Safety protection system, method and apparatus, device, storage medium and program product
By detecting the host's login behavior information in the server and creating an automatic encryption plan, the problem of poor protection during brute-force attacks in the existing technology is solved, and more efficient host security protection is achieved.
Patent Information
- Application Number
- PCT/CN2024/115293
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-21
- Filing Date
- 2024-08-28
- Publication Date
- 2025-06-26
AI Technical Summary
Existing security products have poor protection by blocking the source IP address when facing brute force attacks, especially when attackers use proxy IP.
By obtaining the host's login behavior information in the server, detecting whether there is a password cracking behavior, and when the cracking behavior is detected, an automatic encryption plan is created through the bastion machine, and the host's password is periodically modified.
It effectively reduces the probability of password being cracked, improves the security of the host, and improves the overall resource management performance of the system through the server's risk identification function and the bastion machine's control function.
Smart Images

Figure CN2024115293_26062025_PF_FP_ABST
Abstract
Description
Security protection system, method, device, equipment, storage medium and program product
[0001] This disclosure claims priority to the Chinese patent application filed with the China Patent Office on December 21, 2023, with application number 202311782118X and application name “Security protection system, method, device, equipment, storage medium and program product”, the entire contents of which are incorporated by reference in this disclosure. Technical Field
[0002] The present disclosure relates to the field of computer technology, and in particular to a security protection system, method, apparatus, device, storage medium, and program product. Background Art
[0003] Passwords are one of the most commonly used authentication methods for hosts. Preventing passwords from being cracked by malicious attackers using brute force is a key area of focus in the security product field.
[0004] Existing security products protect against brute force attacks by limiting the number of attempts and blocking the source IP (Internet Protocol) address if too many attempts are made. However, when attackers use proxy IP addresses to attack hosts, the attack source can change frequently, making blocking the source IP address ineffective.
[0005] Therefore, there is an urgent need for a method to provide security protection for the host, improve the protection effect against brute force cracking, and improve the security of the host.
[0006] Summary of the Invention
[0007] The present disclosure provides a security protection system, method, apparatus, device, storage medium and program product for improving the security of a host.
[0008] In a first aspect, an embodiment of the present disclosure provides a security protection system, including: a host, a server, and a bastion host.
[0009] The server is used to obtain login behavior information of the host, wherein the login behavior information is used to indicate the behavior of logging into the host using a password; based on the login behavior information of the host, detect whether there is a password cracking behavior against the host; if the password cracking behavior is detected, create an automatic password change plan for the host through the bastion host; wherein the automatic password change plan is used to change the password of the host;
[0010] The bastion host is used to modify the password of the host according to the automatic password change plan.
[0011] Optionally, the host is deployed with a client, and the client is used to collect network logs of the host and report them to the server, wherein the network logs include the login behavior information;
[0012] The server is deployed with the service end, and the service end is used to detect whether there is any password cracking behavior targeting the host based on the network log collected by the client of the host.
[0013] Optionally, the host and the server communicate with each other via a network device;
[0014] The network side device is used to collect the login behavior information of the host and send it to the server;
[0015] The server is specifically configured to detect whether there is any password cracking behavior targeting the host according to the login behavior information sent by the network side device.
[0016] Optionally, when the server detects whether there is any password cracking behavior against the host based on the login behavior information of the host, it is specifically configured to:
[0017] If, based on the login behavior information, it is detected that the host login behavior occurs for a preset number of consecutive times within a preset time period and all logins fail, it is confirmed that there is a password cracking behavior against the host.
[0018] Optionally, the automatic password change plan is specifically used to periodically change the password of the host. When the server creates the automatic password change plan for the host through the bastion host, it is specifically used to:
[0019] Determine whether the password has been cracked based on the login behavior information; determine the password change cycle of the automatic password change plan and / or the security level of the modified password based on whether the password has been cracked; or
[0020] Determine whether an automatic password change plan for the host already exists; if not, create an automatic password change plan for the host through the bastion host; if so, modify the password change period and / or the security level of the modified password in the automatic password change plan.
[0021] Optionally, the automatic password change plan is specifically used to periodically change the password of the host, and the server is further used to:
[0022] After creating an automatic password change plan, if no password cracking behavior is detected within a preset period of time, the automatic password change plan is deleted through the bastion host.
[0023] In a second aspect, an embodiment of the present disclosure provides a security protection method applied to a server, the method comprising:
[0024] Obtaining login behavior information of the host; wherein the login behavior information is used to indicate the behavior of logging into the host using a password;
[0025] Detecting whether there is any password cracking behavior targeting the host based on the login behavior information of the host;
[0026] If a password cracking attempt against the host is detected, an automatic password change plan for the host is created through the bastion host, so that the bastion host changes the password of the host according to the automatic password change plan;
[0027] The automatic password change plan is used to change the password of the host.
[0028] Optionally, the host is deployed with a client, and the server is deployed with a server; obtaining the login behavior information of the host includes:
[0029] The network log of the host collected by the client is obtained through the server, and the network log includes the login behavior information.
[0030] Optionally, the host and the server communicate with each other via a network device; obtaining the login behavior information of the host includes:
[0031] Obtain the host login behavior information collected by the network side device.
[0032] Optionally, detecting whether there is any password cracking behavior targeting the host based on the login behavior information of the host includes:
[0033] If, based on the login behavior information, it is detected that the host login behavior occurs for a preset number of consecutive times within a preset time period and all logins fail, it is confirmed that there is a password cracking behavior against the host.
[0034] Optionally, the automatic password change plan is specifically used to periodically change the password of the host. Creating the automatic password change plan for the host through the bastion host includes:
[0035] Determine whether the password has been cracked based on the login behavior information; determine the password change cycle of the automatic password change plan and / or the security level of the modified password based on whether the password has been cracked; or
[0036] Determine whether an automatic password change plan for the host already exists; if not, create an automatic password change plan for the host through the bastion host; if so, modify the password change period and / or the security level of the modified password in the automatic password change plan.
[0037] Optionally, the automatic password change plan is specifically used to periodically change the password of the host, and the method further includes:
[0038] After creating an automatic password change plan, if no password cracking behavior is detected within a preset period of time, the automatic password change plan is deleted through the bastion host.
[0039] In a third aspect, an embodiment of the present disclosure provides a safety protection device, comprising:
[0040] An acquisition module is used to acquire the login behavior information of the host; wherein the login behavior information is used to indicate the behavior of logging into the host using a password;
[0041] A detection module, configured to detect whether there is any password cracking behavior targeting the host based on the login behavior information of the host;
[0042] A creation module is used to create an automatic password change plan for the host through the bastion host when a password cracking behavior against the host is detected, so that the bastion host changes the password of the host according to the automatic password change plan;
[0043] The automatic password change plan is used to change the password of the host.
[0044] In a fourth aspect, an embodiment of the present disclosure provides an electronic device, including:
[0045] at least one processor; and
[0046] a memory communicatively coupled to the at least one processor;
[0047] The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor to enable the electronic device to execute the method described in the second aspect.
[0048] In a fifth aspect, an embodiment of the present disclosure provides a computer-readable storage medium, wherein the computer-readable storage medium stores computer-executable instructions. When a processor executes the computer-executable instructions, the method described in the second aspect is implemented.
[0049] In a sixth aspect, an embodiment of the present disclosure provides a computer program product, including a computer program, which implements the method described in the second aspect when executed by a processor.
[0050] The security protection system, method, apparatus, device, storage medium and program product provided by the embodiments of the present disclosure include: a host, a server and a bastion host, wherein the server is used to obtain the login behavior information of the host, wherein the login behavior information is used to indicate the behavior of logging into the host through a password; based on the login behavior information of the host, detecting whether there is a password cracking behavior against the host; if the password cracking behavior is detected, creating an automatic password change plan for the host through the bastion host; wherein the automatic password change plan is used to modify the password of the host; the bastion host is used to modify the password of the host according to the automatic password change plan. The embodiments of the present disclosure can detect the password cracking behavior against the host in a timely manner and call the bastion host to automatically change the password, effectively reducing the probability of the password being cracked and improving the security of the host. In addition, the embodiments of the present disclosure achieve security protection for the host through the risk identification function of the server and the management and control function of the bastion host, and also improve the server's security protection capabilities for the host and the bastion host's management and control capabilities for the host, thereby improving the overall resource management performance of the system, providing users with a higher level of protection capabilities, and improving the user's asset security. BRIEF DESCRIPTION OF THE DRAWINGS
[0051] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present disclosure and, together with the description, serve to explain the principles of the present disclosure.
[0052] FIG1 is a schematic diagram of an application scenario provided by an embodiment of the present disclosure;
[0053] FIG2 is a schematic diagram of a safety protection system provided by an embodiment of the present disclosure;
[0054] FIG3 is a schematic diagram of another safety protection system provided by an embodiment of the present disclosure;
[0055] FIG4 is a schematic diagram of a client interaction interface provided by an embodiment of the present disclosure;
[0056] FIG5 is a schematic diagram of a flow chart of a security protection method provided by an embodiment of the present disclosure;
[0057] FIG6 is a schematic structural diagram of a safety protection device provided in an embodiment of the present disclosure;
[0058] FIG7 is a schematic structural diagram of an electronic device provided by an embodiment of the present disclosure.
[0059] The above drawings illustrate specific embodiments of the present disclosure, which will be described in more detail below. These drawings and textual descriptions are not intended to limit the scope of the present disclosure in any way, but rather to illustrate the concepts of the present disclosure to those skilled in the art by reference to specific embodiments. DETAILED DESCRIPTION
[0060] Exemplary embodiments will be described in detail herein, with examples illustrated in the accompanying drawings. In the following description, when referring to the drawings, identical numerals in different figures represent identical or similar elements, unless otherwise indicated. The embodiments described in the following exemplary embodiments are not intended to represent all possible embodiments consistent with the present disclosure. Rather, they are merely examples of apparatus and methods consistent with certain aspects of the present disclosure, as detailed in the appended claims.
[0061] It should be noted that the user information (including but not limited to user device information, user attribute information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this disclosure are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with relevant laws, regulations and standards, and corresponding operation entrances must be provided for users to choose to authorize or refuse.
[0062] First, the terms involved in this disclosure are explained:
[0063] Brute force cracking: Brute force cracking is an attack method that attempts to obtain a password or key by trying a large number of possible combinations, guessing the password one by one until the correct password is found. Hackers generally use brute force cracking methods such as exhaustive attacks, dictionary attacks, and rainbow table attacks.
[0064] Automatic and regular password changes: Automatically and periodically change and back up host account passwords to reduce or eliminate weak passwords and comply with level protection requirements.
[0065] Bastion host: An operation and maintenance and security audit management platform that can collect and monitor the status of each host in the cluster in real time to facilitate centralized alarming, timely processing, and audit accountability. In the disclosed embodiment, the encryption service provided by the bastion host can be used to improve host security.
[0066] The present disclosure can be applied to any scenario where the host protection effect needs to be improved. For example, it can be applied to protecting a single host or to protecting hosts in a cluster.
[0067] Figure 1 is a schematic diagram of an application scenario provided by an embodiment of the present disclosure. As shown in Figure 1, a cluster can be deployed in a user's local computer room. The cluster includes multiple hosts, which are used to process tasks for the user's industry. A bastion host and servers can be deployed in the cloud. The servers can communicate with the hosts and control their security, while the bastion host can be used to manage and audit host tasks.
[0068] Specifically, the server can be deployed with host security services, which can provide basic security protection capabilities for the host, such as risk identification, vulnerability protection, sensitive data protection, cloud firewall, etc.
[0069] A bastion host acts as an intermediary for users to control hosts. After logging in, users can manage host assets through the bastion host, for example, by adding or removing hosts and setting access permissions for them. Different users can have varying access rights to host resources. The bastion host also allows for auditing and analysis of operations performed on hosts, building a comprehensive resource control system for users, reducing maintenance workload and improving resource management effectiveness.
[0070] In actual applications, attackers will launch attacks on the host through brute force cracking. If the host password is cracked, it will cause immeasurable losses to the user.
[0071] In order to effectively protect the user's host resource security, the embodiment of the present disclosure provides a security protection system that can monitor the host's login behavior through the server, and detect whether there is brute force cracking behavior based on the login behavior. If so, an automatic password change plan is created for the host through the bastion host, wherein the automatic password change plan can be used for automatic periodic password change, that is, the password is modified at preset intervals.
[0072] The security protection system provided by the embodiment of the present disclosure can timely and accurately detect password cracking behavior against the host, and call the bastion host to automatically and regularly change the password, effectively reducing the probability of attackers cracking the password and improving the security of the host. In addition, the embodiment of the present disclosure realizes security protection of the host through the risk identification function of the server and the management and control function of the bastion host, and also improves the security protection capability of the server for the host and the management and control capability of the bastion host for the host, thereby improving the overall resource management performance of the system, providing users with a higher level of protection capability, and improving the security of users' assets.
[0073] Some embodiments of the present disclosure are described in detail below with reference to the accompanying drawings. The following embodiments and features thereof may be combined with one another unless they conflict with each other. Furthermore, the sequence of steps in the following method embodiments is provided for illustrative purposes only and is not intended to be a strict limitation.
[0074] Figure 2 is a schematic diagram of a security protection system provided by an embodiment of the present disclosure. As shown in Figure 2, the system may include: a host, a server and a bastion host; the server is used to obtain the login behavior information of the host, wherein the login behavior information is used to indicate the behavior of logging into the host through a password; based on the login behavior information of the host, it is detected whether there is a password cracking behavior against the host; if the password cracking behavior is detected, an automatic password change plan for the host is created through the bastion host; wherein the automatic password change plan is used to modify the password of the host.
[0075] The host can be any host in the cluster or a standalone host. Users can log in to the host using a password. Without the password, attackers may be able to log in to the host through brute force.
[0076] The server is used to obtain the login behavior information of the host. The login information can be used to indicate the behavior of a user or an attacker logging into the host using a password. This embodiment does not limit the way in which the server obtains the login behavior of the host. The server can obtain the login behavior information of the host at preset time intervals, or the host can send the login behavior information to the server at preset time intervals.
[0077] After the server obtains the host's login behavior information, it can detect whether an attacker is attempting to crack the host's password based on the host's login behavior information. If password cracking is detected, an automatic password change plan for the host is created through the bastion host. The automatic password change plan is used to change the host's password.
[0078] Optionally, the automatic password change plan can be used to change the host password once or multiple times. For example, the automatic password change plan can be used to periodically change the host password, that is, change the password once every preset period to further improve the host security.
[0079] After the password is changed, the changed password can be sent to the user so that the user can log in to the host using the changed password. Optionally, the user can also be allowed to configure one or more devices for accessing the host. After the password is changed, the changed password can also be synchronized to the devices allowed to access the host.
[0080] Optionally, the bastion host can provide an API (Application Programming Interface) for creating an automatic encryption plan. When the server creates an automatic encryption plan for the host through the bastion host, it can be used to create an automatic encryption plan for the host by calling the bastion host's API.
[0081] Specifically, the bastion host can modify the host's password according to the automatic password change plan created by the server, such as changing the host's password once a day or every other week, to improve the host's password protection level.
[0082] Optionally, if an automatic password change plan is used to periodically change host passwords, once created, the plan can be executed continuously or stopped after a period of time. For example, after creating an automatic password change plan, if no password cracking activity is detected within a preset period, confirming that password cracking activity has ceased, the automatic password change plan can be deleted from the bastion host. Alternatively, the automatic password change plan can be synchronized with the user, who can then decide whether to terminate the automatic password change plan and the specific termination time after password cracking activity ceases.
[0083] In this way, when the server detects an attack against the host, it indicates that the host is at a high risk of exposure. By creating an automatic password change plan through the bastion host, the host password is updated regularly, reducing the chance of the password being cracked by brute force and improving security.
[0084] In an optional implementation, a host security service can be provided to the user's host. The host security service can provide real-time detection, analysis, and identification of security threats, helping users achieve automated and secure host operations. The host security service can include a client and a server, and can detect brute force attacks by collecting network logs.
[0085] Specifically, the host is deployed with a client, which is used to collect the host's network logs and report them to the server. The network logs include login behavior information; the server is deployed with a server, which is used to detect whether there is any password cracking behavior against the host based on the network logs collected by the host's client.
[0086] The client can collect the network log of the host, which contains login behavior information, which can be used to indicate the login time, whether the login is successful, etc. The client can send the network log to the server in real time or at preset intervals, which is not limited in this embodiment.
[0087] The server can receive the network logs collected by the client on the host and detect whether there is any password cracking behavior against the host based on the received network logs.
[0088] Figure 3 is a schematic diagram of another security protection system provided by an embodiment of the present disclosure. As shown in Figure 3, the system includes a host, a server, and a bastion host. The host and server can each be deployed with a client and a server. The following steps a through e illustrate the working process of this system:
[0089] Step a: The attacker cracks the host password by brute force using methods such as exhaustive attack, dictionary attack, and rainbow table attack.
[0090] Step b: The client installed on the host collects network logs.
[0091] Step c: The client reports the collected network logs to the server.
[0092] Step d: The server processes the network logs, detects password cracking behavior, and calls the bastion host API to create an automatic password change plan.
[0093] Step e: The bastion host changes the host's password using SSH (Secure Shell Protocol) or RDP (Remote Desktop Protocol) according to the automatic password change schedule. Network logs detail login activity against the host. The server uses these logs to determine whether password cracking attempts have been made against the host, improving accuracy.
[0094] In an optional implementation, when the server detects whether there is any password cracking behavior against the host based on the host's login behavior information, it can specifically be used to:
[0095] If, based on the login behavior information, it is detected that the host has been logged in for a preset number of times within a preset time period, and all logins have failed, it is confirmed that there has been a password cracking attempt against the host.
[0096] For example, the preset time is 5 minutes and the preset number of times is 10 times. Based on the acquired login behavior information, the server detects that there are 10 consecutive login attempts to the host within 5 minutes, and each login result is a failure, then it is confirmed that there is a password cracking attempt against the host.
[0097] In this way, judging whether there is a password cracking behavior based on whether there are consecutive preset number of failed host logins within a preset time can improve the accuracy of the judgment result and reduce the probability of misjudgment.
[0098] In another optional implementation, when the server detects whether there is any password cracking behavior against the host based on the host's login behavior information, it can specifically be used to:
[0099] If, based on the login behavior information, it is detected that a host login behavior occurs for a preset number of consecutive times within a preset time period, it is confirmed that there is a password cracking behavior against the host.
[0100] Specifically, if a preset number of consecutive login attempts to the host are detected within a preset time period, regardless of whether the logins are successful, it is considered an attempt to crack the host's password, further improving the host's security. Since users typically don't log in frequently in large numbers within a short period of time, this method can also ensure a certain degree of accuracy.
[0101] The specific values of the preset time and the preset number of times may be the same as or different from those in the aforementioned embodiment, and may be set by the user or adopt default values.
[0102] In addition to the method shown in FIG3 , the embodiment of the present disclosure also provides a solution that can assist in detecting password cracking behavior through network-side devices.
[0103] Optionally, the host and the server communicate via a network-side device; the network-side device is used to collect login behavior information of the host and send it to the server; the server is specifically used to detect whether there is any password cracking behavior against the host based on the login behavior information sent by the network-side device.
[0104] Specifically, the host and server communicate via a network device, such as a switch. The network device can obtain the host's five-tuple data, which includes the communication protocol, source IP address, source port, destination IP address, and destination port. The network device can use the five-tuple data to identify the host's login behavior information and send it to the server. The login behavior information can be used to indicate login time, etc.
[0105] The server can detect whether there is any password cracking behavior against the host based on the login behavior information sent by the network side device. For example, if the host login behavior occurs a preset number of times within a preset time, it is confirmed that there is a password cracking behavior against the host.
[0106] Because the login behavior information identified by the network-side device based on the quintuple data generally cannot indicate whether the login was successful, the server, based on the login behavior information sent by the network-side device, detects a preset number of consecutive login attempts to the host within a preset time period, and then confirms that a password cracking attempt has occurred against the host. Compared to the server's method of determining whether a password cracking attempt has occurred based on network logs, when detecting based on the login behavior information sent by the network-side device, the preset number of times can be set to be shorter, reducing the length of time the host is exposed to a successful brute force attack, thereby improving the host's security.
[0107] In other optional implementations, the network-side device may also send the five-tuple data as login behavior information to the server, and the server determines whether there is any password cracking behavior based on the five-tuple data.
[0108] In this way, the host's login behavior information is collected by the network side device and sent to the server, so that the server can determine whether there is password cracking behavior based on the host's login behavior information, which can effectively reduce the host's burden.
[0109] In actual applications, you can use network logs or information sent by network-side devices for detection, either or both. For example, the server can obtain network logs collected by the host client and login behavior information collected by the network-side device, and then perform detection on each of these two data points to check for password cracking attempts targeting the host. If either detection result indicates password cracking, the server can call the bastion host API to create an automatic password change plan for the host, further improving the host's security.
[0110] Optionally, the server is further configured to obtain a password change policy configured by the user, where the password change policy includes at least one of the following: a preset time, a preset number of times, and a password change cycle in an automatic password change plan.
[0111] Specifically, a user can input a password change policy through a terminal device, which can then communicate directly or indirectly with a server to send the policy. The password change policy can include a preset time, a preset number of times, and a password change cycle within an automatic password change plan. The preset time and number of times are used by the server to detect password cracking attempts based on login behavior information, while the password change cycle is the periodic interval for changing the host password.
[0112] The embodiment of the present disclosure also supports configuring different encryption strategies for different hosts, as well as modifying the encryption strategies. Figure 4 is a schematic diagram of an interactive interface provided by the embodiment of the present disclosure. As shown in Figure 4, the value corresponding to the parameter item "Current preset time" in the encryption strategy is 5 minutes, the value corresponding to the parameter item "Preset number of times" is 10 times, and the value corresponding to the parameter item "Encryption cycle" is 3 days. The user can enter the corresponding values in the input boxes corresponding to the parameter items "Preset time after modification", "Preset number of times after modification" and "Encryption cycle after modification" according to actual needs. After the input is completed, click the confirmation button, and the terminal device will send the modified encryption strategy entered by the user to the server.
[0113] In this way, users can modify the existing password change policy as needed. When the host stores important data or has just been attacked, the preset time, the preset number of times, or the password change cycle can be reduced to improve the security and flexibility of the host. Optional, the automatic password change plan is specifically used to periodically change the host's password. When the server creates an automatic password change plan for the host through the bastion host, it is specifically used to:
[0114] Determine whether the password has been cracked based on login behavior information; determine the password change cycle of the automatic password change plan and / or the security level of the password after the change based on whether the password has been cracked; or
[0115] Determine whether an automatic password change plan for the host already exists. If not, create an automatic password change plan for the host through the bastion host. If so, modify the password change cycle and / or the security level of the modified password in the automatic password change plan.
[0116] Specifically, the server can first determine whether the attacker has successfully logged in based on the obtained login behavior information, that is, whether the attacker has failed to log in all the time or finally succeeded. If the login is successful, it is considered that the password has been cracked. The password change cycle of the automatic password change plan and / or the security level of the modified password can be determined based on whether the login is successful.
[0117] For example, compared to a situation where the attacker repeatedly fails to log in, the server's automatic password change schedule created when the attacker finally succeeds has a shorter cycle, and the modified password has a higher security level. The security level of a password can be reflected by its complexity; the more complex the password, the higher the security level.
[0118] The server can also first determine whether an automatic password change plan for the host already exists. If not, an automatic password change plan can be created through the bastion host. If it already exists, the password change cycle and / or the security level of the modified password of the automatic password change plan can be modified.
[0119] For example, if the server determines that there is already an automatic password resetting plan for the host, it means that the attacker has previously cracked the password. Therefore, after detecting the password cracking behavior again, the security of the host can be further improved, such as shortening the password resetting cycle of the existing password resetting plan and improving the security level of the modified password.
[0120] In this way, the risk level of the current host can be determined based on whether the attacker has successfully logged in or whether an automatic password change plan already exists. The password change cycle and the security level of the modified password can be determined based on the risk level of the host. This can make the modified password level or password change cycle more compatible with the current situation, thereby improving the security factor.
[0121] In one or more embodiments of the present disclosure, when the server detects whether there is any password cracking behavior against the host based on the login behavior information of the host, in addition to the above method (detecting whether the host login behavior occurs a preset number of times consecutively within a preset time), other methods can also be used to implement it. For example, a trained cracking recognition model can be used for detection. The specific process is as follows:
[0122] The server inputs the host's login behavior information into the trained cracking recognition model, and the output information of the trained cracking recognition model is used to indicate whether a password cracking behavior targeting the host occurs.
[0123] Optionally, the specific training process of the cracking identification model is as follows: normal login behavior information and risky login behavior information are collected, wherein the risky login behavior information can be login behavior information collected when artificially simulating brute force cracking of the host (such as network logs), and the normal login behavior information can be login behavior information collected when the host is not attacked. Based on the normal login behavior information and the risky login behavior information, training samples can be constructed respectively, wherein when the training sample is normal login behavior information, the corresponding label is used to indicate that no password cracking behavior against the host occurs, and when the training sample is risky login behavior information, the corresponding label is used to indicate that password cracking behavior against the host occurs.
[0124] Based on the constructed training samples, a neural network model or other deep learning model can be trained to obtain a cracking recognition model.
[0125] Optionally, when constructing training samples, the risk level of password cracking behavior can be added to the label. The risk level can be determined by indicators such as the cracking method, the probability of password cracking, and the time it takes to crack the password. Optionally, an attacker can be simulated to launch a brute force crack on the host. Different cracking methods may correspond to different cracking success probabilities and password cracking time, and thus correspond to different risk levels.
[0126] After training the model using training samples, it can also output the corresponding risk level. The server can call the bastion host API to create different automatic password resetting plans based on the risk level. The higher the risk level, the shorter the resetting cycle in the automatic resetting plan, and the more complex the password after the resetting.
[0127] Optionally, in actual applications, the server can also send a host high-risk warning to the terminal device when the risk level of the cracking identification model output is greater than the preset risk value, so that the user can reconfigure the encryption policy after receiving the host high-risk warning through the terminal device to improve the security of the host or transfer important data in the host.
[0128] Optionally, in addition to obtaining the user-configured decryption policy, the server may also set a default decryption policy. The default decryption policy may include an enhanced decryption policy and a weakened decryption policy. The default decryption policy may modify the decryption period in the automatic decryption plan. An automatic decryption plan modified with an enhanced decryption policy will have a shorter decryption period; an automatic decryption plan modified with a weakened decryption policy will have a longer decryption period.
[0129] After detecting password cracking and creating an automatic password change plan, if it is subsequently detected that the host meets the preset conditions, the server can modify the automatic password change plan using the default password change policy.
[0130] In an optional implementation, which default password rewriting strategy to adopt may be determined by the situation in which the host is attacked. For example, the server may count the number of times the host is attacked within multiple preset time periods. Within each preset time period, if a preset number of login behaviors occur within the preset time period, it is considered that password cracking behaviors are detected, and detection will continue within the next preset time period. Each time a password cracking behavior is detected, the number of times the host is attacked increases once. After statistics are completed for multiple preset time periods, if the number of times the host is attacked exceeds the first preset number, the default enhanced password rewriting strategy is adopted to modify the automatic password rewriting plan. If the number of times the host is attacked is less than the second preset number, the default weakened password rewriting strategy is adopted to modify the automatic password rewriting plan.
[0131] In another optional implementation, the default rekeying policy can be determined by the host's security level and the attack scenario. The host's security level can be set by the user, based on the host's functions or the importance of the stored data. The host's security level can be categorized as Level 1, Level 2, or Level 3, with Level 1 being the weakest and Level 3 being the strongest. The user can adjust the host's security level in real time through a terminal device. After the adjustment is complete, click the Confirm button, and the terminal device will send the host's security level to the server. The server will then determine the default rekeying policy based on the host's current attack scenario and the host's security level.
[0132] Specifically, the enhanced decryption policy may include level 1 enhanced decryption policy, level 2 enhanced decryption policy, and level 3 enhanced decryption policy, among which level 1 enhanced decryption policy has the lowest security level, and level 3 enhanced decryption policy has the highest security level. The weakened decryption policy may include level 1 weakened decryption policy, level 2 weakened decryption policy, and level 3 weakened decryption policy, among which level 1 weakened decryption policy has the highest security level, and level 3 weakened decryption policy has the lowest security level. Table 1 is a mapping relationship table between the security level of the host and the default decryption policy provided in an embodiment of the present disclosure.
[0133] Table 1
[0134] The server can count the number of times the host is attacked within multiple preset time periods. If the number of times the host is attacked exceeds a first preset number, the security level of the host can be further determined. If the security level of the host is level 3, it means that the security level of the host is very high. Referring to Table 1, it can be seen that a level 3 enhanced encryption strategy is adopted. If the security level of the host is level 1, it means that the security level of the host is not high. Referring to Table 1, it can be seen that a level 1 enhanced encryption strategy is adopted. If the number of times the host is attacked is lower than a second preset number, the security level of the host is further determined. If the security level of the host is level 3, referring to Table 1, it can be seen that a level 1 weakened encryption strategy is adopted, so that the host protection level is weakened to a lower level. If the security level of the host is level 1, referring to Table 1, it can be seen that a level 3 weakened encryption strategy is adopted, so that the host protection level is weakened to a higher level.
[0135] In another optional implementation, the default encryption policy can be determined by both the industry and the host attack scenario. The default encryption policy can be divided according to the industry. For industries with higher security requirements, the default encryption policy security level is set higher, while for industries with lower security requirements, the default encryption policy security level is set lower.
[0136] In this way, the encryption strategy can be automatically determined based on the attack situation, the host's security level and the industry, and a more compatible encryption strategy can be obtained, further improving the host's security.
[0137] In one or more embodiments of the present disclosure, the security level of the host can optionally be adjusted according to the situation in which the host is attacked, and data transfer or task reallocation can be performed according to the adjusted security level to improve the overall security of the system. The specific implementation method is as follows: the server counts the number of times the host is attacked within a plurality of preset time periods, and adjusts the security level of the host according to the number of times the host is attacked. For example, if the number of times the host is attacked is greater than a preset threshold, the security level of the host is adjusted downward. After the adjustment is completed, the server sends the adjusted security level to the terminal device, so that the user can reallocate tasks and / or transfer data according to the security levels of different hosts.
[0138] For example, the security levels of a host are categorized as Level 1, Level 2, and Level 3, with Level 3 being the highest. The higher the security level of a host, the more important the data that can be stored, and the higher the level of the tasks that can be assigned. The importance of the data stored in the host and / or the level of the assigned tasks match the host's current security level. When the security level of a host decreases, data stored in the host whose importance exceeds the host's current security level can be transferred to other matching hosts, and / or tasks assigned to the host whose security level exceeds the host's current security level can be assigned to other matching hosts.
[0139] FIG5 is a flow chart of a security protection method provided by an embodiment of the present disclosure. The method in this embodiment can be applied to a server. As shown in FIG5 , the method may include:
[0140] Step 501: Acquire the login behavior information of the host; wherein the login behavior information is used to indicate the behavior of logging into the host using a password.
[0141] Specifically, the server can actively obtain the host's login behavior, or the host can send login behavior information to the server. The login behavior information can indicate the behavior of the user or attacker logging into the host using a password.
[0142] Optionally, the host is deployed with a client and the server is deployed with a server to obtain the host's login behavior information, including:
[0143] The server obtains the network logs of the host collected by the client, which include login behavior information.
[0144] Specifically, the host deploys the client of the host security service, and the server deploys the server of the host security service. The client can collect the network log of the host and send it to the server in the server. The server receives the login behavior of the host sent by the client.
[0145] Optionally, the host and server communicate via a network device to obtain the host's login behavior information, including:
[0146] Obtain the host login behavior information collected by the network side device.
[0147] Specifically, the host and the server communicate with each other through a network-side device. The network-side device can collect the login behavior information of the host and send it to the server. The server receives the login behavior information of the host sent by the network-side device.
[0148] Step 502: Detect whether there is any password cracking behavior targeting the host based on the host's login behavior information.
[0149] Optionally, based on the host's login behavior information, detect whether an attacker is attempting to crack the host's password, including:
[0150] If, based on the login behavior information, it is detected that the host has been logged in for a preset number of times within a preset time period, and all logins have failed, it is confirmed that there has been a password cracking attempt against the host.
[0151] Step 503: If a password cracking behavior against the host is detected, an automatic password change plan for the host is created through the bastion host, so that the bastion host changes the password of the host according to the automatic password change plan.
[0152] Among them, the automatic password change plan is used to change the host password.
[0153] Specifically, if the server detects a password cracking attempt against the host, it creates an automatic password change plan for the host by calling the bastion host's API. After the automatic password change plan is created, the bastion host can modify the host's password according to the automatic password change plan.
[0154] Optionally, an automatic password change plan is used to periodically change the host's password. Create an automatic password change plan for the host using the bastion host, including:
[0155] Determine whether the password has been cracked based on the login behavior information; determine the password change cycle of the automatic password change plan and / or the security level of the password after the change based on whether the password has been cracked; or
[0156] Determine whether an automatic password change plan for the host already exists. If not, create an automatic password change plan for the host through the bastion host. If so, modify the password change cycle and / or the security level of the modified password in the automatic password change plan.
[0157] Optionally, the method may further include:
[0158] After creating an automatic password change plan, if no password cracking activity is detected within the preset period, the automatic password change plan is deleted through the bastion host.
[0159] Optionally, the security protection method provided by the present disclosure may further include: obtaining a password resetting policy configured by the user, wherein the password resetting policy includes at least one of the following:
[0160] Preset time, preset number of times, and the encryption cycle in the automatic encryption plan.
[0161] Specifically, the user can input the password change policy on the host, where the password change policy may include at least one of a preset time, a preset number of times, and a password change cycle in the automatic password change plan. After the user completes the input, he clicks the confirmation button, and the host sends the password change policy input by the user to the server.
[0162] The specific implementation principles and beneficial effects of the security protection method provided by the embodiments of the present disclosure can be found in the aforementioned embodiments and will not be repeated here.
[0163] Corresponding to the above-mentioned security protection method, the embodiment of the present disclosure further provides a security protection device. FIG6 is a schematic structural diagram of a security protection device provided by the embodiment of the present disclosure. The device is applied to a server, as shown in FIG6 , and the device includes:
[0164] The acquisition module 601 is used to obtain the login behavior information of the host; wherein the login behavior information is used to indicate the behavior of logging into the host using a password;
[0165] Detection module 602, used to detect whether there is any password cracking behavior targeting the host based on the host's login behavior information;
[0166] Creation module 603, for creating an automatic password change plan for the host through the bastion host when a password cracking behavior against the host is detected, so that the bastion host changes the password of the host according to the automatic password change plan;
[0167] Among them, the automatic password change plan is used to change the host password.
[0168] Optionally, the host is deployed with a client, which is used to collect the host's network logs and report them to the server. The network logs include login behavior information.
[0169] The server is deployed with a server, which includes an acquisition module 601, a detection module 602, and a creation module 603. The detection module 602 is specifically used to detect whether there is any password cracking behavior against the host based on the network log collected by the client of the host.
[0170] Optionally, the host and the server communicate via a network-side device;
[0171] The network side device is used to collect the login behavior information of the host and send it to the acquisition module 601;
[0172] The detection module 602 is specifically configured to detect whether there is any password cracking behavior targeting the host based on the login behavior information sent by the network-side device.
[0173] Optionally, the detection module 602 is specifically configured to:
[0174] If, based on the login behavior information, it is detected that the host has been logged in for a preset number of times within a preset time period, and all logins have failed, it is confirmed that there has been a password cracking attempt against the host.
[0175] Optionally, the automatic password change plan is specifically used to periodically change the password of the host. When creating the automatic password change plan for the host through the bastion host, the creation module 603 is specifically used to:
[0176] Determine whether the password has been cracked based on the login behavior information; determine the password change cycle of the automatic password change plan and / or the security level of the password after the change based on whether the password has been cracked; or
[0177] Determine whether an automatic password change plan for the host already exists. If not, create an automatic password change plan for the host through the bastion host. If so, modify the password change cycle and / or the security level of the modified password in the automatic password change plan.
[0178] Optionally, the creation module 603 is further configured to:
[0179] After creating an automatic password change plan, if no password cracking activity is detected within the preset period, the automatic password change plan is deleted through the bastion host.
[0180] Optionally, the creation module 603 is further configured to:
[0181] Get the user-configured password change policy, which includes at least one of the following:
[0182] Preset time, preset number of times, and the encryption cycle in the automatic encryption plan.
[0183] The various devices provided in the embodiments of the present disclosure are used to execute the corresponding method embodiments described above. The specific implementation principles and beneficial effects can be found in the aforementioned embodiments and will not be repeated here.
[0184] FIG7 is a schematic diagram of the structure of an electronic device provided by an embodiment of the present disclosure. As shown in FIG7 , the electronic device of this embodiment may include:
[0185] at least one processor 701; and
[0186] a memory 702 in communication with at least one processor;
[0187] The memory 702 stores instructions that can be executed by at least one processor 701 , and the instructions are executed by at least one processor 701 to enable the electronic device to perform a method as described in any of the above embodiments.
[0188] Optionally, the memory 702 may be independent or integrated with the processor 701 .
[0189] The implementation principle and technical effects of the electronic device provided in this embodiment can be found in the aforementioned embodiments and will not be described in detail here.
[0190] An embodiment of the present disclosure further provides a computer-readable storage medium, in which computer-executable instructions are stored. When a processor executes the computer-executable instructions, the method of any of the aforementioned embodiments is implemented.
[0191] An embodiment of the present disclosure further provides a computer program product, including a computer program, which implements the method of any of the aforementioned embodiments when executed by a processor.
[0192] In the several embodiments provided in this disclosure, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the module division is only a logical function division. In actual implementation, other division methods may be used. For example, multiple modules can be combined or integrated into another system, or some features can be ignored or not implemented.
[0193] The integrated modules implemented in the form of software function modules can be stored in a computer-readable storage medium. The software function modules stored in a storage medium include several instructions for causing a computer device (which can be a personal computer, server, or network device, etc.) or a processor to perform some of the steps of the methods of various embodiments of the present disclosure.
[0194] It should be understood that the above-mentioned processor can be a processing unit (Central Processing Unit, CPU), or other general-purpose processors, digital signal processors (Digital Signal Processor, DSP), application-specific integrated circuits (Application Specific Integrated Circuit, ASIC), etc. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor, etc. The steps of the method disclosed in the application can be directly embodied as being executed by a hardware processor, or can be executed by a combination of hardware and software modules in the processor. The memory may include high-speed random access memory (Random Access Memory, RAM), and may also include non-volatile memory (NVM), such as at least one disk storage, and can also be a USB flash drive, a mobile hard disk, a read-only memory, a magnetic disk or an optical disk, etc.
[0195] The storage medium can be implemented by any type of volatile or non-volatile memory device, or a combination thereof, such as static random-access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk. The storage medium can be any available medium that can be accessed by a general-purpose or special-purpose computer.
[0196] An exemplary storage medium is coupled to a processor so that the processor can read information from the storage medium and write information to the storage medium. Of course, the storage medium can also be an integral part of the processor. The processor and the storage medium can be located in an application specific integrated circuit (ASIC). Of course, the processor and the storage medium can also exist as discrete components in an electronic device or a main control device.
[0197] It should be noted that, in this document, the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, article, or apparatus comprising a series of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, method, article, or apparatus. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of other identical elements in the process, method, article, or apparatus comprising the element.
[0198] The serial numbers of the above-mentioned embodiments of the present disclosure are for description only and do not represent the advantages or disadvantages of the embodiments.
[0199] Through the description of the above implementation methods, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be implemented by means of software plus the necessary general hardware platform, and of course can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present disclosure, or the part that contributes to the prior art, can be embodied in the form of a software product, which is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), and includes a number of instructions for enabling a terminal device (which can be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods of the various embodiments of the present disclosure.
[0200] The above are only preferred embodiments of the present disclosure and are not intended to limit the patent scope of the present disclosure. Any equivalent structure or equivalent process transformation made using the contents of the present disclosure and the drawings, or directly or indirectly applied in other related technical fields, are also included in the patent protection scope of the present disclosure.
Claims
1. A safety protection system, wherein: include: Host, server and bastion host, The server is used to obtain the login behavior information of the host, wherein the login behavior information is used to indicate the behavior of logging into the host through a password; based on the login behavior information of the host, detect whether there is a password cracking behavior against the host; if the password cracking behavior is detected, create an automatic password change plan for the host through the bastion host; wherein the automatic password change plan is used to modify the password of the host; The bastion host is used to modify the password of the host according to the automatic password change plan.
2. The system according to claim 1, wherein: The host is deployed with a client, the client is used to collect the network log of the host and report it to the server, the network log includes the login behavior information; The server is deployed with the service end, and the service end is used to detect whether there is any password cracking behavior against the host according to the network log collected by the client of the host.
3. The system according to claim 1, wherein: The host and the server communicate with each other through a network device; The network side device is used to collect the login behavior information of the host and send it to the server; The server is specifically used to detect whether there is any password cracking behavior against the host according to the login behavior information sent by the network side device.
4. The system according to any one of claims 1 to 3, wherein: When the server detects whether there is any password cracking behavior against the host according to the login behavior information of the host, it is specifically used to: If, according to the login behavior information, it is detected that the host login behavior occurs for a preset number of consecutive times within a preset time and all logins fail, it is confirmed that there is a password cracking behavior for the host.
5. The system according to any one of claims 1 to 3, wherein: The automatic password modification plan is specifically used to periodically modify the password of the host; when the server creates the automatic password modification plan of the host through the bastion host, it is specifically used to: Determine whether the password has been cracked according to the login behavior information; determine the password change cycle of the automatic password change plan and / or the security level of the modified password according to whether the password has been cracked; or, Determine whether there is an automatic password change plan for the host; if not, create an automatic password change plan for the host through the bastion host; if so, modify the password change period and / or the security level of the modified password of the automatic password change plan.
6. The system according to any one of claims 1 to 5, wherein: The automatic password modification plan is specifically used to periodically modify the password of the host; the server is also used to: After the automatic password change plan is created, if no password cracking behavior is detected within a preset period of time, the automatic password change plan is deleted through the bastion host.
7. A security protection method, wherein: Applied to a server, the method comprises: Obtaining login behavior information of the host; wherein the login behavior information is used to indicate the behavior of logging into the host through a password; According to the login behavior information of the host, detecting whether there is any password cracking behavior against the host; If a password cracking behavior against the host is detected, an automatic password change plan for the host is created through the bastion host, so that the bastion host modifies the password of the host according to the automatic password change plan; The automatic password change plan is used to change the password of the host.
8. The method according to claim 7, wherein: The host is deployed with a client, and the server is deployed with a server; obtaining the login behavior information of the host includes: The network log of the host collected by the client is obtained through the server, and the network log includes the login behavior information.
9. The method according to claim 7, wherein: The host and the server communicate with each other through network side equipment; Get the host's login behavior information, including: Obtain the host login behavior information collected by the network side device.
10. The method according to any one of claims 7 to 9, wherein: Detecting whether there is any password cracking behavior against the host according to the login behavior information of the host, including: If, according to the login behavior information, it is detected that the host login behavior occurs for a preset number of consecutive times within a preset time and all logins fail, it is confirmed that there is a password cracking behavior for the host.
11. The method according to any one of claims 7 to 9, wherein: The automatic password change plan is specifically used to periodically change the password of the host. The automatic password change plan of the host is created by the bastion host, including: Determine whether the password is cracked according to the login behavior information; determine the password change cycle of the automatic password change plan and / or the security level of the modified password according to whether the password is cracked; or Determine whether there is an automatic password change plan for the host; if not, create an automatic password change plan for the host through the bastion host; if so, modify the password change period and / or the security level of the modified password of the automatic password change plan.
12. The method according to any one of claims 7 to 11, wherein: The automatic password modification plan is specifically used to periodically modify the password of the host. The method further includes: After the automatic password change plan is created, if no password cracking behavior is detected within a preset period of time, the automatic password change plan is deleted through the bastion host.
13. A safety protection device, wherein: include: An acquisition module, used to acquire the login behavior information of the host; wherein the login behavior information is used to indicate the behavior of logging into the host through a password; A detection module, used to detect whether there is any password cracking behavior against the host according to the login behavior information of the host; A creation module, used for creating an automatic password modification plan for the host through the bastion host when a password cracking behavior against the host is detected, so that the bastion host modifies the password of the host according to the automatic password modification plan; The automatic password change plan is used to change the password of the host.
14. An electronic device, wherein: include: at least one processor; as well as a memory communicatively coupled to the at least one processor; The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor to enable the electronic device to perform the method described in any one of claims 7 to 12.
15. A computer-readable storage medium, wherein: The computer-readable storage medium stores computer-executable instructions, and when the processor executes the computer-executable instructions, the method according to any one of claims 7 to 12 is implemented.
16. A computer program product comprising a computer program, wherein: When the computer program is executed by a processor, the method according to any one of claims 7 to 12 is implemented.
Citation Information
Patent Citations
Account information protection method and system thereof
CN104954350A
Secure login control method, device and terminal device
CN109635557A
Password modification method and system, target server and storage medium
CN109787989A
Batch password changing method and device and computer readable storage medium
CN112347463A
Automatic resource password changing system based on secure bastion host
CN115795439A
Cited By
Power grid dispatching cloud platform access authentication method, device and equipment based on bastion host, storage medium and program product
CN121037044A