Network host full life cycle safety management system and method

By dividing the entire lifecycle of network hosts into stages and implementing unified security management, combined with online real-time execution and offline hardening, the problems of security vulnerabilities and management complexity of dedicated network hosts are solved, and full lifecycle security protection and traceability management are achieved.

CN121462297APending Publication Date: 2026-02-03GUANGZHOU ZHIAN TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511748035.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-26
Publication Date
2026-02-03

AI Technical Summary

Technical Problem

In existing technologies, private network hosts are designed with a focus on functionality rather than security considerations, resulting in persistent security vulnerabilities. Traditional security measures are unable to effectively address unknown malware and advanced persistent threats, and are also highly complex to manage.

Method used

By dividing the entire lifecycle of network hosts into stages, a unified security management platform is built. Combined with online real-time execution modules and portable tools for offline hardening, a closed-loop management of online-offline collaborative strategies is formed, realizing proactive defense and full-lifecycle traceable management.

Benefits of technology

It achieves full lifecycle security management system integrity, enhances the ability to protect against unknown malware, reduces the risk of complex attacks, and supports accurate location and tracing of security incidents.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121462297A_ABST
    Figure CN121462297A_ABST
Patent Text Reader

Abstract

The invention provides a network host full-life-cycle safety management system and a network host full-life-cycle safety management method. The method belongs to the cross technical field of network security and life cycle management. The method comprises the following steps: carrying out full life cycle stage division on a network special host, generating core stage data, constructing a unified security management platform according to the core stage data, and uniformly arranging security policies for each stage through the management platform to form initial security management framework data; by constructing the safety management method covering the full life cycle of the special host, the safety management of the whole process from registration, monitoring, reinforcement to decommissioning is realized, the problem of stage splitting in a traditional safety scheme is effectively solved, and the systematicness and integrity of safety management are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention proposes a network host full lifecycle security management system and method, which belongs to the cross-technical field of network security and lifecycle management. Background Technology

[0002] With the rapid development of information technology, private networks (VPCs) are increasingly widely used in various organizations and enterprises, but their security has become a serious challenge. VPC hosts, such as servers and workstations, are core components of information systems, storing large amounts of high-value confidential data. However, these hosts are often designed with a focus on functionality, with relatively insufficient security considerations. Furthermore, due to system compatibility issues, patch upgrades are difficult, leading to persistent security vulnerabilities. Traditional security measures, such as antivirus software based on blacklist mechanisms, are ineffective against unknown malware and advanced persistent threats (APTs). In addition, the specialized software and protocols of VPCs also increase the complexity of security management. Summary of the Invention

[0003] This invention provides a network host full lifecycle security management system and method to solve the problems mentioned in the background section above:

[0004] This invention proposes a method for full lifecycle security management of network hosts, the method comprising:

[0005] S1. Divide the network private host into full life cycle stages, generate core stage data, build a unified security management platform based on the core stage data, and uniformly arrange security policies for each stage through the management platform to form initial security management framework data.

[0006] S2. Based on the initial security management framework data, deploy a real-time execution module on the client. At the same time, use portable tools to harden the offline host, generate offline host hardening data, and import the hardening data into the unified security management platform to form online-offline collaborative initial policy closed-loop management data.

[0007] S3. Based on the initial strategy closed-loop management data of online-offline collaboration, perform corresponding processing on different core stages to obtain the corresponding data;

[0008] S4. Perform a fusion analysis of the host's security posture throughout its entire lifecycle using relevant data to generate comprehensive host security posture data; use the comprehensive host security posture data to optimize and adjust the initial security management framework data to form optimized security management strategy data;

[0009] S5. Based on the optimized security management strategy data, deploy proactive defense strategies and generate host proactive defense execution data; perform risk tracing management for each stage of the host's entire lifecycle based on the host proactive defense execution data, and generate host full lifecycle traceable management data; perform risk warning processing based on the host full lifecycle traceable management data, and generate network host full lifecycle security warning data.

[0010] This invention proposes a network host full lifecycle security management system, comprising:

[0011] One or more processors;

[0012] Memory, used to store one or more programs.

[0013] Wherein, when the one or more programs are executed by the one or more processors, the one or more processors are made to implement the method described in any one of the above.

[0014] The beneficial effects of this invention are as follows: By constructing a security management method covering the entire lifecycle of dedicated hosts, it achieves end-to-end security management from registration, monitoring, hardening to decommissioning, effectively solving the problem of fragmented stages in traditional security solutions and improving the systematicness and completeness of security management. Utilizing a unified security policy orchestration platform, combined with real-time baseline scanning, peripheral device control, and virus protection operations executed by the client, as well as the hardening and data import functions of portable tools for offline hosts, a closed-loop policy management system integrating online and offline collaboration is formed, significantly enhancing the flexibility and real-time nature of security protection. This method achieves proactive defense against dedicated hosts, effectively preventing the infection and operation of unknown malicious software through a software whitelist mechanism, greatly improving the ability to resist complex attacks such as Advanced Persistent Threats (APTs). This method supports full-lifecycle traceable management, enabling precise location and tracing of security incidents, providing strong support for security auditing and accountability. Attached Figure Description

[0015] Figure 1 This is a diagram illustrating the steps of the method described in this invention. Detailed Implementation

[0016] The preferred embodiments of the present invention will be described below with reference to the accompanying drawings. It should be understood that the preferred embodiments described herein are for illustration and explanation only and are not intended to limit the present invention.

[0017] One embodiment of the present invention, such as Figure 1 As shown, a method for full lifecycle security management of network hosts includes:

[0018] S1. Divide the network private server into full lifecycle stages and generate core stage data. The core stages include host registration stage data, host monitoring stage data, host hardening stage data, and host retirement stage data. Build a unified security management platform based on the core stage data, and use the management platform to uniformly orchestrate security policies for each stage to form initial security management framework data.

[0019] S2. Based on the initial security management framework data, a real-time execution module is deployed on the client. The security execution module is used to perform baseline scanning operations to obtain the host's initial security baseline data, implement peripheral control operations to generate peripheral usage control data, and perform virus protection operations to obtain virus protection status data. At the same time, a portable tool is used to perform hardening operations on the offline host to generate offline host hardening data, and the hardening data is imported into the unified security management platform to form an online-offline collaborative initial policy closed-loop management data.

[0020] S3. Based on the initial closed-loop management data of the online-offline collaborative strategy, perform identity authentication and authorization processing on the host registration stage data to obtain host registration security authentication data; perform real-time security status monitoring and analysis on the host monitoring stage data to generate host real-time security status data; evaluate the hardening effect of the host hardening stage data to obtain host hardening effect evaluation data; and perform data cleaning and system recovery processing on the host decommissioning stage data to form host decommissioning security processing data.

[0021] S4. By integrating and analyzing the host's security posture throughout its entire lifecycle using host registration security authentication data, host real-time security status data, host hardening effect evaluation data, and host retirement security processing data, a comprehensive host security posture data is generated. The comprehensive host security posture data is then used to optimize and adjust the initial security management framework data, resulting in optimized security management strategy data.

[0022] S5. Based on the optimized security management strategy data, deploy proactive defense strategies and generate host proactive defense execution data; perform risk tracing management for each stage of the host's entire lifecycle based on the host proactive defense execution data, and generate host full lifecycle traceable management data; perform risk warning processing based on the host full lifecycle traceable management data, and generate network host full lifecycle security warning data.

[0023] The working principle and effects of the above technical solution are as follows:

[0024] By clearly defining the four core stages of registration, monitoring, hardening, and decommissioning and building a unified security management platform, the disconnect between security management at each stage is avoided, the problem of security vulnerabilities being missed due to fragmented management is reduced, and the systematic nature of the entire lifecycle management of network private hosts is improved.

[0025] The online client performs baseline scanning, peripheral device management, and virus protection in real time. Combined with portable tools, it covers offline host hardening, reducing security blind spots caused by the lack of protection on offline hosts, reducing the risk of virus spread through mobile media and unauthorized access, and enhancing the comprehensiveness of host security protection.

[0026] The data at each stage undergoes refined processing, including identity authentication, status monitoring, and effect evaluation. Combined with full lifecycle situational analysis to optimize strategies, this reduces defense failures caused by delayed initial strategies, minimizes resource waste from blind protection, and improves the accuracy of security data and the adaptability of strategies.

[0027] Proactive defense strategies intercept risks in advance, and full-cycle traceability management facilitates rapid identification of the root cause of problems, reducing the handling costs after a security incident occurs. Risk warning mechanisms can avoid hidden dangers in advance, improve the overall security and stability of network hosts, reduce business interruption losses caused by security incidents, and enhance the initiative and traceability of risk management.

[0028] In one embodiment of the present invention, S1 includes:

[0029] S11. Based on the actual operation and maintenance process of network private hosts (servers, workstations, engineering stations, etc.), determine the business boundaries of the core stages (such as the registration stage from the first access of the device to the granting of permissions, and the decommissioning stage from the decommissioning of the device to the recycling of hardware), sort out the key operation nodes of each stage (such as the registration stage requiring hardware information entry and network partitioning, and the decommissioning stage requiring data cleanup and system restoration), and generate a full life cycle stage division standard.

[0030] S12. Based on the generated phase division standard, define core data dimensions for each phase. Specifically, the registration phase requires host hardware fingerprint (CPU / motherboard serial number), operating system version, affiliated business system, and responsible person information; the monitoring phase requires resource usage (CPU / memory / disk I / O), process execution logs, and peripheral access records; the hardening phase requires security baseline compliance items, vulnerability remediation records, and whitelist configuration information; and the decommissioning phase requires data backup lists, sensitive data cleanup logs, and hardware recycling certificates. Standardize the core data fields (e.g., unify hardware information formats and standardize log timestamps) to generate structured data for each core phase.

[0031] S13. Based on the core stage's structured data storage and interaction requirements, build the platform's core architecture. The platform's core architecture includes a data layer using an encrypted distributed database, supporting both structured and unstructured data storage; a functional layer developing four modules: asset management (interfacing with registration data), policy orchestration (supporting rule configuration for each stage), status monitoring (associating with monitoring data), and alarm handling; an interface layer reserving interfaces for client access and portable tool data import; and completing platform deployment and module debugging to ensure the normal reception and storage of core stage data, generating unified security management platform infrastructure data.

[0032] S14. Based on the platform architecture, security policies are orchestrated for each stage. These security policies include: configuring a two-factor authentication rule of "hardware fingerprint + account password" and a least privilege allocation policy during the registration stage; setting resource thresholds (such as alarms for CPU exceeding 80% for 5 consecutive minutes) and abnormal behavior identification rules (such as blocking unauthorized USB flash drive access) during the monitoring stage; formulating Level 3 security protection baseline standards and 24-hour remediation rules for high-risk vulnerabilities during the hardening stage; and clarifying the sensitive data "three-time overwrite" cleanup process and system recovery verification standards during the decommissioning stage. The security policies are then entered into the platform and execution trigger conditions are configured (such as the registration policy being automatically activated when the host first connects), forming the initial security management framework data.

[0033] The working principle and effects of the above technical solution are as follows:

[0034] By clearly defining the business boundaries and key operational nodes of each core stage, operational confusion during stage transitions is avoided, and problems such as registration omissions and incomplete data cleanup due to ambiguous stage divisions are reduced, thereby improving the clarity of the entire lifecycle management of network private hosts.

[0035] Defining standardized data dimensions and standardizing field formats by stage avoids messy data formats at different stages, reduces the format conversion cost when integrating data on the platform later, reduces the risk of information loss due to data incompatibility, and enhances the uniformity of data in the core stage.

[0036] Encrypted distributed databases enhance data storage security, functional modules precisely meet the needs of each stage, and reserved interfaces reduce the difficulty of adaptation for subsequent client and portable tool access, avoiding the problem of incompatibility with other tools after the platform is built, thus improving the practicality of the unified security management platform.

[0037] Differentiated strategies were developed for each stage (such as two-factor authentication in the registration stage and resource threshold alarms in the monitoring stage), avoiding a one-size-fits-all approach to protection, reducing security vulnerabilities caused by mismatched strategies, minimizing risks and hidden dangers caused by inadequate initial protection, and enhancing the targeting of initial security strategies.

[0038] In one embodiment of the present invention, S2 includes:

[0039] S21. Based on the monitoring-hardening phase strategy requirements of the initial security management framework in S14, develop the following core client functional modules: baseline scanning module (supports comparison of custom scan items with the baseline), peripheral device management module (configurable USB / CD drive "disable / read-only / write" mode), and virus protection module (integrates offline signature library and supports fast / full disk scanning). Adapt the client version according to the host operating system (Windows / Linux / domestic system), complete the module installation and parameter configuration on the online host (such as synchronizing platform baseline standards and virus signature library), and generate client deployment configuration data.

[0040] S22. Start the client module deployed in S21 and execute operations according to the platform policy, specifically including: the baseline scanning module performs a full compliance scan of online hosts, marks non-compliant items (such as weak password accounts, redundant open ports), and generates initial security baseline data for the hosts; the peripheral device management module monitors peripheral device access in real time, records device information and operation behavior, blocks unauthorized access, and generates peripheral device usage management data; the virus protection module performs a full scan, records virus detection and isolation results, and generates virus protection status data; these three types of data are uploaded to the unified security management platform in real time to form the initial security dataset for online hosts;

[0041] S23. For hosts that are not connected to the internet (such as engineering workstations in isolation zones), use a portable tool (encrypted USB drive) with a pre-configured S14 framework policy. First, use the tool's offline detection module to collect host hardware information, operating system status, and process list, and compare them with the built-in baseline standard. Then, start the one-click hardening module to automatically fix weak passwords, close high-risk ports, update the local whitelist, record the status changes before and after hardening (e.g., non-compliant items are reduced from 12 to 3), and generate offline host hardening data.

[0042] S24. Import the offline host hardening data generated in S23 into the unified security management platform built in S13 in the form of encrypted files, and integrate it with the online host initial security dataset in S22. The platform performs correlation matching on the two types of data (such as using the host's unique ID to associate online monitoring data with offline hardening records), verifies the consistency of policy execution (such as whether the baseline standards of online and offline hosts are consistent), and forms the initial policy closed-loop management data for online-offline collaboration.

[0043] The working principle and effects of the above technical solution are as follows:

[0044] Corresponding versions have been developed for Windows, Linux and domestic systems, and features such as custom scanning and multi-mode peripheral control have been added to reduce installation failures of protection tools caused by system incompatibility, avoid protection gaps on online hosts, and improve the compatibility of clients with different operating systems.

[0045] Baseline scanning can accurately identify non-compliant items such as weak passwords and redundant ports; peripheral device management can block unauthorized access in real time; and virus protection supports full scanning and isolation, reducing the security risks caused by compliance vulnerabilities and violations on online hosts, reducing the possibility of virus spread and data leakage, and enhancing the real-time security management capabilities of online hosts.

[0046] Portable tools using encrypted USB flash drives with pre-configured strategies can collect offline host status, automatically harden the system, and record changes before and after the event. This prevents isolated or offline hosts from becoming security blind spots due to lack of protection, reduces the problem of vulnerability retention and malicious program lurking in offline environments, and fills the protection gap for offline hosts.

[0047] By associating two types of data with a unique host ID and verifying policy consistency, the overall security management is improved, avoiding the disconnect between online and offline host protection standards, reducing policy execution deviations caused by fragmented management, making the security status of hosts in all scenarios more controllable, and realizing a collaborative closed loop of online and offline data.

[0048] In one embodiment of the present invention, step S24 includes:

[0049] Extract the encrypted offline host hardening data file generated in S23, and decrypt it through the dedicated decryption interface of the unified security management platform (using an asymmetric encryption algorithm) to obtain the original hardening record (including hardware information, hardening items, before and after state comparison, etc.); according to the platform data storage specifications in S13, convert the offline data into a format consistent with the online data (such as unified timestamp format, standardized vulnerability level identifier) ​​to generate a standardized offline host hardening dataset.

[0050] Based on the generated standardized offline host hardening dataset, it is uploaded to the unified security management platform built on S13 through the platform's data import module; the system automatically assigns a unique identifier to each piece of offline data and builds an index based on the host hardware fingerprint (such as the motherboard serial number), associating it with the basic information of the corresponding host (such as model and business area); at the same time, a data verification mechanism is started to check the integrity of fields (such as whether it contains hardening time and executor information), and an offline data import status report is generated (including the number of successful entries and the reasons for failure).

[0051] Based on the constructed index, the platform's data association engine is invoked to match the offline host hardening dataset with the initial online host security dataset generated by S22: the online monitoring data (such as real-time resource usage) and offline hardening records (such as vulnerability remediation status) of the same host are associated through the host's unique ID (hardware fingerprint + logical number); for offline hosts that are connected for the first time, a new host profile is automatically created and its hardening data is associated; a cross-scenario data association graph is generated to intuitively display the security data association relationship of the same host in online / offline states;

[0052] Based on the baseline standards (such as password complexity requirements and port opening specifications) in the initial security management framework generated by S14, compare the correlated online and offline data: verify whether the online host baseline scan results are consistent with the offline host hardening standards (such as both adopting the Level 3 Security Protection Baseline); check whether the execution rules for similar operations are consistent (such as the online and offline hosts having a 24-hour time limit for fixing high-risk vulnerabilities); mark and analyze the reasons for any discrepancies found (such as the offline host baseline version being outdated), and generate a policy execution consistency verification report;

[0053] The cross-scenario data association map and consistency verification report are integrated and structured through the platform's data fusion module: For the consistent items that have passed the verification, they are summarized according to the dimension of "host ID-stage-security indicator"; for the discrepancies, adjustment suggestions are attached (such as updating the offline tool baseline library version); and initial policy closed-loop management data covering online and offline hosts and running through the monitoring-hardening stages are formed.

[0054] The working principle and effects of the above technical solution are as follows:

[0055] By using asymmetric encryption and decryption and standardized format conversion, offline hardened data can be smoothly integrated into the online data system, reducing data integration failures caused by format differences, avoiding the phenomenon of offline information silos, and improving the compatibility of offline data with the platform.

[0056] By building an index based on hardware fingerprints and verifying the integrity of fields, it is ensured that each piece of offline data can be accurately associated with the basic information of the corresponding host, reducing the risk of mismatch due to confusing identification, reducing redundancy and erroneous records in data management, and enhancing the accuracy of data association.

[0057] By connecting security records in two scenarios through the host's unique ID, the complete state transition of the same host can be presented intuitively, avoiding the fragmentation of online monitoring and offline hardening, improving the continuity of security data throughout the entire lifecycle, and realizing the panoramic association between online and offline data.

[0058] By comparing and verifying baseline standards and operating rules, differences in online and offline execution can be identified and marked in a timely manner, reducing protection vulnerabilities caused by inconsistent standards, mitigating security risks caused by flexible policy execution, making full-scenario protection more standardized and controllable, and strengthening the uniformity of security policy execution.

[0059] In one embodiment of the present invention, S3 includes:

[0060] S31. Based on the basic information of the registration stage in the collaborative closed-loop management data of S24, perform identity authentication, compare the host hardware fingerprint with the pre-entered information, and verify the validity of the responsible person's account password; offline registered hosts require manual review of hardware credentials and business ownership proof; after authentication, according to the least privilege policy of S14, configure operation permissions for the host (such as operation and maintenance personnel only have monitoring / hardening permissions), record the effective time and scope of permissions, and generate host registration security authentication data;

[0061] S32. Extract the dynamic data (resource usage, process logs, peripheral device records) from the closed-loop data of S24 during the monitoring phase and perform real-time analysis. The real-time analysis includes identifying resource anomalies (such as a sudden increase in memory which may be a malicious process), marking non-whitelisted processes (such as unfamiliar .exe programs), and counting the frequency of unauthorized peripheral device access. Classify and sort abnormal events according to risk level (low / medium / high), and attach the reporting time, scope of impact, and preliminary handling suggestions to generate real-time security status data of the host.

[0062] S33. Based on the hardening records (baseline repair, vulnerability handling, whitelist update) in the closed-loop data of S24, set evaluation indicators. The evaluation indicators include compliance indicators (baseline non-compliance item repair rate, vulnerability repair completion rate) and security indicators (change in virus detection rate after hardening, violation behavior blocking rate). Compare the security data before and after hardening (e.g., 8 high-risk vulnerabilities before hardening, zero after hardening), calculate the indicator values, analyze the reasons for not meeting the standards (e.g., some patches conflict with business), and generate host hardening effect evaluation data.

[0063] S34. Referring to the decommissioning strategy in S14, based on the basic decommissioning information in the closed-loop data in S24, perform data cleanup. The data cleanup includes deleting sensitive files according to the "three-time overwrite" standard, performing a drop table operation on the database, and recording the cleanup path and time; restoring the system to its initial installation state, verifying whether the operating system version and patch level meet the requirements; organizing the cleanup logs, recovery verification report, and hardware recycling certificate, and generating host decommissioning security processing data.

[0064] The working principle and effects of the above technical solution are as follows:

[0065] By comparing hardware fingerprints, manually reviewing offline host credentials, and configuring the least privileges (such as granting monitoring / hardening permissions only to operations and maintenance personnel), the risk of unauthorized hosts accessing the network is reduced, the potential for exceeding operational boundaries due to excessive permission allocation is avoided, and the security of host registration is improved.

[0066] Real-time analysis of resource usage, process logs, and peripheral device records can quickly identify anomalies such as sudden increases in memory and unfamiliar processes. It also classifies anomalies by risk level and provides handling suggestions, reducing the probability of security incidents caused by malicious processes lurking or unauthorized peripheral device access, reducing the situation of missed detection or delayed handling of abnormal events, and enhancing the efficiency of anomaly response during the monitoring phase.

[0067] By comparing data before and after hardening based on compliance (baseline repair rate) and security (changes in virus detection rate) indicators, the hardening effect can be clearly understood. It can also analyze the reasons for non-compliance (such as patch conflicts with business), avoid the waste of resources in blind hardening, reduce the problem of vulnerabilities still existing after hardening, and improve the effectiveness of hardening work.

[0068] By overwriting sensitive data three times and verifying the system recovery status, the risk of leakage caused by data residue is reduced, and retired hardware is prevented from becoming a security hazard due to incomplete processing. This makes the security management throughout the entire life cycle more closed-loop and enhances the security of host retirement.

[0069] In one embodiment of the present invention, step S4 includes:

[0070] S41. Collect the four types of core data generated by S3 (registration and authentication, real-time status, hardening assessment, and decommissioning data), perform preprocessing; convert data of different formats (log text, structured indicators) into a unified format, associate data of each stage with host unique ID, and generate an integrated full lifecycle security dataset.

[0071] S42. Based on the integrated full lifecycle security dataset, construct a situational analysis model. Analyze the trends of security events at each stage in the time dimension (e.g., a 50% decrease in the number of high-risk vulnerabilities detected in the past month); compare the host risks in different network partitions in the spatial dimension (e.g., the rate of unauthorized peripheral device access on production area hosts is lower than that on office area hosts); statistically analyze the distribution of high-risk vulnerabilities and the frequency of malicious behavior in the risk dimension; comprehensively assess the situational level (low / medium / high), locate core risk points (e.g., delayed offline host patch updates), and generate comprehensive host security situational data.

[0072] S43. Based on comprehensive situational data, evaluate the initial framework of S14. The evaluation includes identifying policy vulnerabilities (such as the lack of coverage of "offline host process tampering" monitoring), optimizing parameters (such as adjusting the original "high-risk vulnerability 24-hour repair" to "core host 24 hours, non-core 48 hours" due to insufficient operation and maintenance resources), and supplementing scenarios (such as adding a "security detection before hardware recycling" strategy); record the problems found in the evaluation and the optimization direction, and generate an initial framework adaptability evaluation report;

[0073] S44. Based on the initial framework compatibility assessment report, adjust the initial framework. The adjustments include supplementing offline host process monitoring rules, updating vulnerability remediation time parameters, and adding a hardware recycling detection process. Pilot the new strategy on 2-3 non-core hosts. After verifying that there is no impact on business, update it to the unified security management platform in full and generate optimized security management strategy data.

[0074] The working principle and effects of the above technical solution are as follows:

[0075] By integrating four types of core data, including registration and authentication, and real-time status, and unifying the format and associating them with the host's unique ID, the information gap caused by data fragmentation is reduced, and the problem of data being stored separately at different stages and unable to be analyzed in a coordinated manner is avoided. This provides complete data support for subsequent situation assessment and improves the continuity of security data throughout the entire lifecycle.

[0076] By analyzing multiple dimensions, including time (event trends), space (partition risks), and risk (vulnerability / behavior distribution), we can discover the trend of a 50% decrease in high-risk vulnerabilities in the past month, as well as locate core risks such as the lag in offline host patches. This reduces the probability of missing key hidden dangers due to single-dimensional analysis and enhances the accuracy of security situation assessment.

[0077] During the assessment, it can accurately identify uncovered scenarios (such as offline host process tampering monitoring) and optimize unreasonable parameters (such as adjusting vulnerability repair time limits). This reduces the problem of the original framework being a one-size-fits-all approach that does not fit the actual operation and maintenance situation. It avoids the execution problem of insufficient operation and maintenance resources but still requiring 24-hour repair of all high-risk vulnerabilities, and improves the adaptability of the initial security framework.

[0078] The new policy was first piloted on 2-3 non-core hosts to verify that it had no impact before a full update was implemented. This enhanced the practicality of the optimized policy, reduced the possibility of business interruption caused by blindly adjusting the policy, and enabled security management to both patch vulnerabilities and not hinder business operations, thereby reducing the business risks of policy optimization.

[0079] In one embodiment of the present invention, S42 includes:

[0080] S421. Based on the integrated full lifecycle security dataset generated by S41, a multi-dimensional situational analysis model framework is built: the core indicators of the three major analysis dimensions of time, space, and risk are defined (time dimension includes the frequency of security events and the duration of remediation; space dimension includes network partition risk density and host distribution characteristics; risk dimension includes the proportion of vulnerability levels and the scope of influence of malicious behavior, etc.), the data sources of each indicator are defined (e.g., vulnerability data is taken from hardening assessment data, and behavior logs are taken from real-time status data), the indicator weights are configured (e.g., the weight of high-risk vulnerability proportion is higher than that of medium-risk vulnerability), and a situational analysis model indicator system is generated.

[0081] S422. Extract time series data from each stage of the integrated data in S41 (such as the number of high-risk vulnerabilities detected each week in the past 3 months and the number of times unauthorized peripheral devices are connected each month), calculate the trend change rate using the sliding window statistical method (such as a 50% month-on-month decrease in a certain type of event), visualize key nodes through time series graphs (such as the peak of vulnerability detection corresponding to a certain batch of host access), identify trend anomalies (such as a sudden increase in virus infection in a certain week) and associate them with event background (such as the period of frequent external USB flash drive access), and generate a time-dimensional security trend analysis report.

[0082] S423. Based on the host network partition attributes (such as production area, office area, and isolation area) in the integrated data of S41, aggregate security indicators by spatial dimension, including: calculating the average risk value of hosts in each partition (comprehensive indicators such as vulnerabilities and violations), high-risk event occurrence rate (such as an average of 2 high-risk events per 100 hosts per month in the production area), and policy compliance rate (such as a baseline compliance rate of 98% for hosts in the isolation area). Present the differences in partition risk distribution through heatmaps, analyze the causes of differences (such as a high rate of unauthorized access due to lax peripheral device control in the office area), and generate spatial dimension partition risk comparison data.

[0083] S424. For risk-related indicators (vulnerability level, malicious process type, data leakage risk, etc.) in the integrated data of S41, a risk matrix method is used for quantitative assessment: high-risk vulnerabilities are assigned 5 points according to their impact scope (e.g., affecting core business), and medium-risk vulnerabilities are assigned 3 points; malicious behaviors are assigned 5 points according to their destructive power (e.g., file encryption ransomware), and abnormal connections are assigned 2 points; the risk scores of single hosts and the overall risk are summarized and calculated, and the distribution of high-scoring items is statistically analyzed (e.g., 70% of high-scoring risks are concentrated on offline hosts), generating quantitative assessment results for risk dimensions;

[0084] S425, integrating the time trend of S422, the spatial distribution of S423, and the risk quantification results of S424, assesses the overall situation level based on preset level thresholds (e.g., a comprehensive score of 0-30 indicates low risk, 31-60 indicates medium risk, and 61-100 indicates high risk). If the time dimension shows a decreasing risk trend but the risk in a certain area of ​​the spatial dimension suddenly increases, or the high-scoring items in the risk dimension account for 20%, it is comprehensively judged as medium risk. Simultaneously, the level assessment basis is generated (e.g., "the overall risk is reduced due to timely vulnerability repair in the production area, but the risk of unauthorized access in the office area increases"), forming multi-dimensional situation level assessment data.

[0085] Based on the situation level and analysis results of S425, S426 identifies core risk points: it identifies persistently high-incidence events from time trends (such as delayed offline host patches), identifies high-risk areas from spatial distribution (such as 30% unauthorized software installation rate in the R&D area), and extracts the root causes of high-scoring items from risk quantification (such as weak password reuse leading to account theft); it integrates core risk points, situation level, and characteristics of each dimension into structured data, with risk diffusion warnings (such as "if not fixed, high-risk events are expected to increase by 15% next month"), and generates comprehensive host security situation data.

[0086] The working principle and effects of the above technical solution are as follows:

[0087] By clearly defining the core indicators and weights of the three dimensions of time, space, and risk, the one-sidedness of single-indicator analysis is avoided, the omission of key risks due to missing dimensions is reduced, the situation analysis has a clear framework to support it, and the systematic nature of security situation analysis is improved.

[0088] Using the sliding window statistical method to calculate the rate of change and mark key nodes in the time series graph can intuitively identify anomalies such as a sudden increase in virus infection in a certain week and associate them with the background, reducing the probability of misjudging the development trend of security incidents, reducing the delay in response caused by unclear trends, and enhancing the identification of time trends.

[0089] By aggregating indicators by network partition and presenting differences through heatmaps, it is possible to quickly identify areas with high rates of unauthorized access in office areas. This avoids a vague understanding of risks in different partitions as a whole, reduces the mismatch between resource investment and risk distribution, and improves the visibility of spatial partition risks.

[0090] Using the risk matrix method to quantify and assign values ​​to vulnerabilities and malicious behaviors provides a comparable standard for the risks of high-risk vulnerabilities affecting core business and abnormal connections, reduces the bias of subjective judgment, avoids unreasonable handling of different risks in the same way, and enhances the objectivity of risk assessment.

[0091] By integrating the results of time, space, and risk dimensions for comprehensive risk assessment, and providing specific evidence (such as lowering the risk in the production area but raising it in the office area), the one-sidedness of relying on a single dimension for risk assessment is reduced, making the severity of the security situation more realistic and improving the accuracy of the situation level assessment.

[0092] It accurately identifies core risk points such as delayed offline host patches and provides early warnings of their spread, reducing ineffective investment in non-critical issues, avoiding a scattershot approach to protection, allowing resources to be concentrated on solving real problems, and enhancing the targeted nature of risk management.

[0093] In one embodiment of the present invention, S422 includes:

[0094] From the integrated full lifecycle security dataset generated by S41, time-related indicators for each stage are selected. These strongly correlated indicators include the number of high / medium-risk vulnerabilities detected each week for the past three months, the number and types of unauthorized peripheral device accesses each month, daily virus infection event records, and the security policy compliance rate for each week. The extracted data is then cleaned to generate a standardized time-series dataset.

[0095] Based on the generated standardized time series dataset, the sliding window statistical method (window size set to 7 days, step size 1 day) is used to calculate the trend change rate of each indicator: for vulnerability detection, the percentage difference between the mean within the window and the mean of the previous window is calculated (e.g., the mean of this week decreased by 50% compared to last week); for violation events, the month-on-month growth rate of the cumulative number of times within the window is calculated (e.g., the number of illegal accesses in a certain window increased by 30% month-on-month); the fluctuation of the indicators is quantified by the trend formula (change rate = (current window value - previous window value) / previous window value × 100%), generating time-dimensional trend change rate data;

[0096] Based on trend change rate data, time points where the fluctuation amplitude exceeds a preset threshold (e.g., absolute value of change rate ≥ 30%) are selected as key nodes, including: peak points of vulnerability detection (e.g., 20 high-risk vulnerabilities detected in a certain week, the highest in the past 3 months), points of sudden increase in violations (e.g., 15 sudden increases in the number of violations of USB flash drive access at the beginning of a certain month), and low points of policy compliance rate (e.g., compliance rate drops to 60% in a certain week). The key nodes are visualized using a time-series line chart with event markers. The business background corresponding to the key nodes is marked in the chart (e.g., the peak point corresponds to the batch access of new employee hosts), generating a time-series visualization chart of key nodes.

[0097] Identify trend anomalies from time series graphs: For indicators that are continuously declining (such as vulnerability repair time), if a window suddenly rebounds (e.g., from an average of 8 hours to 24 hours), mark it as an anomaly; for indicators that fluctuate steadily (such as daily virus detection), if a window shows a peak value far exceeding the historical average (e.g., the average is 5 viruses / day, but a window reaches 20 viruses / day), mark it as an anomaly; by tracing back the related records in the S41 integrated data (such as the operation and maintenance logs and peripheral device access records for the time period corresponding to the anomaly), analyze the causes of the anomalies (e.g., the rebound in repair time is due to operation and maintenance personnel taking time off, and the peak in virus detection is due to the batch access of external USB drives), and generate a trend anomaly point and cause analysis table;

[0098] Integrating trend change rate data, time series graphs, and anomaly analysis, a report is generated according to the structure of indicator type, trend description, key nodes, and anomaly causes. The report includes: for vulnerability indicators, an explanation that "the overall number of high-risk vulnerability detections has decreased by 50% in the past three months, but a peak occurred in the fifth week due to new host access"; for violations, an explanation that "the number of unauthorized peripheral device accesses fluctuates and decreases each month, with a sudden increase in temporary projects in the third week of February, leading to the access of related external collaborative USB drives." The report also includes dynamic trend predictions (e.g., "If the current remediation efficiency is maintained, the number of vulnerability detections is expected to decrease by another 15% next month"), forming a time-dimensional security trend analysis report.

[0099] The working principle and effects of the above technical solution are as follows:

[0100] By screening and cleaning core indicators that are strongly correlated with time (such as the number of vulnerabilities detected and the number of unauthorized accesses), the interference of messy data on the analysis is reduced, and the bias in trend judgment caused by non-standard data is avoided, laying a solid foundation for subsequent analysis and improving the reliability of time series data.

[0101] The sliding window method is used to calculate specific change rates (such as a 50% month-on-month decrease in the number of vulnerabilities detected), transforming vague descriptions such as reduced risk and increased violations into measurable values. This reduces subjective errors based on experience, makes security trend fluctuations clear at a glance, and enhances the quantitative clarity of trend changes.

[0102] Adding business background markers to time series graphs (such as vulnerability peaks corresponding to new employee host access) can intuitively show the causes of important time points, reduce the time cost of finding patterns in pure data, avoid missing critical events that affect security, and improve the efficiency of identifying key nodes.

[0103] Accurate identification of anomalies (such as a sudden increase in repair time) and tracing back to the cause (such as maintenance personnel taking time off) reduces the risk of anomalies escalating; the trend predictions attached to the report (such as the expected 15% decrease in vulnerability detections next month) also reduce the blindness of subsequent maintenance decisions, make resource allocation more targeted, and accelerate the pace of handling anomalies.

[0104] In one embodiment of the present invention, step S5 includes:

[0105] S51. Based on the optimized security management strategy data, design an active defense scheme. The active defense scheme includes a risk prediction level, which configures "pre-access scanning + post-access monitoring" rules for high-frequency risks (USB virus propagation); a dynamic response level, which sets up a "abnormal process → automatic isolation → alarm maintenance" process; a collaborative defense level, which synchronizes online host vulnerability characteristics to portable tools; and deploys security management strategies on the platform, records execution time, number of hosts covered, and handling results (such as blocking unauthorized USB flash drives from accessing the platform 12 times), and generates active defense execution data for the hosts.

[0106] S52, the base defense execution data and the data of each stage of S3 are used to establish a traceability mechanism. The traceability mechanism includes event traceability (such as tracing a virus event to the source of a USB flash drive access and the propagation path), responsibility traceability (such as the operation and maintenance personnel who failed to fix the vulnerability on time), and data traceability (retrieving the baseline comparison records before and after hardening); compile traceability reports, responsibility determination results, and historical data lists to generate full-lifecycle traceable management data for the host.

[0107] S53. Based on the full lifecycle traceable management data of the host, set early warning thresholds (such as three hosts detecting the same high-risk vulnerability within one hour triggering an area early warning) and monitoring indicators (sudden increase in the frequency of defense rule triggering and escalation of situation level); build a real-time early warning model to continuously monitor the security status of the host. Once the threshold is triggered, it automatically generates early warning information (including type, level, handling suggestions, and deadline), generating full lifecycle security early warning data for the network host.

[0108] S54. Push the early warning data to the responsible person (low-risk push to the maintenance team, high-risk synchronize with the security manager) via SMS and platform messages, track the handling progress (such as the completion status of vulnerability repair); record the early warning response time, handling results, and control effects (such as repairing high-risk vulnerabilities within 2 hours after the early warning and preventing their spread), form a risk control closed loop of early warning-handling-verification, and generate full lifecycle risk control result data.

[0109] The working principle and effects of the above technical solution are as follows:

[0110] For high-frequency risks such as USB-borne viruses, it can perform pre-access scanning and post-access monitoring, and can also automatically isolate abnormal processes and synchronize vulnerability characteristics to portable tools, reducing the chance of virus spread after intrusion, lowering the probability of actual security incidents, avoiding the passive situation of waiting for an incident to occur before dealing with it, and improving the initiative of risk interception.

[0111] Whether it's the virus transmission path, the person responsible for failing to fix vulnerabilities on time, or the baseline changes before and after hardening, the traceability mechanism can quickly pinpoint the source, reducing the chance of not being able to find the source, lowering the possibility of similar problems recurring, making responsibility identification and experience summarization more efficient, and enhancing the clarity of problem tracing.

[0112] Setting a warning threshold for three hosts detecting the same high-risk vulnerability within one hour, and monitoring the frequency of defense rule triggers and changes in the status level in real time, can alert and address risks before they escalate, reducing the risk of small vulnerabilities turning into major incidents, avoiding the aggravation of losses due to late detection, and increasing the lead time for vulnerability detection.

[0113] The warnings are pushed to the corresponding responsible persons according to their levels. The progress of the repair is also tracked and the effect of the handling is recorded, forming a closed loop of warning-handling-verification. This reduces the situation where warnings are issued but no one pays attention or the handling is ineffective. It also reduces the additional losses caused by untimely or inadequate handling and enhances the integrity of risk handling.

[0114] One embodiment of the present invention provides a network host full lifecycle security management system, comprising:

[0115] One or more processors;

[0116] Memory, used to store one or more programs.

[0117] Wherein, when the one or more programs are executed by the one or more processors, the one or more processors are made to implement the method described in any one of the above.

[0118] Obviously, those skilled in the art can make various modifications and variations to this invention without departing from its spirit and scope. Therefore, if these modifications and variations fall within the scope of the claims of this invention and their equivalents, this invention also intends to include these modifications and variations.

Claims

1. A method for full lifecycle security management of network hosts, characterized in that, The method includes: S1. Divide the network private server into stages throughout its entire lifecycle, generate core stage data, build a unified security management platform based on the core stage data, and uniformly orchestrate security policies for each stage to form initial security management framework data. S2. Based on the initial security management framework data, deploy a real-time execution module on the client. At the same time, use portable tools to harden the offline host, generate offline host hardening data, and import the hardening data into the unified security management platform to form online-offline collaborative initial policy closed-loop management data. S3. Based on the initial strategy closed-loop management data of online-offline collaboration, perform corresponding processing on different core stages to obtain the corresponding data; S4. Perform a fusion analysis of the host's security posture throughout its entire lifecycle using relevant data to generate comprehensive host security posture data; use the comprehensive host security posture data to optimize and adjust the initial security management framework data to form optimized security management strategy data; S5. Based on the optimized security management strategy data, deploy proactive defense strategies and generate host proactive defense execution data; perform risk tracing management for each stage of the host's entire lifecycle based on the host proactive defense execution data, and generate host full lifecycle traceable management data; perform risk warning processing based on the host full lifecycle traceable management data, and generate network host full lifecycle security warning data.

2. The network host full lifecycle security management method according to claim 1, characterized in that, S1 includes: S11. Based on the actual operation and maintenance process of the network dedicated host, determine the business boundaries of the core stage, sort out the key operation nodes of each stage, and generate the full life cycle stage division standard. S12. Based on the generated stage division standard, define core data dimensions for each stage, standardize the fields of the core data, and generate core stage structured data. S13. Based on the core stage's structured data storage and interaction requirements, build the platform's core architecture, deploy the platform and debug modules, and generate unified security management platform infrastructure data. S14. Based on the platform architecture, orchestrate security policies for each stage, input the security policies into the platform and configure execution trigger conditions to form initial security management framework data.

3. The network host full lifecycle security management method according to claim 2, characterized in that, The security strategy includes: configuring hardware fingerprint + account password two-factor authentication rules and least privilege allocation strategy during the registration phase; setting resource thresholds and abnormal behavior identification rules during the monitoring phase; formulating Level 3 security protection baseline standards and 24-hour high-risk vulnerability repair rules during the hardening phase; and clarifying the sensitive data three-time overwrite and cleanup process and system recovery verification standards during the decommissioning phase.

4. The network host full lifecycle security management method according to claim 1, characterized in that, S2 includes: S21. Based on the monitoring-hardening phase strategy requirements in the initial security management framework, develop the core functional modules of the client, adapt the client version according to the host operating system, complete the module installation and parameter configuration of the online host, and generate client deployment configuration data. S22. Start the deployed client module, execute operations according to the platform policy, and upload it to the unified security management platform in real time to form the initial security dataset of online hosts; S23. For offline hosts, use a portable tool with a pre-defined framework strategy to process and generate offline host hardening data; S24. Import the generated offline host hardening data into the unified security management platform in the form of encrypted files and integrate it with the initial security dataset of online hosts. The platform performs correlation matching between the two types of data, verifies the consistency of policy execution, and forms the initial policy closed-loop management data for online-offline collaboration.

5. The network host full lifecycle security management method according to claim 4, characterized in that, The operation performed according to the platform policy specifically includes: the baseline scanning module performs a full compliance scan on the online host, marks non-compliant items, and generates initial security baseline data for the host; the peripheral device management module monitors peripheral device access in real time, records device information and operation behavior, blocks unauthorized access, and generates peripheral device usage management data; and the virus protection module performs a full scan, records virus detection and isolation results, and generates virus protection status data.

6. The network host full lifecycle security management method according to claim 1, characterized in that, The S3 includes: S31. Based on the basic information of the registration stage in the collaborative closed-loop management data, perform identity authentication. After successful authentication, configure operation permissions for the host according to the least privilege allocation strategy, record the effective time and scope of the permissions, and generate host registration security authentication data. S32. Extract dynamic data from the monitoring phase of the closed-loop data, perform real-time analysis, classify and sort abnormal events according to risk level, and attach reporting time, impact scope, and preliminary handling suggestions to generate real-time security status data of the host. S33. Based on the reinforcement records in the closed-loop data, set evaluation indicators; compare the safety data before and after reinforcement, calculate the indicator values, analyze the reasons for non-compliance, and generate host reinforcement effect evaluation data. S34. Referring to the decommissioning strategy, based on the basic decommissioning information in the closed-loop data, perform data cleanup, restore the system to its initial installation state, and verify whether the operating system version and patch level meet the requirements; organize and clean up the logs, restore the verification report, and hardware recycling certificate, and generate host decommissioning security processing data.

7. The network host full lifecycle security management method according to claim 1, characterized in that, The S4 includes: S41. Obtain the four types of core data generated and perform preprocessing; convert data of different formats into a unified format, associate data of each stage with host unique ID, and generate an integrated full lifecycle security dataset. S42. Based on the integrated full lifecycle security dataset, construct a situation analysis model; comprehensively assess the situation level, locate core risk points, and generate comprehensive host security situation data. S43. Based on the integrated situational data, evaluate the initial framework, record the problems found in the evaluation and the optimization direction, and generate an initial framework adaptability evaluation report. S44. Based on the initial framework compatibility assessment report, adjust the initial framework, pilot the new strategy on 2-3 non-core hosts, and after verifying that there is no impact on business, update it to the unified security management platform to generate optimized security management strategy data.

8. The network host full lifecycle security management method according to claim 7, characterized in that, S42 includes: S421. Based on the generated and integrated full lifecycle security dataset, build a basic framework for a multi-dimensional situational analysis model and generate a situational analysis model indicator system. S422. Extract time series data from each stage of the integrated data, calculate the trend change rate using the sliding window statistical method, visualize key nodes through time series graphs, identify trend anomalies and associate them with event backgrounds, and generate a time-dimensional security trend analysis report. S423. Based on the host network partition attributes in the integrated data, aggregate security indicators by spatial dimension, present the differences in partition risk distribution through heat map, analyze the causes of differences, and generate spatial dimension partition risk comparison data. S424. For risk-related indicators in the integrated data, use the risk matrix method to conduct quantitative assessment and generate quantitative assessment results for risk dimensions. S425. Integrating time trends, spatial distribution, and risk quantification results, the overall situation level is assessed based on preset level thresholds; the assessment criteria are generated simultaneously, forming multi-dimensional situation level assessment data; S426. Based on the situation level and analysis results of each dimension, locate the core risk points; integrate the core risk points, situation level, and characteristics of each dimension into structured data, attach risk diffusion warning, and generate comprehensive host security situation data.

9. The network host full lifecycle security management method according to claim 1, characterized in that, The S5 includes: S51. Based on the optimized security management policy data, design an active defense scheme, deploy security management policies on the platform, record execution time, number of hosts covered, and handling results, and generate host active defense execution data. S52, base defense execution data and data at each stage, establish a traceability mechanism; compile traceability reports, responsibility determination results, and historical data lists to generate full-lifecycle traceable management data for the host; S53. Based on the full lifecycle traceable management data of the host, set early warning thresholds and monitoring indicators; build a real-time early warning model to continuously monitor the security status of the host. Once the threshold is triggered, early warning information is automatically generated, generating security early warning data for the entire lifecycle of the network host. S54. Push early warning data to the responsible person via SMS and platform messages, track the progress of handling; record the early warning response time, handling results, and control effects to form a risk control closed loop of early warning-handling-verification, and generate full life cycle risk control result data.

10. A network host full lifecycle security management system, characterized in that, The system includes: One or more processors; Memory, used to store one or more programs; Wherein, when the one or more programs are executed by the one or more processors, the one or more processors implement the method of any one of claims 1 to 9.