Baseline configuration rollback method and device based on security reinforcement system

By using the baseline configuration rollback method and device of the safety hardening system, the problem of configuration chaos in hardening failure items was solved, realizing the safety hardening of power plant equipment and the stable operation of information systems, and improving the efficiency of hardening operations.

CN121743083APending Publication Date: 2026-03-27LUYUAN HYDROPOWER CO NORTHEAST BRANCH OF STATE GRID
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-09-25
Publication Date
2026-03-27

Smart Images

  • Figure CN121743083A_ABST
    Figure CN121743083A_ABST
Patent Text Reader

Abstract

The invention relates to the field of security reinforcement, in particular to a baseline configuration rollback method and device of a security reinforcement system. Comprising the following steps: 1) acquiring target equipment information of to-be-reinforced equipment, and generating a target reinforcement command; 2) obtaining a reinforcement rule according to the reinforcement command; and (3) reinforcement is conducted according to the reinforcement rule, and whether rollback needs to be conducted or not is judged according to the reinforcement result. According to the method, the security baselines of the host and the operating system can be configured, each reinforcement result is checked, after reinforcement is completed, anomaly detection is performed on the host and the operating system, whether the system is abnormal due to the reinforcement is detected, and rollback operation is performed on reinforcement failure items and reinforcement items which enable the system to be abnormal, so that the reinforcement failure items and the reinforcement items which enable the system to be abnormal. Maintenance and expansion of an administrator are facilitated, and the efficiency of reinforcement operation is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of security hardening, and more specifically to a baseline configuration rollback method and apparatus for a security hardening system. Background Technology

[0002] With the rapid development of information technology and the deepening of digital transformation, the power industry, as a vital pillar of the national economy, not only carries enormous economic and social value but also directly relates to national energy security and the stability of people's daily lives. However, with the increasing complexity of cyberspace and the growing severity of cybersecurity threats, power plants are facing significantly increased cybersecurity risks.

[0003] To effectively address these challenges and ensure the stable operation and data security of power plant information systems, baseline hardening of power plants has become a necessary and urgent task. Baseline verification of power plant network equipment involves analyzing non-compliance items, correlating these non-compliant items with operating systems, versions, services, and other information to identify common issues and provide risk warnings. Assets exhibiting similar characteristics are then prompted for hardening. Currently, most hardening systems do not support baseline configuration rollback, resulting in disorganized baseline configuration records for failed hardening attempts. Furthermore, the number of configuration files for failed hardening attempts increases exponentially with the number of hardening items added. Summary of the Invention

[0004] This invention provides a baseline configuration rollback method and apparatus for a security hardening system, which restores the configuration file of the system to the previous state after hardening failure or hardening completion. It can effectively configure the baseline file, reduce unnecessary debugging time, and effectively configure hardening failure or hardening items that cause system abnormalities.

[0005] The technical solution adopted by the present invention to achieve the above objectives is as follows:

[0006] A baseline configuration rollback method based on a security hardening system includes the following steps:

[0007] 1) Obtain target equipment information for the equipment to be reinforced in the power plant and generate target reinforcement commands;

[0008] 2) Obtain reinforcement rules based on the reinforcement command;

[0009] 3) Reinforce according to the reinforcement rules, and determine whether the reinforcement results need to be rolled back.

[0010] Step 1) includes the following steps:

[0011] 1.1) Select the target equipment information of the equipment to be reinforced from the pre-built list of reinforced equipment, and select the reinforcement items of the equipment to be reinforced from the target equipment information;

[0012] 1.2) Determine the corresponding reinforcement type based on the reinforcement item;

[0013] 1.3) Based on the reinforcement type and the current reinforcement items, prepare target inspection scripts according to regulations or different project types;

[0014] 1.4) Test the inspection script, obtain the test results of the inspection script, and then write the hardening script as the target hardening command.

[0015] The target device information includes system version, account policy, peripheral interface information, firewall, network services, host port, remote login management, audit configuration, log configuration, resource access permissions, system configuration, and password policy.

[0016] Step 2) specifically refers to:

[0017] Based on the target hardening command and the usage rules set by different operating systems, obtain the hardening rules for the current hardening item.

[0018] Step 3) specifically refers to:

[0019] After the reinforcement is completed, obtain the current reinforcement item value of the device to be reinforced, and compare the current value with the baseline standard in the target device information. If they do not match, the reinforcement fails, the reinforcement is rolled back to the unreinforced baseline configuration, the current baseline reinforcement item and baseline file configuration are recorded, and the relevant information is backed up to the cloud. If they match, the reinforcement is successful, the reinforcement is archived, and the current information is backed up to the cloud.

[0020] It also includes step 4), after reinforcement, anomaly detection is performed on the reinforced equipment, specifically:

[0021] If the current reinforcement causes equipment abnormality, identify the reinforcement item that caused the abnormality, roll back the baseline configuration of this reinforcement item to the unreinforced baseline configuration, record the current reinforcement item and the current baseline configuration file, and back up the current information to the cloud.

[0022] If this reinforcement does not cause any equipment malfunction, the current baseline configuration file will be recorded and the current information will be backed up to the cloud.

[0023] Once it is determined that the hardening has not caused any equipment abnormalities, the system continues to check whether the total number of baselines scanned is consistent with the set total number of compliant baselines. If they are consistent, it indicates that all baselines are compliant and the equipment is in a safe state. If they are inconsistent, the system further checks whether the number of repaired baselines is consistent with the number of non-compliant baselines. If they are consistent, it indicates that all non-compliant baselines have been repaired and the equipment is currently in a compliant state.

[0024] A baseline configuration rollback device based on a security hardening system, comprising:

[0025] The configuration management module is used to obtain target equipment information of equipment to be reinforced in the power plant and generate target reinforcement commands.

[0026] The reinforcement result analysis module is used to obtain reinforcement rules based on reinforcement commands;

[0027] The reinforcement rollback module is used to perform reinforcement according to reinforcement rules and determine whether the reinforcement results need to be rolled back.

[0028] The system anomaly detection module is used to perform anomaly detection on the hardened equipment after hardening.

[0029] The present invention has the following beneficial effects and advantages:

[0030] This invention can configure the security baseline of the host and operating system, verify the results of each hardening, and perform anomaly detection on the host and operating system after hardening is completed. It can detect whether the system has become abnormal due to this hardening, and perform rollback operations on hardening failure items and hardening items that caused system anomalies. This is beneficial for administrators to maintain and expand, and improves the efficiency of hardening operations. Attached Figure Description

[0031] Figure 1 This is a schematic diagram illustrating the workflow of a baseline configuration rollback method for a security hardening system proposed in this invention.

[0032] Figure 2 A flowchart illustrating the workflow for configuring a rollback method for a security-hardened system;

[0033] Figure 3 A system block diagram for configuring a rollback device on the baseline of a security hardening system. Detailed Implementation

[0034] The present invention will now be described in further detail with reference to the accompanying drawings and embodiments.

[0035] like Figure 1 As shown, one aspect of the present invention provides a baseline configuration rollback method for a security hardening system, comprising:

[0036] Select the target equipment information of the equipment to be reinforced from the pre-built list of reinforced equipment, and determine the corresponding reinforcement items of the equipment to be reinforced;

[0037] Determine the reinforcement type corresponding to the current reinforcement item, generate a target reinforcement command based on the reinforcement type and the current reinforcement item, and verify the target reinforcement command to obtain the verification result of the target reinforcement command;

[0038] The reinforcement rules for the current reinforcement item are obtained based on the verification results of the target reinforcement command. The reinforcement rules include the device type, device operating system, device operating system version, and reinforcement item name of the device to be reinforced.

[0039] like Figure 2 As shown, further, the reinforcement items are reinforced according to the set reinforcement rules. After the reinforcement is completed, its current value is obtained and compared with the baseline standard contained in the configuration parameters.

[0040] If the current value of the reinforcement item does not match the baseline standard value, the reinforcement will fail, the current reinforcement will be rolled back to the unreinforced baseline configuration, the current baseline reinforcement item and baseline file configuration will be recorded, and the relevant information will be backed up to the cloud.

[0041] If the current value of the reinforcement item matches the baseline standard value, the reinforcement is successful, the reinforcement is archived, and the current information is backed up to the cloud.

[0042] Furthermore, a host system anomaly detection task is created to perform anomaly detection on the system status after this hardening process to determine whether the hardening process has caused system anomalies.

[0043] If the current reinforcement causes a system anomaly, identify the reinforcement item that caused the system anomaly, roll back the baseline configuration of this reinforcement item to the unreinforced baseline configuration, record the current reinforcement item and the current baseline configuration file, and back up the current information to the cloud.

[0044] If this reinforcement does not cause any system anomalies, the current baseline configuration file will be recorded and the current information will be backed up to the cloud.

[0045] The system checks whether the total number of scanned baselines matches the total number of compliant baselines. If they match, all baselines are compliant and the system is in a safe state. If they do not match, the system checks whether the number of repaired baselines matches the number of non-compliant baselines. If they match, all non-compliant baselines have been repaired and the system is in a compliant state.

[0046] like Figure 3 As shown, another aspect of the present invention provides a baseline configuration rollback device for a security hardening system, comprising: a configuration management module, a hardening result analysis module, a system anomaly detection module, an anomaly hardening item identification module, and a rollback module;

[0047] The configuration management module records the current operation time and current configuration after each operation is completed. The operations include: baseline hardening and baseline configuration rollback.

[0048] The verification module is used to verify whether the host hardening results are effective;

[0049] The anomaly detection module is used to detect whether the system anomaly is caused by this hardening process;

[0050] The rollback module performs rollback operations on items that failed to be hardened and items that caused system anomalies, restoring the configuration files to their state before hardening.

Claims

1. A baseline configuration rollback method based on a security hardening system, characterized in that, Includes the following steps: 1) Obtain target equipment information for the equipment to be reinforced in the power plant and generate target reinforcement commands; 2) Obtain reinforcement rules based on the reinforcement command; 3) Reinforce according to the reinforcement rules, and determine whether the reinforcement results need to be rolled back.

2. The baseline configuration rollback method based on a security hardening system according to claim 1, characterized in that, Step 1) includes the following steps: 1.1) Select the target equipment information of the equipment to be reinforced from the pre-built list of reinforced equipment, and select the reinforcement items of the equipment to be reinforced from the target equipment information; 1.2) Determine the corresponding reinforcement type based on the reinforcement item; 1.3) Based on the reinforcement type and the current reinforcement items, prepare target inspection scripts according to regulations or different project types; 1.4) Test the inspection script, obtain the test results of the inspection script, and then write the hardening script as the target hardening command.

3. The baseline configuration rollback method based on a security hardening system according to claim 2, characterized in that, The target device information includes system version, account policy, peripheral interface information, firewall, network services, host port, remote login management, audit configuration, log configuration, resource access permissions, system configuration, and password policy.

4. The baseline configuration rollback method based on a security hardening system according to claim 1, characterized in that, Step 2) specifically refers to: Based on the target hardening command and the usage rules set by different operating systems, obtain the hardening rules for the current hardening item.

5. The baseline configuration rollback method based on a security hardening system according to claim 1, characterized in that, Step 3) specifically refers to: After the reinforcement is completed, obtain the current reinforcement item value of the device to be reinforced, compare the current value with the baseline standard in the target device information, and if they do not match, the reinforcement fails. Roll back the reinforcement to the unreinforced baseline configuration, record the current baseline reinforcement item and baseline file configuration, and back up the relevant information to the cloud. If a match is found, the reinforcement is successful, and the reinforcement will be archived and the current information will be backed up to the cloud.

6. The baseline configuration rollback method based on a security hardening system according to claim 1, characterized in that, It also includes step 4), after reinforcement, anomaly detection is performed on the reinforced equipment, specifically: If the current reinforcement causes equipment abnormality, identify the reinforcement item that caused the abnormality, roll back the baseline configuration of this reinforcement item to the unreinforced baseline configuration, record the current reinforcement item and the current baseline configuration file, and back up the current information to the cloud. If this reinforcement does not cause any equipment malfunction, the current baseline configuration file will be recorded and the current information will be backed up to the cloud. Once it is determined that the hardening has not caused any equipment abnormality, the next step is to check whether the total number of baselines that have been scanned is consistent with the set total number of compliant baselines. If they are consistent, it means that all baselines are compliant and the equipment is in a safe state. If the results are inconsistent, further determine whether the number of repairs is consistent with the number of non-compliant baselines. If the results are consistent, it means that all non-compliant baselines have been repaired and the current device is in a compliant state.

7. A baseline configuration rollback device based on a security hardening system, characterized in that, include The configuration management module is used to obtain target equipment information of equipment to be reinforced in the power plant and generate target reinforcement commands. The reinforcement result analysis module is used to obtain reinforcement rules based on reinforcement commands; The reinforcement rollback module is used to perform reinforcement according to reinforcement rules and determine whether the reinforcement results need to be rolled back. The system anomaly detection module is used to perform anomaly detection on the hardened equipment after hardening.