A multi-source heterogeneous digital asset unified management system and method
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- HANGZHOU ZHISHUN TECH CO LTD
- Filing Date
- 2026-07-02
- Publication Date
- 2026-08-07
AI Technical Summary
本发明通过构建异构标签属性集合形成动态校验时间窗口,并结合实时配置特征向量与原始资产基线向量确认配置工单的流转状态,将配置指令下发环节与底层物理节点的真实生效结果相绑定,修补了多云异构环境下因异步执行导致的管理指令控制流与资产状态流之间的拓扑断裂,防止了仅依据接口响应而造成的合规状态失真;同时,本发明以校验通过状态对应的实时配置特征向量为基准构建容差圆柱体,将纳管资产的离散状态转化为沿时间轴连续分布的游丝轨迹,通过计算实时状态坐标点至底面圆心的径向偏移量构建了针对配置漂移的持续几何约束模型,弥补了静态快照无法捕捉随时间推移产生的隐性越界行为的缺陷,并在游丝轨迹触碰容差圆柱体内壁时,基于向心校准向量触发局部配置复位与闭环验证,使纳管系统具备对本地环境暗中篡改引发的隐性配置漂移进行定向约束与闭环修复的能力。
Smart Images

Figure CN122533859A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of digital asset management technology, and more specifically, to a unified management system and method for multi-source heterogeneous digital assets. Background Technology
[0002] As enterprises deepen their digital transformation, IT infrastructure is gradually evolving into a multi-cloud heterogeneous structure, encompassing public clouds, private clouds, and on-premises physical machines. Under this complex network architecture, how to uniformly configure and distribute massive, dispersed, and structurally diverse digital assets and manage their security baselines to ensure the continuous compliance of all network assets has become an important research direction in the field of digital asset management.
[0003] In the existing technology, there are some solutions for the management and control of digital assets. For example, patent application CN119690769A discloses a digital asset monitoring method and system. This technology maps data asset objects from multiple business systems to target nodes in a graph isomorphic network, updates the asset feature vectors of each node through neighborhood aggregation, and then outputs the real-time monitoring status of the data asset objects, solving the data integration problem caused by the inconsistency of interfaces and protocols among various systems in related technologies. Another example is patent application CN119739772A, which discloses a data asset management method and system based on multiple heterogeneous data sources. It constructs engineering data asset cards based on engineering elements of engineering projects and determines the data topology. It uses open-source ETL scripts to connect to multiple heterogeneous data sources and establishes a data distribution and sharing monitoring mechanism to perform data distribution monitoring.
[0004] However, existing asset management solutions still face hidden security blind spots in the actual operation and maintenance scenarios of multi-cloud heterogeneous assets. After maintenance personnel issue a unified security baseline configuration work order to cloud hosts or local physical machines from different cloud vendors, the ITSM work order system and CMDB asset dashboard usually show that the status of all hosts in that batch is "compliant" or "configured successfully". However, after running for a few hours, some local physical machines or specific cloud hosts' built-in local scheduled tasks (Cron) or underlying security daemons will quietly roll back the newly issued configuration, such as unauthorized re-opening of high-risk ports that have been closed. Since the maintenance dashboard is completely unaware of this subsequent covert tampering, the entire management platform becomes "blind". This static management perspective gives the system a false sense of security, causing these hosts, which are in a vulnerable state, to be scanned and intruded by malicious ransomware or have their core data stolen at any time, and may even cause network security incidents such as lateral movement across the internal network. Summary of the Invention
[0005] In multi-cloud heterogeneous environments, configuration deployment is typically asynchronous and discrete. Operations and maintenance (O&M) platforms often rely on responses from cloud vendor API gateways for strong status verification only at specific moments after an instruction is issued. Once a "success" response is received, the process engine automatically closes the configuration work order and updates the asset registration ledger. This management model, based on the assumption that "API response is fact," ignores the inherent environmental autonomy of the underlying heterogeneous digital assets. In real-world cloud-native and physical machine hybrid environments, underlying nodes are not static carriers passively accepting configurations. Their configuration states are continuously affected by local dependency conflicts, silent retry mechanisms, or third-party security processes, causing them to deviate from the original baseline over time, resulting in continuous configuration drift. Because traditional management methods only record the instruction issuance status and lack a continuous geometric constraint model on the asset configuration status over time, static management snapshots cannot capture implicit out-of-bounds behaviors that occur over time. This ultimately leads to a topological break between the instruction control flow and the actual state flow of the underlying assets in the unified digital asset management process, resulting in a deep distortion between the compliance status from the management perspective and the actual state of the underlying physical nodes.
[0006] This invention is primarily applied to the operation and maintenance management scenarios of multi-cloud hybrid IT infrastructure in large enterprises or cloud service providers. It is particularly suitable for centralized security management environments that require simultaneous management of public cloud instances, private cloud container clusters, and local legacy physical servers, and have strict and continuous compliance requirements for core network security boundary indicators such as port permissions and firewall rules. To overcome the aforementioned deficiencies of existing technologies, this invention provides a unified management system and method based on multi-source heterogeneous digital assets. It constructs a dynamic verification time window by building a set of heterogeneous tag attributes, and combines real-time configuration feature vectors with the original asset baseline vectors to confirm the flow status of configuration work orders. A tolerance cylinder is constructed based on the verified feature vectors, transforming the discrete configuration state of assets into a continuously distributed gossamer trajectory along the time axis. This scheme establishes a continuous geometric constraint on configuration drift by calculating the radial offset of the gossamer trajectory to the center of the bottom circle, and triggers local configuration reset and closed-loop verification when the trajectory touches the tolerance boundary. This repairs the topological break between the command control flow and the asset state flow in a multi-cloud environment, enabling the management system to provide targeted constraints and automated repair for implicit configuration drift caused by covert modifications to the local environment.
[0007] To achieve the above objectives, the present invention provides the following technical solution: A unified management method for multi-source heterogeneous digital assets includes: Construct a heterogeneous set of tag attributes for the target managed assets, form a dynamic verification time window for the target managed assets, construct a real-time configuration feature vector based on the dynamic verification time window, and extract the original asset baseline vector of the target managed assets. Based on the real-time configuration feature vector and the original asset baseline vector, confirm whether to set the flow status of the configuration work order to the configuration verification passed status. A tolerance cylinder is constructed based on the real-time configuration feature vector that has been confirmed to have passed configuration verification. The real-time status coordinates of the target managed assets are collected to form a spiral trajectory. The radial offset between each real-time status coordinate point in the spiral trajectory and the center coordinate point of the bottom surface of the tolerance cylinder is calculated. Based on the radial offset, it is determined whether the spiral trajectory has touched the inner wall of the tolerance cylinder. If the spiral trajectory has touched the inner wall of the tolerance cylinder, a centripetal calibration operation is triggered. The centripetal calibration operation includes calculating the centripetal calibration vector and performing a local configuration reset based on the centripetal calibration vector. After the local configuration reset is completed, the reset result is verified in a closed loop.
[0008] The heterogeneous tag attribute set is obtained by acquiring and combining the cloud service provider type identifier, hardware infrastructure type identifier, operating system version identifier, and network region identifier of the target managed asset.
[0009] The method for generating the dynamic verification time window includes: Retrieve a set of historical similar configuration work order records based on the heterogeneous tag attribute set. Calculate the average effective delay time corresponding to the heterogeneous tag attribute set based on the configuration instruction issuance timestamp and the actual effective timetamp of the underlying configuration for each work order record in the historical similar configuration work order record set. Calculate the verification trigger timestamp based on the average effective delay time and use the verification trigger timestamp as the start time of the dynamic verification time window.
[0010] The method for constructing real-time configuration feature vectors includes: Change the workflow status of the configuration work order from the instruction issued status to the verification waiting suspended status, write the verification trigger timestamp of the dynamic verification time window into the workflow node of the configuration work order as a time lock parameter, and generate a listening suspended node with time lock parameter. When the system clock reaches the verification trigger timestamp specified by the time lock parameter, the listening suspended node automatically releases the suspended state and sends a real-time configuration collection command to the management agent program deployed on the target managed asset. The management agent program collects the security baseline configuration parameter values of the target managed asset at the current moment and constructs a real-time configuration feature vector. The security baseline configuration parameter values include port permission quantization encoding values, firewall rule quantization encoding values, critical service process running status values, and system account permission configuration values.
[0011] The method for confirming whether to set the configuration work order's workflow status to configuration verification passed status includes: Calculate the Euclidean distance deviation between the real-time configuration feature vector and the original asset baseline vector, compare the Euclidean distance deviation with a preset compliance judgment threshold, and when the Euclidean distance deviation is less than the preset compliance judgment threshold, change the flow status of the configuration work order to the configuration verification passed status.
[0012] The method further includes: When the Euclidean distance deviation is greater than or equal to the compliance judgment threshold, the flow status of the configuration work order is frozen and a reverse compensation work order is generated and sent to the management agent program to perform the compensation configuration operation. The system counts the cumulative number of reverse compensation work orders triggered by the target managed assets within the most recent preset time period. The cumulative number is divided by the number of days in the preset time period to obtain the daily average trigger frequency. When the daily average trigger frequency is greater than the preset upper limit value, the compliance judgment threshold is adjusted by adding a preset scaling step size to the current value to complete the adaptive scaling of the compliance judgment threshold.
[0013] The method for constructing the tolerance cylinder includes: Extract the port permission quantization code value and firewall rule quantization code value from the real-time configuration feature vector corresponding to the configuration verification pass status as the values of two key configuration parameter dimensions. Use the values of the two key configuration parameter dimensions as the horizontal axis coordinate value and the vertical axis coordinate value in the two-dimensional plane coordinate system to obtain the coordinate point of the center of the bottom surface of the tolerance cylinder. Query the tolerance radius benchmark value according to the heterogeneous tag attribute set and use the tolerance radius benchmark value as the radius parameter of the tolerance cylinder. In a three-dimensional coordinate system, the two-dimensional plane containing the center coordinate point of the bottom surface of the tolerance cylinder is taken as the bottom surface, and the time axis is taken as the third vertical axis. The bottom circular surface containing the center coordinate point of the bottom surface is continuously extended along the time axis to form the tolerance cylinder space.
[0014] The method for generating the hairspring trajectory includes: The management agent program periodically collects the real-time values of the port permission quantification code value and firewall rule quantification code value of the target managed asset according to the preset continuous collection cycle. The two real-time values obtained in each collection are used as the horizontal axis coordinate value and the vertical axis coordinate value respectively, and the timestamp of the collection is used as the time axis coordinate value to obtain the real-time status coordinate point. The real-time status coordinate points obtained by continuous collection are connected in chronological order to form a spiral trajectory.
[0015] The method for determining whether the hairspring trajectory has touched the inner wall of the tolerance cylinder includes: The warning threshold is obtained based on the radius parameter of the tolerance cylinder. The radial offset is compared with the warning threshold. When the radial offset is greater than or equal to the radius parameter, it is determined that the hairspring trajectory has touched the inner wall of the tolerance cylinder.
[0016] A unified management system for multi-source heterogeneous digital assets is provided to implement the aforementioned unified management method for multi-source heterogeneous digital assets. The system includes: Dynamic configuration verification module: It is used to construct a heterogeneous tag attribute set of the target managed assets, form a dynamic verification time window corresponding to the target managed assets, construct a real-time configuration feature vector based on the dynamic verification time window, and extract the original asset baseline vector of the target managed assets. Based on the real-time configuration feature vector and the original asset baseline vector, it confirms whether to set the flow status of the configuration work order to the configuration verification passed status. Tolerance Cylinder Monitoring Module: Constructs a tolerance cylinder based on the real-time configuration feature vector that has been confirmed to have passed configuration verification, collects the real-time status coordinates of the target managed assets to form a spiral trajectory, calculates the radial offset between each real-time status coordinate point in the spiral trajectory and the center coordinate point of the bottom surface of the tolerance cylinder, and determines whether the spiral trajectory has touched the inner wall of the tolerance cylinder based on the radial offset. Centripetal calibration execution module: If the spiral spring trajectory has touched the inner wall of the tolerance cylinder, the centripetal calibration operation is triggered. The centripetal calibration operation includes calculating the centripetal calibration vector and performing a local configuration reset based on the centripetal calibration vector. After the local configuration reset is completed, the reset result is verified in a closed loop.
[0017] Compared with the prior art, the beneficial effects of the present invention are as follows: This invention constructs a dynamic verification time window by building a heterogeneous set of tag attributes, and combines real-time configuration feature vectors with original asset baseline vectors to confirm the flow status of configuration work orders. It binds the configuration instruction issuance stage with the actual effective results of the underlying physical nodes, repairing the topological break between the management instruction control flow and the asset state flow caused by asynchronous execution in a multi-cloud heterogeneous environment, and preventing the distortion of compliance status caused by relying solely on interface responses. At the same time, this invention constructs a tolerance cylinder based on the real-time configuration feature vector corresponding to the verification pass status, transforming the discrete state of managed assets into a continuously distributed gossamer trajectory along the time axis. By calculating the radial offset from the real-time state coordinate point to the center of the bottom circle, a continuous geometric constraint model for configuration drift is constructed, which makes up for the defect that static snapshots cannot capture implicit out-of-bounds behavior that occurs over time. When the gossamer trajectory touches the inner wall of the tolerance cylinder, a local configuration reset and closed-loop verification are triggered based on the centripetal calibration vector, enabling the managed system to perform directional constraints and closed-loop repairs on implicit configuration drift caused by covert tampering with the local environment. Attached Figure Description
[0018] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0019] Figure 1 This is a flowchart of a method for unified management of multi-source heterogeneous digital assets in this invention; Figure 2 This is a schematic diagram illustrating the compliance determination of Euclidean distance deviation in this invention. Figure 3 This is a schematic diagram illustrating the construction of the center coordinates of the bottom surface of the tolerance cylinder in this invention; Figure 4 This is a schematic diagram of the tolerance cylinder space and the spiral spring trajectory in this invention; Figure 5 This is a schematic diagram of the three-level determination region division in this invention; Figure 6 This is a functional module diagram of a unified management system for multi-source heterogeneous digital assets in this invention. Detailed Implementation
[0020] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0021] Example 1: Please see Figure 1 As shown, this embodiment provides a method for unified management of multi-source heterogeneous digital assets, including: Step S10: Construct a heterogeneous tag attribute set for the target managed assets, form a dynamic verification time window corresponding to the target managed assets, construct a real-time configuration feature vector based on the dynamic verification time window, and extract the original asset baseline vector of the target managed assets. Based on the real-time configuration feature vector and the original asset baseline vector, confirm whether to set the flow status of the configuration work order to the configuration verification passed status. Further, step S10 includes: Step S11: Obtain the cloud service provider type identifier, hardware infrastructure type identifier, operating system version identifier, and network region identifier of the target managed asset to form a heterogeneous tag attribute set of the target managed asset; Specifically, the cloud service provider type identifier is used to mark the cloud service provider platform to which the target managed asset belongs. The cloud service provider type identifier is obtained as follows: the management agent program calls the metadata service interface of the virtualization layer where the target managed asset resides, reads the supplier field value from the instance metadata, and converts the supplier field value into a standardized cloud service provider type identifier using a preset cloud service provider encoding mapping table. The cloud service provider encoding mapping table is used to uniformly encode heterogeneous supplier field values returned by different cloud service providers into a fixed-length string identifier, eliminating interference caused by differences in the returned formats of different cloud service provider metadata interfaces on the subsequent retrieval process. The hardware foundation type identifier is used to mark the underlying computing resource form of the target managed asset. The hardware foundation type identifier is obtained as follows: the management agent program reads the system device information file of the target managed asset, extracts the processor architecture field and virtualization type field, concatenates the processor architecture field and virtualization type field, and then performs a hash operation to obtain the hardware foundation type identifier. The operating system version identifier is used to mark the operating system release version running on the target managed asset. The operating system version identifier is obtained by the management agent program reading the operating system release information file of the target managed asset, extracting the release name field and the version number field, and concatenating the release name field and the version number field to form the operating system version identifier. The network region identifier is used to mark the security domain location of the target managed asset in the logical network topology. The network region identifier is obtained by the management agent program querying the network interface configuration information of the target managed asset, obtaining the IP address range of the target managed asset, and matching the IP address range with the preset network region division rules to obtain the network region identifier. The network region division rules are pre-configured by the operation and maintenance management platform according to the actual network topology and distributed to the management agent program. The cloud service provider type identifier, hardware infrastructure type identifier, operating system version identifier, and network region identifier are combined according to a preset concatenation order to form a heterogeneous tag attribute set for the target managed asset. The heterogeneous tag attribute set is stored in a quadruple structure. The position of each element in the quadruple is fixed and corresponds one-to-one with the identifier type, so that the heterogeneous tag attribute sets of different target managed assets can be compared one by one according to the element position, providing structured search conditions for retrieving the historical similar configuration work order record set in step S12.
[0022] Step S11 extracts and uniformly encodes four types of heterogeneous environmental attribute information scattered across different system levels into a standardized four-tuple structure. This allows managed assets from different cloud service providers, hardware architectures, operating system versions, and network regions to be categorized into groups with the same environmental characteristics. This lays the classification foundation for the subsequent step S12, which retrieves historical similar configuration work order records based on the heterogeneous tag attribute set. Without the heterogeneous tag attribute set constructed in step S11, step S12 cannot determine the range of historical work orders with the same environmental characteristics as the target managed asset, causing the calculation of the average effective delay time to lose its category specificity. Consequently, the time lock parameter of the dynamic verification time window in step S13 deviates from the actual configuration effective rhythm of the target managed asset. The heterogeneous tag attribute set constructed in step S11 is also referenced in step S21 to query the tolerance radius benchmark value, enabling managed assets with different environmental characteristics to correspond to different tolerance ranges. This achieves a complete parameter transmission link from asset classification to delay calculation to tolerance control.
[0023] Step S12: Retrieve the historical similar configuration work order record set based on the heterogeneous tag attribute set. Calculate the average effective delay time corresponding to the heterogeneous tag attribute set based on the configuration instruction issuance timestamp and the actual effective timestamp of the underlying configuration for each work order record in the historical similar configuration work order record set, and form a dynamic verification time window corresponding to the target managed asset. The difference between the configuration instruction issuance timestamp and the actual effective timestamp of the underlying configuration for each work order record in the historical set of similar configuration work orders is calculated to obtain the single effective delay duration. The arithmetic mean of all single effective delay durations corresponding to the historical set of similar configuration work order records is calculated to obtain the average effective delay duration. The average effective delay duration is multiplied by the heterogeneous environment fluctuation coefficient to obtain the verification waiting time. The configuration instruction issuance timestamp and the verification waiting time are added to obtain the verification trigger timestamp. The verification trigger timestamp is used as the start time of the dynamic verification time window. Specifically, the retrieval method for the historical similar configuration work order record set is as follows: using the heterogeneous tag attribute set of the target managed asset constructed in step S11 as the retrieval condition, the completed work order records in the configuration work order database that completely match the heterogeneous tag attribute set of the target managed asset are searched, and all matching completed work order records are combined into a historical similar configuration work order record set. A complete match means that the four elements—cloud service provider type identifier, hardware basic type identifier, operating system version identifier, and network area identifier—are all equal. When the number of work order records in the historical similar configuration work order record set is less than the preset minimum sample size threshold M, the retrieval condition is relaxed to at least three elements matching in the heterogeneous tag attribute set. The method for determining the minimum sample size threshold M is: based on the statistical distribution characteristics of the configuration activation delay time, the minimum number of samples is selected such that the confidence interval width of the sample mean is less than or equal to the preset upper limit of the confidence interval width.
[0024] For each work order record in the historical set of similar configuration work order records, the timestamp of the configuration instruction issuance and the timestamp of the actual effective date of the underlying configuration are read from the work order record. The timestamp of the configuration instruction issuance is subtracted from the timestamp of the actual effective date of the underlying configuration to obtain the single-time effective delay duration. The timestamp of the configuration instruction issuance refers to the moment when the configuration work order sends the configuration instruction from the operation and maintenance management platform to the target managed asset. The timestamp of the actual effective date of the underlying configuration refers to the moment when the configuration change is actually completed and takes effect at the operating system level or application service level of the target managed asset. The timestamp of the actual effective date of the underlying configuration is actively reported by the management agent program after detecting that the configuration change has taken effect. The average effective delay duration is obtained by summing the single-time effective delay durations of all work order records in the historical set of similar configuration work order records and dividing by the total number of work order records. The method for determining the heterogeneous environment fluctuation coefficient is as follows: The environmental feature complexity is set based on the set of heterogeneous tag attributes. The environmental feature complexity is measured by the product of the number of unique values of the four identifier elements in the heterogeneous tag attribute set. The product value is input into a preset fluctuation coefficient lookup table to obtain the heterogeneous environment fluctuation coefficient. This fluctuation coefficient lookup table is pre-calibrated by the operation and maintenance management platform based on the fluctuation amplitude of configuration activation delay under different environmental complexities in historical operation data. The average activation delay time is multiplied by the heterogeneous environment fluctuation coefficient to obtain the verification waiting time. The timestamp of the current configuration work order's configuration instruction issuance is added to the verification waiting time to obtain the verification trigger timestamp. The verification trigger timestamp is used as the start time of the dynamic verification time window.
[0025] For example, Table 1 shows how to find the fluctuation coefficient of heterogeneous environments: Table 1. Lookup table for heterogeneous environmental fluctuation coefficients
[0026] P1 and P2 are preset environmental complexity thresholds. P2 is greater than P1, K1 is less than K2 and K2 is less than K3. This indicates that the more complex the managed assets are, the greater the fluctuation range of the configuration activation delay. They need to be multiplied by a larger fluctuation coefficient to allow for more sufficient verification waiting time.
[0027] Step S12 uses the heterogeneous tag attribute set constructed in Step S11 as the basis for category retrieval, extracting configuration work order delay information with the same environmental characteristics as the target managed asset from historical data. This ensures that the calculation of the verification waiting time is based on the historical behavior statistics of similar assets, rather than using a fixed waiting time. Due to differences in configuration distribution link lengths among different cloud service providers, configuration reload mechanisms in different operating system versions, and transmission delays in different network regions, managed assets from different heterogeneous environments exhibit significant differences in configuration activation delays. Using a fixed waiting time would lead to some assets being verified before their configurations take effect, resulting in misjudgments, while some assets would still be waiting after their configurations have taken effect, wasting verification time. Step S12 uses a heterogeneous environment fluctuation coefficient to elastically amplify the average activation delay time, enabling the verification trigger timestamp to cover a reasonable fluctuation range in the configuration activation delay of similar assets, reducing the probability of premature verification triggering due to abnormally large activation delays in individual work orders. The verification trigger timestamp generated in Step S12 is directly passed to Step S13 as a time lock parameter written into the configuration work order, establishing a data path from historical delay statistics to work order flow control.
[0028] Step S13: Change the flow status of the configuration work order from the instruction issued state to the verification waiting suspended state, write the verification trigger timestamp of the dynamic verification time window into the flow node of the configuration work order as a time lock parameter, and generate a listening suspended node with time lock parameter. Specifically, the flow status of the configuration work order refers to the lifecycle stage marker of the configuration work order in the work order flow engine of the operation and maintenance management platform. The "instruction issued" status indicates that the configuration instruction has been issued to the target managed asset through the operation and maintenance management platform but has not yet been verified and confirmed. When the flow status of the configuration work order is changed from "instruction issued" to "verification waiting suspended", the work order flow engine suspends the subsequent flow processing of the configuration work order. The configuration work order in the "verification waiting suspended" status will not be mistakenly judged as an overdue unprocessed work order, avoiding the work order timeout monitoring mechanism of the operation and maintenance management platform from performing abnormal processing on the configuration work order during the verification waiting period. The time lock parameter is used to control the timing of the release of the listening suspended node. The value of the time lock parameter is the verification trigger timestamp calculated in step S12. The work order flow engine inserts a new flow node into the flow node sequence of the configuration work order, writes the verification trigger timestamp into the trigger condition field of the new flow node, sets the type marker of the new flow node to time trigger type, and generates a listening suspended node with time lock parameter. Once generated, the listening suspended node enters a suspended state. The clock monitoring thread in the work order flow engine continuously compares the current time value of the system clock with the time lock parameter of the listening suspended node. When the current time value of the system clock reaches or exceeds the verification trigger timestamp specified by the time lock parameter, the state transition of the listening suspended node is triggered.
[0029] Step S13 establishes a time-lock-based workflow control mechanism in the work order workflow engine. It embeds the verification trigger timestamp calculated in step S12 based on historical delay statistics into the workflow node sequence of the work order, making the verification trigger timing of configuration work orders data-driven rather than manually set. Without the suspension mechanism in step S13, configuration work orders would immediately flow to the verification stage after the instruction is issued, while the underlying configuration of the target managed asset may not yet have actually taken effect. The security baseline configuration parameter values collected in step S14 would still be the old values before the configuration change, and the Euclidean distance deviation calculated in step S15 would not reflect the true result of the configuration change. The listening suspension node mechanism in step S13 allows the work order workflow engine to release processing resources for configuration work orders during the waiting period. The clock listening thread only performs time value comparison operations, and the computational overhead is negligible, ensuring that the processing capacity of the work order workflow engine is not occupied by invalid waiting when managing a large number of concurrent configuration work orders.
[0030] Step S14: When the system clock reaches the verification trigger timestamp specified by the time lock parameter, the listening suspended node automatically releases the suspended state and sends a real-time configuration collection command to the management agent program deployed on the target managed asset. The management agent program collects the security baseline configuration parameter values of the target managed asset at the current moment and constructs a real-time configuration feature vector; and extracts the security baseline configuration parameter values recorded when the target managed asset passed the compliance verification for the last time before the configuration collection command was issued, and constructs the original asset baseline vector; the security baseline configuration parameter values include port permission quantization encoding values, firewall rule quantization encoding values, critical service process running status values, and system account permission configuration values; Specifically, when the system clock reaches the verification trigger timestamp specified by the time lock parameter, the state of the listening suspended node generated in step S13 changes from suspended to active. The listening suspended node sends a real-time configuration collection command to the management agent program deployed on the target managed asset. After receiving the real-time configuration collection command, the management agent program sequentially collects the current security baseline configuration parameter values of the target managed asset according to the preset collection item list. The security baseline configuration parameter values include values in four dimensions: port permission quantization encoding value, firewall rule quantization encoding value, critical service process running status value, and system account permission configuration value.
[0031] The method for collecting the port permission quantification code value is as follows: The management agent program reads the port listening list and port access control policy file of the target managed asset operating system. For each port in the port listening list that is in an open state, it queries the corresponding risk weight value according to the preset port risk weight table. The risk weight values of all ports in an open state are weighted and summed to obtain the port permission quantification code value. The port risk weight table uses the port number range as the index key and the risk weight value as the index value. The risk weight value corresponding to the port number in the high-risk port range is greater than the risk weight value corresponding to the port number in the normal port range. This ensures that the change in the state of high-risk ports has a greater numerical impact on the port permission quantification code value than the change in the state of normal ports. The weighted summation operation is used to convert the port permission configuration content into continuous values, so that port configuration information of different scales can be compressed into feature values with uniform dimensions. The greater the difference in port configuration content, the greater the numerical difference in the port permission quantification code value, which facilitates the vector distance calculation in the subsequent step S15. The method for collecting the quantified encoding value of firewall rules is as follows: The management agent program reads the firewall rule table of the target managed asset, assigns a numerical rule strength score to each rule entry in the firewall rule table according to the rule type and coverage range, and then performs a weighted sum of the rule strength scores of all rule entries to obtain the quantified encoding value of the firewall rule. The rule for assigning the rule strength score is: the rule strength score of the deny rule is higher than that of the allow rule, and the rule strength score of the rule entry with a larger coverage range of IP addresses is higher. Therefore, the greater the difference in the firewall rule configuration content, the greater the difference in the numerical value of the quantified encoding value of the firewall rule. The method for collecting the running status value of the critical service process is as follows: The management agent program checks the running status of each service process one by one from the preset critical service process list, encodes the running status of each service process into binary bits, and concatenates the running status binary bits of all service processes in the order of the service process list and converts them into decimal values to obtain the running status value of the critical service process. The system account permission configuration value is collected as follows: the management agent program reads the system account permission configuration file of the target managed asset, extracts the permission level and permission scope of all accounts, and then numerically encodes the permission level and permission scope according to a preset encoding rule and accumulates them to obtain the system account permission configuration value. The collected port permission quantified encoding value, firewall rule quantified encoding value, critical service process running status value, and system account permission configuration value are arranged in sequence to construct a four-dimensional real-time configuration feature vector.
[0032] The method for extracting the original asset baseline vector is as follows: Retrieve the security baseline configuration parameter values recorded in the configuration baseline record library of the target managed asset at the time of the last compliance verification before the configuration collection command was issued. The compliance verification refers to the process by which the operation and maintenance management platform checks the security baseline configuration parameter values of the managed asset according to preset security compliance benchmarks. These benchmarks include constraints on port open range, firewall rule coverage, a list of constraints requiring critical service processes to be running, and constraints that system account permissions must not exceed preset permission limits. When the security baseline configuration parameter values of the managed asset meet all the constraints in the security compliance benchmarks, the compliance verification result is determined to be passed. The operation and maintenance management platform writes the security baseline configuration parameter values at the time of passing the compliance verification into the configuration baseline record library as a compliance baseline snapshot of the managed asset. This compliance verification is a different verification process from the configuration verification performed based on Euclidean distance deviation in step S15. The passing status of the configuration verification in step S15 does not trigger an update operation in the configuration baseline record library. The compliance baseline snapshot recorded in the configuration baseline record library is only updated when the operation and maintenance management platform performs compliance verification and determines it to be passed. The port permission quantization encoding values, firewall rule quantization encoding values, critical service process running status values, and system account permission configuration values from the retrieved compliance baseline snapshot are arranged sequentially to construct the original asset baseline vector. The real-time configuration feature vector has the same number of dimensions and dimension arrangement order as the original asset baseline vector, enabling step S15 to calculate the difference between the two vectors one by one along their corresponding dimensions.
[0033] Step S14 extracts and encodes the security baseline configuration information of the target managed asset from scattered system files and process states into a uniformly structured numerical vector. This allows subsequent step S15 to quantify the degree of configuration change offset through mathematical distance calculation, transforming qualitative configuration compliance judgment into quantitative numerical comparison. Step S14 and step S13 work in tandem: step S13 controls the timing of step S14's data collection through a time lock parameter, ensuring that the managed agent program only performs the data collection operation after the underlying configuration has likely taken effect. This ensures that the real-time configuration feature vector reflects the actual state after the configuration change, rather than an intermediate state during the change process. After verification in step S15, the real-time configuration feature vector constructed in step S14 is used in step S21 to extract the quantified encoding values of port permissions and firewall rules to construct the center coordinates of the base of a tolerance cylinder, forming a data transfer from configuration verification to continuous monitoring.
[0034] Step S15: See Figure 2The system calculates the Euclidean distance deviation between the real-time configuration feature vector and the original asset baseline vector, compares the Euclidean distance deviation with a preset compliance judgment threshold, and changes the flow status of the configuration work order to the configuration verification passed status and updates the configuration item status of the target managed asset to the compliant status when the Euclidean distance deviation is less than the compliance judgment threshold. When the Euclidean distance deviation is greater than or equal to the compliance judgment threshold, the flow status of the configuration work order is frozen and a reverse compensation work order is generated and sent to the management agent program to perform compensation configuration operations. Specifically, the Euclidean distance deviation is calculated as follows: The numerical difference between the real-time configuration feature vector constructed in step S14 and the original asset baseline vector is calculated in each dimension. The numerical difference in each dimension is squared, and the square root of the sum of the squared values across all dimensions is taken to obtain the Euclidean distance deviation between the real-time configuration feature vector and the original asset baseline vector. The Euclidean distance deviation characterizes the overall deviation of the real-time configuration state from the compliance baseline state. A larger Euclidean distance deviation indicates a greater difference between the real-time configuration state and the compliance baseline state. The Euclidean distance is calculated using the well-known Euclidean distance formula, which is the square root of the sum of the squares of the differences between corresponding elements of two equal-dimensional vectors.
[0035] The method for determining the compliance judgment threshold is as follows: Historical compliance verification records with the same heterogeneous tag attribute set as the target managed asset are selected. From these records, all real-time configuration feature vectors that passed compliance verification and their corresponding original asset baseline vectors are extracted. The Euclidean distance deviation between each pair of vectors is calculated. All Euclidean distance deviations are arranged in ascending order of value. The Euclidean distance deviation value at a preset upper quantile position Q is taken as the initial value of the compliance judgment threshold. The upper quantile position Q is greater than 0.5 and less than or equal to 1, set by the operation and maintenance security policy according to tolerance requirements. The closer the upper quantile position Q is to 1, the larger the compliance judgment threshold and the more lenient the compliance judgment; the closer the upper quantile position Q is to 0.5, the smaller the compliance judgment threshold and the stricter the compliance judgment. The Euclidean distance deviation is compared with the compliance judgment threshold. The compliance judgment threshold represents the maximum Euclidean distance upper limit allowed for the real-time configuration state to deviate from the compliance baseline state. That is, when the deviation between the real-time configuration state and the compliance baseline state is within the compliance judgment threshold, the configuration state is considered to still be within the compliance range. When the Euclidean distance deviation is less than the compliance judgment threshold, it indicates that the offset of the real-time configuration feature vector relative to the original asset baseline vector is within the allowable offset range of the compliance baseline status. The configuration change has been fully effective and the configuration status is consistent with the compliance baseline status. The workflow status of the configuration work order is changed from the verification pending state to the configuration verification passed state. At the same time, the configuration item status of the target managed asset in the asset status registration table is updated to the compliant state. When the Euclidean distance deviation is greater than or equal to the compliance judgment threshold, it indicates that the offset of the real-time configuration feature vector relative to the original asset baseline vector has exceeded the allowable offset range of the compliance baseline status. The configuration change may not have been correctly effective or the configuration status has deviated unexpectedly. At this time, the workflow status of the configuration work order is frozen, and a reverse compensation work order is generated. The list of non-compliant configuration parameter dimensions is determined as follows: the absolute value of the difference between the real-time configuration feature vector and the original asset baseline vector in each dimension is compared with the expected value of the corresponding single-dimensional change. Dimensions whose absolute value of the difference is less than the expected value of the corresponding single-dimensional change are marked as non-compliant dimensions. The expected value of the single-dimensional change is determined by the absolute value of the difference between the target configuration parameter value of each dimension recorded in the configuration work order and the value of the corresponding dimension in the original asset baseline vector. The configuration work order records the target configuration parameter values for each dimension. The target configuration parameter values for each dimension refer to the expected values of the port permission quantification code value, firewall rule quantification code value, critical service process running status value, and system account permission configuration value that the target managed asset should achieve after the configuration change is required by the configuration work order. The target configuration parameter values for each dimension are written into the configuration work order by the operation and maintenance management platform according to the security compliance benchmark when the configuration work order is created.The reverse compensation work order includes a heterogeneous set of tag attributes of the target managed asset, a list of unqualified configuration parameter dimensions, and the difference between the target value and the actual value of each unqualified dimension. After receiving the reverse compensation work order, the management agent program performs a compensation configuration operation based on the difference information to adjust the unqualified configuration parameters to the target value.
[0036] Step S15 compresses the multi-dimensional differences in configuration parameters into a single numerical indicator using Euclidean distance deviation. This eliminates the need to set independent judgment rules for each configuration parameter dimension during the compliance judgment process, reducing the complexity of rule management for joint judgment of multi-dimensional configuration parameters. Euclidean distance deviation geometrically measures the distance between the real-time configuration state point and the compliance baseline state point in a high-dimensional space. It can simultaneously capture the cumulative contribution of small offsets across multiple configuration parameter dimensions. Even if the offset in a single dimension does not exceed the range of independent judgment rules, the superposition of offsets in multiple dimensions may still result in an Euclidean distance deviation greater than or equal to the compliance judgment threshold, thereby triggering reverse compensation. The reverse compensation work order mechanism in step S15 forms a closed loop with the configuration data collection in step S14: when configuration changes are not fully effective, the reverse compensation work order, carrying precise difference information, is reissued to the management agent program, avoiding indiscriminate reset of all configuration parameters. Without the quantitative determination in step S15, the configuration work order will lack objective criteria for approval / failure after being suspended in step S13. Work order processing will rely on manual review, making it impossible to maintain consistent judgment standards when managing large numbers of heterogeneous assets. The configuration verification pass status determined in step S15 provides a prerequisite for extracting the center coordinates of the tolerance cylinder's base in step S20, ensuring that the configuration status of managed assets entering the continuous monitoring phase has been quantitatively verified.
[0037] Step S16: Count the cumulative number of reverse compensation work orders triggered by the target managed assets in the most recent preset time period, divide the cumulative number by the number of days in the preset time period to obtain the daily average trigger frequency, and when the daily average trigger frequency is greater than the preset upper limit value, add the preset scaling step size to the compliance judgment threshold based on the current value to complete the adaptive scaling of the compliance judgment threshold.
[0038] Specifically, the method for determining the most recent preset time period is as follows: It is determined based on the configuration change frequency of the target managed asset's category. The reciprocal of the configuration change frequency is multiplied by a preset period coefficient C to obtain the number of days in the most recent preset time period. The period coefficient C is set according to the monitoring granularity requirements of the operation and maintenance management platform to ensure that the most recent preset time period contains a sufficient number of configuration change events to make the statistical frequency representative. The cumulative number of reverse compensation work orders triggered by the target managed asset within the most recent preset time period is counted. The cumulative number of reverse compensation work orders is obtained by querying the work order flow engine for the number of work order records associated with the target managed asset, with the work order type being reverse compensation work orders, and whose creation time is within the most recent preset time period. The cumulative number of reverse compensation work orders is divided by the number of days in the most recent preset time period to obtain the daily average trigger frequency.
[0039] The frequency upper limit is determined as follows: based on the historical trigger frequency statistical distribution of reverse compensation work orders under normal operating conditions of the target managed asset category, the average of the historical trigger frequencies is added to a preset standard deviation multiple N, multiplied by the standard deviation of the historical trigger frequencies, to obtain the frequency upper limit. The standard deviation multiple N is set according to the strictness of the operation and maintenance security strategy. When the daily average trigger frequency is greater than the frequency upper limit, it indicates that the trigger frequency of reverse compensation work orders for the target managed asset exceeds the normal range, and the current compliance judgment threshold may be set too low, causing a large number of configuration work orders with a deviation within the normal fluctuation range in step S15 to be misjudged as failing the verification. The compliance judgment threshold is then increased by a preset scaling step size to widen the allowable deviation range of the compliance judgment. The scaling step size is determined as follows: the current value of the compliance judgment threshold is multiplied by a preset scaling ratio coefficient R to obtain the scaling step size. The scaling ratio coefficient R is set according to the stability requirements of the compliance judgment threshold adjustment, and its value range is obtained from the parameter configuration library of the operation and maintenance management platform. The new value obtained by adding the scaling step size to the compliance judgment threshold will be applied to step S15 of the judgment process for all subsequent configuration work orders of the target managed assets.
[0040] Step S16 establishes a feedback adjustment path from the frequency of reverse compensation work orders to the compliance judgment threshold, enabling the compliance judgment threshold to be adaptively adjusted according to the actual operational performance of the target managed assets. In the scenario of managing multi-source heterogeneous digital assets, the magnitude of configuration changes and configuration offset characteristics of different types of managed assets vary. The pre-set compliance judgment threshold may be too tight for some asset categories and too loose for others. Step S16 uses the frequency of reverse compensation work orders as an indirect indicator of the reasonableness of the compliance judgment threshold. When reverse compensation work orders are frequently triggered, it indicates a mismatch between the compliance judgment threshold and the actual configuration offset characteristics of the target managed assets. Step S16 adjusts the compliance judgment threshold towards a more lenient direction by adding a scaling step, so that the judgment result of the subsequent step S15 is more consistent with the actual configuration change effect of the target managed assets. The reverse compensation work order mechanism in steps S16 and S15 is linked: the reverse compensation work order generated in step S15 is used to trigger the management agent program to execute compensation configuration operations, and also serves as the data source for step S16 to monitor the rationality of the compliance judgment threshold. This allows a single reverse compensation event to simultaneously serve two purposes: immediate configuration repair and long-term threshold optimization. Without step S16, the compliance judgment threshold would remain static. As the configuration environment of managed assets undergoes gradual changes, the mismatch between the compliance judgment threshold and the actual configuration deviation characteristics will continue to accumulate, leading to a continuous increase in the triggering frequency of reverse compensation work orders and consuming significant operational resources.
[0041] Step S10 incorporates heterogeneous environment differences into the calculation of the verification waiting time. This ensures that the verification triggering timing for managed assets in the same batch of configuration work orders, targeting different heterogeneous environments, varies. The verification timing for each managed asset matches the historical configuration effectiveness delay characteristics of its respective heterogeneous environment category, avoiding the dilemma of some assets being verified too early, leading to misjudgment, and others being verified too late, leading to delay, when using a uniform fixed waiting time. Four different types and dimensions of security baseline configuration parameters—port permission quantification values, firewall rule quantification values, critical service process running status values, and system account permission configuration values—are encoded into a unified numerical vector. The four-dimensional configuration differences are compressed into a single metric using Euclidean distance deviation, enabling joint evaluation of cross-dimensional configuration offsets. A managed asset with slight offsets in each of the four dimensions will still be judged as failing configuration verification and triggering reverse compensation if the Euclidean distance deviation corresponding to the vector synthesis result of the four-dimensional offsets is greater than or equal to the compliance judgment threshold. This joint evaluation capability can capture the cumulative offset risk missed by independent judgment in single-dimensional configuration parameters. The adaptive scaling mechanism of the compliance judgment threshold in step S10 enables the entire verification process to have self-correcting capabilities. The value of the compliance judgment threshold is continuously adjusted according to the actual operational feedback of the target managed assets, avoiding long-term judgment mismatch caused by improper initial threshold setting or gradual changes in the managed asset environment. The configuration verification pass status in step S10 also serves as a prerequisite for entering the tolerance cylinder continuous monitoring in step S20, ensuring that the managed assets entering the continuous monitoring stage have undergone a complete configuration verification closed loop. The verified configuration status is used as the reference benchmark for the center coordinates of the bottom surface of the tolerance cylinder, so that the benchmark point for subsequent continuous monitoring is established on the verified compliant configuration status.
[0042] Step S20: Construct a tolerance cylinder based on the real-time configuration feature vector confirmed to have passed configuration verification, collect the real-time status coordinate points of the target managed assets to form a spiral trajectory, calculate the radial offset between each real-time status coordinate point in the spiral trajectory and the center coordinate point of the bottom surface of the tolerance cylinder, determine whether the spiral trajectory has touched the inner wall of the tolerance cylinder based on the radial offset, and trigger a centripetal calibration operation if the spiral trajectory has touched the inner wall of the tolerance cylinder. The centripetal calibration operation includes calculating a centripetal calibration vector and performing a local configuration reset based on the centripetal calibration vector. After the local configuration reset is completed, perform closed-loop verification on the reset result.
[0043] Further, step S20 includes: Step S21: Extract the port permission quantization code value and firewall rule quantization code value from the real-time configuration feature vector corresponding to the configuration verification pass status as the values of two key configuration parameter dimensions. Use the values of the two key configuration parameter dimensions as the horizontal axis coordinate value and the vertical axis coordinate value in the two-dimensional plane coordinate system to obtain the coordinate point of the center of the bottom surface of the tolerance cylinder; query the tolerance radius benchmark value according to the heterogeneous tag attribute set, and use the tolerance radius benchmark value as the radius parameter of the tolerance cylinder. Specifically, the tolerance cylinder is a geometric constraint in three-dimensional space used to define the acceptable drift range of the managed asset's configuration status. The coordinates of the center point of the tolerance cylinder's base correspond to the standard configuration status position of the managed asset at the moment the configuration verification passes. The radius parameter of the tolerance cylinder defines the upper limit of the distance that the configuration status is allowed to deviate from the standard configuration status position at any time. Step S21 extracts the port permission quantization code value and the firewall rule quantization code value from the real-time configuration feature vector corresponding to the configuration verification passed status determined in step S15, and selects the port permission quantization code value and the firewall rule quantization code value as two key configuration parameter dimensions. The selection of port permission quantization and firewall rule quantization as key configuration parameter dimensions is based on the following: Among the four dimensions included in the security baseline configuration parameter values, port permission quantization reflects the permission status of the network communication channels exposed to the outside world by the target managed asset, and firewall rule quantization reflects the filtering policy status of the target managed asset for inbound and outbound traffic. Together, they constitute the core configuration indicators of the network security boundary of the target managed asset. During operation, they are more likely to change due to external attack attempts, operational errors, configuration drift, and other factors than the running status values of key service processes and system account permission configuration values. Continuous monitoring of these two values can promptly detect when the network security boundary configuration deviates.
[0044] Step S21 selects the port permission quantization encoding value and firewall rule quantization encoding value from the four-dimensional real-time configuration feature vector as two key configuration parameter dimensions for continuous monitoring of the tolerance cylinder, but does not include the key service process running status value and system account permission configuration value in the continuous monitoring dimensions of the tolerance cylinder. The specific reasons are as follows: First, differences in security sensitivity layering. Port permission configuration and firewall rule configuration together constitute the security boundary barrier of the target managed asset facing the external network. Port permission configuration determines the number of network communication channels exposed by the target managed asset and the scope of access permissions, while firewall rule configuration determines the coverage of the target managed asset's filtering and interception policies for inbound and outbound traffic. Once the port permission configuration and firewall rule configuration deviate unexpectedly, the target managed asset will directly face the risk of scanning, probing, and intrusion attacks from the external network. The harmful consequences of unexpected deviations are immediate and highly severe. Critical service process running status values reflect whether a specific service process is running, while system account permission configuration values reflect the permission level settings of system accounts. Both are configuration indicators at the internal operational level of the target managed asset. The harmful consequences of unexpected changes require multiple steps of lateral penetration to transform into an external security threat; the harm propagation path is longer than that when port permission configuration and firewall rule configuration deviate. Secondly, there is a difference in the probability of spontaneous drift. In actual multi-cloud heterogeneous operating environments, port permission configuration and firewall rule configuration are easily affected by factors such as scheduled tasks of the target managed asset's underlying operating system, automatic policy refreshes of security daemons, and security group synchronization mechanisms of cloud service provider platforms, resulting in silent changes without human intervention. Changes in the running status of critical service processes usually require explicit service management commands (such as systemctl restart, service stop, etc.). Under conditions of no human intervention and no abnormal crash of the service process itself, the running status of critical service processes remains unchanged. Changes in system account permission configuration usually require account management operations or permission change approval processes by the system administrator. Under conditions of no administrator operation, the system account permission configuration remains unchanged. Therefore, the probability of port permission quantization encoding values and firewall rule quantization encoding values spontaneously drifting during continuous operation is significantly higher than that of critical service process running status values and system account permission configuration values. Third, there are computational efficiency constraints in continuous monitoring. Tolerance cylinder continuous monitoring requires the management agent program to periodically collect data and calculate radial offsets for the target managed assets according to the continuous collection cycle. When the management platform simultaneously manages a large number of target managed assets, each additional continuous monitoring dimension will correspondingly increase the data transmission and computational load for each collection and offset calculation.By limiting continuous monitoring to two dimensions—port permission quantification values and firewall rule quantification values—which have the highest probability of spontaneous drift and pose the most direct security risks, we can maintain the ability to continuously track the drift risk of the highest priority configurations while controlling the amount of data collected and the amount of radial offset calculations in large-scale concurrent monitoring scenarios. Although the running status values of critical service processes and the configuration values of system account permissions are not included in the continuous real-time monitoring dimensions of the tolerance cylinder, in the closed-loop verification stage of step S24, all four dimensions of security baseline configuration parameter values are re-collected and a repaired real-time configuration feature vector is constructed. The four-dimensional Euclidean distance deviation between the repaired real-time configuration feature vector and the original asset baseline vector is calculated for compliance judgment, ensuring that the running status of critical service processes and the configuration of system account permissions are still included in the compliance judgment scope in the closed-loop verification stage.
[0045] Using the port permission quantization code value as the horizontal axis coordinate value in a two-dimensional plane coordinate system and the firewall rule quantization code value as the vertical axis coordinate value, the ordered pair formed by the port permission quantization code value and the firewall rule quantization code value is the coordinate point of the center of the base of the tolerance cylinder. See also Figure 3 This is a schematic diagram of constructing the coordinate points of the center of the bottom surface of a tolerance cylinder, provided in an embodiment of this application. Figure 3 The diagram illustrates a two-dimensional plane coordinate system with port permission quantization encoding values on the horizontal axis and firewall rule quantization encoding values on the vertical axis, as well as the base circle, center coordinates, and radius parameters of a tolerance cylinder located within this coordinate system. The horizontal axis of the two-dimensional plane coordinate system represents the numerical measurement of the port permission configuration status, and the vertical axis represents the numerical measurement of the firewall rule configuration status. The position of the center coordinates of the base circle uniquely corresponds to a set of port permission quantization encoding values and firewall rule quantization encoding values that have passed the configuration verification in step S15.
[0046] The tolerance radius benchmark value is obtained as follows: the heterogeneous tag attribute set of the target managed assets constructed in step S11 is used as the query condition, and a matching query is performed in the tolerance radius configuration table pre-established in the operation and maintenance management platform. The tolerance radius configuration table uses the four-tuple combination of the heterogeneous tag attribute set as the index key and the tolerance radius benchmark value as the index value. Different four-tuple combinations correspond to different tolerance radius benchmark values. The calibration method of the tolerance radius benchmark value is as follows: for historical managed asset groups with the same heterogeneous tag attribute set, the fluctuation amplitude data of port permission quantization encoding value and firewall rule quantization encoding value of all managed assets in the group during the normal operation cycle is collected. The statistical distribution of the fluctuation amplitude data is calculated, and the fluctuation amplitude value corresponding to the preset coverage quantile position F in the statistical distribution is taken as the tolerance radius benchmark value. The coverage quantile position F is set by the operation and maintenance security policy according to the miss detection tolerance. The tolerance radius benchmark value is used as the radius parameter of the tolerance cylinder. Figure 3 The radius parameter is represented by a line segment pointing from the center coordinate point of the bottom circle to the edge of the bottom circle, and the radius parameter determines the circular boundary range of the tolerance cylinder on the cross section perpendicular to the time axis.
[0047] For example, Table 2 shows the differences in the tolerance radius benchmark values corresponding to different heterogeneous tag attribute sets: Table 2. Tolerance radius benchmark values for different heterogeneous tag attribute sets
[0048] In the table, A1 and A2 represent different cloud service provider types, B1 and B2 represent different hardware infrastructure types, C1 and C2 represent different operating system versions, D1 and D2 represent different network regions, and Rtol_1, Rtol_2, and Rtol_3 represent the corresponding tolerance radius benchmark values. The configuration fluctuation range of managed assets during normal operation varies under different heterogeneous environments; therefore, the tolerance radius benchmark value changes with the heterogeneous tag attribute set.
[0049] Step S21 maps the two key dimension values in the real-time configuration feature vector verified in step S15 to coordinate points in a two-dimensional plane, giving the abstract security baseline configuration parameter values a positional representation in geometric space. This provides a base positioning reference for step S22 to construct the tolerance cylinder in three-dimensional space. Step S21 queries the tolerance radius reference value through the heterogeneous tag attribute set constructed in step S11, so that managed assets with different heterogeneous environmental characteristics correspond to different sizes of tolerance cylinders. Heterogeneous environments with larger configuration fluctuations correspond to larger tolerance radii, and heterogeneous environments with smaller configuration fluctuations correspond to smaller tolerance radii. This avoids the situation where some assets frequently trigger unnecessary centripetal calibration operations due to excessively small tolerances when a uniform tolerance radius is applied to all managed assets, and some assets fail to detect abnormal configuration drift in a timely manner due to excessively large tolerances. Step S21 and step S10 form a seamless upstream-downstream connection: the configuration verification in step S10 ensures that the port permission quantization encoding value and firewall rule quantization encoding value extracted as the center coordinates of the bottom surface have been verified by Euclidean distance deviation, thus establishing the geometric center of the tolerance cylinder on a compliant and verified configuration state, rather than on an unverified configuration state. Without step S21, step S22 cannot determine the position of the bottom center and radius parameters of the tolerance cylinder, the tolerance cylinder space cannot be generated, the radial offset calculation in step S23 will lose its reference base, and the centripetal calibration vector in step S24 will lose its target pointing point.
[0050] Step S22: In a three-dimensional coordinate system, with the two-dimensional plane containing the center coordinate point of the bottom surface of the tolerance cylinder as the bottom surface and the time axis as the third vertical axis, the bottom surface containing the center coordinate point of the bottom surface is continuously extended along the time axis to form a tolerance cylinder space; the management agent program periodically collects the real-time values of the port permission quantization code value and firewall rule quantization code value of the target managed asset according to the preset continuous collection cycle. The two real-time values obtained in each collection are used as the horizontal axis coordinate value and the vertical axis coordinate value respectively, and the timestamp corresponding to the collection is used as the time axis coordinate value to obtain the real-time status coordinate point. The real-time status coordinate points obtained by continuous collection are connected in time order to form a spiral trajectory. Specifically, see Figure 4 This is a schematic diagram of a tolerance cylindrical space and a hairspring trajectory provided in an embodiment of this application. Figure 4The diagram illustrates a three-dimensional coordinate system, a tolerance cylinder space, the coordinates of the center point of the bottom surface, radius parameters, real-time status coordinates, and the trajectory of the spiral spring extending along the time axis. In the three-dimensional coordinate system, the two-dimensional plane containing the center point of the bottom surface of the tolerance cylinder determined in step S21 is used as the bottom plane. The horizontal axis of the bottom plane corresponds to the numerical space of the port permission quantization encoding value, and the vertical axis corresponds to the numerical space of the firewall rule quantization encoding value. The time axis is used as the third vertical axis of the three-dimensional coordinate system, with its direction aligned with the time progression direction. The coordinate values of the time axis are represented by timestamp values. Using the center point of the bottom surface of the tolerance cylinder as the center and the tolerance radius reference value obtained in step S21 as the radius, a bottom circular surface is generated on the bottom plane. This bottom circular surface is continuously extended along the positive direction of the time axis, forming a tolerance cylinder space that extends infinitely along the time axis. This tolerance cylinder space... Figure 4 It is presented in the form of a three-dimensional cylinder, and the radius parameter of its base circle is... Figure 4 The tolerance cylinder space is represented by a line segment pointing from the center point of the bottom circle to the edge of the bottom circle. The cross-section of the tolerance cylinder space at any time axis coordinate value is a circle with the center point of the bottom circle as the center and the tolerance radius reference value as the radius. This characteristic of the cross-section remaining unchanged makes the tolerance cylinder space maintain a constant tolerance range for configuration drift throughout the entire monitoring period.
[0051] The formation process of the spiral trajectory is as follows: the management agent program periodically collects the port permission quantization code values and firewall rule quantization code values of the target managed asset according to a preset continuous collection period. The method for determining the continuous collection period is as follows: based on the historical configuration change frequency of the target managed asset's category, the minimum time interval between two adjacent configuration changes in the historical configuration change frequency is taken, and the minimum time interval is divided by a preset sampling multiplier coefficient G to obtain the initial value of the continuous collection period. The sampling multiplier coefficient G is determined according to the ratio of the minimum sampling frequency to the signal frequency required to avoid aliasing in the sampling theorem. The value of G is not less than 2. For example, when G is 2, the continuous collection period is half of the minimum time interval, ensuring that the collection frequency of the continuous collection period can capture the time nodes when the port permission quantization code values and firewall rule quantization code values of the target managed asset change. At the end of each continuous collection cycle, the management agent program reads the real-time values of the port permission quantification code and firewall rule quantification code of the target managed asset at the current moment. The real-time value of the port permission quantification code is used as the horizontal axis coordinate value, the real-time value of the firewall rule quantification code is used as the vertical axis coordinate value, and the timestamp corresponding to the current collection is used as the time axis coordinate value. The three coordinate values form a real-time status coordinate point. Figure 4Multiple real-time status coordinate points are marked with discrete points, each point corresponding to a combination of configuration status value and timestamp obtained from a single acquisition. The real-time status coordinate points obtained from multiple consecutive acquisitions are connected sequentially in ascending order of timestamps to form a continuous curve extending along the time axis in three-dimensional space. This continuous curve is the spiral spring trajectory. Figure 4 The image clearly shows the shape of the hairspring trajectory extending along the time axis, formed by connecting multiple real-time state coordinate points in sequence. The name "hairspring trajectory" originates from the spatial morphology of the hairspring trajectory in three-dimensional space, which resembles the spiral movement of a clock hairspring within a cylinder. When the configuration state remains stable, the hairspring trajectory closely adheres to the axis of the tolerance cylinder and extends along the time axis; when the configuration state drifts, the hairspring trajectory deviates from the axis and moves towards the inner wall of the tolerance cylinder.
[0052] Step S22 organizes the discrete, periodically acquired configuration data into a continuous trajectory in three-dimensional space, providing a geometric spatial representation of the temporal evolution of the configuration state. The axis of the tolerance cylinder extends along the time axis, allowing the tolerance boundary to continuously constrain the drift range of the configuration state across the entire monitoring period. The superposition of the spiral spring trajectory and the tolerance cylinder in the same three-dimensional coordinate system enables step S23 to determine whether the configuration drift has exceeded the allowable range by calculating the geometric distance between each real-time state coordinate point on the spiral spring trajectory and the coordinate point of the bottom center of the tolerance cylinder. Step S22 and step S21 work together: the coordinate point of the bottom center and the radius parameters determined in step S21 provide all the geometric parameters for generating the tolerance cylinder space in step S22, while the spiral spring trajectory formed by periodic acquisition in step S22 provides the spatial data sequence to be evaluated for the radial offset calculation in step S23. Without step S22, the coordinates of the bottom center point and radius parameters constructed in step S21 will only exist as static values and cannot be used for continuous tracking of the configuration status of the target managed asset. Step S23 will also be unable to obtain real-time status coordinates to calculate the radial offset. The continuous acquisition mechanism of step S22 extends the one-time configuration verification completed in step S10 to the continuous configuration monitoring in step S20, making up for the monitoring gap between the verification of step S10 and the next configuration change work order. During the gap, if the port permission configuration or firewall rule configuration of the target managed asset drifts due to unexpected factors, the gossamer trajectory can record the drift process as spatial coordinate displacement, so that the drift can be detected by step S23.
[0053] Step S23: Calculate the Euclidean distance between the real-time state coordinate point on the cross section perpendicular to the time axis and the center coordinate point of the bottom surface of the tolerance cylinder to obtain the radial offset. Compare the radial offset with the warning threshold obtained by multiplying the radius parameter of the tolerance cylinder by the warning triggering ratio coefficient. When the radial offset is less than the warning threshold, continue to execute the next acquisition according to the continuous acquisition cycle. When the radial offset is greater than or equal to the warning threshold and less than the radius parameter, generate a drift warning record and shorten the continuous acquisition cycle to half of the current value. When the radial offset is greater than or equal to the radius parameter, determine that the hairspring trajectory has touched the inner wall of the tolerance cylinder and trigger the centripetal calibration operation. Specifically, see Figure 5 This is a schematic diagram of a three-level determination region division provided in an embodiment of this application. Figure 5 The diagram illustrates the coordinates of the center point of the bottom surface, radius parameters, warning threshold boundaries, warning thresholds, the inner wall of the tolerance cylinder, and the divided safety and warning areas. The radial offset is calculated as follows: for each real-time state coordinate point in the spiral trajectory, the two-dimensional projected coordinates of the real-time state coordinate point on a section perpendicular to the time axis are taken. The Euclidean distance between the two-dimensional projected coordinates and the center point of the bottom surface of the tolerance cylinder is used as the radial offset. The two-dimensional projected coordinates refer to the ordered pairs of horizontal and vertical coordinates of the real-time state coordinate point after ignoring the time axis coordinates. The radial offset is calculated using the well-known two-dimensional Euclidean distance formula, which is the square root of the sum of the squares of the differences between the corresponding components of two two-dimensional coordinate points. The physical meaning of the radial offset is: the deviation distance of the real-time state coordinate point from the center point of the bottom surface of the tolerance cylinder on the configuration state plane. The larger the radial offset, the greater the difference between the current port permission quantization code value and firewall rule quantization code value combination of the target managed asset and the port permission quantization code value and firewall rule quantization code value combination at the time of configuration verification.
[0054] The method for determining the warning trigger ratio coefficient is as follows: It is set according to the requirements of the operation and maintenance security policy regarding the sensitivity of drift warnings. The value of the warning trigger ratio coefficient is provided by the security policy configuration library of the operation and maintenance management platform. The value range of the warning trigger ratio coefficient is between 0 and 1, excluding 0 and 1. The warning threshold is obtained by multiplying the radius parameter of the tolerance cylinder by the warning trigger ratio coefficient. This warning threshold is within... Figure 5 The warning threshold is represented by a dashed circle, which divides the internal space of the tolerance cylinder into two concentric annular regions: an inner circle centered on the bottom center and with the warning threshold as its radius, serving as the safe zone; and an outer circle centered on the warning threshold and with the radius parameter of the tolerance cylinder as its outer diameter, serving as the warning zone. The safe zone and the warning zone are located within... Figure 5 The inner wall of the tolerance cylinder is marked with different concentric ring regions. Figure 5 The outermost solid circle represents the center, and the radius parameter is in Figure 5 The radial offset is represented by a line segment pointing from the center coordinate point of the bottom circle to the inner wall of the tolerance cylinder. Step S23 performs a three-level judgment on the radial offset: When the radial offset is less than the warning threshold, the real-time status coordinate point is within the safe area, and the port permission configuration and firewall rule configuration of the target managed asset are within the normal fluctuation range. The management agent program continues to execute the next collection according to the current continuous collection cycle; When the radial offset is greater than or equal to the warning threshold and less than the radius parameter of the tolerance cylinder, the real-time status coordinate point is within the warning area, and the configuration status of the target managed asset has deviated from the safe area but has not yet touched the inner wall of the tolerance cylinder. At this time, a drift warning record is generated and the continuous collection cycle is shortened to half of the current value; When the radial offset is greater than or equal to the radius parameter of the tolerance cylinder, the real-time status coordinate point has reached or exceeded the inner wall position of the tolerance cylinder. It is determined that the hairspring trajectory has touched the inner wall of the tolerance cylinder and a centripetal calibration operation is triggered.
[0055] For example, Table 3 illustrates the response behavior for the three-level decision-making process: Table 3. Level III Judgment Methods
[0056] The drift warning record includes a heterogeneous tag attribute set of the target managed asset, the three-dimensional coordinates of the real-time status coordinate point that triggered the drift warning, the radial offset value, and the corresponding timestamp. The drift warning record is written to the drift warning log library of the operation and maintenance management platform. The design basis for shortening the continuous acquisition cycle to half of the current value is: when the real-time status coordinate point enters the warning area, the configuration state is close to the tolerance boundary, and it is necessary to track the change trend of the configuration state with a higher acquisition frequency so that the wall-touching event can be detected more promptly when the configuration state continues to move towards the inner wall of the tolerance cylinder. The shortening of the continuous acquisition cycle is only performed once when the real-time status coordinate point first enters the warning area from the safe area. During the period when the continuous acquisition cycle is already in the shortened state, even if the real-time status coordinate point acquired subsequently is still in the warning area, the continuous acquisition cycle will not be further halved. After the continuous acquisition cycle is shortened, if the radial offset of the real-time status coordinate point acquired subsequently falls back to less than the warning threshold, the continuous acquisition cycle will be restored to the initial continuous acquisition cycle value determined in step S22. When the radial offset remains within the warning area, the continuous acquisition period will not be shortened further, maintaining the value shortened when the area first enters the warning area, thus avoiding excessive consumption of acquisition resources due to the acquisition period being halved indefinitely.
[0057] Step S23 establishes a progressive response mechanism—from normal monitoring to accelerated acquisition of warning data and then to triggering repair operations—by comparing the radial offset with the warning threshold and radius parameter in a tiered manner. If the judgment rule is simplified to only execute a response when the radial offset is greater than or equal to the radius parameter, the transitional monitoring of the warning area will be skipped. During the rapid movement of configuration drift from the safe zone to the wall-touching position, the managed agent program will be unable to capture the acceleration trend of drift by shortening the acquisition cycle, potentially leading to a significant delay between the actual occurrence time of the wall-touching event and the time it is detected. The warning area mechanism in step S23 provides the operation and maintenance management platform with historical trend data on configuration drift through the accumulation of drift warning records. The platform can identify managed assets with a persistent drift tendency and take early intervention measures by analyzing the temporal distribution and radial offset change trends of drift warning records for the same target managed asset in the drift warning log library. Step S23 works in conjunction with step S22 to control the acquisition frequency: Step S22 performs periodic acquisition to form the hairspring trajectory using an initial continuous acquisition cycle. Step S23 dynamically adjusts the continuous acquisition cycle based on changes in radial offset, maintaining a normal sampling density for the hairspring trajectory within the safe zone to control acquisition resource consumption, and increasing the sampling density to twice the normal level within the warning zone to enhance tracking capabilities against rapid drift. Without step S23, the real-time state coordinates acquired in step S22 would only be stored as data and could not be used to determine whether the tolerance range had been exceeded, thus lacking a trigger condition for the centripetal calibration operation in step S24. The wall-touching event determined in step S23 provides step S24 with a trigger signal for performing a local configuration reset and the real-time state coordinates at the moment of wall-touching, enabling step S24 to calculate the direction and components of the centripetal calibration vector.
[0058] Step S24: Calculate the direction vector from the real-time state coordinate point of the inner wall of the tolerance cylinder to the coordinate point of the center of the bottom surface of the tolerance cylinder to obtain the centripetal calibration vector. Retrieve the corresponding atomic repair instruction based on the component value of the centripetal calibration vector in each key configuration parameter dimension. The component value represents the specific numerical amount that the corresponding configuration parameter needs to be adjusted. Combine all atomic repair instructions into a composite repair instruction package and send it to the target managed asset through the management agent program to perform a partial configuration reset. After the partial configuration reset is completed, perform closed-loop verification on the reset result.
[0059] Specifically, the centripetal calibration vector is calculated as follows: Taking the two-dimensional projection coordinates of the real-time state coordinate point (determined in step S23 as touching the inner wall of the tolerance cylinder) on a section perpendicular to the time axis as the starting point, and the center coordinate point of the bottom surface of the tolerance cylinder as the ending point, the direction vector from the starting point to the ending point is the centripetal calibration vector. The horizontal component of the centripetal calibration vector is equal to the horizontal coordinate value of the center coordinate point of the bottom surface of the tolerance cylinder minus the horizontal coordinate value of the real-time state coordinate point touching the inner wall of the tolerance cylinder. The vertical component of the centripetal calibration vector is equal to the vertical coordinate value of the center coordinate point of the bottom surface of the tolerance cylinder minus the vertical coordinate value of the real-time state coordinate point touching the inner wall of the tolerance cylinder. The sign and absolute value of the horizontal component of the centripetal calibration vector represent the direction and magnitude of adjustment required for the port permission quantization encoding value, and the sign and absolute value of the vertical component of the centripetal calibration vector represent the direction and magnitude of adjustment required for the firewall rule quantization encoding value.
[0060] The retrieval method for atomic repair commands is as follows: The operation and maintenance management platform pre-establishes an atomic repair command mapping library. This library uses the configuration parameter dimension identifier and component value range as a combined index key, and the atomic repair command as the index value. An atomic repair command refers to the smallest-granularity repair operation command for a single configuration parameter dimension, including two categories: port permission repair commands and firewall rule repair commands. For the component values of the centripetal calibration vector along the horizontal axis, the port permission quantization encoding value is used as the configuration parameter dimension identifier. The absolute value of the component value is matched with the preset component value range in the atomic repair command mapping library, and the port permission repair command corresponding to the matched component value range is retrieved. The port permission repair command includes a list of ports to be adjusted and the corresponding permission change operation type. The permission change operation type is determined by the sign of the component value: when the component value is positive, the permission change operation type is to reclaim the port permissions to the state at the time of configuration verification; when the component value is negative, the permission change operation type is to extend the port permissions to the state at the time of configuration verification. For the component values of the centripetal calibration vector along the vertical axis, the firewall rule quantization encoding value is used as the configuration parameter dimension identifier, and the same retrieval logic is used to obtain the firewall rule repair instructions. The obtained port permission repair instructions and firewall rule repair instructions are combined into a composite repair instruction package. This composite repair instruction package contains repair operation commands for both key configuration parameter dimensions. After receiving the composite repair instruction package, the management agent program executes the port permission repair instructions and firewall rule repair instructions sequentially according to a preset execution order, completing a partial configuration reset. This partial configuration reset only adjusts the configuration items corresponding to the port permission quantization encoding value and the firewall rule quantization encoding value, without changing the configuration items corresponding to the critical service process running status value and the system account permission configuration value, thus avoiding unnecessary reset operations on configuration parameters that have not drifted.
[0061] After the partial configuration reset is completed, closed-loop verification is performed on the reset result. The closed-loop verification process is as follows: the post-repair verification time window corresponding to the partial configuration reset is recalculated. The calculation method of the post-repair verification time window is the same as that of the dynamic verification time window in step S12. The heterogeneous tag attribute set constructed in step S11 is used as the search condition to search the historical similar configuration work order record set. The average effective delay time is calculated and multiplied by the heterogeneous environment fluctuation coefficient to obtain the post-repair verification waiting time. The timestamp of the partial configuration reset command execution time is added to the post-repair verification waiting time to obtain the post-repair verification trigger timestamp. When the system clock reaches the post-repair verification trigger timestamp, the management agent program re-collects the port permission quantization code value, firewall rule quantization code value, key service process running status value, and system account permission configuration value of the target managed asset at the current moment. The program constructs the post-repair real-time configuration feature vector, extracts the original asset baseline vector, calculates the Euclidean distance deviation between the post-repair real-time configuration feature vector and the original asset baseline vector, and compares the post-repair Euclidean distance deviation with the compliance judgment threshold. When the Euclidean distance deviation after repair is less than the compliance judgment threshold, it is determined that the partial configuration reset has been completed and the configuration status after reset has been restored to the compliance range. The port permission quantization code value and firewall rule quantization code value in the real-time configuration feature vector after repair are re-extracted to update the coordinate point of the bottom center of the tolerance cylinder. The radius parameter of the tolerance cylinder remains unchanged, still being the tolerance radius benchmark value obtained from the heterogeneous tag attribute set in step S21, so that the geometric center of the tolerance cylinder is aligned with the configuration status after reset. The management agent program continues to execute subsequent gossamer trajectory monitoring according to the continuous collection cycle. When the Euclidean distance deviation after repair is greater than or equal to the compliance judgment threshold, it is determined that the partial configuration reset has not achieved the expected result. A new round of reverse compensation work order is generated and sent to the management agent program to perform the compensation configuration operation again.
[0062] Step S24 uses a centripetal calibration vector to transform the geometric offset between the real-time state coordinates of the inner wall of the tolerance cylinder and the coordinates of the bottom center point into specific adjustment amounts in each dimension of the key configuration parameters, making the local configuration reset operation directional and quantitative. The component values of the centripetal calibration vector directly correspond to the adjustment range required for port permission configuration and firewall rule configuration, avoiding indiscriminate reset of all configuration items without knowing the specific values of the offsets in each dimension. The closed-loop verification mechanism in step S24 reuses the dynamic verification time window calculation method in step S12 of step S10 and the Euclidean distance deviation judgment method in step S15, ensuring that the verification standard for local configuration reset is consistent with the initial verification standard of the configuration work order, and guaranteeing that the configuration state after reset undergoes the same quantitative evaluation process as the initial configuration verification. After the closed-loop verification is passed, the coordinates of the bottom center point of the tolerance cylinder are updated, ensuring that the reference point for subsequent spring trajectory monitoring always follows the latest compliant configuration state, avoiding the accumulation of systematic deviations between the configuration state and the bottom center point after multiple resets when the bottom center point remains unchanged. Steps S24 and S23 work together to trigger execution: Step S23 determines the wall-touching event and provides the real-time state coordinates at the moment of contact; Step S24 uses the real-time state coordinates at the moment of contact as input to calculate the centripetal calibration vector. The data transfer between the two steps ensures the consistency of the triggering conditions and the direction of the repair operation. Without step S24, the wall-touching event detected by step S23 will only remain at the warning level and will not trigger the actual configuration repair operation. The spring trajectory will continue to deviate outwards unrestrained after touching the inner wall of the tolerance cylinder, and the port permission configuration and firewall rule configuration of the target managed asset will continuously deviate from the compliance baseline.
[0063] Step S20 extends the one-time configuration verification completed in step S10 into continuous geometric spatial configuration drift monitoring, making the configuration verification pass status no longer a static final state but a starting benchmark for continuous monitoring. The tolerance cylinder solidifies the allowable range of configuration drift in three-dimensional space in the form of geometric boundaries, the gossamer trajectory visualizes the time-series changes of the configuration status in the form of spatial curves, and the radial offset compresses the degree of configuration drift into a single distance metric. The combination of these three transforms the detection of configuration drift from a parameter-by-parameter judgment method that sets independent thresholds for multiple configuration parameters to a joint judgment method based on geometric distance. Under the joint judgment method, the individual offset or the composite offset of the port permission quantization encoding value and the firewall rule quantization encoding value in any dimension is uniformly measured as a radial offset. This allows for the detection of cases where the two dimensions each have small offsets but the composite offset direction is consistent. In contrast, under the parameter-by-parameter independent judgment method, the offsets of the two dimensions may not exceed their respective independent thresholds and thus be missed. Step S23's early warning zone mechanism introduces dynamic adjustment capabilities for the acquisition frequency. When the configuration state approaches the tolerance boundary, the continuous acquisition cycle is shortened to half, reducing the detection time window for wall-touching events to half of the normal acquisition cycle, thus improving the response speed to rapid drift. When the configuration state is in the safe zone, the normal acquisition cycle is maintained to avoid unnecessary acquisition resource consumption. Step S24's centripetal calibration vector transforms the offset in geometric space into specific configuration parameter adjustment instructions, enabling the repair operation to be precise in the adjustment direction and magnitude of each key configuration parameter dimension, avoiding the risk of configuration service interruption caused by a full reset without dimension differentiation. Step S24's closed-loop verification mechanism reuses the dynamic verification time window and Euclidean distance deviation judgment method in step S10, ensuring that the verification standard after partial configuration reset is consistent with the verification standard of the initial configuration work order, guaranteeing that the configuration state of the managed assets after reset has passed the same quantitative evaluation as the initial verification when entering subsequent monitoring cycles. After the closed-loop verification is passed, the coordinates of the center point of the bottom surface of the tolerance cylinder are updated so that the geometric center of the tolerance cylinder always follows the latest compliance configuration state. After the target managed assets have undergone multiple configuration drifts and resets, the coordinates of the center point of the bottom surface of the tolerance cylinder can be adapted to the latest compliance benchmark instead of being fixed at the configuration state position at the initial verification time. This eliminates the interference of the systematic cumulative deviation between the configuration state and the initial benchmark caused by multiple resets on the accuracy of subsequent monitoring.
[0064] Example 2: This embodiment, based on Embodiment 1, provides a unified management system for multi-source heterogeneous digital assets, such as... Figure 6 As shown, it includes: Dynamic configuration verification module: It is used to construct a heterogeneous tag attribute set of the target managed assets, form a dynamic verification time window corresponding to the target managed assets, construct a real-time configuration feature vector based on the dynamic verification time window, and extract the original asset baseline vector of the target managed assets. Based on the real-time configuration feature vector and the original asset baseline vector, it confirms whether to set the flow status of the configuration work order to the configuration verification passed status. Tolerance Cylinder Monitoring Module: Constructs a tolerance cylinder based on the real-time configuration feature vector that has been confirmed to have passed configuration verification, collects the real-time status coordinates of the target managed assets to form a spiral trajectory, calculates the radial offset between each real-time status coordinate point in the spiral trajectory and the center coordinate point of the bottom surface of the tolerance cylinder, and determines whether the spiral trajectory has touched the inner wall of the tolerance cylinder based on the radial offset. Centripetal calibration execution module: If the spiral spring trajectory has touched the inner wall of the tolerance cylinder, the centripetal calibration operation is triggered. The centripetal calibration operation includes calculating the centripetal calibration vector and performing a local configuration reset based on the centripetal calibration vector. After the local configuration reset is completed, the reset result is verified in a closed loop.
[0065] Furthermore, in the dynamic configuration verification module, the method for generating the dynamic verification time window includes: Retrieve a set of historical similar configuration work order records based on the heterogeneous tag attribute set. Calculate the average effective delay time corresponding to the heterogeneous tag attribute set based on the configuration instruction issuance timestamp and the actual effective timetamp of the underlying configuration for each work order record in the historical similar configuration work order record set. Calculate the verification trigger timestamp based on the average effective delay time and use the verification trigger timestamp as the start time of the dynamic verification time window.
[0066] The method for constructing real-time configuration feature vectors includes: Change the workflow status of the configuration work order from the instruction issued status to the verification waiting suspended status, write the verification trigger timestamp of the dynamic verification time window into the workflow node of the configuration work order as a time lock parameter, and generate a listening suspended node with time lock parameter. When the system clock reaches the verification trigger timestamp specified by the time lock parameter, the listening suspended node automatically releases the suspended state and sends a real-time configuration collection command to the management agent program deployed on the target managed asset. The management agent program collects the security baseline configuration parameter values of the target managed asset at the current moment and constructs a real-time configuration feature vector. The security baseline configuration parameter values include port permission quantization encoding values, firewall rule quantization encoding values, critical service process running status values, and system account permission configuration values.
[0067] The method for confirming whether to set the configuration work order's workflow status to configuration verification passed status includes: Calculate the Euclidean distance deviation between the real-time configuration feature vector and the original asset baseline vector, compare the Euclidean distance deviation with a preset compliance judgment threshold, and when the Euclidean distance deviation is less than the preset compliance judgment threshold, change the flow status of the configuration work order to the configuration verification passed status.
[0068] Furthermore, in the tolerance cylinder monitoring module, the method for constructing the tolerance cylinder includes: Extract the port permission quantization code value and firewall rule quantization code value from the real-time configuration feature vector corresponding to the configuration verification pass status as the values of two key configuration parameter dimensions. Use the values of the two key configuration parameter dimensions as the horizontal axis coordinate value and the vertical axis coordinate value in the two-dimensional plane coordinate system to obtain the coordinate point of the center of the bottom surface of the tolerance cylinder. Query the tolerance radius benchmark value according to the heterogeneous tag attribute set and use the tolerance radius benchmark value as the radius parameter of the tolerance cylinder. In a three-dimensional coordinate system, the two-dimensional plane containing the center coordinate point of the bottom surface of the tolerance cylinder is taken as the bottom surface, and the time axis is taken as the third vertical axis. The bottom circular surface containing the center coordinate point of the bottom surface is continuously extended along the time axis to form the tolerance cylinder space.
[0069] The methods and systems of this application may be implemented in many ways. For example, they may be implemented by software, hardware, firmware, or any combination of software, hardware, and firmware. The above-described order of steps for the method is for illustrative purposes only, and the steps of the method of this application are not limited to the order specifically described above, unless otherwise specifically stated.
[0070] In addition, the parts of the technical solutions provided in the embodiments of this application that are consistent with the implementation principles of the corresponding technical solutions in the prior art have not been described in detail, so as to avoid excessive elaboration.
[0071] The specific embodiments described above further illustrate the purpose, technical solution, and beneficial effects of the present invention. It should be understood that the above descriptions are merely specific embodiments of the present invention and are not intended to limit the invention. Any modifications, equivalent substitutions, or improvements made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.
Claims
1. A method for unified management of multi-source heterogeneous digital assets, characterized in that, The method includes: Construct a heterogeneous set of tag attributes for the target managed assets, form a dynamic verification time window for the target managed assets, construct a real-time configuration feature vector based on the dynamic verification time window, and extract the original asset baseline vector of the target managed assets. Based on the real-time configuration feature vector and the original asset baseline vector, confirm whether to set the flow status of the configuration work order to the configuration verification passed status. A tolerance cylinder is constructed based on the real-time configuration feature vector that has been confirmed to have passed configuration verification. The real-time status coordinates of the target managed assets are collected to form a spiral trajectory. The radial offset between each real-time status coordinate point in the spiral trajectory and the center coordinate point of the bottom surface of the tolerance cylinder is calculated. Based on the radial offset, it is determined whether the spiral trajectory has touched the inner wall of the tolerance cylinder. If the spiral trajectory has touched the inner wall of the tolerance cylinder, a centripetal calibration operation is triggered. The centripetal calibration operation includes calculating the centripetal calibration vector and performing a local configuration reset based on the centripetal calibration vector. After the local configuration reset is completed, the reset result is verified in a closed loop.
2. The method for unified management of multi-source heterogeneous digital assets according to claim 1, characterized in that, The heterogeneous tag attribute set is obtained by acquiring and combining the cloud service provider type identifier, hardware infrastructure type identifier, operating system version identifier, and network region identifier of the target managed asset.
3. The method for unified management of multi-source heterogeneous digital assets according to claim 1, characterized in that, The method for generating the dynamic verification time window includes: Retrieve a set of historical similar configuration work order records based on the heterogeneous tag attribute set. Calculate the average effective delay time corresponding to the heterogeneous tag attribute set based on the configuration instruction issuance timestamp and the actual effective timetamp of the underlying configuration for each work order record in the historical similar configuration work order record set. Calculate the verification trigger timestamp based on the average effective delay time and use the verification trigger timestamp as the start time of the dynamic verification time window.
4. The method for unified management of multi-source heterogeneous digital assets according to claim 3, characterized in that, The method for constructing real-time configuration feature vectors includes: Change the workflow status of the configuration work order from the instruction issued status to the verification waiting suspended status, write the verification trigger timestamp of the dynamic verification time window into the workflow node of the configuration work order as a time lock parameter, and generate a listening suspended node with time lock parameter. When the system clock reaches the verification trigger timestamp specified by the time lock parameter, the listening suspended node automatically releases the suspended state and sends a real-time configuration collection command to the management agent program deployed on the target managed asset. The management agent program collects the security baseline configuration parameter values of the target managed asset at the current moment and constructs a real-time configuration feature vector. The security baseline configuration parameter values include port permission quantization encoding values, firewall rule quantization encoding values, critical service process running status values, and system account permission configuration values.
5. A method for unified management of multi-source heterogeneous digital assets according to claim 4, characterized in that, The method for confirming whether to set the configuration work order's workflow status to configuration verification passed status includes: Calculate the Euclidean distance deviation between the real-time configuration feature vector and the original asset baseline vector, compare the Euclidean distance deviation with a preset compliance judgment threshold, and when the Euclidean distance deviation is less than the preset compliance judgment threshold, change the flow status of the configuration work order to the configuration verification passed status.
6. The method for unified management of multi-source heterogeneous digital assets according to claim 5, characterized in that, The method further includes: When the Euclidean distance deviation is greater than or equal to the compliance judgment threshold, the flow status of the configuration work order is frozen and a reverse compensation work order is generated and sent to the management agent program to perform the compensation configuration operation. The system counts the cumulative number of reverse compensation work orders triggered by the target managed assets within the most recent preset time period. The cumulative number is divided by the number of days in the preset time period to obtain the daily average trigger frequency. When the daily average trigger frequency is greater than the preset upper limit value, the compliance judgment threshold is adjusted by adding a preset scaling step size to the current value to complete the adaptive scaling of the compliance judgment threshold.
7. A method for unified management of multi-source heterogeneous digital assets according to claim 4, characterized in that, The method for constructing the tolerance cylinder includes: Extract the port permission quantization code value and firewall rule quantization code value from the real-time configuration feature vector corresponding to the configuration verification pass status as the values of two key configuration parameter dimensions. Use the values of the two key configuration parameter dimensions as the horizontal axis coordinate value and the vertical axis coordinate value in the two-dimensional plane coordinate system to obtain the coordinate point of the center of the bottom surface of the tolerance cylinder. Query the tolerance radius benchmark value according to the heterogeneous tag attribute set and use the tolerance radius benchmark value as the radius parameter of the tolerance cylinder. In a three-dimensional coordinate system, the two-dimensional plane containing the center coordinate point of the bottom surface of the tolerance cylinder is taken as the bottom surface, and the time axis is taken as the third vertical axis. The bottom circular surface containing the center coordinate point of the bottom surface is continuously extended along the time axis to form the tolerance cylinder space.
8. A method for unified management of multi-source heterogeneous digital assets according to claim 7, characterized in that, The method for generating the hairspring trajectory includes: The management agent program periodically collects the real-time values of the port permission quantification code value and firewall rule quantification code value of the target managed asset according to the preset continuous collection cycle. The two real-time values obtained in each collection are used as the horizontal axis coordinate value and the vertical axis coordinate value respectively, and the timestamp of the collection is used as the time axis coordinate value to obtain the real-time status coordinate point. The real-time status coordinate points obtained by continuous collection are connected in chronological order to form a spiral trajectory.
9. A method for unified management of multi-source heterogeneous digital assets according to claim 7, characterized in that, The method for determining whether the hairspring trajectory has touched the inner wall of the tolerance cylinder includes: The warning threshold is obtained based on the radius parameter of the tolerance cylinder. The radial offset is compared with the warning threshold. When the radial offset is greater than or equal to the radius parameter, it is determined that the hairspring trajectory has touched the inner wall of the tolerance cylinder.
10. A unified management system for multi-source heterogeneous digital assets, used to implement the unified management method for multi-source heterogeneous digital assets as described in any one of claims 1-9, characterized in that, The system includes: Dynamic configuration verification module: It is used to construct a heterogeneous tag attribute set of the target managed assets, form a dynamic verification time window corresponding to the target managed assets, construct a real-time configuration feature vector based on the dynamic verification time window, and extract the original asset baseline vector of the target managed assets. Based on the real-time configuration feature vector and the original asset baseline vector, it confirms whether to set the flow status of the configuration work order to the configuration verification passed status. Tolerance Cylinder Monitoring Module: Constructs a tolerance cylinder based on the real-time configuration feature vector that has been confirmed to have passed configuration verification, collects the real-time status coordinates of the target managed assets to form a spiral trajectory, calculates the radial offset between each real-time status coordinate point in the spiral trajectory and the center coordinate point of the bottom surface of the tolerance cylinder, and determines whether the spiral trajectory has touched the inner wall of the tolerance cylinder based on the radial offset. Centripetal calibration execution module: If the spiral spring trajectory has touched the inner wall of the tolerance cylinder, the centripetal calibration operation is triggered. The centripetal calibration operation includes calculating the centripetal calibration vector and performing a local configuration reset based on the centripetal calibration vector. After the local configuration reset is completed, the reset result is verified in a closed loop.
Citation Information
Patent Citations
Digital asset monitoring method and system
CN119690769A
Data asset management and control method and system based on multi-source heterogeneous data source
CN119739772A