Digital asset safety monitoring method, device, equipment, medium and program product
By deploying a security engine to the agent terminal and analyzing monitoring events in real time, the problem of delayed security response caused by the complexity of the traditional agent probe upgrade process is solved, and the ability to quickly respond to digital asset security threats is expanded and the monitoring results are efficiently analyzed is realized.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- CHINA MOBILE INFORMATION TECHNOLOGY CO LTD
- Filing Date
- 2026-01-27
- Publication Date
- 2026-05-08
AI Technical Summary
Existing data asset security monitoring and auditing products suffer from a lag in security response when dealing with digital asset security threats, making it difficult to quickly respond to the rapid evolution of new threats. Furthermore, the traditional proxy probe upgrade process is complex, resulting in insufficient scalability.
By sending the security engine installation package and engine deployment instructions to the agent terminal, a security engine for digital asset security monitoring is deployed. The monitoring events are acquired and parsed through the first device, enabling rapid expansion of the security engine and real-time parsing of monitoring results, thus avoiding the code refactoring and version iteration process of the agent terminal.
It enables the deployment of a security engine without requiring complex processes on proxy terminals, improving security operation efficiency, reducing security response delays, and enhancing the ability to respond to digital asset security threats.
Smart Images

Figure CN121997341A_ABST
Abstract
Description
Technical Field
[0001] This application belongs to the field of security monitoring technology, and specifically relates to a digital asset security monitoring method, device, equipment, medium and program product. Background Technology
[0002] With the rapid development of information technology, businesses and individuals are increasingly reliant on digital assets. However, this reliance also brings new security challenges. Cyberattacks, malware, and data breaches are rampant, posing significant security risks to business operations and personal privacy. Furthermore, security threats are constantly evolving; cyberattack methods are becoming more diversified. Traditional attack methods such as viruses, worms, and Trojans still exist, but the methods are becoming more complex and covert.
[0003] With the widespread adoption of big data and cloud computing, the amount of data collected and stored by enterprises has increased dramatically. This has led to frequent data breaches caused by security threats and cyberattacks, resulting not only in economic losses but also potential legal disputes and reputational damage. The rise of internal threats, including malicious acts or negligence by employees or partners, has also become a significant security risk. Because attackers often have access to the system, internal threats are frequently more difficult to prevent.
[0004] In summary, the information technology (IT) environment of modern enterprises is becoming increasingly complex, involving various forms such as physical servers, virtual machines, containers, and cloud services. This complexity increases the difficulty of management and protection. Faced with increasingly complex security threats, traditional data asset security monitoring and auditing products cannot meet the needs. Existing data asset security monitoring and auditing products often achieve the restoration, monitoring, and auditing of data asset flow through bypass traffic mirroring mode or agent probes. Among these, the method of deploying lightweight agents on the near-source host means that the monitoring capabilities and scope of data assets depend on the specific agent's functions, such as configuration baseline scanning and content baseline scanning. However, it has insufficient scalability. If it is necessary to add data asset monitoring types, such as File Transfer Protocol (FTP) files, static resource files, or other monitoring requirements, the agent probe needs to undergo a development and compilation process, and requires complex processes such as updates and upgrades on the near-source host. This leads to a lag in security response and makes it difficult to cope with the rapid evolution of new threats. Summary of the Invention
[0005] This application provides a digital asset security monitoring method, apparatus, device, medium, and program product to address the problem of delayed security response in existing methods of responding to digital asset security threats by upgrading proxy probes.
[0006] In a first aspect, embodiments of this application provide a digital asset security monitoring method, applied to a first device, the method comprising:
[0007] Send a security engine installation package and an engine deployment instruction to the agent terminal, wherein the security engine installation package includes a security engine for digital asset security monitoring, and the engine deployment instruction is used to instruct the agent terminal to deploy the security engine on the target host;
[0008] Send first configuration information to the agent terminal, the first configuration information being used to instruct the agent terminal to start the security engine for digital asset security monitoring;
[0009] The agent terminal sends a digital asset security monitoring event, which is obtained by the agent terminal using the security engine to perform digital asset security monitoring.
[0010] The digital asset security monitoring events are analyzed to obtain the digital asset security monitoring results.
[0011] Optionally, before sending the security engine installation package and engine deployment instructions to the agent terminal, the method further includes:
[0012] The security engine is generated based on the digital asset security detection task;
[0013] The security engine is configured to read second configuration information, wherein the second configuration information includes at least one of the following: address information of the first message queue, connection port between the proxy terminal and the security engine, and topic of the digital asset security monitoring event transmission channel in the first message queue;
[0014] Configure the file format for the digital asset security monitoring events output by the security engine;
[0015] Based on the security engine, generate the security engine installation package.
[0016] Optionally, generating the security engine installation package based on the security engine includes:
[0017] The scripts of the security engine are compiled to obtain binary files;
[0018] Perform a hash calculation on the binary file to obtain a hash file;
[0019] The binary file and the hash file are packaged together to obtain the security engine installation package.
[0020] Optionally, before obtaining the digital asset security monitoring event sent by the agent terminal, the method further includes:
[0021] Deploy the security engine result parsing service according to the security engine result parsing service installation package and parsing service deployment instructions; wherein, the security engine result parsing service is used to parse the digital asset security monitoring events;
[0022] The process involves analyzing the digital asset security monitoring events to obtain the digital asset security monitoring results, including:
[0023] The security engine result parsing service is used to analyze the digital asset security monitoring events and obtain the digital asset security monitoring results.
[0024] Optionally, deploying the security engine result parsing service according to the security engine result parsing service installation package and parsing service deployment instructions includes:
[0025] Configure the security engine result parsing service to listen to and read the second configuration information according to the parsing service deployment instruction, wherein the second configuration information includes at least one of the following: the address information of the first message queue, the connection port between the proxy terminal and the security engine, and the topic of the digital asset security monitoring event in the transmission channel of the first message queue;
[0026] Configure the file format of the digital asset security monitoring events parsed by the security engine result parsing service.
[0027] Optionally, the security engine result parsing service installation package is obtained by packaging the script, startup script and stop script of the security engine result parsing service;
[0028] The step of deploying the security engine result parsing service according to the security engine result parsing service installation package and parsing service deployment instructions includes:
[0029] According to the parsing service deployment instructions, the security engine result parsing service installation package is registered;
[0030] According to the parsing service deployment instructions, the security engine result parsing service installation package is decompressed to obtain the security engine result parsing service script, the startup script, and the stop script;
[0031] The security engine result parsing service is deployed according to the script of the security engine result parsing service, the startup script, and the stop script.
[0032] Optionally, before sending the security engine installation package and engine deployment instructions to the agent terminal, the method further includes:
[0033] Send third configuration information to the proxy terminal, wherein the third configuration information is used to register the proxy terminal on the server corresponding to the proxy terminal, and the third configuration information includes at least one of the following: the address information of the server corresponding to the proxy terminal, and the port registered by the proxy terminal;
[0034] Receive registration information sent by the agent terminal.
[0035] Optionally, sending the security engine installation package and engine deployment instructions to the agent terminal includes:
[0036] The engine deployment command is sent to the proxy terminal through the server corresponding to the proxy terminal;
[0037] The engine deployment instruction includes the identifier of the agent terminal and the download address of the security engine installation package;
[0038] The server corresponding to the proxy terminal is used to parse the engine deployment command, obtain the identifier of the proxy terminal, and send the engine deployment command to the proxy terminal according to the identifier of the proxy terminal;
[0039] The proxy terminal is used to obtain the security engine installation package according to the download address of the security engine installation package.
[0040] Optionally, obtaining the digital asset security monitoring event sent by the agent terminal includes:
[0041] The digital asset security monitoring event sent by the agent terminal is obtained through the second configuration information and the first message queue;
[0042] The second configuration information includes at least one of the following: the address information of the first message queue, the connection port between the agent terminal and the security engine, and the topic of the digital asset security monitoring event transmission channel in the first message queue.
[0043] Optionally, obtaining the digital asset security monitoring event sent by the agent terminal includes:
[0044] Send a first message to the proxy terminal, the first message being used to instruct the proxy terminal to monitor the digital asset security monitoring event;
[0045] Receive the digital asset security monitoring event sent by the agent terminal.
[0046] Secondly, embodiments of this application provide a digital asset security monitoring method applied to a proxy terminal, the method comprising:
[0047] The system receives a security engine installation package and an engine deployment instruction sent by a first device, and deploys a security engine on a target host according to the engine deployment instruction and the security engine installation package; wherein, the security engine installation package includes a security engine for digital asset security monitoring.
[0048] Receive the first configuration information sent by the first device, and start the security engine to perform digital asset security monitoring according to the first configuration information;
[0049] The security engine is used to perform digital asset security monitoring to obtain digital asset security monitoring events, and the digital asset security monitoring events are sent to the first device.
[0050] Optionally, before receiving the security engine installation package and engine deployment instructions sent by the first device, the method further includes:
[0051] The system receives third configuration information sent by the first device, registers on the server corresponding to the proxy terminal according to the third configuration information, and obtains registration information; wherein, the third configuration information includes at least one of the following: the address information of the server corresponding to the proxy terminal, and the port registered by the proxy terminal;
[0052] Send the registration information to the first device.
[0053] Optionally, receiving the security engine installation package and engine deployment instructions sent by the first device, and deploying the security engine on the target host according to the engine deployment instructions and the security engine installation package, includes:
[0054] Receive the engine deployment instruction sent through the server corresponding to the agent terminal, wherein the engine deployment instruction includes the identifier of the agent terminal and the download address of the security engine installation package;
[0055] Obtain the security engine installation package from the download address of the security engine installation package.
[0056] Optionally, the process of obtaining digital asset security monitoring events using the security engine includes:
[0057] Receive the first message sent by the first device;
[0058] Generate task description information based on the first message;
[0059] Digital asset security monitoring events are obtained by performing digital asset security monitoring based on the task description information and the security engine.
[0060] Thirdly, embodiments of this application provide a digital asset security monitoring device, the device comprising:
[0061] The first sending module is used to send a security engine installation package and an engine deployment instruction to the agent terminal. The security engine installation package includes a security engine for digital asset security monitoring, and the engine deployment instruction is used to instruct the agent terminal to deploy the security engine on the target host.
[0062] The second sending module is used to send first configuration information to the agent terminal, the first configuration information being used to instruct the agent terminal to start the security engine to perform digital asset security monitoring.
[0063] The first acquisition module is used to acquire digital asset security monitoring events sent by the agent terminal, wherein the digital asset security monitoring events are obtained by the agent terminal using the security engine to perform digital asset security monitoring.
[0064] The first processing module is used to analyze the digital asset security monitoring events and obtain the digital asset security monitoring results.
[0065] Fourthly, embodiments of this application provide a digital asset security monitoring device, the device comprising:
[0066] The second processing module is used to receive a security engine installation package and an engine deployment instruction sent by the first device, and deploy a security engine on the target host according to the engine deployment instruction and the security engine installation package; wherein, the security engine installation package includes a security engine for digital asset security monitoring;
[0067] The third processing module is used to receive the first configuration information sent by the first device, and start the security engine to perform digital asset security monitoring according to the first configuration information.
[0068] The fourth processing module is used to perform digital asset security monitoring using the security engine to obtain digital asset security monitoring events, and to send the digital asset security monitoring events to the first device.
[0069] Fifthly, embodiments of this application provide an electronic device, including: a processor, a memory, and a program stored in the memory and executable on the processor, wherein when the program is executed by the processor, it implements the steps of the digital asset security monitoring method as described in any one of the first aspects.
[0070] In a sixth aspect, embodiments of this application provide a terminal device, including: a processor, a memory, and a program stored in the memory and executable on the processor, wherein when the program is executed by the processor, it implements the steps of the digital asset security monitoring method as described in any one of the second aspects.
[0071] In a seventh aspect, embodiments of this application provide a readable storage medium storing a program that, when executed by a processor, implements the steps of the digital asset security monitoring method as described in any one of the first aspects, or implements the steps of the digital asset security monitoring method as described in any one of the second aspects.
[0072] Eighthly, embodiments of this application provide a computer program product, including computer instructions, which, when executed by a processor, implement the steps of the digital asset security monitoring method as described in any one of the first aspects, or implement the steps of the digital asset security monitoring method as described in any one of the second aspects.
[0073] The beneficial effects of this application are:
[0074] The digital asset security monitoring method provided in this application sends a security engine installation package and an engine deployment instruction to a proxy terminal via a first device. The security engine installation package includes a security engine for digital asset security monitoring, and the engine deployment instruction instructs the proxy terminal to deploy the security engine on a target host. The first device also sends first configuration information to the proxy terminal, instructing the proxy terminal to start the security engine for digital asset security monitoring. This method enables the first device to extend the deployment of a security engine for digital asset security monitoring on the proxy terminal, eliminating the need for complex processes such as code refactoring, version iteration, and upgrades on the proxy terminal. The proxy terminal has the capability to address digital asset security threats or new data asset security needs. A first device acquires digital asset security monitoring events sent by the proxy terminal, which are obtained by the proxy terminal using the security engine for digital asset security monitoring. The first device parses these digital asset security monitoring events to obtain the digital asset security monitoring results. This eliminates the need for the proxy terminal to parse the digital asset security monitoring events, improving security operation efficiency and reducing security response delays. Attached Figure Description
[0075] Figure 1 This is a flowchart of a digital asset security monitoring method applied to a first device, provided in an embodiment of this application;
[0076] Figure 2 This is a schematic diagram of the business interaction architecture between the first device and the agent terminal provided in the embodiments of this application;
[0077] Figure 3 This is a flowchart of the security engine and security engine result parsing service extension provided in the embodiments of this application;
[0078] Figure 4 This is a flowchart of task execution provided in an embodiment of this application;
[0079] Figure 5 This is a flowchart of a digital asset security monitoring method applied to a proxy terminal, provided in an embodiment of this application.
[0080] Figure 6 This is one of the structural schematic diagrams of the digital asset security monitoring device provided in the embodiments of this application;
[0081] Figure 7 This is a second schematic diagram of the structure of the digital asset security monitoring device provided in the embodiments of this application;
[0082] Figure 8 This is a schematic diagram of the structure of the first device provided in the embodiments of this application. Detailed Implementation
[0083] The technical solutions of the embodiments of this application will be clearly described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this application. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0084] In the following description, specific details such as particular configurations and components are provided merely to aid in a comprehensive understanding of the embodiments of this application. Therefore, those skilled in the art will understand that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of this application. Furthermore, for clarity and brevity, descriptions of known functions and constructions have been omitted.
[0085] It should be understood that the phrase "one embodiment" or "an embodiment" throughout the specification means that a specific feature, structure, or characteristic related to the embodiment is included in at least one embodiment of this application. Therefore, "in one embodiment" or "in an embodiment" appearing throughout the specification does not necessarily refer to the same embodiment. Furthermore, these specific features, structures, or characteristics can be combined in any suitable manner in one or more embodiments.
[0086] In the various embodiments of this application, it should be understood that the sequence number of each process described below does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.
[0087] The terms "first," "second," etc., used in the specification and claims of this application are used to distinguish similar objects and are not used to describe a specified order or sequence. It should be understood that such use of data can be interchanged where appropriate so that embodiments of this application can be implemented in orders other than those illustrated or described herein, and the objects distinguished by "first" and "second" are generally of the same class, not limited in number; for example, a first object can be one or more. Furthermore, in the specification and claims, "and" indicates at least one of the connected objects, and the character " / " generally indicates that the preceding and following objects are in an "or" relationship.
[0088] Furthermore, the "or" in this application indicates at least one of the connected objects. For example, "A or B" covers three scenarios: Scenario 1: includes A but excludes B; Scenario 2: includes B but excludes A; Scenario 3: includes both A and B. The character " / " generally indicates that the preceding and following objects are in an "or" relationship.
[0089] The term "instruction" in this application can be either a direct instruction (or explicit instruction) or an indirect instruction (or implicit instruction). A direct instruction can be understood as one in which the sender explicitly informs the receiver of specific information, the operation to be performed, or the requested result, etc.; an indirect instruction can be understood as one in which the receiver determines the corresponding information based on the instruction sent by the sender, or makes a judgment and determines the operation to be performed or the requested result, etc., based on the judgment result.
[0090] Before describing the specific implementation methods of this application, the following points should be noted:
[0091] In existing technical architectures, data asset security monitoring systems typically consist of lightweight probe agents deployed near the source and cloud servers. Their data asset security monitoring capabilities are deeply coupled to the agent's implementation. Common data asset security monitoring capabilities include: database baseline scanning, database content baseline scanning, file change monitoring, full-traffic threat analysis, and internal network asset discovery. As cybersecurity threats evolve in a diversified manner, this architecture exposes significant scalability deficiencies. Adding new data asset security monitoring capabilities requires complex processes such as agent code refactoring, version iteration, and endpoint agent upgrades, leading to delayed security responses and difficulty in addressing the rapid evolution of new threats. Furthermore, because different security scenarios require different data asset security monitoring capabilities, traditional data asset security monitoring products struggle to flexibly customize and utilize different monitoring capabilities for different data asset security scenarios.
[0092] To address the issue of delayed security response in existing methods of responding to digital asset security threats by upgrading proxy probes, this application provides a digital asset security monitoring method, apparatus, device, medium, and program product.
[0093] like Figure 1 As shown in the figure, this application provides a digital asset security monitoring method, applied to a first device, the method comprising:
[0094] Step 101: Send a security engine installation package and an engine deployment instruction to the agent terminal, wherein the security engine installation package includes a security engine for digital asset security monitoring, and the engine deployment instruction is used to instruct the agent terminal to deploy the security engine on the target host.
[0095] Before describing the specific process of the digital asset security monitoring method provided in the embodiments of this application, it should first be noted that:
[0096] The structural diagram of the first device and the business interaction architecture between the first device and the agent terminal provided in this application embodiment are shown below. Figure 2 As shown. Figure 2 As shown, the first device includes a digital asset security operation and management platform (hereinafter referred to as the security operation platform), a second message queue, an agent server, a database (DB), a security analysis engine (baseline analysis engine, file analysis engine, vulnerability scan analysis engine, etc.), a first message queue (also known as a security event message queue), and third-party traditional security tools. The agent terminal is deployed on the terminal server (or terminal host, target host), and the terminal server also includes a security monitoring engine (including a baseline scanning engine, a vulnerability scanning engine, a real-time monitoring engine for configuration file changes, a database content baseline scanning engine, etc.).
[0097] In the embodiments of this application, the agent terminal may also be referred to as an agent, a near-source probe, a near-source agent, or a probe agent.
[0098] The security operations platform mainly includes: engine repository management module, engine service deployment module, asset security task management module, configuration management module, and data display module.
[0099] The engine repository management module primarily manages the data asset security engine extension installation package, including uploading and distributing these packages. The data asset security task management module creates and distributes security tasks. The configuration management module manages the security engine's configuration, including creating and distributing engine configurations. The data display module displays the analysis results reported by the data asset security engine. The data asset security engine parsing service deployment module enables hot deployment of the engine parsing service, allowing new engine deployment services to go live. Generally, the security operations platform also includes an alarm handling module and a policy distribution module. Since this application's embodiment primarily emphasizes a near-source agent probe data asset security capability extension method, other common sub-modules will not be elaborated upon.
[0100] Communication between the security operations platform and the agent_server: Each submodule of the security operations platform issues message commands to the operations platform through a subscription and publish mode of the second message queue, and the agent_server listens to the message publishing channel of the security operations platform to receive commands.
[0101] The agent_server communicates with the near-source agent probes using the Google Remote Procedure Call (GRPC) protocol. This primarily includes the following GRPC communication interface definitions: probe agent registration interface, heartbeat interface, security engine deployment interface, task generation interface, engine management interface, task management interface, policy execution interface, configuration management interface, and event reporting interface. The agent_server's main function is to implement communication and management functions for the agent probes, primarily handling the parsing and forwarding of commands issued by the security operations platform.
[0102] The interface is defined as follows:
[0103] service AgentService {
[0104] rpc Register(AgentInfo) returns (RegisterResponse); / / Registration interface
[0105] rpc Heartbeat(HeartbeatReq) returns (HeartbeatResponse); / / Heartbeat interface
[0106] `rpcDeployEngine(AgentIdInfo) returns (stream EngineDeployInfo);` / / Engine deployment interface
[0107] `rpc ConfigureEngine(AgentIdInfo) returns (stream EngineConfigInfo);` / / Configure the distribution interface
[0108] rpc ReceiveTasks(AgentIdInfo) returns (stream TaskInfo); / / Task receiving interface
[0109] `rpc UploadEventResult(EventReq) returns (EventResp);` / / Event reporting interface
[0110] }
[0111] The agent terminal primarily implements the security engine's management functions, including heartbeat reporting, security engine status monitoring, task description script generation, and security engine management (including installation, startup, and shutdown). The agent also runs a separate thread listening on port 50052, which provides WebSocket services.
[0112] Security engines are specific security capabilities, generally including: baseline scanning engines, file change monitoring engines, vulnerability scanning engines, script execution engines, internal network asset discovery engines, full-flow threat analysis engines, and customized special security engines for different security needs. Security engines are divided into one-time execution task-type security engines and resident process (long-running) security engines.
[0113] It should be noted that the interaction logic of the decoupled design between the agent and the security engine is mainly implemented using the following two methods: Method 1 and Method 2.
[0114] Method 1: For security engines that perform task execution, when invoking the security engine to execute a task, specify the path to the task description file generated by the agent. The security engine reads the specified task description file and, based on the content of the task file and the specific security business logic, executes the corresponding security task. After the security task is completed, the task execution result is uploaded to the first message queue, where it is parsed and stored by the corresponding parsing service.
[0115] Method 2: For security engines with a persistent process, the agent management end has a thread listening on port 50052 (127.0.0.1). This port provides a WebSocket service, and the security engine starts connecting to this port. This enables bidirectional communication between the security engine and the agent management end. Similarly, after the security engine completes its specific security tasks, it uploads the task execution results to the first message queue, where the corresponding parsing service parses and stores them.
[0116] It should be noted that in both Method 1 and Method 2, the content of the security engine's task description file and the content of the WebSocket communication are sent from the platform to the first message queue (e.g., Remote Dictionary Server, redis)). The agent_server listens to this first message queue, reads the message content, parses it, and then sends it to the corresponding agent. The agent then further sends it to the corresponding security engine through the task description file and WebSocket.
[0117] The first message queue (security event message queue) is mainly used to receive security event data collected by the security engine, and to support the uploading of security events by third-party security devices (i.e., third-party traditional security tools), so as to achieve unified management and improve the efficiency of unified management and processing of enterprise security events.
[0118] The security engine results analysis engine listens to the second message queue, obtains data reported by the security engine, analyzes and processes the security data, and saves the results to the database after processing. The data display module of the security operations platform then displays the security events and security data.
[0119] The following describes the specific process of the digital asset security monitoring method provided in this application embodiment. In this step, the first device sends the security engine installation package and engine deployment instructions to the online agent terminal through the security operation management platform, so as to enable the agent terminal to bring the newly added security capabilities to the source host side.
[0120] The security engine installation package includes (or carries) a security engine for digital asset security monitoring, and the engine deployment instructions are used to instruct the agent terminal to deploy the security engine on the target host (i.e., the near-source host).
[0121] For example, the message format of the engine deployment command is as follows:
[0122] {
[0123] "agent_ids": ["agent-001"],
[0124] "type": "engine_deploy",
[0125] "deploy_payload": {
[0126] "engine_name": "execution_engine",
[0127] "version": "8.0",
[0128] "download_url": "http: / / example.com / xxx.tar",
[0129] "md5": "xxxxx",
[0130] "unzip": "xxxxx",
[0131] }
[0132] }
[0133] Step 102: Send first configuration information to the agent terminal, the first configuration information being used to instruct the agent terminal to start the security engine for digital asset security monitoring.
[0134] Optionally, the first configuration information is a configuration message.
[0135] In this step, the first device sends the first configuration message to the second message queue through the security operation management platform. The agent_server listens to the second message queue, and upon receiving the instruction to send the first configuration message, it parses out the agent terminal identifier (agentId) corresponding to the first configuration message and sends the first configuration message to the specified agent terminal based on the agent terminal identifier. The agent terminal then starts the security engine process based on the first configuration information.
[0136] For example, the message format of the first configuration information is as follows:
[0137] {
[0138] "agent_ids": ["agent-001"],
[0139] "type": "engine_config",
[0140] "config_payload": {
[0141] "engine_name": "execution_engine",
[0142] "agent_server": {"host":ipv4,"port":0000},
[0143] "log_level": "info",
[0144] "engine_list": {
[0145] "execution_engine":
[0146] {
[0147] "enable": true, "max_cpu_percent": 50,
[0148] "max_memory_bytes": 100,
[0149] "log_level": "debug|",
[0150] "kafka": {"host":ipv4,"port": 0000,"topic":"execution_topic"},
[0151] "extend_config": {}},
[0152] }
[0153] }
[0154] }
[0155] Through the above steps 101 and 102, a security engine for digital asset security monitoring is deployed by the first device as an extension of the agent terminal. This eliminates the need for complex processes such as code refactoring, version iteration, and upgrades of the agent terminal, and enables the agent terminal to cope with digital asset security threats or new data asset security requirements.
[0156] Step 103: Obtain the digital asset security monitoring event sent by the agent terminal. The digital asset security monitoring event is obtained by the agent terminal using the security engine to perform digital asset security monitoring.
[0157] In this step, the agent terminal starts the security engine and listens for digital asset security monitoring events through the security engine. If a digital asset security monitoring event is detected, the agent terminal sends the digital asset security monitoring event to the first message queue of the specified topic (also known as the security event message queue) through the address information of the first message queue in the configuration file (i.e., Internet Protocol (IP)), the connection port between the agent terminal and the security engine, and the topic of the transmission channel of the digital asset security monitoring event in the first message queue. The first device then obtains the digital asset security monitoring event.
[0158] Step 104: Analyze the digital asset security monitoring events to obtain the digital asset security monitoring results.
[0159] In this step, a security engine result parsing service is deployed on the first device. The deployed security engine result parsing service parses the events of digital asset security monitoring events to obtain digital asset security monitoring results (such as whether there are security risks), and stores the digital asset security monitoring results in the database.
[0160] Through steps 103 and 104, the first device analyzes the digital asset security monitoring events to obtain the digital asset security monitoring results. This eliminates the need for a proxy terminal to analyze the digital asset security monitoring events, thereby improving security operation efficiency and reducing security response delays.
[0161] In some embodiments, the method further includes, before sending the security engine installation package and engine deployment instructions to the agent terminal:
[0162] The security engine is generated based on the digital asset security testing task (or digital asset security protection task), i.e., security engine development is performed. For example, the generated security engine includes a baseline scanning engine, a file change monitoring engine, and a vulnerability scanning engine.
[0163] The generated security engine must meet the following specifications:
[0164] In addition to providing the corresponding digital asset security detection task (or digital asset security protection task), the security engine also needs to be configured to read the second configuration information, wherein the second configuration information includes at least one of the following: the address information of the first message queue, the connection port between the agent terminal and the security engine, and the topic of the digital asset security monitoring event in the transmission channel of the first message queue.
[0165] Optionally, the second configuration information is a configuration file, or a configuration file in a directory, and the content of the configuration file is still in a markup language (Yet Another Markup Language, YAML) format.
[0166] The second configuration information includes at least one of the following: the address information (host, such as IP) of the first message queue, the connection port (port) between the proxy terminal and the security engine, and the topic (topic) of the digital asset security monitoring event transmission channel in the first message queue.
[0167] For example, the format of the second configuration information is as follows:
[0168] Kafka:
[0169] host: 0.0.0.0
[0170] port: 0000
[0171] topic: test
[0172] After the security engine starts, it needs to read the second configuration information to obtain the IP address of the first message queue, the connection port between the agent terminal and the security engine, and the topic of the corresponding digital asset security monitoring event transmission channel in the first message queue. After the agent terminal completes the data security scanning task or detects a digital asset security monitoring event, it sends the task result or event information (i.e., the digital asset security monitoring event) to the first message queue specified by the second configuration information.
[0173] After the security engine is developed, a security engine message output format needs to be output, that is, the file format configured for the security engine to output the digital asset security monitoring events. For example, the file format is a JSON file, specifically as shown below:
[0174] {
[0175] "agent_id": "test",
[0176] "key1": "value1",
[0177] "key2": "value2", ...
[0179] }
[0180] Based on the security engine, generate the security engine installation package (or security engine extension installation package).
[0181] After completing the generation and configuration of the security engine, generate or create a security engine installation package.
[0182] In some embodiments, the process of creating a security engine installation package includes generating the security engine installation package based on the security engine, comprising:
[0183] The script of the security engine is compiled to obtain a binary file. Specifically, the security engine code is compiled to generate a binary file.
[0184] The binary file is hashed to obtain a hash file. Specifically, the binary file is MD5 fingerprinted and saved into an MD5 file (i.e., a hash file).
[0185] The binary file and the hash file are packaged together to obtain the security engine installation package.
[0186] Specifically, the binary file, MD5 file, and installation script are merged and packaged into a tgz file, and a password is set for the tgz file to decompress it.
[0187] The installation script only needs to move the security engine binary file to the opt / engines / xxx / directory in the current directory, where xxx is the filename of the security engine binary file. If the directory does not exist, it will be created, and then the file will be moved.
[0188] It should be noted that after the security engine installation package is created, the first device will upload the created security engine installation package to the engine management repository of the security operation platform.
[0189] In some embodiments, before obtaining the digital asset security monitoring event sent by the proxy terminal, the method further includes:
[0190] Deploy the security engine result parsing service according to the security engine result parsing service installation package and parsing service deployment instructions; wherein, the security engine result parsing service is used to parse the digital asset security monitoring events.
[0191] In this embodiment, a corresponding security engine result parsing service is developed on the first device. This security engine result parsing service needs to parse the digital asset security monitoring events reported by the security engine.
[0192] The process involves analyzing the digital asset security monitoring events to obtain the digital asset security monitoring results, including:
[0193] The security engine result parsing service is used to analyze the digital asset security monitoring events and obtain the digital asset security monitoring results.
[0194] Specifically, after the agent terminal uploads the digital asset security monitoring event to the first message queue, the security engine result parsing service parses the result content (i.e., the digital asset security monitoring event) to obtain the digital asset security monitoring result, and stores the digital asset security monitoring result in the database.
[0195] In some embodiments, deploying the security engine result parsing service according to the security engine result parsing service installation package and the parsing service deployment instructions includes:
[0196] Configure the security engine result parsing service to listen for and read the second configuration information according to the parsing service deployment instructions. The second configuration information includes at least one of the following: the address information of the first message queue, the connection port between the proxy terminal and the security engine, and the topic of the digital asset security monitoring event in the transmission channel of the first message queue.
[0197] Specifically, a corresponding security engine result parsing service is developed. This security engine result parsing service needs to read the second configuration information mentioned above. Optionally, the second configuration information is a configuration file, and the content of the configuration file is in YAML format.
[0198] For example, the second configuration information in YAML format is as follows:
[0199] Kafka:
[0200] host: 0.0.0.0
[0201] port: 0000
[0202] topic: test
[0203] After the security engine result parsing service starts, it needs to read the configuration file in the current directory to obtain the IP, port and topic of the first message queue. The security engine result parsing service needs to listen to the topic specified in the configuration file, receive the security event data (i.e. digital asset security monitoring events) transmitted back by the security engine, parse the data (i.e. digital asset security monitoring events) accordingly and store it in the database.
[0204] Specifically, it should be noted that the development specifications and parsing methods for the security engine result parsing service must meet the following development specifications:
[0205] The security engine result parsing service needs to provide the ability to read secondary configuration information, including the ability to read the following:
[0206] a) The IP address, port, and channel of the first message queue, such as 127.0.0.1 9092, and the Kafka topic;
[0207] b. The IP address (host), port (port), database name (dbname), username (username), and password (password) of the database.
[0208] Specifically, as follows:
[0209] Kafka:
[0210] host: 127.0.0.1
[0211] port: 9092
[0212] topic: test
[0213] database:
[0214] host: 127.0.0.1
[0215] port: 3306
[0216] dbname: test
[0217] username: test
[0218] password: test
[0219] After the security engine result parsing service starts, it first checks whether there is a storage table for the digital asset security monitoring results obtained after parsing and processing the corresponding digital asset security monitoring event. If there is no storage table, it will be created first; if it exists, the creation step will be skipped.
[0220] After the security engine result parsing service starts, it listens to the specified topic in the first message queue specified in the configuration file, and sets the security engine result parsing service process as a resident process to continuously receive messages (i.e. digital asset security monitoring events) sent from the topic in the first message queue.
[0221] Configure the file format of the digital asset security monitoring events parsed by the security engine result parsing service.
[0222] Specifically, it receives the message content (i.e., digital asset security monitoring event) sent by the first message queue, parses the message, and configures the file format of the message as JSON.
[0223] The file format is a reference to the file format of the digital asset security monitoring events output by the corresponding security engine, generally in JSON format. The specific business logic is related to the specific business logic of the security engine. For example, if the security engine is a baseline scanning engine, the file format of the digital asset security monitoring events is as follows:
[0224] {
[0225] "agent_id": "3624f790-ac05-4a7b-bbd7-ee57d39a9005",
[0226] "task_id": "1234567",
[0227] "base_line_type": "mysql",
[0228] "trace_id": "xxxxx",
[0229] "results": [
[0230] {
[0231] "config_path": " / proc / 3690 / root / etc / my.cnf.d / 6379.cnf",
[0232] "command": "grep SSL",
[0233] "id": 1,
[0234] "output": "SSL off",
[0235] "exit_code": 0,
[0236] "success": true,
[0237] "error_msg": "",
[0238] "start_time": 1745288228,
[0239] "end_time": 1745288228,
[0240] "expect": "SSL on"
[0241] },
[0242] ],
[0243] "start_time": 1745288228,
[0244] "end_time": 1745288228,
[0245] "success": true,
[0246] "success_count": 2,
[0247] "failed_count": 0,
[0248] "error_msg": ""
[0249] }
[0250] The reported content is the result of the digital asset security monitoring event of the baseline scanning engine. After the security engine result parsing service receives the message (i.e. digital asset security monitoring event) in the first message queue, it retrieves the result list, traverses the result list to determine whether the output and expectation of each element are consistent. If they are consistent, the baseline item is deemed compliant; otherwise, it is deemed non-compliant. The judgment result, along with other fields, is stored in the storage table of the security engine parsing result for recording.
[0251] Based on the message format specified by the security engine result parsing service, perform corresponding message parsing and business logic processing, and save the results to the aforementioned storage table after processing.
[0252] In some embodiments, the security engine result parsing service installation package is obtained by packaging the script, startup script, and stop script of the security engine result parsing service;
[0253] Specifically, after completing the above logic, create the startup script and stop script for the security engine result parsing service. The security engine result parsing service is started as a separate process. The startup script is named start.sh and the stop script is named stop.sh.
[0254] If the security engine result parsing service is a Java service, then the security engine result parsing service will be packaged into an xxx.jar file, and the startup command will be java -jar xxx.jar;
[0255] If the security engine result parsing service is a Golang service, then compile the security engine result parsing service into a binary file named xxx, and start it with the command sh xxx.
[0256] Package the scripts, startup scripts, and shutdown scripts of the Security Engine Result Parsing Service into a single tgz compressed file, which is the Security Engine Result Parsing Service installation package.
[0257] The step of deploying the security engine result parsing service according to the security engine result parsing service installation package and parsing service deployment instructions includes:
[0258] Register the security engine result parsing service installation package according to the parsing service deployment instructions.
[0259] Specifically, the security engine result parsing service's .tgz compressed package is uploaded to the parsing service management module for registration on the first device's security operation management platform. The parsing service registration process is as follows:
[0260] Upload the security engine result parsing service to the security operations management platform. Register the security engine result parsing service on the security operations management platform and fill in the name of the security engine result parsing service, such as: baseline_service.
[0261] According to the deployment instructions for the parsing service, the installation package of the security engine result parsing service is decompressed to obtain the script of the security engine result parsing service, the startup script, and the stop script.
[0262] Specifically, the security operations management platform decompresses the security engine result parsing service installation package and extracts it to a specified directory, such as / opt / [parsing service name], for example, / opt / baseline_service.
[0263] The security engine result parsing service is deployed according to the script of the security engine result parsing service, the startup script, and the stop script.
[0264] Specifically, the startup process for deploying the security engine result parsing service is as follows:
[0265] The security operations platform selects the security engine result parsing service and clicks "Start Service." The security operations platform then calls the startup script, such as: / opt / baseline_service / start.sh.
[0266] The shutdown procedure for deploying the security engine result parsing service is as follows:
[0267] The security operations platform selects the security engine result parsing service, clicks "Stop Service," and the security operations platform calls the stop script, such as: / opt / baseline_service / stop.sh;
[0268] The script stops the process of the security engine result parsing service.
[0269] Further use of data persisted to disk by the security engine results parsing service:
[0270] Digital asset security monitoring events are pushed to relevant business platforms through log external transmission.
[0271] In summary, the development of the security engine result parsing service was completed according to the development specifications. Registration of the security engine result parsing service was completed through the registration process. Hot deployment of the parsing service was controlled by the security operations platform, enabling uninterrupted expansion of the parsing service. Finally, the security operations platform pushed security engine-related data to the business platform, enabling further use of the security data.
[0272] The security engine message parsing service is deployed and registered on the security operation platform of the first device. The compressed package of the security engine message parsing service is uploaded and the parsing service name is filled in. The service deployment module of the security operation platform decompresses the tgz compressed package of the security engine message parsing service to / opt / [service name] and calls start.sh to start the parsing service. The start.sh and stop.sh scripts are used to start and stop the parsing service. Thus, the dynamic hot deployment processing of the result reporting message parsing service of the near-source host security capability extension engine is realized.
[0273] In some embodiments, before sending the security engine installation package and engine deployment instructions to the agent terminal, the method further includes:
[0274] Send third configuration information to the proxy terminal, wherein the third configuration information is used to register the proxy terminal on the server corresponding to the proxy terminal.
[0275] Optionally, the third configuration information is a configuration file.
[0276] The third configuration information includes at least one of the following: the address information of the server corresponding to the agent terminal (such as the IP of agent_server), and the port registered by the agent terminal.
[0277] Specifically, the agent terminal needs to be installed on the host side (i.e., the target host) for data asset security protection. This is achieved by specifying the IP address of the server (i.e., agent server, agent_server) corresponding to the agent terminal and the port where the agent terminal is registered through third-party configuration information. The server corresponding to the agent terminal initiates a connection request (i.e., a GRPC connection request) to the agent terminal, and the agent terminal receives the connection request and registers for connection.
[0278] Receive registration information sent by the agent terminal.
[0279] Specifically, after the agent terminal successfully connects and registers, it calls the register interface to report relevant registration information. After receiving the registration information, the server corresponding to the agent terminal stores the registration information in memory.
[0280] For example, the registration information includes the agent ID of the agent terminal.
[0281] In some embodiments, sending the security engine installation package and engine deployment instructions to the agent terminal includes:
[0282] The server corresponding to the proxy terminal sends the engine deployment instruction to the proxy terminal; wherein, the engine deployment instruction includes the identifier of the proxy terminal and the download address of the security engine installation package.
[0283] The server corresponding to the proxy terminal is used to parse the engine deployment command, obtain the identifier of the proxy terminal, and send the engine deployment command to the proxy terminal according to the identifier of the proxy terminal;
[0284] The proxy terminal is used to obtain the security engine installation package according to the download address of the security engine installation package.
[0285] Specifically, the process by which the security operation management platform of the first device distributes the security engine extension installation package to the online agent terminal includes: the security operation management platform sends the engine deployment instruction to the second message queue; the server corresponding to the agent terminal (i.e., the agent server, agent_server) listens to the second message queue through the listening channel to receive the engine deployment instruction; the server corresponding to the agent terminal (i.e., the agent server, agent_server) parses the engine deployment instruction, obtains the identifier of the agent terminal (i.e., the agent ID) in the engine deployment instruction, finds the communication channel between the agent terminal and the server corresponding to the agent terminal in memory, and sends the engine deployment instruction to the agent terminal; after receiving the engine deployment instruction, the agent terminal parses the content of the engine deployment instruction, obtains the download address of the security engine extension installation package, calls the download address and downloads the security engine extension installation package; after the download is completed, it decompresses the security engine extension installation package according to the decompression password and executes the security engine script within it; at this point, the new security capability has been deployed to the near-source host side.
[0286] The following is combined with Figure 3 The flowchart details the security engine and the security engine result parsing service extension.
[0287] like Figure 3As shown, the security administrator uploads the security engine installation package, security engine result parsing service, and engine deployment instructions to the security operations management platform. The security operations management platform sends the engine deployment instructions to the second message queue. The server (agent_server) corresponding to the agent terminal listens to the second message queue through the listening channel to receive the engine deployment instructions. The agent terminal deploys the engine through the GPRC interface to complete the deployment of the new security capability extension. After completing the deployment of the new security capability extension, the agent terminal sends a response to the security operations management platform through the server corresponding to the agent terminal and the second message queue. The security administrator uploads the parsing service deployment instructions to the security operations management platform, and the security operations management platform completes the deployment of the security engine result parsing service according to the parsing service deployment instructions.
[0288] In some embodiments, obtaining the digital asset security monitoring event sent by the agent terminal includes:
[0289] The digital asset security monitoring event sent by the agent terminal is obtained through the second configuration information and the first message queue; the first message queue is used to receive the digital asset security monitoring event.
[0290] The second configuration information includes at least one of the following: the address information of the first message queue, the connection port between the agent terminal and the security engine, and the topic of the digital asset security monitoring event transmission channel in the first message queue.
[0291] Specifically, the security operation platform of the first device operates the configuration distribution of this extended engine (i.e., the distribution of the second configuration information). The second configuration information includes the IP address, port, and topic of the first message queue. The platform distributes the configuration message to the first message queue. The agent_server listens to the first message queue. After receiving the configuration distribution instruction, it parses the corresponding agentId and distributes the configuration instruction to the specified agent. The agent generates a YAML configuration file based on the information in the second configuration information and starts the security engine process through a fork. The security engine starts and listens for digital asset security monitoring events. If a digital asset security monitoring event is detected, it sends the digital asset security monitoring event to the first message queue of the specified topic (also known as the security event message queue) using the IP address, port, and topic of the first message queue in the configuration file (i.e., the second configuration information). The security engine result parsing service parses the event content and stores it in the database. At this point, the entire security capability extension method is complete.
[0292] In some embodiments, obtaining the digital asset security monitoring event sent by the agent terminal includes:
[0293] Send a first message to the proxy terminal, the first message being used to instruct the proxy terminal to monitor the digital asset security monitoring event;
[0294] Receive the digital asset security monitoring event sent by the agent terminal.
[0295] It should be noted that for security engines that require script execution, a security task script is created on the security operations platform of the first device, triggering the security task distribution. The security operations management platform then distributes the task message (i.e., the first message) to the second message queue. The agent_server receives the task message from the second message queue, parses the message, obtains the agentId, searches for the agent's communication channel in the agent_server's memory, and calls the agent gRPC task receiving interface. After receiving the task message, the agent generates task description information (which can be a task description file) based on the message content and places it in the specified task description file directory. The security engine monitors the task description file directory; if a new task description file is found to be generated, it reads the task description file and starts executing the task. After the task is completed, the task execution result (i.e., the digital asset security monitoring event) is uploaded to the first message queue. The corresponding security engine result parsing service listens to the corresponding first message queue, and after obtaining the security event message (i.e., the digital asset security monitoring event), the security engine result parsing service parses the result content and stores it in the database.
[0296] For example, the task message format is as follows:
[0297] {
[0298] "agent_ids": ["agent_001"],
[0299] "type": "execute_task",
[0300] "task_payload": {
[0301] "taskId": "xxx",
[0302] "baseline_type": "mysql",
[0303] "engine_name": "execution_engine",
[0304] "cmds": [{"cmd": "grep ssl","expect":"on"}]
[0305] }
[0306] }
[0307] For example, the task description script generated by the agent has the following format:
[0308] {"task_id":"1234567","base_line_type":"mysql","files_path":[" / proc / 3690 / root / etc / my.cnf"," / proc / 369 0 / root / etc / my.cnf.d / 6379.cnf"," / proc / 3690 / root / etc / my.cnf.d / mysql-server.cnf"],"cmds":[{"cmd":"grep SSL","expect":"on"},{"cmd":"grep ListenAddr","expect":"!0.0.0.0"}],"timeout":5,"create_time":1745289344,"start_time":0,"end_time":0,"success":false,"error_msg":"","status":"pending"}
[0309] The following is combined with Figure 4 The specific steps for task execution are as follows:
[0310] The security administrator creates and distributes security tasks; the security operations platform sends security task messages to the second message queue; the server corresponding to the agent terminal listens to the second message queue and receives the first message (i.e., the security task message); the agent terminal receives the first message through the GPRC task receiving interface; the agent terminal generates task description information based on the first message, and uses the task description information and the security engine to listen for digital asset security monitoring events; the agent terminal reports the task execution result (i.e., the digital asset security monitoring event) to the first message queue; the security engine result parsing service listens to the first message queue and receives the task execution result (i.e., the digital asset security monitoring event); the security engine result parsing service parses the digital asset security monitoring event and obtains the parsing result (i.e., the digital asset security monitoring result); the parsing result is saved to the database; the security management platform can query the parsing result through the database.
[0311] like Figure 5 As shown in the embodiments of this application, a digital asset security monitoring method is also provided, applied to a proxy terminal, the method comprising:
[0312] Step 501: Receive the security engine installation package and engine deployment instruction sent by the first device, and deploy the security engine on the target host according to the engine deployment instruction and the security engine installation package; wherein, the security engine installation package includes a security engine for digital asset security monitoring.
[0313] In the embodiments of this application, the agent terminal may also be referred to as an agent, a near-source probe, a near-source agent, or a probe agent.
[0314] In this step, the first device sends the security engine installation package and engine deployment instructions to the online agent terminal through the security operation management platform, so that the agent terminal can bring the new security capabilities closer to the source host.
[0315] The security engine installation package includes (or carries) a security engine for digital asset security monitoring, and the engine deployment instructions are used to instruct the agent terminal to deploy the security engine on the target host (i.e., the near-source host).
[0316] Step 502: Receive the first configuration information sent by the first device, and start the security engine to perform digital asset security monitoring according to the first configuration information.
[0317] In this step, the first device sends the first configuration message to the second message queue through the security operation management platform. The agent_server listens to the second message queue, and upon receiving the instruction to send the first configuration message, it parses out the agent terminal identifier (agentId) corresponding to the first configuration message and sends the first configuration message to the specified agent terminal based on the agent terminal identifier. The agent terminal then starts the security engine process based on the first configuration information.
[0318] Through the above steps 501 and 502, a security engine for digital asset security monitoring is deployed by the first device as an extension of the agent terminal. This eliminates the need for complex processes such as code reconstruction, version iteration, and upgrades of the agent terminal, and enables the agent terminal to cope with digital asset security threats or new data asset security requirements.
[0319] Step 503: Use the security engine to perform digital asset security monitoring to obtain digital asset security monitoring events, and send the digital asset security monitoring events to the first device.
[0320] In this step, the agent terminal starts the security engine and listens for digital asset security monitoring events through the security engine. If a digital asset security monitoring event is detected, the agent terminal sends the digital asset security monitoring event to the first message queue of the specified topic (also known as the security event message queue) through the address information of the first message queue in the configuration file (i.e., Internet Protocol (IP)), the connection port between the agent terminal and the security engine, and the topic of the transmission channel of the digital asset security monitoring event in the first message queue. The first device then obtains the digital asset security monitoring event.
[0321] The first device deploys a security engine result parsing service, which parses the events of digital asset security monitoring events to obtain digital asset security monitoring results (such as whether there are security risks) and stores the digital asset security monitoring results in the database.
[0322] In step 503, the first device analyzes the digital asset security monitoring events to obtain the digital asset security monitoring results. This eliminates the need for a proxy terminal to analyze the digital asset security monitoring events, thereby improving security operation efficiency and reducing security response delays.
[0323] In some embodiments, before receiving the security engine installation package and engine deployment instructions sent by the first device, the method further includes:
[0324] The system receives third configuration information sent by the first device, registers on the server corresponding to the proxy terminal according to the third configuration information, and obtains registration information; wherein, the third configuration information includes at least one of the following: the address information of the server corresponding to the proxy terminal, and the port registered by the proxy terminal;
[0325] Send the registration information to the first device.
[0326] Optionally, the third configuration information is a configuration file.
[0327] Specifically, the agent terminal needs to be installed on the host side (i.e., the target host) for data asset security protection. This is achieved by specifying the IP address of the server (i.e., agent server, agent_server) corresponding to the agent terminal and the port where the agent terminal is registered through third-party configuration information. The server corresponding to the agent terminal initiates a connection request (i.e., a GRPC connection request) to the agent terminal, and the agent terminal receives the connection request and registers for connection.
[0328] After the proxy terminal successfully connects and registers, it calls the register interface to report the relevant registration information. After receiving the registration information, the server corresponding to the proxy terminal stores the registration information in memory.
[0329] For example, the registration information includes the agent ID of the agent terminal.
[0330] In some embodiments, receiving the security engine installation package and engine deployment instructions sent by the first device, and deploying the security engine on the target host according to the engine deployment instructions and the security engine installation package, includes:
[0331] Receive the engine deployment instruction sent through the server corresponding to the agent terminal, wherein the engine deployment instruction includes the identifier of the agent terminal and the download address of the security engine installation package;
[0332] Obtain the security engine installation package from the download address of the security engine installation package.
[0333] Specifically, the process by which the security operation management platform of the first device distributes the security engine extension installation package to the online agent terminal includes: the security operation management platform sends the engine deployment instruction to the second message queue; the server corresponding to the agent terminal (i.e., the agent server, agent_server) listens to the second message queue through the listening channel to receive the engine deployment instruction; the server corresponding to the agent terminal (i.e., the agent server, agent_server) parses the engine deployment instruction, obtains the identifier of the agent terminal (i.e., the agent ID) in the engine deployment instruction, finds the communication channel between the agent terminal and the server corresponding to the agent terminal in memory, and sends the engine deployment instruction to the agent terminal; after receiving the engine deployment instruction, the agent terminal parses the content of the engine deployment instruction, obtains the download address of the security engine extension installation package, calls the download address and downloads the security engine extension installation package; after the download is completed, it decompresses the security engine extension installation package according to the decompression password and executes the security engine script within it; at this point, the new security capability has been deployed to the near-source host side.
[0334] In some embodiments, the process of using the security engine to perform digital asset security monitoring to obtain digital asset security monitoring events includes:
[0335] Receive the first message sent by the first device;
[0336] Generate task description information based on the first message;
[0337] Digital asset security monitoring events are obtained by performing digital asset security monitoring based on the task description information and the security engine.
[0338] Specifically, for security engines that require script execution, a security task script is created on the security operation platform of the first device, triggering the security task distribution. The security operation management platform then distributes the task message (i.e., the first message) to the second message queue. The agent_server receives the task message from the second message queue, parses the message, obtains the agentId, searches for the agent's communication channel in the agent_server's memory, and calls the agent gRPC task receiving interface. After receiving the task message, the agent generates task description information (which can be a task description file) based on the message content and places it in the specified task description file directory. The security engine monitors the task description file directory; if a new task description file is found to be generated, it reads the task description file and starts executing the task. After the task is completed, the task execution result (i.e., the digital asset security monitoring event) is uploaded to the first message queue. The corresponding security engine result parsing service monitors the corresponding first message queue, and after obtaining the security event message (i.e., the digital asset security monitoring event), the security engine result parsing service parses the result content and stores it in the database.
[0339] Generally, different security engines are used for different data asset security protection scenarios. Furthermore, to cope with diverse attack methods, new protection capabilities need to be flexibly added to the agent terminal, achieving security capability expansion without refactoring or restarting the agent. Simultaneously, it achieves unified management of existing traditional security protection equipment event collection, improving security operation efficiency. The digital asset security monitoring method provided in this application embodiment enhances the scalability of data asset security monitoring products. Different data asset security monitoring capabilities can be flexibly deployed for different security scenarios. New security capabilities can be hot-deployed for emerging cybersecurity threats or new data asset security needs without requiring complex processes such as code refactoring, version iteration, and upgrades of near-source agents.
[0340] Through the processes described in the above embodiments, this application enables online expansion of probe data asset security capabilities without upgrading or reconstructing the agent. It achieves unified management and control of data asset security and allows for customized deployment of security engines based on different security scenarios. For specific scenarios or new security threats, when pre-built security capabilities are insufficient, online expansion can be performed using the method provided in this application. The method provided in this application is highly scalable and meets the security capability expansion needs of different security scenarios. It supports online expansion of near-source host security capabilities without updating or restarting the agent probe. Simultaneously, it supports the management of existing agents from different security vendors, enhancing the unified management and control capabilities of data asset security.
[0341] Specifically, this application proposes a hot update scheme for security event analysis services. The analysis service developed through the security engine result analysis service development specification can be uploaded to the engine repository to achieve hot deployment of the analysis service and realize dynamic expansion of security event data analysis and processing.
[0342] This application proposes a layered decoupling design between the near-source probe agent and the security capability engine. The agent probe is responsible for managing the security engine, including deployment, startup, shutdown, and task generation, while the security engine performs specific security tasks. This method enables the addition of new and extended security capabilities without restarting or reconstructing the agent probe, providing underlying design support for online expansion of security capabilities. It also supports the inclusion of existing agent probes from other vendors or in general management, achieving unified control and enhancing the unified management capabilities of data asset security.
[0343] This application proposes an asynchronous communication mode between the data asset security operation platform and the agent. The platform issues commands through a message queue. The agent_server listens to the message queue, parses the received messages, and selects the corresponding agent to issue commands. Simultaneously, the security engine on the agent side uploads the task execution results to the corresponding message queue channel. The security engine parsing service listens to the corresponding channel to parse the task results. Multiple instances of the agent_server, security engine parsing service, and message queue can be deployed, enabling flexible scaling and supporting distributed deployment of components such as the agent_server, security engine parsing service, and message queue. Furthermore, this application also enables elastic scaling, supporting large-scale data security asset monitoring and data processing.
[0344] The agent probe in this application first uses the gRPC communication protocol to achieve bidirectional streaming communication between the agent and the server, resulting in higher efficiency in handling and responding to security incidents. Secondly, it adopts a decoupled design for agent management functions and the security capability engine, providing effective support for the agent to flexibly extend host security capabilities. Control plane messages are received by the agent probe, which generates a task description file. The agent probe then initiates the security capability engine to read the task description file and process the task. Data plane messages are directly reported to the message queue by the security capability engine.
[0345] This application proposes a dynamic security engine extension and security engine reporting data parsing scheme. Combined with engine repository management functions, it can realize an open security capability ecosystem. Any security engine made by any vendor or individual according to this specification can be quickly integrated to improve host security protection capabilities and security scanning capabilities.
[0346] The asynchronous communication mode adopted in this application supports large-scale data asset security monitoring and management capabilities. Components such as the agent_server, security event parsing service, and message queue all support distributed deployment. This allows for elastic scaling, enhancing the scale of data asset security monitoring.
[0347] This application enables the deployment of different security capabilities under different security scenarios, achieving a high degree of alignment with the security capabilities required by actual business scenarios and minimizing the impact on host resources (Central Processing Unit (CPU), memory, etc.).
[0348] This application aims to address the lack of scalability in the field of data asset security monitoring and protection. Faced with complex network security risks associated with logs and a complex information technology (IT) ecosystem, traditional data asset security protection products struggle to scale flexibly and be customized on demand, and they cannot integrate with existing or different vendors' agent products. Based on this application, an open and ecological data asset security protection platform can be implemented, allowing both in-house employees and third-party vendors to access this security ecosystem. Customized data asset security protection capabilities can be implemented for different scenarios and security needs. The data asset security operation platform implemented based on this application can improve enterprise security operation efficiency, save security operation management costs, and enhance the protection capabilities of enterprise database assets and security assets, demonstrating promising market prospects.
[0349] like Figure 6 As shown in the illustration, this application also provides a digital asset security monitoring device, the device comprising:
[0350] The first sending module 601 is used to send a security engine installation package and an engine deployment instruction to the agent terminal. The security engine installation package includes a security engine for digital asset security monitoring, and the engine deployment instruction is used to instruct the agent terminal to deploy the security engine on the target host.
[0351] The second sending module 602 is used to send first configuration information to the agent terminal, the first configuration information being used to instruct the agent terminal to start the security engine to perform digital asset security monitoring.
[0352] The first acquisition module 603 is used to acquire digital asset security monitoring events sent by the agent terminal, wherein the digital asset security monitoring events are obtained by the agent terminal using the security engine to perform digital asset security monitoring.
[0353] The first processing module 604 is used to analyze the digital asset security monitoring events and obtain the digital asset security monitoring results.
[0354] Optionally, the device further includes:
[0355] The fifth processing module is used to generate the security engine based on the digital asset security detection task;
[0356] The sixth processing module is used to configure the security engine to read the second configuration information, wherein the second configuration information includes at least one of the following: the address information of the first message queue, the connection port between the proxy terminal and the security engine, and the topic of the digital asset security monitoring event transmission channel in the first message queue;
[0357] The seventh processing module is used to configure the file format for the digital asset security monitoring events output by the security engine;
[0358] The eighth processing module is used to generate the security engine installation package based on the security engine.
[0359] Optionally, the eighth processing module includes:
[0360] The first processing unit is used to compile the script of the security engine to obtain a binary file;
[0361] The second processing unit is used to perform hash calculations on the binary file to obtain a hash file;
[0362] The third processing unit is used to package the binary file and the hash file to obtain the security engine installation package.
[0363] Optionally, the device further includes:
[0364] The ninth processing module is used to deploy the security engine result parsing service according to the security engine result parsing service installation package and the parsing service deployment instructions; wherein, the security engine result parsing service is used to parse the digital asset security monitoring events;
[0365] The first processing module 604 includes:
[0366] The fourth processing unit is used to analyze the digital asset security monitoring events using the security engine result parsing service to obtain the digital asset security monitoring results.
[0367] Optionally, the ninth processing module includes:
[0368] The fifth processing unit is configured to listen to and read the second configuration information according to the parsing service deployment instruction, wherein the second configuration information includes at least one of the following: the address information of the first message queue, the connection port between the proxy terminal and the security engine, and the topic of the digital asset security monitoring event in the transmission channel of the first message queue;
[0369] The sixth processing unit is used to configure the file format of the digital asset security monitoring events parsed by the security engine result parsing service.
[0370] Optionally, the security engine result parsing service installation package is obtained by packaging the script, startup script and stop script of the security engine result parsing service;
[0371] The ninth processing module includes:
[0372] The seventh processing unit is used to register the security engine result parsing service installation package according to the parsing service deployment instruction;
[0373] The eighth processing unit is used to decompress the security engine result parsing service installation package according to the parsing service deployment instruction to obtain the security engine result parsing service script, the startup script and the stop script;
[0374] The ninth processing unit is used to deploy the security engine result parsing service according to the script of the security engine result parsing service, the startup script and the stop script.
[0375] Optionally, the device further includes:
[0376] The third sending module is used to send third configuration information to the proxy terminal, wherein the third configuration information is used to register the proxy terminal on the server corresponding to the proxy terminal, and the third configuration information includes at least one of the following: the address information of the server corresponding to the proxy terminal, and the port registered by the proxy terminal;
[0377] The first receiving module is used to receive the registration information sent by the agent terminal.
[0378] Optionally, the first transmitting module 601 includes:
[0379] The first sending unit is used to send the engine deployment instruction to the proxy terminal through the server corresponding to the proxy terminal;
[0380] The engine deployment instruction includes the identifier of the agent terminal and the download address of the security engine installation package;
[0381] The server corresponding to the proxy terminal is used to parse the engine deployment command, obtain the identifier of the proxy terminal, and send the engine deployment command to the proxy terminal according to the identifier of the proxy terminal;
[0382] The proxy terminal is used to obtain the security engine installation package according to the download address of the security engine installation package.
[0383] Optionally, the first acquisition module includes:
[0384] The first acquisition unit is used to acquire the digital asset security monitoring event sent by the agent terminal through the second configuration information and the first message queue;
[0385] The second configuration information includes at least one of the following: the address information of the first message queue, the connection port between the agent terminal and the security engine, and the topic of the digital asset security monitoring event transmission channel in the first message queue.
[0386] Optionally, the first acquisition module includes:
[0387] The second sending unit is used to send a first message to the agent terminal, the first message being used to instruct the agent terminal to monitor the digital asset security monitoring event;
[0388] The first receiving unit is used to receive the digital asset security monitoring event sent by the agent terminal.
[0389] It should be noted that the digital asset security monitoring device provided in this application embodiment is a device capable of executing the digital asset security monitoring method executed by the first device described above. Therefore, all embodiments of the digital asset security monitoring method executed by the first device described above are applicable to this device and can achieve the same or similar technical effects.
[0390] like Figure 7 As shown in the illustration, this application also provides a digital asset security monitoring device, the device comprising:
[0391] The second processing module 701 is used to receive a security engine installation package and an engine deployment instruction sent by the first device, and deploy a security engine on the target host according to the engine deployment instruction and the security engine installation package; wherein, the security engine installation package includes a security engine for digital asset security monitoring.
[0392] The third processing module 702 is used to receive the first configuration information sent by the first device and start the security engine to perform digital asset security monitoring according to the first configuration information.
[0393] The fourth processing module 703 is used to perform digital asset security monitoring using the security engine to obtain digital asset security monitoring events, and to send the digital asset security monitoring events to the first device.
[0394] Optionally, the device further includes:
[0395] The tenth processing module is used to receive third configuration information sent by the first device, register on the server corresponding to the proxy terminal according to the third configuration information, and obtain registration information; wherein, the third configuration information includes at least one of the following: the address information of the server corresponding to the proxy terminal, and the port registered by the proxy terminal;
[0396] The third sending module is used to send the registration information to the first device.
[0397] Optionally, the second processing module 701 includes:
[0398] The second receiving unit is configured to receive the engine deployment instruction sent by the server corresponding to the proxy terminal, wherein the engine deployment instruction includes the identifier of the proxy terminal and the download address of the security engine installation package;
[0399] The second acquisition unit is used to acquire the security engine installation package according to the download address of the security engine installation package.
[0400] Optionally, the fourth processing module 703 includes:
[0401] The third receiving unit is used to receive the first message sent by the first device;
[0402] The tenth processing unit is used to generate task description information based on the first message;
[0403] The eleventh processing unit is used to obtain digital asset security monitoring events by performing digital asset security monitoring based on the task description information and the security engine.
[0404] It should be noted that the digital asset security monitoring device provided in this application embodiment is a device capable of executing the digital asset security monitoring method executed by the proxy terminal described above. Therefore, all embodiments of the digital asset security monitoring method executed by the proxy terminal described above are applicable to this device and can achieve the same or similar technical effects.
[0405] like Figure 8As shown in the figure, this application embodiment also provides an electronic device, including: a processor 801; and a memory 803 connected to the processor 801 via a bus interface 802, the memory 803 being used to store programs and data used by the processor 801 when performing operations, and the processor 801 calling and executing the programs and data stored in the memory 803.
[0406] The transceiver 804 is connected to the bus interface 802 and is used to receive and send data under the control of the processor 801. Specifically, the processor 801 is used to read the program in the memory 803, and the transceiver 804 is used to execute the following processes:
[0407] Send a security engine installation package and an engine deployment instruction to the agent terminal, wherein the security engine installation package includes a security engine for digital asset security monitoring, and the engine deployment instruction is used to instruct the agent terminal to deploy the security engine on the target host;
[0408] Send first configuration information to the agent terminal, the first configuration information being used to instruct the agent terminal to start the security engine for digital asset security monitoring;
[0409] The processor 801 is used to perform the following procedures:
[0410] The agent terminal sends a digital asset security monitoring event, which is obtained by the agent terminal using the security engine to perform digital asset security monitoring.
[0411] The digital asset security monitoring events are analyzed to obtain the digital asset security monitoring results.
[0412] Optionally, before sending the security engine installation package and engine deployment instructions to the agent terminal, the processor 801 is further configured to:
[0413] The security engine is generated based on the digital asset security detection task;
[0414] The security engine is configured to read second configuration information, wherein the second configuration information includes at least one of the following: address information of the first message queue, connection port between the proxy terminal and the security engine, and topic of the digital asset security monitoring event transmission channel in the first message queue;
[0415] Configure the file format for the digital asset security monitoring events output by the security engine;
[0416] Based on the security engine, generate the security engine installation package.
[0417] Optionally, the processor 801 is specifically used for:
[0418] The scripts of the security engine are compiled to obtain binary files;
[0419] Perform a hash calculation on the binary file to obtain a hash file;
[0420] The binary file and the hash file are packaged together to obtain the security engine installation package.
[0421] Optionally, before acquiring the digital asset security monitoring event sent by the agent terminal, the processor 801 is further configured to:
[0422] Deploy the security engine result parsing service according to the security engine result parsing service installation package and parsing service deployment instructions; wherein, the security engine result parsing service is used to parse the digital asset security monitoring events;
[0423] Specifically, the processor 801 is used for:
[0424] The security engine result parsing service is used to analyze the digital asset security monitoring events and obtain the digital asset security monitoring results.
[0425] Optionally, the processor 801 is specifically used for:
[0426] Configure the security engine result parsing service to listen to and read the second configuration information according to the parsing service deployment instruction, wherein the second configuration information includes at least one of the following: the address information of the first message queue, the connection port between the proxy terminal and the security engine, and the topic of the digital asset security monitoring event in the transmission channel of the first message queue;
[0427] Configure the file format of the digital asset security monitoring events parsed by the security engine result parsing service.
[0428] Optionally, the security engine result parsing service installation package is obtained by packaging the script, startup script and stop script of the security engine result parsing service;
[0429] Specifically, the processor 801 is used for:
[0430] According to the parsing service deployment instructions, the security engine result parsing service installation package is registered;
[0431] According to the parsing service deployment instructions, the security engine result parsing service installation package is decompressed to obtain the security engine result parsing service script, the startup script, and the stop script;
[0432] The security engine result parsing service is deployed according to the script of the security engine result parsing service, the startup script, and the stop script.
[0433] Optionally, before sending the security engine installation package and engine deployment instructions to the agent terminal, the transceiver 804 is further configured to:
[0434] Send third configuration information to the proxy terminal, wherein the third configuration information is used to register the proxy terminal on the server corresponding to the proxy terminal, and the third configuration information includes at least one of the following: the address information of the server corresponding to the proxy terminal, and the port registered by the proxy terminal;
[0435] Receive registration information sent by the agent terminal.
[0436] Optionally, the transceiver 804 is specifically used for:
[0437] The engine deployment command is sent to the proxy terminal through the server corresponding to the proxy terminal;
[0438] The engine deployment instruction includes the identifier of the agent terminal and the download address of the security engine installation package;
[0439] The server corresponding to the proxy terminal is used to parse the engine deployment command, obtain the identifier of the proxy terminal, and send the engine deployment command to the proxy terminal according to the identifier of the proxy terminal;
[0440] The proxy terminal is used to obtain the security engine installation package according to the download address of the security engine installation package.
[0441] Optionally, the processor 801 is specifically used for:
[0442] The digital asset security monitoring event sent by the agent terminal is obtained through the second configuration information and the first message queue;
[0443] The second configuration information includes at least one of the following: the address information of the first message queue, the connection port between the agent terminal and the security engine, and the topic of the digital asset security monitoring event transmission channel in the first message queue.
[0444] Optionally, the transceiver 804 is specifically used for:
[0445] Send a first message to the proxy terminal, the first message being used to instruct the proxy terminal to monitor the digital asset security monitoring event;
[0446] Receive the digital asset security monitoring event sent by the agent terminal.
[0447] Among them, Figure 8 In this context, the bus architecture may include any number of interconnected buses and bridges, specifically linking various circuits together, represented by one or more processors (processor 801) and memory (memory 803). The bus architecture may also link together various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art and therefore will not be described further herein. A bus interface provides a user interface 805. A transceiver 804 may be multiple elements, including transmitters and receivers, providing units for communicating with various other devices over a transmission medium. Processor 801 is responsible for managing the bus architecture and general processing, and memory 803 may store data used by processor 801 during operation.
[0448] This application embodiment also provides a terminal device, including: a processor; and a memory connected to the processor via a bus interface, the memory being used to store programs and data used by the processor when performing operations, and the processor calling and executing the programs and data stored in the memory.
[0449] The transceiver is connected to the bus interface and is used to receive and send data under the control of the processor.
[0450] It should be noted that the terminal device provided in this application embodiment is similar to... Figure 8 The structures of the electronic devices shown are basically the same, so they will not be described in detail here.
[0451] Specifically, the processor is used to read the program from the memory, and the transceiver is used to execute the following processes:
[0452] Receive the security engine installation package and engine deployment instructions sent by the first device;
[0453] The processor is used to perform the following procedures:
[0454] According to the engine deployment instructions and the security engine installation package, the security engine is deployed on the target host; wherein, the security engine installation package includes a security engine for digital asset security monitoring;
[0455] The transceiver is used to perform the following processes:
[0456] Receive the first configuration information sent by the first device;
[0457] The processor is used to perform the following procedures:
[0458] Based on the first configuration information, the security engine is activated to perform digital asset security monitoring;
[0459] The security engine is used to perform digital asset security monitoring to obtain digital asset security monitoring events.
[0460] The transceiver is used to perform the following processes:
[0461] Send the digital asset security monitoring event to the first device.
[0462] Optionally, before receiving the security engine installation package and engine deployment instructions sent by the first device, the transceiver is further configured to:
[0463] Receive the third configuration information sent by the first device;
[0464] Optionally, the processor is further configured to:
[0465] The agent terminal registers on the server corresponding to the agent terminal according to the third configuration information to obtain registration information; wherein, the third configuration information includes at least one of the following: the address information of the server corresponding to the agent terminal, and the port on which the agent terminal registers;
[0466] Optionally, the transceiver is further used for:
[0467] Send the registration information to the first device.
[0468] Optionally, the transceiver is specifically used for:
[0469] Receive the engine deployment instruction sent through the server corresponding to the agent terminal, wherein the engine deployment instruction includes the identifier of the agent terminal and the download address of the security engine installation package;
[0470] Obtain the security engine installation package from the download address of the security engine installation package.
[0471] Optionally, the transceiver is specifically used for:
[0472] Receive the first message sent by the first device;
[0473] The processor is specifically used for:
[0474] Generate task description information based on the first message;
[0475] Digital asset security monitoring events are obtained by performing digital asset security monitoring based on the task description information and the security engine.
[0476] In addition, specific embodiments of this application also provide a readable storage medium having a computer program stored thereon, wherein when the program is executed by a processor, it implements the steps in the digital asset security monitoring method as described above.
[0477] In the several embodiments provided in this application, it should be understood that the disclosed methods and apparatus can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between devices or units may be electrical, mechanical, or other forms.
[0478] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can be physically included separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or in the form of hardware plus software functional units.
[0479] The integrated units implemented as software functional units described above can be stored in a computer-readable storage medium. These software functional units, stored in a storage medium, include several instructions that cause a computer device (which may be a personal computer, server, or network device, etc.) to execute partial steps of the resource selection method described in the various embodiments of this application, or to execute partial steps of the information transmission method described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0480] A specific embodiment of this application also provides a computer program product, including computer instructions, which, when executed by a processor, implement the above-described functionality. Figure 1 or Figure 5 The various processes of the method embodiments shown can achieve the same technical effect, and will not be described again here to avoid repetition.
[0481] The embodiments of this application have been described above with reference to the accompanying drawings. However, this application is not limited to the specific embodiments described above. The specific embodiments described above are merely illustrative and not restrictive. Those skilled in the art can make many other forms under the guidance of this application without departing from the spirit and scope of the claims, and all of these forms are within the protection scope of this application.
Claims
1. A method for monitoring the security of digital assets, characterized in that, Applied to a first device, the method includes: Send a security engine installation package and an engine deployment instruction to the agent terminal, wherein the security engine installation package includes a security engine for digital asset security monitoring, and the engine deployment instruction is used to instruct the agent terminal to deploy the security engine on the target host; Send first configuration information to the agent terminal, the first configuration information being used to instruct the agent terminal to start the security engine for digital asset security monitoring; The agent terminal sends a digital asset security monitoring event, which is obtained by the agent terminal using the security engine to perform digital asset security monitoring. The digital asset security monitoring events are analyzed to obtain the digital asset security monitoring results.
2. The method according to claim 1, characterized in that, Before sending the security engine installation package and engine deployment instructions to the agent terminal, the method further includes: The security engine is generated based on the digital asset security detection task; The security engine is configured to read second configuration information, wherein the second configuration information includes at least one of the following: address information of the first message queue, connection port between the proxy terminal and the security engine, and topic of the digital asset security monitoring event transmission channel in the first message queue; Configure the file format for the digital asset security monitoring events output by the security engine; Based on the security engine, generate the security engine installation package.
3. The method according to claim 2, characterized in that, The step of generating the security engine installation package based on the security engine includes: The scripts of the security engine are compiled to obtain binary files; Perform a hash calculation on the binary file to obtain a hash file; The binary file and the hash file are packaged together to obtain the security engine installation package.
4. The method according to claim 1, characterized in that, Before acquiring the digital asset security monitoring event sent by the proxy terminal, the method further includes: Deploy the security engine result parsing service according to the security engine result parsing service installation package and parsing service deployment instructions; wherein, the security engine result parsing service is used to parse the digital asset security monitoring events; The process involves analyzing the digital asset security monitoring events to obtain the digital asset security monitoring results, including: The security engine result parsing service is used to analyze the digital asset security monitoring events and obtain the digital asset security monitoring results.
5. The method according to claim 4, characterized in that, The step of deploying the security engine result parsing service according to the security engine result parsing service installation package and parsing service deployment instructions includes: Configure the security engine result parsing service to listen to and read the second configuration information according to the parsing service deployment instruction, wherein the second configuration information includes at least one of the following: the address information of the first message queue, the connection port between the proxy terminal and the security engine, and the topic of the digital asset security monitoring event in the transmission channel of the first message queue; Configure the file format of the digital asset security monitoring events parsed by the security engine result parsing service.
6. The method according to claim 4, characterized in that, The security engine result parsing service installation package is obtained by packaging the script, startup script and stop script of the security engine result parsing service. The step of deploying the security engine result parsing service according to the security engine result parsing service installation package and parsing service deployment instructions includes: According to the parsing service deployment instructions, the security engine result parsing service installation package is registered; According to the parsing service deployment instructions, the security engine result parsing service installation package is decompressed to obtain the security engine result parsing service script, the startup script, and the stop script; The security engine result parsing service is deployed according to the script of the security engine result parsing service, the startup script, and the stop script.
7. The method according to claim 1, characterized in that, Before sending the security engine installation package and engine deployment instructions to the agent terminal, the method further includes: Send third configuration information to the proxy terminal, wherein the third configuration information is used to register the proxy terminal on the server corresponding to the proxy terminal, and the third configuration information includes at least one of the following: the address information of the server corresponding to the proxy terminal, and the port registered by the proxy terminal; Receive registration information sent by the agent terminal.
8. The method according to claim 1, characterized in that, Sending the security engine installation package and engine deployment instructions to the agent terminal includes: The engine deployment command is sent to the proxy terminal through the server corresponding to the proxy terminal; The engine deployment instruction includes the identifier of the agent terminal and the download address of the security engine installation package; The server corresponding to the proxy terminal is used to parse the engine deployment command, obtain the identifier of the proxy terminal, and send the engine deployment command to the proxy terminal according to the identifier of the proxy terminal; The proxy terminal is used to obtain the security engine installation package according to the download address of the security engine installation package.
9. The method according to claim 1, characterized in that, The acquisition of digital asset security monitoring events sent by the agent terminal includes: The digital asset security monitoring event sent by the agent terminal is obtained through the second configuration information and the first message queue; The second configuration information includes at least one of the following: the address information of the first message queue, the connection port between the agent terminal and the security engine, and the topic of the digital asset security monitoring event transmission channel in the first message queue.
10. The method according to claim 1, characterized in that, The acquisition of digital asset security monitoring events sent by the agent terminal includes: Send a first message to the proxy terminal, the first message being used to instruct the proxy terminal to monitor the digital asset security monitoring event; Receive the digital asset security monitoring event sent by the agent terminal.
11. A method for monitoring the security of digital assets, characterized in that, Applied to a proxy terminal, the method includes: The system receives a security engine installation package and an engine deployment instruction sent by a first device, and deploys a security engine on a target host according to the engine deployment instruction and the security engine installation package; wherein, the security engine installation package includes a security engine for digital asset security monitoring. Receive the first configuration information sent by the first device, and start the security engine to perform digital asset security monitoring according to the first configuration information; The security engine is used to perform digital asset security monitoring to obtain digital asset security monitoring events, and the digital asset security monitoring events are sent to the first device.
12. The method according to claim 11, characterized in that, Before receiving the security engine installation package and engine deployment instructions sent by the first device, the method further includes: The system receives third configuration information sent by the first device, registers on the server corresponding to the proxy terminal according to the third configuration information, and obtains registration information; wherein, the third configuration information includes at least one of the following: the address information of the server corresponding to the proxy terminal, and the port registered by the proxy terminal; Send the registration information to the first device.
13. The method according to claim 11, characterized in that, The step of receiving the security engine installation package and engine deployment instructions sent by the first device, and deploying the security engine on the target host according to the engine deployment instructions and the security engine installation package, includes: Receive the engine deployment instruction sent through the server corresponding to the agent terminal, wherein the engine deployment instruction includes the identifier of the agent terminal and the download address of the security engine installation package; Obtain the security engine installation package from the download address of the security engine installation package.
14. The method according to claim 11, characterized in that, The digital asset security monitoring events obtained by using the security engine include: Receive the first message sent by the first device; Generate task description information based on the first message; Digital asset security monitoring events are obtained by performing digital asset security monitoring based on the task description information and the security engine.
15. A digital asset security monitoring device, characterized in that, The device includes: The first sending module is used to send a security engine installation package and an engine deployment instruction to the agent terminal. The security engine installation package includes a security engine for digital asset security monitoring, and the engine deployment instruction is used to instruct the agent terminal to deploy the security engine on the target host. The second sending module is used to send first configuration information to the agent terminal, the first configuration information being used to instruct the agent terminal to start the security engine to perform digital asset security monitoring. The first acquisition module is used to acquire digital asset security monitoring events sent by the agent terminal, wherein the digital asset security monitoring events are obtained by the agent terminal using the security engine to perform digital asset security monitoring. The first processing module is used to analyze the digital asset security monitoring events and obtain the digital asset security monitoring results.
16. A digital asset security monitoring device, characterized in that, The device includes: The second processing module is used to receive a security engine installation package and an engine deployment instruction sent by the first device, and deploy a security engine on the target host according to the engine deployment instruction and the security engine installation package; wherein, the security engine installation package includes a security engine for digital asset security monitoring; The third processing module is used to receive the first configuration information sent by the first device, and start the security engine to perform digital asset security monitoring according to the first configuration information. The fourth processing module is used to perform digital asset security monitoring using the security engine to obtain digital asset security monitoring events, and to send the digital asset security monitoring events to the first device.
17. An electronic device, characterized in that, include: A processor, a memory, and a program stored in the memory and executable on the processor, wherein the program, when executed by the processor, implements the steps of the digital asset security monitoring method as described in any one of claims 1 to 10.
18. A terminal device, characterized in that, include: A processor, a memory, and a program stored in the memory and executable on the processor, wherein the program, when executed by the processor, implements the steps of the digital asset security monitoring method as described in any one of claims 11 to 14.
19. A readable storage medium, characterized in that, The readable storage medium stores a program that, when executed by a processor, implements the steps of the digital asset security monitoring method as described in any one of claims 1 to 10, or implements the steps of the digital asset security monitoring method as described in any one of claims 11 to 14.
20. A computer program product, characterized in that, The method includes computer instructions that, when executed by a processor, implement the steps in the digital asset security monitoring method as described in any one of claims 1 to 10, or implement the steps in the digital asset security monitoring method as described in any one of claims 11 to 14.