File security monitoring method, device and equipment

By deploying file probes on multiple target servers and using secure channels to transmit real-time monitoring strategies, cross-platform real-time monitoring and alarms are achieved. This solves the technical problems existing in the prior art, ensures communication security and data integrity, reduces false alarms in file monitoring and alarms, improves alarm management efficiency and accuracy, and realizes closed-loop management of the entire file lifecycle.

CN121615128APending Publication Date: 2026-03-06HEFEI TANOVO INFORMATION SECURITY TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511815187.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-04
Publication Date
2026-03-06

AI Technical Summary

Technical Problem

Existing file monitoring solutions suffer from limitations in monitoring scope and real-time performance, insufficient cross-platform compatibility, risks to communication security and data integrity, and false alarms during routine operations, leading to delayed security responses and increased operational complexity.

Method used

By acquiring file probes from multiple target servers and utilizing a secure channel for real-time file transmission monitoring, cross-platform real-time monitoring and alarms are achieved. National cryptographic encryption methods are employed to ensure communication security, and an intelligent aggregation mechanism is used to reduce false alarms.

Benefits of technology

It enables real-time file monitoring across platforms, improves the efficiency and accuracy of alarm management, ensures communication security and data integrity, reduces the fatigue of operation and maintenance personnel, and realizes closed-loop management of the entire file lifecycle.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121615128A_ABST
    Figure CN121615128A_ABST
Patent Text Reader

Abstract

The invention provides a file security monitoring method, device and equipment. The method comprises the following steps: acquiring a plurality of to-be-monitored target servers which are input by a user and are provided with different operating systems; according to the target server, obtaining a target file probe installed on the target server; acquiring a file real-time monitoring strategy of a target file probe installed on the target server, and transmitting the file real-time monitoring strategy to the target file probe through a secure channel; through the secure channel, obtaining a monitoring result of real-time monitoring and warning of the file operation state on the target server by the target file probe according to the file real-time monitoring strategy; and decrypting the monitoring result and displaying the decrypted monitoring result on a display interface of the platform end. According to the scheme, the communication security and the data integrity can be ensured, the specified file range is monitored, efficient and flexible alarm aggregation and remote strategy management capability can be provided, and false alarm caused by a large number of conventional operations is prevented.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of information security technology, and in particular to a method, apparatus and equipment for file security monitoring. Background Technology

[0002] With the deepening application of information technology in various industries, enterprises and organizations have an increasing demand for the security of core business data and important documents. Especially in critical information infrastructure and scenarios involving sensitive data, if sensitive operations on important documents are not effectively monitored, they can easily lead to serious security incidents such as data leakage, tampering, or unauthorized access. Existing file monitoring solutions typically rely on operating system logs or specific application interfaces, failing to cover all critical file operation types (such as privilege escalation operations). Furthermore, data collection and transmission suffer from latency, making it difficult to achieve real-time monitoring and alerts at the second or even millisecond level, resulting in delayed security responses. Additionally, most file monitoring tools typically support only a single operating system environment, lacking compatibility with mainstream operating systems, causing inconvenience for unified deployment and management in heterogeneous environments, increasing operational costs and complexity. Moreover, communication between platforms often lacks sufficient encryption protection during transmission, posing a risk of sensitive alert information being eavesdropped on or tampered with. Furthermore, network fluctuations or disconnections prevent effective caching of alert data, easily leading to data loss and hindering the tracing and analysis of security incidents. Most importantly, conventional file monitoring alerts often contain numerous non-truthful operations, causing security personnel to become fatigued due to excessive abnormal alerts, resulting in the neglect of genuine threat operations. Summary of the Invention

[0003] This invention provides a file security monitoring method, apparatus, and device, which solves the problems of limited monitoring scope and real-time performance, insufficient cross-platform compatibility, risks to communication security and data integrity, and a large number of false alarms during routine operations.

[0004] To solve the above-mentioned technical problems, the technical solution of the present invention is as follows: This invention provides a file security monitoring method, including: Acquire user input regarding multiple target servers with different operating systems installed that are to be monitored; Based on the target server, obtain the target file probe installed on the target server; Obtain the real-time file monitoring policy of the target file probe installed on the target server and transmit it to the target file probe through a secure channel; The security channel is used to obtain the monitoring results of the target file probe's real-time monitoring and alarm on the file operation status on the target server according to the real-time file monitoring strategy. The monitoring results are decrypted and displayed on the platform's interface.

[0005] Optionally, based on the target server, obtain the target file probe installed on the target server, including: Based on the binding relationship between the target server and the file probe, determine the identification code; Based on the identifier of the target server, obtain the target file probe installed on the target server.

[0006] Optionally, the real-time file monitoring policy of the target file probe installed on the target server is obtained and transmitted to the target file probe through a secure channel, including: Obtain the file real-time monitoring policy configured by the user, wherein the file real-time monitoring policy includes at least one of the following: the file directory path to be monitored, the file extension type to be monitored, and the file operation type to be monitored; The real-time file monitoring strategy is sent to the corresponding target file probe through the secure channel.

[0007] Optionally, the real-time file monitoring strategy is distributed to the corresponding target file probe via the secure channel, including: The real-time file monitoring strategy is encrypted using the first encryption method of the secure channel to obtain the encrypted real-time file monitoring strategy. The encrypted file real-time monitoring strategy is sent to the corresponding target file probe.

[0008] Optionally, through the secure channel, the monitoring results of the target file probe performing real-time monitoring and alarms on the file operation status on the target server according to the real-time file monitoring strategy are obtained, including: The secure channel receives encrypted monitoring results sent by the target file probe; wherein the monitoring results are encrypted monitoring results obtained by the target file probe in real time monitoring the file operation status on the target server according to the real-time file monitoring strategy after intelligent aggregation and encryption processing, and the encrypted monitoring results are obtained by encryption calculation using the second encryption method of the secure channel.

[0009] Optionally, the monitoring results are decrypted and displayed on the platform's display interface, including: According to the decryption and verification method corresponding to the second encryption method of the secure channel, the encrypted monitoring results obtained through the secure channel are decrypted and verified to obtain the monitoring results to be displayed. The monitoring results to be displayed are shown on the user interface of the platform according to their urgency.

[0010] Optional, also includes: An alarm notification is generated based on the monitoring results to be displayed.

[0011] This invention also provides a file security monitoring device, comprising: The acquisition module is used to acquire user input regarding multiple target servers to be monitored, each with different operating systems installed. The processing module is used to: obtain the target file probe installed on the target server; obtain the real-time file monitoring policy of the target file probe installed on the target server and transmit it to the target file probe through a secure channel; obtain the monitoring results of the target file probe's real-time monitoring and alarm on the file operation status on the target server according to the real-time file monitoring policy through the secure channel; and decrypt the monitoring results and display them on the display interface of the platform.

[0012] This invention also provides a computing device, including: a processor and a memory storing a computer program, wherein the computer program, when run by the processor, executes the above-described method.

[0013] This invention also provides a computer-readable storage medium storing instructions that, when executed on a computer, cause the computer to perform the above-described method.

[0014] The technical solution of the present invention has at least the following effects: The above-described solution of the present invention obtains multiple target servers with different operating systems installed, input by the user, to be monitored; obtains target file probes installed on the target servers; obtains the real-time file monitoring strategy of the target file probes installed on the target servers and transmits it to the target file probes through a secure channel; obtains the monitoring results of the target file probes' real-time monitoring and alarming of file operation status on the target servers according to the real-time file monitoring strategy through the secure channel; and decrypts and displays the monitoring results on the display interface of the platform. This ensures communication security and data integrity, monitors a specified file range, provides efficient and flexible alarm aggregation and remote policy management capabilities, and prevents false alarms caused by numerous routine operations. Attached Figure Description

[0015] Figure 1 This is a flowchart of the file security monitoring method provided in the embodiments of the present invention; Figure 2 This is a core workflow diagram provided by an embodiment of the present invention; Figure 3 This is a structural diagram of the file security monitoring device provided in an embodiment of the present invention; Figure 4This is a schematic diagram of the structure of the computing device provided in an embodiment of the present invention. Detailed Implementation

[0016] Exemplary embodiments of the invention will now be described in more detail with reference to the accompanying drawings. While exemplary embodiments of the invention are shown in the drawings, it should be understood that the invention may be implemented in various forms and should not be limited to the embodiments set forth herein. Rather, these embodiments are provided so that this invention will be thorough and complete, and will fully convey the scope of the invention to those skilled in the art.

[0017] like Figure 1 and Figure 2 As shown, an embodiment of the present invention proposes a file security monitoring method, applied to a platform, comprising: Step 11: Obtain the user-input data for multiple target servers with different operating systems installed to be monitored; Step 12: Obtain the target file probe installed on the target server based on the target server; Step 13: Obtain the real-time file monitoring policy of the target file probe installed on the target server and transmit it to the target file probe through a secure channel; Step 14: Obtain the monitoring results of the target file probe's real-time monitoring and alarm on the file operation status on the target server according to the real-time file monitoring strategy through the secure channel; Step 15: Decrypt the monitoring results and display them on the display interface of the platform.

[0018] In this embodiment, in step 11, multiple target servers to be monitored, each with a different operating system installed, are obtained from user input. These multiple target servers have different operating systems installed, such as Windows or Linux.

[0019] In step 12, a unique identifier is generated for each different server, and each unique identifier corresponds to one server. The unique identifier is configured in the file probe's configuration file to achieve a one-to-one binding between the file probe and the server (asset). This means that a one-to-one mapping relationship has been established between the file probe and the asset. After binding, the platform can find the target file probe corresponding to the server based on the unique identifier in the saved server information.

[0020] In step 13, a file probe program is run on the target server. After the probe program starts, it automatically establishes a connection with the platform via encrypted communication. This connection is bidirectional, and the system monitors the status of the connection channel in real time, including connection success and connection failure. Once the platform successfully establishes a connection with the file probe, the platform synchronizes the current real-time file monitoring strategy to the corresponding probe through a secure channel. The probe receives the strategy and it takes effect immediately.

[0021] In step 14, the file probe monitors the specified file operations in real time using the system-level application programming interface (API) according to the monitoring strategy. Once an alarm event that meets the conditions is detected, the file probe will perform intelligent aggregation to obtain the monitoring results.

[0022] In step 15, when the file probe successfully connects to the platform, it pushes the monitoring results to the platform in real time using commercial encryption. If the file probe disconnects from the platform, it caches the monitoring results locally. Once the connection is restored, the file probe automatically pushes the cached offline monitoring results to the platform. After receiving the monitoring results, the platform displays them to the user through a visualization page.

[0023] This technical solution comprehensively enhances the cross-platform capabilities of file monitoring. By building a highly secure end-to-end communication system, it ensures the integrity and real-time delivery of abnormal information, significantly improves the efficiency and accuracy of alarm management, and realizes closed-loop management of the entire file lifecycle.

[0024] In an optional embodiment of the present invention, step 11, obtaining the user-inputted list of multiple target servers to be monitored, each with a different operating system installed, may include: Step 111: Obtain the user-inputted multiple target servers with Windows operating systems installed to be monitored; Step 112: Obtain the user-input data for multiple target servers with Linux operating systems installed to be monitored.

[0025] In this embodiment, the platform corresponds to multiple target servers, including servers with Windows operating systems, servers with Linux operating systems, and servers with other mainstream operating systems. These multiple target servers are registered with the platform by the user as asset information. This asset information includes management information such as asset name (server name), network protocol (Internet Protocol, IP) address, responsible person, department, and operating system type. Users can add detailed asset information through a graphical user interface and assign corresponding security personnel and maintenance staff to each asset.

[0026] In an optional embodiment of the present invention, step 12, obtaining the target file probe installed on the target server according to the target server, may include: Step 121: Determine the identification code based on the binding relationship between the target server and the file probe; Step 122: Obtain the target file probe installed on the target server based on the identifier code of the target server.

[0027] In this embodiment, the file probe refers to a lightweight software program installed on the server to be monitored. The file probe runs in the background of memory with system-level (highest level) privileges, consuming very few resources, to acquire all user operations. Simultaneously, the file probe performs monitoring by calling the operating system's system-level APIs, forming a complete monitoring system in conjunction with the platform. Based on the asset information of the target server registered by the user, a unique identifier corresponding to the target server can be obtained. This identifier can be generated through random allocation by the platform or through a combination of inherent server attributes, such as a Media Access Control (MAC) address + host serial number + operating system.

[0028] By binding the identifier code to the probe one-to-one, the server asset and the file probe are accurately associated. Specifically, when the file probe is deployed, it has a local configuration file, and the unique identifier code is configured in the configuration file to complete the static binding between the file probe and the asset. The platform obtains the target file probe by searching for the file probe with the same identifier code as the target server.

[0029] In an optional embodiment of the present invention, step 13, obtaining the real-time file monitoring policy of the target file probe installed on the target server and transmitting it to the target file probe through a secure channel, may include: Step 131: Obtain the file real-time monitoring strategy configured by the user. The file real-time monitoring strategy includes at least one of the following: the file directory path to be monitored, the file extension type to be monitored, and the file operation type to be monitored. Step 132: The real-time file monitoring strategy is sent to the corresponding target file probe through the secure channel.

[0030] In this embodiment, in step 131, the real-time file monitoring strategy is an execution plan configured by the administrator for the file probe in the user interface on the platform. The real-time file monitoring strategy includes at least one of the following: the file directory path to be monitored, the file extension type to be monitored, and the file operation type to be monitored. The real-time file monitoring strategy can be flexibly adjusted, and the adjusted strategy can take effect immediately and be synchronized to the file probe through a secure channel. It also supports batch addition and modification of real-time file monitoring strategies, which greatly improves management efficiency.

[0031] In step 132, the probe establishes an initial connection with the platform through the basic communication protocol. Since the initial connection channel cannot guarantee secure information transmission, it is necessary to encrypt the initial connection channel using the national cryptographic algorithm to obtain a secure channel, ensuring the confidentiality, integrity, and immutability of abnormal information of the monitoring results during transmission, and meeting high-level security compliance requirements.

[0032] The initial connection establishment process is completed by the file probe calling the operating system's interface. The corresponding interfaces for the Linux operating system are the socket interface and the connect interface; the corresponding interface for the Windows operating system is the Windows Sockets Application Programming Interface (WSAConnect). The specific connection process includes: the platform starts a service to listen for any activity on a specific port and wait for the probe to connect; after the file probe starts, it actively initiates a connection request to the platform's IP address and port; the two parties establish a communication connection through a three-way handshake process; once the connection is successfully established, this communication link will be maintained unless the network is interrupted or one party actively disconnects.

[0033] The secure channel employs Chinese national cryptographic encryption. The specific process is as follows: The platform presents its secure digital certificate to the probe, which verifies whether the certificate was issued by a trusted root certificate authority to confirm the platform's legitimacy. The probe also configures a client security certificate to prove its legitimacy to the platform, achieving two-way authentication and preventing impersonation. Subsequently, both parties use a key exchange protocol to collaboratively calculate a shared master key known only to both parties without transmitting the key itself, completing the key negotiation process. Both parties confirm that subsequent communication will use the same Chinese national cryptographic encryption algorithm key for data encryption, and then use a different Chinese national cryptographic decryption algorithm key corresponding to the encrypted key for decryption and data integrity verification; thus completing the establishment of the secure channel.

[0034] When the connection status is successful, the platform will synchronize the real-time file monitoring strategy to the file probe through a secure channel. This process implies that the target file probe is encrypted, transmitted, and transformed, which can effectively transform the actual monitoring intent (real-time file monitoring strategy) into an action plan that the probe can execute. The action plan is a set of instructions that the file probe needs to execute. The monitoring strategy will specify the monitoring scope, monitoring actions, and ignore rules, including the monitored directories, file types, operations, and ignored files.

[0035] The process of encrypting all incoming and outgoing messages includes: when the real-time file monitoring strategy is actively sent to the corresponding target file probe, the real-time file monitoring strategy is encrypted using a first encryption method; and the monitoring results are encrypted using a second encryption method before the file probe sends the monitoring results.

[0036] After a secure channel is established between the file probe and the platform, the current connection status of the secure channel can be determined. The connection status includes successful connection (online) and failed connection (offline). When the connection status is successful, the file probe and the platform can send data to each other; when the connection status is failed, data cannot be transmitted.

[0037] The specific encryption and decryption process of the first encryption method of the real-time file monitoring strategy includes: The platform generates a cryptographically secure strong random number for each instruction, concatenates the random number with the shared master key, and then uses a key-derived master function to calculate the hash value of the concatenated data. This hash value is the temporary key required for this encryption. The temporary key is used to encrypt the real-time file monitoring strategy using an encryption function to obtain ciphertext. For example, the operation method can be an XOR operation. After the calculation is completed, the platform sends the random number and ciphertext together to the probe, without sending the temporary key.For example, the real-time file monitoring strategy issued by the platform at this time is to adjust the monitoring log level to DEBUG. The specific process is as follows: the plaintext instruction of the original data is data="SET_LOG_LEVEL=DEBUG"; at this time, the generated random number is Nonce="a7f3d9e1", and the shared master key is concatenated with the random number to obtain the concatenated data CombinedString="MySecretMasterKey123a7f3d9e1"; the SM3 hash algorithm is used as the key derivation function to obtain the temporary key K_temp=SM3(CombinedString) ="5f4d7a...c3b1a9" (a total of 64 hexadecimal characters); through message_bytes=string_to_bytes The plaintext command ("SET_LOG_LEVEL=DEBUG") is converted into bytes. The temporary key is then converted into a byte stream using `key_stream=hex_string_to_bytes(K_temp)`. The plaintext command bytes and the key byte stream are XORed for encryption. The encrypted ciphertext bytes are then converted into a hexadecimal string, i.e., the encrypted string `ciphertext_hex="0c230f..."`. After obtaining the encrypted string, the encrypted string, a random number, and a command type identifier are combined to form a data packet `{"type":"CMD","nonce":"a7f3d9e1","ciphertext_hex":"0c230f..."}`, which is sent to the probe. The command type identifier is used to mark this... The encryption key derivation function and operation encryption method are used; the target file probe finds the corresponding key derivation function and operation encryption method through the instruction type identifier "type":"CMD"; concatenated data is obtained by concatenating the shared master key with a random number, and a temporary key K_temp is calculated using the found key derivation function SM3 hash algorithm; the received ciphertext data "ciphertext_hex":"0c230f..." is converted from a hexadecimal string to a ciphertext byte array, and the temporary key is converted into a byte stream by key_stream=hex_string_to_bytes(K_temp); the ciphertext byte array and the key byte stream are XORed to decrypt the data to obtain a plaintext byte array, and the plaintext byte array is converted into a string to obtain the plaintext instruction of the original data.

[0038] In an optional embodiment of the present invention, step 14, obtaining the monitoring results of the target file probe's real-time monitoring and alarming of file operation status on the target server according to the real-time file monitoring strategy through the secure channel, may include: Step 141: Receive the encrypted monitoring result sent by the target file probe through the secure channel; wherein, the monitoring result is the encrypted monitoring result of the target file probe performing real-time monitoring of the file operation status on the target server according to the real-time file monitoring strategy after intelligent aggregation and encryption processing, and the encrypted monitoring result is obtained by encryption operation using the second encryption method of the secure channel.

[0039] In this embodiment, this step requires extracting potentially security-threatening operation events from a massive amount of raw file operation events. The file probe utilizes a system-level API to achieve real-time, high-precision monitoring of specified sensitive file directories and file extensions, enabling instant capture of sensitive and critical file operations. The file probe captures and generates a raw event anomaly message, including: timestamp, unique identifier, file path, operation type, user, and operation result. However, the number of anomaly messages obtained at this stage is large, including both operations that truly pose a security threat to the system and routine operations that do not. Since not all of these can be reported, intelligent aggregation is needed to filter the initially obtained anomaly messages.

[0040] The intelligent aggregation includes: for N consecutive abnormal events within a preset time window T, originating from the same asset, targeting the same file path F, and with an operation type of O, aggregating them into a single monitoring result, wherein the monitoring result records the time of the first event. Last event time And the total number of events N, thereby compressing N abnormal information alarms into 1; When the number of abnormal messages generated within a unit time Δt exceeds the threshold M, a rate limiting mechanism is activated. The rate limiting strategy is based on the event priority P, and the event priority is calculated using the formula: P = * + * ,in: It is the weighting coefficient of the operation type (for example, the weight of "delete" can be set to be greater than that of "read"); It is a quantified value of the operation type, which is preset based on the potential impact of different file operations on system security and integrity; It is the weighting coefficient of the user (for example, "super user" has a greater weight than "regular user"); It is the user's quantification value, which is preset based on the identity of the subject performing the file operation and its default permission level.

[0041] The system prioritizes reporting the top K anomaly messages with the highest priority P, thereby solving the network congestion and maintenance personnel fatigue caused by the proliferation of anomaly messages. This ensures that the highest-risk events are handled first. For example, if the system generates 3 anomaly messages in an instant and requires rate limiting, only 1 of them can be reported. Examples of settings are shown in Table 1. Examples of settings are shown in Table 2; Table 1 Example of settings

[0042] Table 2 Example of settings

[0043] Assuming the weighting coefficients are set as follows: =0.6 (more focused on the operation itself), =0.4 (also considering the executor).

[0044] First abnormal message (simplified): User 001 (ordinary user, =3) Delete ( If a log file has an event priority of 10, then its event priority is... =0.6*10+0.4*3=6+1.2=7.2; Second error message (simplified): User root (super user), =10) Modify ( =7) If a configuration file is provided, then its event priority is... =0.6*7+0.4*10=4.2+4=8.2; Third error message (simplified): Process unknown.exe (unknown process, =6) Create ( =4) If an executable file is provided, its event priority is... =0.6*4+0.4*6=2.4+2.4=4.8; After calculation, the priority order is as follows: (8.2)> (7.2)> (4.8) The system will report the second abnormal information. At this time, the comprehensive risk score of the second abnormal information is the highest, which is the monitoring result that really needs to be reported and alarmed.

[0045] In addition, when the monitoring results need to be reported to the platform, the monitoring results need to be encrypted using a second encryption method to ensure communication security.

[0046] The specific example of the encryption and decryption process using the second encryption method for monitoring results is as follows: The raw data to be transmitted is message='{"timestamp":20251127100000,"asset_id": The message data is encrypted using the formula: `server-001", "file_path": " / etc / app / config.conf", "operation": "delete", "user": "root", "process_id": 12345}`, resulting in a fixed-length (256 bits / 32 bytes) hash value, `hash = SM3(message)`. This hash value is a unique identifier for the data; any change to the data will result in a completely different hash value. The hash value is then signed using `signature = SM2_Sign(probe_private_key, hash)`, yielding a signature. This signature can be opened with the corresponding public key, where `probe_private_key` is the private key for signing. The original data, hash value, and signature are combined into a complete data packet and converted into a string. Finally, the string is encrypted using the national cryptographic algorithm key negotiated during the establishment of the secure channel, i.e., `encrypted_payload = SM4_Encrypt(session_key)`. The process involves generating the encrypted payload (payload_bytes), where payload_bytes is a string and session_key is the negotiated key. The data is then transmitted through a secure channel. The received data is decrypted using the session key to obtain a string, which is then decomposed into the original data, a hash value, and a signature. The signature is verified using the public key corresponding to the signature private key to confirm that it was generated from the corresponding hash value. Upon successful verification, the hash value of the received message is recalculated and compared with the received hash. If they match, the data has been transmitted securely and completely.

[0047] When the platform is offline or network fluctuations cause connection failure, the file probe itself has the ability to persistently store monitoring results locally. It automatically records the monitoring results of all abnormal information that occurred during the platform's offline period. Once the connection is successfully reconnected, the file probe will uniformly push back the monitoring results from the offline period, thereby ensuring that the abnormal information data is complete and not lost. Specifically, the file probe assigns a monotonically increasing sequence number Seq to each cached monitoring result. During the push, the platform checks the continuity of the sequence number to detect whether there is missing data. If the sequence number is found to be discontinuous (for example, Seq=101 is received first, and Seq=103 is received later), the platform can actively request the probe to retransmit the missing monitoring result data (Seq=102).

[0048] In an optional embodiment of the present invention, step 15, decrypting the monitoring results and displaying them on the display interface of the platform, may include: Step 151: Decrypt and verify the encrypted monitoring results obtained through the secure channel according to the decryption and verification method corresponding to the second encryption method of the secure channel to obtain the monitoring results to be displayed. Step 152: Display the monitoring results to be shown on the user interface of the platform according to their urgency.

[0049] In this embodiment, in step 151, when the connection status is successful, the file probe encrypts the monitoring result and pushes it to the platform. After receiving the alarm information pushed by the probe, the platform decrypts and stores it (see step 14 for the specific decryption and verification process).

[0050] In step 152, the decrypted monitoring results are pushed to the visualization page in real time for display. The display order is sorted in descending order of the current alarm priority, with the data with the highest alarm severity listed first, and so on. The intuitive visualization interface allows users to obtain detailed information about anomalies in the current monitoring results, including key information such as time, file path, operation type, and operating user, facilitating quick problem identification.

[0051] In this embodiment, in an optional embodiment of the present invention, the method further includes: Step 16: Based on the monitoring results to be displayed, send the generated alarm notification to the administrator.

[0052] In this embodiment, the platform will simultaneously send SMS and email notifications to the person in charge and maintenance personnel of the corresponding assets based on the monitoring results to be displayed, ensuring that key personnel (various administrators) can obtain the monitoring results alarms and respond as soon as possible.

[0053] A specific embodiment of the file security monitoring method provided in this invention is as follows: Users can perform asset management, policy configuration, and alarm viewing operations through the platform's user interface. File probes are deployed on monitored servers and collect file operation events in real time via system-level APIs. The file probes connect to the platform via a secure channel and communicate bidirectionally. The probes intelligently aggregate the collected anomaly information, extract the monitoring results to be sent, encrypt the monitoring results, and push them to the platform in real time. The platform receives and parses the encrypted monitoring results, stores them in the database, and updates them in real time on the visualization page, while triggering SMS and email notifications. The platform can also send policy update commands to the file probes, which receive and apply the new policies. All operations and results are displayed and interacted with through the platform's user interface.

[0054] In Linux system probes, high-performance monitoring of the file system is achieved through the kernel-level file event notification interface (inotify). It can accurately capture various types of file change events (such as creation, deletion, permission changes, metadata updates, etc.) and improve monitoring efficiency and system resource utilization in an event-driven manner.

[0055] In the Windows system probe, relying on the underlying file system watcher, which uses the official file change monitoring technology (Win32 File Change Notifications) to monitor directories and files in real time, it achieves fine-grained capture of file addition, deletion and modification operations, and maintains high compatibility with the new technology file system (NTFS).

[0056] In addition, a real-time communication link is established between the probe and the central platform through a long-connection socket channel. An event stream push mechanism is used to achieve low-latency reporting of change events and highly reliable message transmission, providing the platform with stable and real-time file system dynamic awareness capabilities.

[0057] The file security monitoring method proposed in this invention effectively avoids alarm overload through an intelligent aggregation mechanism of abnormal information, reduces alarm fatigue of operation and maintenance personnel, improves the high response to truly critical abnormal information, realizes refined monitoring, and also ensures the traceability and integrity of security events.

[0058] like Figure 3 As shown, this embodiment of the invention also provides a file security monitoring device 20, comprising: The acquisition module 31 is used to acquire user input of multiple target servers to be monitored, each with a different operating system installed. The processing module 32 is used to: obtain the target file probe installed on the target server; obtain the real-time file monitoring strategy of the target file probe installed on the target server and transmit it to the target file probe through a secure channel; obtain the monitoring results of the target file probe performing real-time monitoring and alarming on the file operation status on the target server according to the real-time file monitoring strategy through the secure channel; and decrypt the monitoring results and display them on the display interface of the platform.

[0059] Optionally, processing module 32 is specifically used for: Based on the binding relationship between the target server and the file probe, determine the identification code; Based on the identifier of the target server, obtain the target file probe installed on the target server.

[0060] Optionally, processing module 32 is specifically used for: Obtain the file real-time monitoring policy configured by the user, wherein the file real-time monitoring policy includes at least one of the following: the file directory path to be monitored, the file extension type to be monitored, and the file operation type to be monitored; The real-time file monitoring strategy is sent to the corresponding target file probe through the secure channel.

[0061] Optionally, the real-time file monitoring strategy is distributed to the corresponding target file probe via the secure channel, including: The real-time file monitoring strategy is encrypted using the first encryption method of the secure channel to obtain the encrypted real-time file monitoring strategy. The encrypted file real-time monitoring strategy is sent to the corresponding target file probe.

[0062] Optionally, processing module 32 is specifically used for: The secure channel receives encrypted monitoring results sent by the target file probe; wherein the monitoring results are encrypted monitoring results obtained by the target file probe in real time monitoring the file operation status on the target server according to the real-time file monitoring strategy after intelligent aggregation and encryption processing, and the encrypted monitoring results are obtained by encryption calculation using the second encryption method of the secure channel.

[0063] Optionally, processing module 32 is specifically used for: According to the decryption and verification method corresponding to the second encryption method of the secure channel, the encrypted monitoring results obtained through the secure channel are decrypted and verified to obtain the monitoring results to be displayed. The monitoring results to be displayed are shown on the user interface of the platform according to their urgency.

[0064] Optionally, the processing module 32 is also specifically used for: An alarm notification is generated based on the monitoring results to be displayed.

[0065] It should be noted that this device is a device corresponding to the above method. All implementation methods in the above method embodiments are applicable to this embodiment and can achieve the same technical effect.

[0066] like Figure 4 As shown, this embodiment of the invention also provides a computing device 40, including a processor 41, a memory 42, and a program or instructions stored in the memory 42 and executable on the processor 41. When the program or instructions are executed by the processor 41, they implement the various processes of the above-described file security monitoring method embodiments and achieve the same technical effects. To avoid repetition, they will not be described again here. It should be noted that the computing device in this embodiment of the invention includes the aforementioned mobile electronic devices and non-mobile electronic devices.

[0067] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of this invention.

[0068] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0069] In the embodiments provided by this invention, it should be understood that the disclosed apparatus and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.

[0070] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0071] In addition, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.

[0072] If the aforementioned functions are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this invention, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, ROM, RAM, magnetic disks, or optical disks.

[0073] Furthermore, it should be noted that in the apparatus and method of the present invention, it is obvious that the components or steps can be decomposed and / or recombined. These decompositions and / or recombinations should be considered equivalent solutions of the present invention. Moreover, the steps performing the above series of processes can naturally be executed in the order described, but are not necessarily required to be executed in chronological order; some steps can be executed in parallel or independently of each other. Those skilled in the art will understand that all or any step or component of the method and apparatus of the present invention can be implemented in any computing device (including processors, storage media, etc.) or network of computing devices, in hardware, firmware, software, or a combination thereof. This is something that those skilled in the art can achieve by using their basic programming skills after reading the description of the present invention.

[0074] Therefore, the object of the present invention can also be achieved by running a program or a set of programs on any computing device. The computing device can be a known general-purpose device. Therefore, the object of the present invention can also be achieved simply by providing a program product containing program code for implementing the method or apparatus. That is, such a program product also constitutes the present invention, and the storage medium storing such a program product also constitutes the present invention. Obviously, the storage medium can be any known storage medium or any storage medium developed in the future. It should also be noted that in the apparatus and method of the present invention, it is obvious that the components or steps can be decomposed and / or recombined. These decompositions and / or recombinations should be considered equivalent to the present invention. Furthermore, the steps for performing the above series of processes can naturally be performed in the order described, but are not necessarily required to be performed in chronological order. Some steps can be performed in parallel or independently of each other.

[0075] The above are preferred embodiments of the present invention. It should be noted that, for those skilled in the art, several improvements and modifications can be made without departing from the principle of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.

Claims

1. A file security monitoring method characterized by, Applied to a platform end, comprising: Obtaining a plurality of target servers installed with different operating systems to be monitored input by a user; According to the target server, obtaining a target file probe installed on the target server; Obtaining the file real-time monitoring strategy of the target file probe installed on the target server, and transmitting to the target file probe through a secure channel; Through the secure channel, obtaining the monitoring result of the target file probe for real-time monitoring and alarm of the file operation state on the target server according to the file real-time monitoring strategy; Decrypting and displaying the monitoring result on the display interface of the platform end.

2. The file security monitoring method of claim 1, wherein, According to the target server, obtaining a target file probe installed on the target server, comprising: According to the binding relationship between the target server and the file probe, determining the identification code; According to the identification code of the target server, obtaining the target file probe installed on the target server.

3. The file security monitoring method of claim 1, wherein, Obtaining the file real-time monitoring strategy of the target file probe installed on the target server, and transmitting to the target file probe through a secure channel, comprising: Obtaining the file real-time monitoring strategy configured by the user, the file real-time monitoring strategy comprising at least one of the file directory path to be monitored, the file suffix type to be monitored and the file operation type to be monitored; Through the secure channel, the file real-time monitoring strategy is issued to the corresponding target file probe.

4. The file security monitoring method according to claim 3, characterized by, Through the secure channel, the file real-time monitoring strategy is issued to the corresponding target file probe, comprising: The file real-time monitoring strategy is encrypted by a first encryption method of the secure channel to obtain an encrypted file real-time monitoring strategy; The encrypted file real-time monitoring strategy is issued to the corresponding target file probe.

5. The file security monitoring method of claim 1, wherein, Through the secure channel, obtaining the monitoring result of the target file probe for real-time monitoring and alarm of the file operation state on the target server according to the file real-time monitoring strategy, comprising: Through the secure channel, receiving the encrypted monitoring result sent by the target file probe; wherein the monitoring result is the encrypted monitoring result of the target file probe for real-time monitoring of the file operation state on the target server according to the file real-time monitoring strategy after intelligent aggregation and encryption processing, and the encrypted monitoring result is obtained by encrypting the second encryption method of the secure channel.

6. The file security monitoring method according to claim 5, characterized by, Decrypting and displaying the monitoring result on the display interface of the platform end, comprising: According to the decryption verification method corresponding to the second encryption method of the secure channel, the encrypted monitoring result obtained through the secure channel is decrypted and verified to obtain the monitoring result to be displayed; The to-be-displayed monitoring result is displayed on the user interface of the platform end according to the emergency level.

7. The file security monitoring method according to claim 6, characterized by, Also comprising: According to the to-be-displayed monitoring result, generating an alarm notification.

8. A file security monitoring apparatus characterized by comprising: Comprising: The obtaining module is used for obtaining a plurality of target servers installed with different operating systems to be monitored input by a user; The processing module is used for obtaining a target file probe installed on the target server according to the target server; Obtaining a file real-time monitoring strategy of an installed target file probe on the target server, and transmitting the file real-time monitoring strategy to the target file probe through a secure channel; Obtaining a monitoring result of real-time monitoring and alarm of a file operation state on the target server by the target file probe according to the file real-time monitoring strategy through the secure channel; and decrypting and displaying the monitoring result on a display interface of a platform end.

9. A computing device, comprising: The method comprises the following steps: A processor and a memory storing a computer program, wherein the computer program is executed by the processor to perform the method according to any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that, An instruction stored in a computer, wherein the instruction is executed by the computer to perform the method according to any one of claims 1 to 7.