Methods, devices, media, and products for handling server weak password alerts.
Patent Information
- Application Number
- CN202511253882.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-03
- Publication Date
- 2026-09-11
AI Technical Summary
[0005]本申请提供一种服务器弱口令告警的处理方法、装置、介质及产品,用以解决服务器的安全性不高的技术问题
[0023] This application provides a method, apparatus, medium, and product for handling weak password alarms on servers. The method involves acquiring weak password alarm information, determining the asset information of servers with weak passwords and the application cluster information corresponding to those servers based on the alarm information, generating a server list, verifying weak passwords based on the server list and the weak password alarm information, obtaining verification results, conducting a risk assessment based on the verification results, and generating weak password remediation suggestions based on the risk assessment results. This solution expands the scope of weak password detection by acquiring a list of servers with weak password alarms for weak password verification, avoiding overlooking similar risks, improving the accuracy of risk investigation, and enhancing server security.
Smart Images

Figure CN122741079A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the fields of financial technology and information security, and in particular to a method, device, medium and product for processing server weak password alarms. Background Technology
[0002] With the development of digitalization, cyberattacks are becoming increasingly frequent, with brute-force attacks and credential stuffing attacks exploiting weak passwords becoming the main intrusion methods. Factors such as users' habit of setting easy-to-remember passwords, lack of security awareness leading to failure to modify system default configurations, and failure to configure server password policies all exacerbate the security risks associated with weak passwords.
[0003] Weak passwords are a common security vulnerability, easily exploited by attackers, leading to serious consequences such as server intrusion and data breaches. Weak password detection for internal network servers primarily relies on passive traffic monitoring or active host scanning techniques. However, these techniques struggle to achieve unified screening and handling of weak passwords across servers within the same application cluster, resulting in low accuracy in risk assessment.
[0004] Therefore, current methods for detecting weak passwords cannot guarantee server security. Summary of the Invention
[0005] This application provides a method, apparatus, medium, and product for handling weak password alarms on servers, in order to solve the technical problem of low server security.
[0006] Firstly, this application provides a method for handling weak password alarms on servers, comprising: obtaining weak password alarm information; calling an asset management system interface to determine the asset information of the server with a weak password and the application cluster information corresponding to the server based on the weak password alarm information; constructing a mapping relationship between the application cluster information corresponding to the server and the asset information of the server to generate a server list; performing weak password verification based on the server list and the weak password alarm information to obtain a verification result; wherein, the server list includes the server and the server address; performing a risk assessment based on the verification result to obtain a risk assessment result; and generating a weak password handling suggestion based on the risk assessment result.
[0007] In one possible implementation, before obtaining weak password alarm information, the method further includes: calling the interface of the traffic monitoring system to extract weak password alarm information and storing it as a traffic alarm record; calling the interface of the host scanning system to extract weak password alarm information and storing it as a host alarm record; wherein, the weak password alarm information includes weak password type, weak password password, weak password account, and address.
[0008] In one possible implementation, the source of the weak password alarm is determined; if the weak password alarm originates from a traffic alarm record, then weak password verification is performed based on the server list and the weak password alarm; if the weak password alarm originates from a host alarm record, then server scanning verification is performed based on the server list and the weak password alarm.
[0009] In one possible implementation, weak password verification is performed based on a server list and weak password alert information, including: determining the weak password type based on the weak password alert information; if the weak password is a protocol weak password, keeping the weak password and weak password account unchanged, logging into a server in the server list; if the login is successful, it indicates that a server with the same weak password and weak password account exists in the server list; if the weak password is an access weak password, keeping the weak password and weak password account unchanged, changing the address to the server address, and performing a preset number of login attempts; if the login is successful, it indicates that a server with the same weak password and weak password account exists in the server list.
[0010] In one possible implementation, server scanning verification is performed based on the server list and weak password alarm information, including: creating a scanning task based on the server list and weak password alarm information, and scanning host alarm records based on the scanning task; if there is an alarm with the same weak password and weak password account as the weak password alarm information, it indicates that there is a server with the same weak password and weak password account in the server list.
[0011] In one possible implementation, risk assessment is performed based on the verification results to obtain risk assessment results, including: performing risk assessment based on the verification results according to preset assessment types to obtain risk assessment results; wherein, the preset assessment types include password reuse rate, application cluster level, password complexity, and weak password type.
[0012] In one possible implementation, the weak password handling recommendations include multiple differentiated weak password handling recommendations. The weak password handling recommendations are generated based on the risk assessment results, including: generating differentiated weak password handling recommendations based on the risk assessment results corresponding to any assessment type in the risk assessment results; and determining the weak password handling recommendations based on the multiple differentiated weak password handling recommendations.
[0013] Secondly, this application provides a processing device for server weak password alarms, comprising: an acquisition module, used to acquire weak password alarm information, call an asset management system interface to determine the asset information of the server with weak passwords and the application cluster information corresponding to the server based on the weak password alarm information; a verification module, used to construct a mapping relationship between the application cluster information corresponding to the server and the asset information of the server to generate a server list; perform weak password verification based on the server list and the weak password alarm information to obtain a verification result; wherein, the server list includes the server and the server address; and a processing module, used to perform a risk assessment based on the verification result to obtain a risk assessment result; and generate weak password handling suggestions based on the risk assessment result.
[0014] In one possible implementation, the acquisition module is further configured to: call the interface of the traffic monitoring system to extract weak password alarm information and store it as a traffic alarm record; call the interface of the host scanning system to extract weak password alarm information and store it as a host alarm record; wherein, the weak password alarm information includes weak password type, weak password password, weak password account, and address.
[0015] In one possible implementation, the source of the weak password alarm is determined; if the weak password alarm originates from a traffic alarm record, then weak password verification is performed based on the server list and the weak password alarm; if the weak password alarm originates from a host alarm record, then server scanning verification is performed based on the server list and the weak password alarm.
[0016] In one possible implementation, the verification module is further configured to: determine the type of weak password based on the weak password alarm information; if the weak password is a protocol weak password, keep the weak password password and weak password account unchanged, log in to a server in the server list, and if the login is successful, it indicates that a server with the same weak password password and weak password account exists in the server list; if the weak password is an access weak password, keep the weak password password and weak password account unchanged, change the address to the server address, and perform a preset number of login attempts; if the login is successful, it indicates that a server with the same weak password password and weak password account exists in the server list.
[0017] In one possible implementation, the verification module is further configured to: create a scanning task based on the server list and weak password alarm information, and scan host alarm records based on the scanning task; if there is an alarm with the same weak password and weak password account as the weak password alarm information, it indicates that there is a server with the same weak password and weak password account in the server list.
[0018] In one possible implementation, the processing module is further configured to: perform a risk assessment on the verification result based on a preset assessment type to obtain a risk assessment result; wherein the preset assessment type includes password reuse rate, application cluster level, password complexity, and weak password type.
[0019] In one possible implementation, the processing module is further configured to: generate differentiated weak password handling suggestions based on the risk assessment results corresponding to any assessment type in the risk assessment results; and determine weak password handling suggestions based on multiple differentiated weak password handling suggestions.
[0020] Thirdly, this application provides an electronic device, including: a processor, and a memory communicatively connected to the processor; the memory stores computer-executable instructions; the processor executes the computer-executable instructions stored in the memory to implement the aforementioned method.
[0021] Fourthly, this application provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, are used to implement the aforementioned method.
[0022] Fifthly, embodiments of this application provide a computer program product, including a computer program that, when executed by a processor, implements the first aspect and / or various possible implementations of the first aspect.
[0023] This application provides a method, apparatus, medium, and product for handling weak password alarms on servers. The method involves acquiring weak password alarm information, determining the asset information of servers with weak passwords and the application cluster information corresponding to those servers based on the alarm information, generating a server list, verifying weak passwords based on the server list and the weak password alarm information, obtaining verification results, conducting a risk assessment based on the verification results, and generating weak password remediation suggestions based on the risk assessment results. This solution expands the scope of weak password detection by acquiring a list of servers with weak password alarms for weak password verification, avoiding overlooking similar risks, improving the accuracy of risk investigation, and enhancing server security. Attached Figure Description
[0024] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.
[0025] Figure 1 A flowchart illustrating a method for handling weak password alerts on servers provided in this application. Figure 1 ;
[0026] Figure 2A schematic diagram of a weak password alarm information processing system provided in this application;
[0027] Figure 3 A flowchart illustrating a method for handling weak password alerts on servers provided in this application. Figure 2 ;
[0028] Figure 4 A schematic diagram of the structure of a server weak password alarm processing device provided in this application;
[0029] Figure 5 This is a schematic diagram of the structure of an electronic device provided in this application.
[0030] The accompanying drawings illustrate specific embodiments of this application, which will be described in more detail below. These drawings and descriptions are not intended to limit the scope of the concept in any way, but rather to illustrate the concept of this application to those skilled in the art through reference to particular embodiments. Detailed Implementation
[0031] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.
[0032] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, storage, use, processing, transmission, provision, disclosure, and application of the relevant data all comply with the relevant laws, regulations, and standards of the relevant countries and regions, have taken necessary confidentiality measures, do not violate public order and good morals, and provide corresponding operation access points for users to choose to authorize or refuse.
[0033] Furthermore, the technical solution involved in this application, which involves big data analysis of user information (including but not limited to personal biometrics, identity data, consumption data, asset data, electronic terminal operation data, etc.) and the use of artificial intelligence technology for automated decision-making, and makes decisions that have a significant impact on personal rights based on the results of automated decision-making, provides users with corresponding operation entry points for users to choose to agree to or reject the results of automated decision-making; if the user chooses to reject, the process will proceed to the expert decision-making process.
[0034] It should be noted that the method, apparatus, device, medium and product for processing server weak password alarms provided in this application can be used in the fields of financial technology and information security, and can also be used in any field other than financial technology and information security. The application fields of the method, apparatus, medium and product for processing server weak password alarms in this application are not limited.
[0035] With the development of digitalization, cyberattacks are becoming increasingly frequent, with brute-force attacks and credential stuffing attacks exploiting weak passwords becoming the main intrusion methods. Factors such as users' habit of setting easy-to-remember passwords, lack of security awareness leading to failure to modify system default configurations, and failure to configure server password policies all exacerbate the security risks associated with weak passwords.
[0036] In an enterprise's intranet environment, numerous servers handle various critical business processes. Weak passwords are a common security vulnerability, easily exploited by attackers, leading to serious consequences such as server intrusion and data breaches. Weak password detection for intranet servers primarily relies on two techniques: passive traffic monitoring and active host scanning. Traffic monitoring identifies weak passwords by analyzing authentication behavior within network traffic, but it can only detect weak password alerts from a single server and lacks the ability to perform correlation analysis at the application cluster level. This makes it impossible to determine whether other servers belonging to the same application are using the same weak password, resulting in incomplete risk mitigation.
[0037] While traditional host scanning technologies can cover multiple servers, they only perform independent detection and handling for a single server, failing to consider situations where multiple servers within the same application cluster on an enterprise intranet share the same weak passwords. They also lack the ability to perform correlation analysis from a business system perspective. Furthermore, they cannot automatically verify whether other servers of the same application exhibit the same weak password pattern. They lack a complete chain from weak password detection to risk management. Moreover, the technical means for weak password detection struggle to achieve unified screening and handling of weak passwords across servers within the same application cluster, resulting in low accuracy in risk assessment.
[0038] Therefore, current methods for detecting weak passwords cannot guarantee server security.
[0039] To address the technical issue of low server security, this application provides a method, apparatus, medium, and product for handling weak password alarms on servers. The method involves acquiring weak password alarm information, determining the asset information of servers with weak passwords and the application cluster information corresponding to those servers based on the alarm information, generating a server list, verifying weak passwords based on the server list and the weak password alarm information, obtaining verification results, conducting a risk assessment based on the verification results, and generating weak password remediation suggestions based on the risk assessment results. This solution expands the scope of weak password detection by acquiring a list of servers with weak password alarms for weak password verification, avoiding overlooking similar risks, improving the accuracy of risk investigation, and enhancing server security.
[0040] The technical solution of this application and how the technical solution of this application solves the above-mentioned technical problems are described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments. The embodiments of this application will now be described with reference to the accompanying drawings.
[0041] Example 1
[0042] Figure 1 A flowchart illustrating a method for handling weak password alerts on servers provided in this application. Figure 1 ,like Figure 1 As shown, the method for handling weak password alarms on servers provided in this application includes:
[0043] S101, obtain weak password alarm information, call the asset management system interface to determine the asset information of the server with weak password and the application cluster information corresponding to the server based on the weak password alarm information.
[0044] A weak password is a password with extremely low security that is easily cracked. Typical characteristics of a weak password include: being too short, using simple character combinations, being related to user information, and using repetitive or patterned combinations. Among these, being too short means the password is less than six digits long; simple character combinations include pure numbers like 888888, pure letters like abcdef, and numbers + letters arranged in sequence like 123abc; being related to user information includes usernames, birthdays, and mobile phone numbers like 12345678; and using repetitive or patterned combinations includes consecutive characters like 123456 and repeated characters like aaaaaaa.
[0045] The asset information of a server with weak passwords includes Internet Protocol address (IP), application, application owner, and system type; the application cluster information corresponding to the server refers to the category of the application cluster, such as application A: data transaction cluster, application B: financial service cluster, and application C: transaction query cluster.
[0046] S102, construct a mapping relationship between the application cluster information corresponding to the server and the asset information of the server, and generate a server list; perform weak password verification based on the server list and weak password alarm information, and obtain the verification result; wherein, the server list includes the server and the server address.
[0047] If a server belongs to multiple clusters, a mapping relationship is established across application clusters. For example, if IP1 belongs to both application A and application B, a mapping relationship is established: IP1: Application A: Application A manager, Application B: Application B manager, System type. This ensures that extended detection covers all associated scenarios.
[0048] A list of server IPs within the same cluster is generated based on the constructed mapping relationships; for example, application A: IP1, IP2, ..., IPn. Weak password verification is performed based on the server list and weak password alerts, obtaining the verification results and overcoming the limitation of verifying only a single server. Furthermore, if a server belongs to multiple systems, a list of servers belonging to the same system is also generated.
[0049] S103, conduct a risk assessment based on the verification results to obtain the risk assessment results; generate weak password handling suggestions based on the risk assessment results.
[0050] Based on the verification results, a risk assessment is conducted to evaluate the account passwords corresponding to weak password alerts. Based on the risk assessment results, action recommendations are generated. The account passwords are then modified according to the generated recommendations to improve server security.
[0051] In practical applications, the system acquires weak password alerts, calls the asset management system interface to determine the asset information of servers with weak passwords and the corresponding application cluster information based on these alerts, constructs a mapping relationship between the application cluster information and the server's asset information, and generates a server list. Weak passwords are then verified using the server list and the weak password alerts, yielding verification results. A risk assessment is performed based on the verification results, resulting in a risk assessment result. Finally, weak password remediation recommendations are generated based on the risk assessment results. This solution expands the scope of weak password detection by acquiring a list of servers with weak password alerts for verification, avoiding overlooking similar risks, improving the accuracy of risk assessment, and enhancing server security.
[0052] In one possible implementation, before obtaining the weak password alarm information, the method further includes:
[0053] The system calls the interface of the traffic monitoring system to extract weak password alarm information and stores it as a traffic alarm record; it also calls the interface of the host scanning system to extract weak password alarm information and stores it as a host alarm record. The weak password alarm information includes the weak password type, weak password password, weak password account, and address.
[0054] Traffic alerts monitor abnormal fluctuations in network traffic, bandwidth usage, or data transmission characteristics to identify risks that may affect business continuity, security, or performance, triggering an early warning mechanism. In practical applications, the system periodically calls the Application Programming Interface (API) provided by the traffic monitoring system to extract key information from weak password alert traffic. This information is stored in a database as traffic alert records. Weak password alert information for traffic alerters includes: the specific resource address (Uniform Resource Locator, target URL), the target IP address, and the target port. Key information for weak password alert traffic is stored in formats such as: sequence number, target IP address, target port, target URL, weak password type, weak password account, and weak password. Weak password types include weak passwords for File Transfer Protocol (FTP), in-memory database login, Secure Shell (SSH) remote login, and website login, among others.
[0055] Host alarms monitor the server's hardware status, system resources, and process operation. Alarms are triggered when metrics exceed normal ranges to prevent service interruptions due to host failures. In practical applications, the API interface provided by the host scanning system is periodically invoked to extract weak password alarm information. This information is stored in the database as host alarm records. Key information for weak password alarm traffic is stored in the following formats: sequence number, server IP, weak password type, weak password account, and weak password. Weak password types include FTP weak passwords, SSH weak passwords, database weak passwords, etc.
[0056] By detecting and classifying weak password alerts through traffic monitoring and host scanning, the system can process both types of weak password alert information.
[0057] In one possible implementation, the method includes: determining the source of the weak password alarm message;
[0058] If the weak password alarm information comes from traffic alarm records, then weak password verification is performed based on the server list and weak password alarm information.
[0059] If the weak password alert originates from the host alert record, then perform a server scan and verification based on the server list and the weak password alert information.
[0060] Specifically, after obtaining weak password alarm information, it is necessary to determine the source of the weak password alarm information. If it comes from traffic alarm records, password verification is performed; if it comes from host alarm sets, server scanning verification is performed. Figure 2 A schematic diagram of a weak password alarm information processing system provided in this application is shown below. Figure 2 As shown, the weak password alarm information processing system includes: an alarm information extraction module, an asset information location and matching module, a restricted mode password verification module, a scanning task configuration and distribution module, a weak password judgment and risk assessment module, and a risk handling module.
[0061] The system comprises the following modules: Alarm Information Extraction Module: Extracts weak password alarm information using traffic monitoring and host scanning tools. Asset Information Location and Matching Module: Links asset information to the asset ledger and matches asset information of servers with weak passwords based on target IPs. Restricted Mode Password Verification Module: Verifies weak password alarms originating from traffic alarm records. Scan Task Configuration and Distribution Module: Modifies scan task configurations and distributes scan tasks in batches to perform server scan verification for weak password alarms originating from host alarm records. Weak Password Judgment and Risk Assessment Module: Analyzes and judges the results of restricted mode password verification and host scan results to determine whether the same application cluster or system uses the same account or weak password, and generates a risk assessment result based on the judgment result. Risk Management Module: Generates management suggestions based on the risk assessment results.
[0062] By selecting different verification methods for weak password alerts from different sources, risks can be accurately identified, improving the accuracy of risk verification.
[0063] In one possible implementation, weak password verification is performed based on a server list and weak password alert information, including:
[0064] Determine the type of weak password based on the weak password alarm information;
[0065] If the weak password is a protocol-wide weak password, keep the weak password and weak password account unchanged and log in to the server in the server list. If the login is successful, it means that there is a server with the same weak password and weak password account in the server list.
[0066] If the weak password is used to access the server, keep the weak password and weak password account unchanged, change the address to the server address, and perform a preset number of login attempts; if the login is successful, it means that there is a server with the same weak password and weak password account in the server list.
[0067] Based on the above examples, the weak password types for traffic alerts include FTP weak passwords, SSH weak passwords, and website login weak passwords; among them, FTP weak passwords and SSH weak passwords are protocol weak passwords; website login weak passwords are access weak passwords.
[0068] Specifically, when verifying weak passwords for a protocol, keep the weak password account and weak password unchanged; sequentially attempt to log in to servers within the same application cluster to verify whether the same weak password and weak password account exist within that application cluster. For example, application cluster A is associated with servers: IP1, IP2, IP3, IP4, IP5, and IP6; among them, the IP address that received the weak password alert is IP2. Then, based on that weak password and weak password account, sequentially log in to servers IP1, IP3, IP4, IP5, and IP6; if any server logs in successfully, it indicates that a server with the same weak password and weak password account exists.
[0069] When verifying passwords for weak access, keep the weak password and weak password account unchanged, change the address to the server address, and perform a preset number of login attempts. If the login is successful, it means that a server with the same weak password and weak password account exists in the server list. The preset number of attempts can be set according to needs, for example, 3 times. For example, modify the target IP in the target URL to an IP in the associated server list, and perform 3 login attempts on the modified IP. If at least one login is successful, it means that a server with the same weak password and weak password account exists; only if all 3 login attempts fail does it mean that a server with the same weak password and weak password account does not exist. By using different password verification methods for protocol weak passwords and access weak passwords, the accuracy of verification can be improved.
[0070] In one possible implementation, server scanning and verification are performed based on a server list and weak password alerts, including:
[0071] Create a scan task based on the server list and weak password alarm information, and scan the host alarm records based on the scan task; if there is an alarm with the same weak password and weak password account as the weak password alarm information, it means that there is a server with the same weak password and weak password account in the server list.
[0072] Based on the above example, the verification of weak password alarms originating from host alarm records involves creating a scan task based on the server list and the weak password alarm information. The scan task checks if any weak password alarms exist that match the weak password and weak password account corresponding to the weak password alarm information. If so, it indicates that a server with the same weak password and weak password account exists in the server list. For example, the server list associated with application cluster A is: IP1, IP2, IP3, IP4, IP5, IP6. A scan task is created: IP1 - weak password alarm information, IP2 - weak password alarm information, IP3 - weak password alarm information, IP4 - weak password alarm information, IP5 - weak password alarm information, IP6 - weak password alarm information. The scan task scans the host alarm records. If, for example, a weak password alarm exists that matches the weak password account and weak password of the IP1 - weak password alarm information, then a server with the same weak password and weak password account exists within the same application cluster. The accuracy of verification is improved by associating verification with the application cluster.
[0073] In one possible implementation, a risk assessment is performed based on the verification results to obtain the risk assessment results, including:
[0074] The verification results are used to conduct a risk assessment based on preset assessment types to obtain the risk assessment results; among which, the preset assessment types include password reuse rate, application cluster level, password complexity, and weak password type.
[0075] The password reuse rate represents the number of times the same weak password appears during verification. For example, if there are 20 servers and 5 servers use the same weak password, the password reuse rate is 5 ÷ 20 = 0.25. A password reuse rate greater than the preset value of 0.55 indicates a high password reuse rate. Application cluster levels include High Level 3: Core Systems, Medium Level 2: Important Business Systems, and Low Level 1: Ordinary Applications. Password complexity includes High Risk 3: Pure letters / numbers and <8 characters, Higher Risk 2: Simple letter + number combination and <8 characters, Medium Risk 1: Uppercase and lowercase letters + numbers and <8 characters. Weak password types include: FTP weak passwords, SSH weak passwords, database weak passwords, and website login weak passwords. The verification result indicates successful login. The verification result is then used for risk assessment based on preset assessment types to obtain the risk assessment result.
[0076] By conducting risk assessments across multiple dimensions, we can reduce biased judgments caused by single-dimensional assessments, improve the accuracy of risk assessments, and avoid misjudging risk levels. This approach overcomes the limitations of traditional assessments that rely solely on password complexity or weak password identification, making risk assessments more scientific and visual.
[0077] Figure 3A flowchart illustrating a method for handling weak password alerts on servers provided in this application. Figure 2 ,like Figure 3 As shown, the process involves: extracting weak password alarm information and determining its source; using the asset management system interface to identify the asset information of servers with weak passwords and the corresponding application cluster information from the asset management system or asset ledger; constructing a mapping relationship between the application cluster information and the server's asset information to generate a server list; selecting different verification methods for weak password alarm information from different sources; verifying weak passwords based on the server list and the weak password alarm information; obtaining verification results; conducting a risk assessment based on the verification results according to four dimensions: password reuse rate, application cluster level, password complexity, and weak password type; and generating differentiated handling suggestions based on the risk assessment results.
[0078] In one possible implementation, the weak password handling recommendations include multiple differentiated weak password handling recommendations, generated based on risk assessment results, including:
[0079] For any assessment type in the risk assessment results, generate differentiated weak password handling suggestions based on the risk assessment results corresponding to the assessment type;
[0080] Based on multiple differentiated weak password handling suggestions, a weak password handling recommendation is determined.
[0081] Based on the above examples and the obtained risk assessment results, differentiated treatment recommendations are generated.
[0082] Specifically, the recommended handling for different application cluster levels is as follows: For core system applications at level 3 (high level), passwords must be changed to a length of ≥12 characters, including uppercase and lowercase letters, numbers, and special characters, and must be changed within 90 days. For important business systems at level 2 (medium level), weak passwords must be changed to uppercase and lowercase letters + numbers + special characters and be ≥8 characters long, and must be changed within 90 days. For ordinary applications at level 1 (low level), it is recommended that weak passwords be changed to letters + numbers + ≥8 characters long, and must be changed within 180 days.
[0083] Recommendations for handling different types of weak passwords are as follows: For weak database passwords, delete anonymous accounts, conduct a full audit of the user table, change the database password, and restart the service. For weak SSH and FTP passwords, check the configuration files and disable anonymous login. For weak website login passwords, adjust password strength, etc.
[0084] For applications with a password reuse rate greater than 0.55, a full cluster password reset is required, and hard-coded passwords in automated deployment scripts must be investigated. For applications with a password reuse rate less than 0.55, weak passwords must be changed. Weak passwords should be changed according to different situations for passwords of varying complexity; for example, if the weak password is high-risk (e.g., 88888), change it to Xy240169785#; if the weak password is low-risk (e.g., Xy2563), change it to Xy240Vwt8593&.
[0085] By generating differentiated handling recommendations based on risk assessment results, passwords can be modified in a targeted manner to improve server security.
[0086] Example 2
[0087] Figure 4 A schematic diagram of a server weak password alarm processing device provided in this application is shown below. Figure 4 As shown, the server weak password alarm processing device 400 provided in this application includes:
[0088] The acquisition module 401 is used to acquire weak password alarm information, call the asset management system interface to determine the asset information of the server with weak password and the application cluster information corresponding to the server based on the weak password alarm information.
[0089] The verification module 402 is used to construct a mapping relationship between the application cluster information corresponding to the server and the asset information of the server, generate a server list; perform weak password verification based on the server list and weak password alarm information, and obtain the verification result; wherein, the server list includes the server and the server address;
[0090] Processing module 403 is used to perform risk assessment based on the verification results and obtain risk assessment results; and to generate weak password handling suggestions based on the risk assessment results.
[0091] The apparatus for handling weak password alarms on servers provided in this embodiment can execute the method provided in the above method embodiment. Its implementation principle and technical effect are similar, and will not be described in detail here.
[0092] Figure 5 This is a schematic diagram of the structure of an electronic device provided in this application. Figure 5 As shown, the electronic device 50 provided in this embodiment includes at least one processor 501 and a memory 502. Optionally, the device 50 further includes a communication component 503. The processor 501, memory 502, and communication component 503 are connected via a bus 504.
[0093] In a specific implementation, at least one processor 501 executes computer execution instructions stored in memory 502, causing at least one processor 501 to perform the above-described method.
[0094] The specific implementation process of processor 501 can be found in the above method embodiments, and its implementation principle and technical effect are similar. It will not be repeated here.
[0095] This application also provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, implement the above-described method; its implementation principle and technical effect are similar and will not be described in detail here.
[0096] This application also provides a computer program product, including a computer program that, when executed by a processor, implements the technical solution of the above method embodiments. Its implementation principle and technical effects are similar, and will not be repeated here.
[0097] It should be noted that, for the sake of simplicity, the foregoing method embodiments are all described as a series of actions. However, those skilled in the art should understand that this application is not limited to the described order of actions, as some steps may be performed in other orders or simultaneously according to this application. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are all optional embodiments, and the actions and modules involved are not necessarily essential to this application.
[0098] It should be further noted that although the steps in the flowchart are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowchart may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these sub-steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the sub-steps or stages of other steps.
[0099] It should be understood that the above-described device embodiments are merely illustrative, and the device of this application can also be implemented in other ways. For example, the division of units / modules in the above embodiments is only a logical functional division, and there may be other division methods in actual implementation. For example, multiple units, modules, or components may be combined, or integrated into another system, or some features may be ignored or not executed.
[0100] Furthermore, unless otherwise specified, the functional units / modules in the various embodiments of this application can be integrated into one unit / module, or each unit / module can exist physically separately, or two or more units / modules can be integrated together. The integrated units / modules described above can be implemented in hardware or as software program modules.
[0101] When integrated units / modules are implemented in hardware, the hardware can be digital circuits, analog circuits, etc. The physical implementation of the hardware structure includes, but is not limited to, transistors, memristors, etc. Unless otherwise specified, the processor can be any suitable hardware processor, such as a CPU, GPU, FPGA, DSP, and ASIC, etc. Unless otherwise specified, the storage unit can be any suitable magnetic or magneto-optical storage medium, such as Resistive Random Access Memory (RRAM), Dynamic Random Access Memory (DRAM), Static Random Access Memory (SRAM), Enhanced Dynamic Random Access Memory (EDRAM), High-Bandwidth Memory (HBM), Hybrid Memory Cube (HMC), etc.
[0102] If the integrated unit / module is implemented as a software program module and sold or used as an independent product, it can be stored in a computer-readable storage device (CMD). Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a memory and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this application. The aforementioned memory includes various media capable of storing program code, such as a USB flash drive, read-only memory (ROM), random access memory (RAM), portable hard drive, magnetic disk, or optical disk.
[0103] In the above embodiments, the descriptions of each embodiment have their own emphasis. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments. The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as the combination of these technical features does not contradict each other, it should be considered within the scope of this specification.
[0104] Other embodiments of this application will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of this application that follow the general principles of this application and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of this application are indicated by the following claims.
[0105] It should be understood that this application is not limited to the precise structure described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of this application is limited only by the appended claims.
Claims
1. A method for handling weak password alerts on servers, characterized in that, include: Obtain weak password alarm information, call the asset management system interface to determine the asset information of the server with weak password and the application cluster information corresponding to the server based on the weak password alarm information; A mapping relationship is constructed between the application cluster information corresponding to the server and the server's asset information to generate a server list; Weak password verification is performed based on the server list and the weak password alarm information to obtain the verification result; wherein, the server list includes servers and server addresses; A risk assessment is performed based on the verification results to obtain the risk assessment results; weak password handling suggestions are generated based on the risk assessment results.
2. The method according to claim 1, characterized in that, Before obtaining weak password alarm information, the process also includes: The system calls the interface of the traffic monitoring system to extract weak password alarm information and stores it as a traffic alarm record; it also calls the interface of the host scanning system to extract weak password alarm information and stores it as a host alarm record; wherein, the weak password alarm information includes weak password type, weak password password, weak password account, and address.
3. The method according to claim 2, characterized in that, The method further includes: Determine the source of the weak password alarm message; If the weak password alarm information originates from the traffic alarm record, then weak password verification is performed based on the server list and the weak password alarm information. If the weak password alarm originates from the host alarm record, then a server scan verification is performed based on the server list and the weak password alarm information.
4. The method according to claim 3, characterized in that, The step of verifying weak passwords based on the server list and the weak password alert information includes: The type of weak password is determined based on the weak password alarm information; If the weak password is a protocol weak password, then keep the weak password and weak password account unchanged, and log in to the server in the server list. If the login is successful, it means that there is a server with the same weak password and weak password account in the server list. If the weak password is an access weak password, then keep the weak password and weak password account unchanged, change the address to the server address, and perform a preset number of login attempts; if the login is successful, it means that there is a server with the same weak password and weak password account in the server list.
5. The method according to claim 3, characterized in that, The step of performing server scanning and verification based on the server list and the weak password alert information includes: A scanning task is created based on the server list and the weak password alarm information, and the host alarm records are scanned based on the scanning task. If there is an alarm with the same weak password and weak password account as the weak password alarm information, it means that there is a server with the same weak password and weak password account in the server list.
6. The method according to claim 1, characterized in that, The step of conducting a risk assessment based on the verification results to obtain the risk assessment results includes: The verification results are used to conduct a risk assessment based on preset assessment types to obtain risk assessment results; wherein, the preset assessment types include password reuse rate, application cluster level, password complexity, and weak password type.
7. The method according to claim 6, characterized in that, The weak password handling recommendations include multiple differentiated weak password handling recommendations. The generation of weak password handling recommendations based on the risk assessment results includes: For any risk assessment result corresponding to any assessment type in the risk assessment results, generate differentiated weak password handling suggestions based on the risk assessment results corresponding to the assessment type; Based on the multiple differentiated weak password handling suggestions, the weak password handling suggestions are determined.
8. A device for processing server weak password alarms, characterized in that, include: The acquisition module is used to acquire weak password alarm information, call the asset management system interface to determine the asset information of the server with weak password and the application cluster information corresponding to the server based on the weak password alarm information. The verification module is used to construct a mapping relationship between the application cluster information corresponding to the server and the asset information of the server, and generate a server list; Weak password verification is performed based on the server list and the weak password alarm information to obtain the verification result; wherein, the server list includes servers and server addresses; The processing module is used to perform a risk assessment based on the verification results and obtain a risk assessment result; and to generate weak password handling suggestions based on the risk assessment result.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the method as described in any one of claims 1 to 7.
10. A computer program product, characterized in that, Includes a computer program that, when executed by a processor, implements the method of any one of claims 1 to 7.