the / etc / passwd and / etc / shadow account information of the linux server, avoids full log capture, thereby reducing the data volume and avoiding transmission bottleneck.

[0214] (3) Secure data transmission: through the data collection capability of the host agent Agent, send the data to the server to form log events. In the process of collection, the information is transmitted by national encryption SM4 and compressed by LZMA to prevent sensitive information leakage.

[0215] (4) Dynamic sharding control engine for distributed cracking: through the logstash collection service of the server, use Kafka to distribute, split the password file according to the host risk and cracking server configuration to different computing nodes. Among them, the data collected in step 2 is to collect the Agent data to the server receiving program, which needs to be decoded, rule matching, etc. to generate json data from the collected raw data. Then through the logstash collection service, collect the json data and send the collected data to the kafka message queue. Here, the logstash collection service of the server is the summary of all agent data, each json contains agent related information such as agent_id, agent_name, account information, etc. The data collected in step 2 is only single agent data.

[0216] a) Query CMDB to divide host assets into high-risk hosts and low-risk hosts (set the risk coefficient of high-risk hosts to 1.5 and the risk coefficient of low-risk hosts to 0.8);

[0217] b) Divide the mass servers into different Kafka Topics according to the network segment and distribute them to the cracking cluster;

[0218] c) Using the slice weight algorithm, dynamically allocate computing power according to the host load (for target host CPU, memory and network delay and other performance indicators, balanced deployment of cracking hosts), improve cracking efficiency;

[0219] (5) Hierarchical repair according to strategy: implement hierarchical repair strategy combined with CMDB asset weight, force lock account of high-risk host and alarm responsible person through SMS; force next login of the password of medium-risk host and send email notification, and only message alarm for low-risk host. Avoid alarm being submerged by massive messages and business interruption;

[0220] (6) Closed-loop verification: check whether the historical weak password HASH value is changed in the next scan, if not changed, it means that the weak password has not been modified, and automatically upgrade the level of disposal for the repeated weak password, and send passwd-e through the server <user>(changepw) or usermod -L <user>(locking the account); if changed, the password file is re-assigned to the cracking node for cracking.

[0221] The mass host weak password closed-loop processing device and method provided by the present example has the following beneficial effects:

[0222] (1) Based on N-gram algorithm, innovative combination of dynamic threshold and threat intelligence injection is used to build password library, and weak password false negative is low.

[0223] (2) Offline cracking occupies less resources and will not be blocked: CS (client-server) mode is used, and lightweight host agent program Agent only collects account information and does not perform other tasks, and the cracking service is on the server and has no effect on the host's own business. At the same time, it avoids the online cracking being easily discovered and intercepted, and also avoids the host itself installing cracking tools to occupy server resources.

[0224] (3) High-performance data processing: by cracking on the server, it does not depend on the server performance of the client itself, and can be flexibly deployed in a distributed and multi-process manner on the server, and supports batch cracking, with high cracking efficiency.

[0225] (4) Support mass host: through the host agent program Agent to collect information to the server for centralized cracking, support mass host cracking at the same time, and there is no limit to the number of hosts, server batch cracking, high efficiency.

[0226] (5) Intelligent identification: using host agent program Agent automation, periodic detection, and according to the detection result, the weak password and weak configuration that do not meet the requirements are notified to the asset owner through CMDB configuration management database, and the control command is automatically issued, and the user is forced to modify the password that meets the security requirements when logging in, and the high-risk account is locked.

[0227] (6) Both prevention and cure: detection, verification and rectification are integrated, control of existing weak passwords, and prevention of new weak passwords through rectification of unsafe strategies on the server.

[0228] Therefore, by implementing this example, a closed-loop security system for detecting, repairing, and verifying weak passwords on hosts is formed by combining threat intelligence, the N-gram algorithm, a host agent, Wazuh (an open-source intrusion detection system and a security information and event management tool), a dynamic sharding control engine, a Kafka distributed message queue, the JTR (John the Ripper) cracking program, a weak password dictionary, and a CMDB configuration management database. It does not rely on the host itself; the lightweight host agent collects host accounts, the server can be deployed in a distributed manner for batch cracking, and it notifies the server owner of corrective actions in real time based on the detection results. Furthermore, the password database of this comprehensive technical solution has higher accuracy in weak password identification, and the offline distributed detection has powerful detection capabilities, making it particularly suitable for weak password identification in environments with massive numbers of hosts, bringing significant technological breakthroughs and progress to the field of network security.

[0229] This invention also provides a computer device for performing the above-described... Figure 2 The method for handling weak passwords on the host is shown.

[0230] Please see Figure 6 , Figure 6 This is a schematic diagram of the structure of a computer device provided in an optional embodiment of the present invention, such as... Figure 6 As shown, the computer device includes one or more processors 10, memory 20, and interfaces for connecting the components, including high-speed interfaces and low-speed interfaces. The components communicate with each other via different buses and can be mounted on a common motherboard or otherwise installed as needed. The processors can process instructions executed within the computer device, including instructions stored in or on memory to display graphical information of a GUI on external input / output devices (such as display devices coupled to the interfaces). In some alternative implementations, multiple processors and / or multiple buses can be used with multiple memories, if desired. Similarly, multiple computer devices can be connected, each providing some of the necessary operations (e.g., as a server array, a group of blade servers, or a multiprocessor system). Figure 6 Take a processor 10 as an example.

[0231] Processor 10 may be a central processing unit, a network processor, or a combination thereof. Processor 10 may further include a hardware chip. The hardware chip may be an application-specific integrated circuit (ASIC), a programmable logic device (PLD), or a combination thereof. The programmable logic device may be a complex programmable logic device (CAMP), a field-programmable gate array (FPGA), a general-purpose array logic (GDA), or any combination thereof.

[0232] The memory 20 stores instructions executable by the at least one processor 10 to cause the at least one processor 10 to perform the methods illustrated by the above embodiments.

[0233] The memory 20 can include a program storage area and a data storage area. The program storage area can store an operating system, application programs required by at least one function, and the like. The data storage area can store data created according to the use of the computer device, and the like. In addition, the memory 20 can include a high-speed random access memory, and can further include a non-transitory memory such as at least one magnetic disk storage device, a flash memory device, or other non-transitory solid-state memory device. In some alternative embodiments, the memory 20 can optionally include a memory disposed remotely from the processor 10, which can be connected to the computer device through a network. Examples of the network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and a combination thereof.

[0234] The memory 20 can include a volatile memory such as a random access memory, and can further include a non-volatile memory such as a flash memory, a hard disk, or a solid state disk, and a combination of the above-mentioned kinds of memories.

[0235] The computer device further includes a communication interface 30 for communication of the computer device with other devices or communication networks.

[0236] The embodiments of the present application also provide a computer readable storage medium, and the above-mentioned method according to the embodiments of the present application can be implemented in hardware, firmware, or recorded in a storage medium, or stored in a remote storage medium or a non-transitory machine readable storage medium and downloaded to a local storage medium through network downloading of computer code, so that the method described herein can be processed by such software on a storage medium using a general purpose computer, a special purpose processor, or programmable or special purpose hardware. The storage medium can be a magnetic disk, an optical disk, a read-only memory, a random access memory, a flash memory, a hard disk, or a solid state disk, and the like. Further, the storage medium can also include a combination of the above-mentioned kinds of memories. It can be understood that the computer, the processor, the microprocessor controller, or the programmable hardware includes a storage component that can store or receive software or computer code, which, when accessed and executed by the computer, the processor, or the hardware, implements the methods illustrated by the above embodiments.

[0237] Part of the present application can be applied as a computer program product, for example, computer program instructions, when executed by a computer, through the operation of the computer, can invoke or provide the method and / or technical solutions according to the present application. Those skilled in the art should understand that the form of computer program instructions in computer readable medium includes but is not limited to source files, executable files, installation package files and the like, and accordingly, the way of computer program instructions executed by computer includes but is not limited to: the computer directly executes the instructions, or the computer compiles the instructions and then executes the corresponding compiled program, or the computer reads and executes the instructions, or the computer reads and installs the instructions and then executes the corresponding installed program. Here, the computer readable medium can be any available computer readable storage medium or communication medium accessible to the computer.

[0238] Although the embodiments of the present application are described in conjunction with the drawings, various modifications and changes can be made by those skilled in the art without departing from the spirit and scope of the present application, and such modifications and changes fall within the scope defined by the appended claims.< / user> < / user> < / user> < / user> < / user> < / user>

Claims

1. A host weak password processing method, characterized in that, The method comprises the following steps: When the shard control engine receives the first host account information set of the host, the preset host asset information set and the cracking server configuration data set of the plurality of JTR cracking clusters are obtained; Based on the preset host asset information set and the cracking server configuration data set, the first host account information set is processed by using a shard weight algorithm to obtain a plurality of second host account information sets; The plurality of second host account information sets are distributed to the plurality of JTR cracking clusters; When the plurality of JTR cracking sets receive the cracking task sent by the shard control engine, based on the cracking task, the weak password in the plurality of second host account information sets is cracked by using a preset dynamic weak password rule library to obtain a plurality of target weak passwords; When the service end control module receives the plurality of target weak passwords, the preset host asset information set is used to determine a hierarchical repair strategy; The plurality of target weak passwords are repaired by using the hierarchical repair strategy to make the host run normally.

2. The method of claim 1, wherein, Based on the preset host asset information set and the cracking server configuration data set, the first host account information set is processed by using a shard weight algorithm to obtain a plurality of second host account information sets, comprising: Based on the preset host asset information set and the cracking server configuration data set, the shard size is obtained through the shard weight algorithm processing; The first host account information set is dynamically sharded by using the shard size to obtain the plurality of second host account information sets.

3. The method of claim 1, wherein, The service end further comprises a data receiving module, and the host is integrated with a host agent program; the method further comprises: The third host account information set of the host collected by the host agent program is received by using the data receiving module; The third host account information set is decrypted and parsed to obtain the first host account information set; The first host account information set is sent to the shard control engine.

4. The method of claim 1, wherein, The method further comprises: Obtaining a target password data set and a preset password rule library, the target password data set comprising a plurality of weak passwords and a plurality of non-weak passwords; The target password data set is segmented by using an algorithm based on a statistical language model to obtain a plurality of first character sequences; Based on the plurality of first character sequences and the preset password rule library, an initial dynamic weak password rule library is constructed by using a dynamic threshold and a threat intelligence injection method; Based on the initial dynamic weak password rule library, the step of segmenting by using an algorithm based on a statistical language model is returned for repeated iteration until the preset dynamic weak password rule library is obtained.

5. The method of claim 4, wherein, Based on the plurality of first character sequences and the preset password rule library, an initial dynamic weak password rule library is constructed by using a dynamic threshold and a threat intelligence injection method, comprising: The method further comprises: When the real-time host account information set of the host is received, the hash value of the plurality of target weak passwords is verified by using the service control module; When the hash value of the plurality of target weak passwords is not changed, the disposal level of the plurality of target weak passwords is upgraded, and a control instruction is sent to the host to make the host perform password modification or account locking operation based on the control instruction; When the hash value of the plurality of target weak passwords is changed, based on the real-time host account information set, the steps of obtaining the preset host asset information set and the cracking server configuration data set of the plurality of JTR cracking clusters are returned for repeated iteration until the host runs normally. The service end further comprises a notification module; the method further comprises: According to the hierarchical repair strategy, the notification module is used to send alarm information. The system comprises a host and a service end, the host is integrated with a host agent program, and the service end comprises a data receiving module, a sharding control engine, a plurality of JTR cracking clusters, a service control module and a notification module; 6. The method of claim 1, wherein, The host is used to obtain a first host account information set by using the host agent program, and the first host account information set is encrypted to obtain a third host account information set, and the third host account information set is sent to the data receiving module; The service end is used to execute the host weak password processing method in any one of claims 1 to 7. The computer readable storage medium stores computer instructions, and the computer instructions are used to make the computer execute the host weak password processing method in any one of claims 1 to 7. The computer readable storage medium stores computer instructions, and the computer instructions are used to make the computer execute the host weak password processing method in any one of claims 1 to 7.

7. The method of claim 1, wherein, The computer readable storage medium stores computer instructions, and the computer instructions are used to make the computer execute the host weak password processing method in any one of claims 1 to 7. ​ 8. A host weak password handling system, characterized by ​ ​ ​ 9. A computer-readable storage medium, characterized in that, ​ 10. A computer program product, characterised in that, ​