Security detection method and apparatus, and electronic device

Through automated security detection methods and devices for multi-cloud environments, enterprises solve the problem of configuration errors and permission management in multi-cloud environments, and achieve efficient security management and risk reduction.

WO2025163422A1PCT designated stage Publication Date: 2025-08-07CLOUD INTELLIGENCE ASSETS HOLDING (SINGAPORE) PTE LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/IB2025/050584
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-01-30
Filing Date
2025-01-21
Publication Date
2025-08-07

AI Technical Summary

Technical Problem

Enterprises have problems such as misconfiguration, excessive permissions, and high risk of data leakage in multi-cloud environments. It is difficult for existing CSPM products to effectively manage the security configuration of multi-cloud environments.

Method used

It provides a security detection method and device, which automatically detects configuration items in multi-cloud environments through client or timing tasks, outputs detection results based on predefined configuration rules, supports user-defined rules updates, and realizes security management of multi-cloud environments.

Benefits of technology

It realizes automatic collection of configuration information for multi-cloud environments, automatically monitors configuration problems, reduces security risks in multi-cloud environments, and helps users evaluate and strengthen the security configuration of cloud resources.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure IB2025050584_07082025_PF_FP_ABST
    Figure IB2025050584_07082025_PF_FP_ABST
Patent Text Reader

Abstract

Embodiments of the present disclosure provide a security detection method and apparatus, and an electronic device. The security detection method comprises: in response to a security detection request, acquiring first configuration information corresponding to a configuration item to be detected, wherein the security detection request is used for instructing to perform security detection on at least one configuration item to be detected that separately corresponds to some cloud environments or all cloud environments among a plurality of cloud environments of a user; and on the basis of a configuration rule of each cloud environment, detecting the first configuration information, and outputting a detection result. The present disclosure achieves security management of a plurality of cloud environments.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Security Detection Method, Apparatus, and Electronic Device This disclosure claims priority to a Chinese patent application filed with the China Patent Office on January 30, 2024, application number 202410133790. 4. The entire contents of this application are incorporated herein by reference. Technical Field This disclosure relates to the field of cloud security, and more specifically, to a security detection method, apparatus, and electronic device. Background: Enterprise cloud environments are large and complex, with numerous resources and accounts requiring maintenance. Users are prone to the following problems when configuring cloud environments: uncertainty about how to correctly configure cloud resources, overly permissive permissions due to diverse user identities, and time-consuming and labor-intensive long-term tracking and maintenance of cloud resource configurations. These issues can easily lead to configuration errors, omissions, and excessive permissions, potentially leading to data leaks and other security incidents. Most enterprises choose hybrid or multi-cloud deployment solutions to leverage the strengths of different cloud service providers or meet compliance requirements. However, different cloud environments have different configuration methods, further complicating security management. SUMMARY OF THE INVENTION The present disclosure provides a security detection method, apparatus, and electronic device to implement security management in a multi-cloud environment. In a first aspect, the present disclosure provides a security detection method, comprising: obtaining first configuration information corresponding to a configuration item to be detected in response to a security detection request, wherein the security detection request is used to instruct a security detection of at least one configuration item to be detected corresponding to each of some or all of a user's multiple cloud environments; detecting the first configuration information based on the configuration rules of each cloud environment, and outputting the detection results. In one implementation, obtaining the first configuration information corresponding to the configuration item to be detected includes: obtaining the first configuration information via an access interface corresponding to each configuration item to be detected in each cloud environment. In one implementation, responding to the security detection request includes: responding to the security detection request triggered by a user through a client page, or responding to the security detection request triggered by a scheduled task. In one implementation, outputting the test results includes at least one of the following: outputting a test report indicating whether each configuration item to be tested, corresponding to each of the multiple cloud environments, passes or fails the test; outputting an alert indicating the risk of the configuration item that failed the test; and outputting remediation information indicating a modification target for the configuration item that failed the test. In another implementation, outputting the test results includes outputting the test results based on the priority ranking of the configuration items to be tested.In one implementation, the method further includes: receiving user-entered custom configuration rule information, and updating the configuration rules of the cloud environment based on the custom configuration rule information. In a second aspect, the present disclosure provides a security detection method, comprising: sending a security detection request to a server, the security detection request instructing a security detection of at least one configuration item to be detected corresponding to each of some or all of the user's multiple cloud environments; and receiving a detection result sent by the server, the detection result being obtained by detecting first configuration information based on the configuration rules of each cloud environment, the first configuration information being configuration information corresponding to the configuration item to be detected. In one implementation, sending the security detection request to the server includes: sending the security detection request to the server in response to a user operation on a client page, wherein the client displays preset configuration items to be detected in all of the user's cloud environments via one or more levels of pages. In one implementation, the device further includes: displaying the test results via a client page, the test results including at least one of the following: a test report indicating whether each configuration item to be tested passed or failed; an alert indicating the risk of the configuration item that failed the test; and repair information indicating a modification target for the configuration item that failed the test. In a third aspect, the present disclosure provides a security testing device, comprising: an acquisition module for acquiring first configuration information corresponding to the configuration item to be tested in response to a security test request, wherein the security test request instructs a security test to be performed on at least one configuration item to be tested corresponding to each of some or all of a user's multiple cloud environments; and a detection module for testing the first configuration information based on the configuration rules of each cloud environment and outputting a test result. In one implementation, the acquisition module is configured to acquire the first configuration information via an access interface corresponding to each configuration item to be tested in each cloud environment. In one implementation, the acquisition module is configured to respond to the security test request triggered by a user via a client page or to the security test request triggered by a scheduled task. In one implementation, the detection module is configured to at least one of the following: output a test report indicating whether each configuration item to be tested, corresponding to each of the multiple cloud environments, passes or fails the test; output an alert indicating the risk of the configuration item that failed the test; and output remediation information indicating a modification target for the configuration item that failed the test. In another implementation, the detection module is configured to output a test result based on the priority ranking of the configuration items to be tested.In one implementation, the system further includes: a receiving module for receiving user-entered custom configuration rule information and updating the configuration rules of the cloud environment based on the custom configuration rule information. In a fourth aspect, the present disclosure provides a security detection device, comprising: a sending module for sending a security detection request to a server, the security detection request instructing a security detection of at least one configuration item to be detected corresponding to each of some or all of a user's multiple cloud environments; and a receiving module for receiving a detection result sent by the server, the detection result being obtained by detecting first configuration information based on the configuration rules of each cloud environment, the first configuration information being configuration information corresponding to the configuration item to be detected. In one implementation, the sending module is configured to: send the security detection request to the server in response to a user operation on a client page, wherein the client displays preset configuration items to be detected in all of the user's cloud environments via one or more levels of pages. In one implementation, the device further includes: a display module configured to display the test results via a client page, wherein the test results include at least one of the following: a test report indicating whether each configuration item to be tested passed or failed; warning information indicating the risk of configuration items that failed the test; and repair information indicating modification targets for configuration items that failed the test. In a fifth aspect, the present disclosure provides an electronic device comprising: a memory and a processor; the memory storing a computer program; and the processor executing the computer program stored in the memory, wherein the computer program, when executed, causes the processor to perform the method according to the first or second aspect. In a sixth aspect, the present disclosure provides a computer-readable storage medium storing a computer program. When the computer program is executed by the processor, the processor performs the method according to the first or second aspect. In a seventh aspect, the present disclosure provides a computer program product comprising the computer program, wherein the computer program, when executed by the processor, implements the method according to the first or second aspect. The security detection method, apparatus, and electronic device provided herein automatically collect configuration information for a multi-cloud environment. Based on predefined configuration rules, they automatically monitor the configuration of the multi-cloud environment and output corresponding detection results, helping users evaluate and strengthen the security configuration of cloud resources and reduce security risks in the multi-cloud environment.To more clearly illustrate the embodiments of the present disclosure or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the prior art descriptions. Obviously, the drawings described below represent some embodiments of the present disclosure. Persons skilled in the art can also derive other drawings based on these drawings without inventive effort. Figure 1 is a schematic diagram of an application scenario of a security detection method provided in an embodiment of the present disclosure; Figure 2 is a schematic diagram of a flow chart of a security detection method provided in an embodiment of the present disclosure; Figure 3 is a schematic diagram of a flow chart of a security detection method provided in an embodiment of the present disclosure; Figure 4 is a schematic diagram of a structure of a security detection device provided in an embodiment of the present disclosure; Figure 5 is a schematic diagram of a structure of a security detection device provided in an embodiment of the present disclosure; and Figure 6 is a schematic block diagram of an electronic device provided in an embodiment of the present disclosure. DETAILED DESCRIPTION OF THE EMBODIMENTS To further clarify the objectives, technical solutions, and advantages of the embodiments of the present disclosure, the following will provide a clear and complete description of the technical solutions in the embodiments of the present disclosure, in conjunction with the accompanying drawings. Obviously, the described embodiments represent only a portion of the embodiments of the present disclosure, but not all of them. All other embodiments derived by persons of ordinary skill in the art based on the embodiments of this disclosure without inventive effort shall fall within the scope of protection of this disclosure. Cloud Security Posture Management (CSPM) is defined as a security product. Currently, most CSPM solutions can implement basic security capabilities such as monitoring cloud environments and detecting configuration errors, but lack compatibility and support for multi-cloud environments. In light of this, the embodiments of this disclosure propose a security detection method that supports multi-cloud environments. This method automatically collects configuration information for multi-cloud environments, automatically monitors the configuration of multi-cloud environments based on predefined rules, and outputs corresponding results. This method helps users evaluate and strengthen the security configuration of cloud resources and reduce security risks in multi-cloud environments. Figure 1 is a schematic diagram of an application scenario for a security detection method provided by an embodiment of the present disclosure. Taking a multi-cloud deployment scenario comprising cloud environments 1, 2, and n as an example, a user triggers a security detection of the multi-cloud environment through client 101. Server 102 responds and collects configuration information for each cloud environment within the multi-cloud environment. Based on predefined rules, it determines configuration issues within the multi-cloud environment and returns the detection results to client 101. Figure 2 is a flowchart of a security detection method provided by an embodiment of the present disclosure. This method is applied to a server, which may optionally be a configuration detection engine. As shown in Figure 2, the method includes the following steps:

[0002] S201. Responding to a security check request, obtaining first configuration information corresponding to a configuration item to be checked. The security check request is used to instruct a security check to be performed on at least one configuration item to be checked corresponding to each of some or all of a user's multiple cloud environments. The security check request can be triggered by a user through a client. The user can trigger a security check on the multi-cloud environment through the client at any time when a security check is required. Alternatively, the security check request can be triggered by a scheduled task. That is, the server can perform security checks periodically according to the schedule task settings, or at specific times set by the schedule task. The schedule task can be pre-set. The triggering method of the security check request is not limited in the embodiments of the present disclosure. That is, the server responds to the security check request triggered by the user through a client page, or responds to the security check request triggered by a scheduled task. In response to a security check request, the server needs to obtain first configuration information corresponding to the configuration items to be checked from the cloud environment indicated by the security check request. The cloud environment indicated by the security check request may be one or more of the user's multiple cloud environments, and the at least one configuration item to be checked corresponding to each cloud environment indicated by the security check request may be some or all of the configuration items to be checked in the cloud environment. For example, the client may display the configuration items to be checked in each cloud environment on a single or multi-level page, from which the user may select one or more configuration items to be checked to trigger a security check. For example, the client page may also display an option to perform a security check on all configuration items to be checked in all cloud environments, allowing the user to directly trigger a security check on all configuration items to be checked in all cloud environments. The configuration items to be checked in a cloud environment may include configuration information for various cloud resources in the cloud environment, such as virtual machines, storage, and networks. The configuration items to be tested for each cloud environment can encompass multiple security dimensions. For example, from the authorization management dimension, these include configuration items for managing and controlling cloud platform usage and access rights. This allows for detection of issues such as over-authorization and password expiration in user accounts, thereby identifying and resolving authorization management issues and improving the security and reliability of the cloud platform. Alternatively, from the security risk dimension, based on the security practices of different cloud vendors, business system security configurations, code vulnerabilities, and log configuration items awaiting testing can be identified to maximize user data and business security.For another example, from the perspective of compliance risk, based on international standards, such as those of the Center for Internet Security (CIS), information security-related configuration items to be tested are identified, thereby improving the network security of cloud products and reducing the risk of network attacks. The server obtains first configuration information for the corresponding configuration items to be tested from each cloud environment. For example, the server can obtain the first configuration information through the access interface corresponding to each configuration item to be tested in each cloud environment. In the disclosed embodiment, the server integrates the access interfaces corresponding to each configuration item to be tested in each cloud environment provided by the cloud service provider. Based on the configuration items to be tested in the cloud environment indicated by the security check request, the server can access the cloud environment through the corresponding access interface to obtain the corresponding first configuration information. It is understood that the configuration items to be tested in each cloud environment can be the same, partially the same, or different. The server can obtain a piece of first configuration information for each configuration item to be tested in each cloud environment.

[0003] S202: Detect the first configuration information based on the configuration rules of each cloud environment and output the detection results. To ensure the security of the cloud environment, for example, ensuring data security and ensuring appropriate permission scopes, corresponding configuration rules need to be preset for each configuration item in each cloud environment. Configuration rules can correspond to each configuration item to be detected. For example, each configuration item to be detected may correspond to a configuration rule, or multiple configuration items to be detected may correspond to a configuration rule. Cloud environment settings based on these configuration rules can ensure security. For example, the configuration item to be detected is the number of incorrect password retries. The configuration rule for this configuration item includes a threshold for configuring the number of incorrect password retries. The first configuration information obtained by the server is the actual number of incorrect password retries configured in the cloud environment. The server determines whether the actual number of incorrect password retries meets the threshold constraint in the configuration rule. Optionally, while ensuring security, the configuration rules of each cloud environment can provide users with the option to customize the threshold configuration according to their needs. The server can receive the customized configuration rule information entered by the user and update the cloud environment configuration rules based on the customized configuration rule information. Optionally, in embodiments of the present disclosure, priorities can be set for the configuration rules of each cloud environment, specifically the priorities of each configuration item to be tested, to indicate the importance or urgency of the risk corresponding to the configuration item to be tested. After obtaining the first configuration information corresponding to the configuration item to be tested, the first configuration information can be compared with the configuration rule corresponding to the configuration item to be tested to determine whether the first configuration rule complies with the configuration rule, and a test result can be output. Optionally, the test result output by the server can include at least one of the following: a test report indicating whether the test passes or fails for each configuration item to be tested corresponding to each of the multiple cloud environments; an alarm indicating the risk of a configuration item that fails the test; or remediation information indicating a modification target for the configuration item that fails the test. Taking the aforementioned configuration item to be tested as the number of incorrect password retries as an example, the configuration rule for this configuration item includes a threshold for the number of incorrect password retries. The first configuration information obtained by the server is the number of incorrect password retries actually configured in the cloud environment. If the server determines that the actually configured number of incorrect password retries meets the threshold constraint in the configuration rule, the configuration item to be tested passes. If the server determines that the actually configured number of incorrect password retries does not meet the threshold constraint in the configuration rule, the configuration item to be tested fails. Optionally, if the configuration item to be tested fails, the server can output an alert to alert the user to the security risk.Optionally, if the configuration item fails the test, the server may output repair information to prompt the user to modify the number of incorrect password retries so that it meets the threshold constraint in the configuration rule. The server compares the first configuration information with the configuration rule corresponding to the configuration item. If the first configuration information meets the configuration rule, the configuration item passes the test; if the first configuration information does not meet the configuration rule, the configuration item fails the test. Optionally, for configuration items that fail the test, the server may output an alarm to prompt the user. Optionally, for configuration items that fail the test, the server may output repair suggestions to prompt the user to modify the configuration item according to the modification target, where the modification target is determined according to the configuration rule for the configuration item. Optionally, to enable the user to more intuitively view security risks, the server may output test results based on the priority of each configuration item. For example, for configuration items that fail the test, configuration items with higher risk priorities may be sorted before configuration items with lower risk priorities. The method of the disclosed embodiments automatically collects configuration information for a multi-cloud environment, automatically monitors the configuration of the multi-cloud environment based on predefined configuration rules, and outputs corresponding detection results, helping users evaluate and strengthen the security configuration of cloud resources and reduce security risks in the multi-cloud environment. Figure 3 is a second flow diagram of a security detection method provided by the disclosed embodiments. This method is applied to a client. As shown in Figure 3, the method includes:

[0004] S301. Send a security check request to a server. The security check request is used to instruct to perform a security check on at least one configuration item to be checked corresponding to some or all of a user's multiple cloud environments.

[0005] S302. Receive a detection result sent by the server. The detection result is obtained by testing first configuration information based on the configuration rules of each cloud environment. The first configuration information is the configuration information corresponding to the configuration item to be tested. The client sends a security detection request to the server. The server obtains the first configuration information corresponding to the configuration item to be tested from the cloud environment indicated by the security detection request, and tests the first configuration information based on the configuration rules of each cloud environment, determines the detection result, and returns the detection result to the client so that the user can promptly understand the security risk. Optionally, in response to a user operation on a client page, the security detection request is sent to the server. The client displays the preset configuration items to be tested in all of the user's cloud environments via one or more levels of pages. The user triggers the security detection request through an operation on the client page. The client page can display an operation control for triggering the security detection request in various forms. For example, the client page can display an operation control for performing a security detection on all of the user's preset configuration items to be tested in all cloud environments. The user can click this operation control to perform a security detection on all detected configuration items in all cloud environments. For example, the client page can display all pre-set configuration items to be tested in the cloud environment in a preset order. Each configuration item to be tested can have a separate security check control. Users can click the control to perform a separate security check on each configuration item to be tested. Alternatively, the client page can display a control for selecting a single or multiple configuration items to be tested. Users can select one or more configuration items to be tested and click the control to trigger a security check on the selected configuration items. Optionally, the client page displays test results, which include at least one of the following: a test report indicating whether each configuration item to be tested passed or failed; an alert indicating the risk of a configuration item that failed the test; and remediation information indicating the modification target for the configuration item that failed the test. Optionally, the test results may also include analytical results, such as the number or proportion of configuration items to be tested that passed or failed the test; the number of high-priority configuration items to be tested among the configuration items to be tested that failed the test; the number or proportion of configuration items to be tested that passed or failed the test in different security dimensions, such as the proportion of configuration items to be tested that failed the test in the authorization management dimension, the proportion of configuration items to be tested that failed the test in the security risk dimension, and the proportion of configuration items to be tested that failed the test in the compliance risk dimension; and the number or proportion of configuration items to be tested that passed or failed the test in each cloud environment, such as the proportion of configuration items to be tested that failed the test in cloud environment 1 and the proportion of configuration items to be tested that failed the test in cloud environment 2.Through the client's display of results, users can intuitively understand detection results and identify security risks, enabling timely remediation of security issues. This enables convenient, efficient, and flexible security management for multi-cloud environments. In the solution of the disclosed embodiment, the server can access cloud environments from different cloud vendors with user authorization, providing a CSPM solution with simple configuration and comprehensive cloud environment coverage. While providing configuration rules pre-defined by professional security personnel, it supports user modification of custom parameters such as thresholds for configuration items, providing a ready-to-use solution while also ensuring flexibility. Figure 4 is a first structural diagram of a security detection device provided in the disclosed embodiment. As shown in Figure 4, security detection device 400 includes: an acquisition module 401, which, in response to a security detection request, acquires first configuration information corresponding to a configuration item to be detected. The security detection request instructs the user to perform a security detection on at least one configuration item to be detected corresponding to each of some or all of the user's multiple cloud environments. A detection module 402, which detects the first configuration information based on the configuration rules of each cloud environment and outputs the detection results. In one implementation, acquisition module 401 is configured to obtain first configuration information via the access interface corresponding to each configuration item to be tested in each cloud environment. In one implementation, acquisition module 401 is configured to respond to a security testing request triggered by a user through a client page, or to a security testing request triggered by a scheduled task. In one implementation, detection module 402 is configured to at least one of the following: output a test report indicating whether a test passes or fails for each configuration item to be tested corresponding to each of the multiple cloud environments; output an alarm indicating the risk of a configuration item that fails the test; or output remediation information indicating a modification target for a configuration item that fails the test. In one implementation, detection module 402 is configured to output a test result based on the priority ranking of the configuration items to be tested. In one implementation, the device further includes a receiving module configured to receive user-entered custom configuration rule information and update the configuration rules of the cloud environment based on the custom configuration rule information. The apparatus of the disclosed embodiments can be used to perform the security testing method of the aforementioned embodiments. Its implementation principles and technical effects are similar and will not be further described here. FIG5 is a second structural diagram of a safety detection device provided in an embodiment of the present disclosure.As shown in Figure 5, the security detection device 500 includes: a sending module 501 for sending a security detection request to a server. The security detection request is used to instruct a security detection of at least one configuration item to be detected corresponding to some or all of a user's multiple cloud environments; and a receiving module 502 for receiving detection results sent by the server. The detection results are obtained by detecting first configuration information based on the configuration rules of each cloud environment. The first configuration information is the configuration information corresponding to the configuration item to be detected. In one implementation, the sending module 501 is used to send the security detection request to the server in response to a user operation on a client page. The client displays the preset configuration items to be detected in all of the user's cloud environments via one or more levels of pages. In one implementation, the device further includes a display module for displaying the detection results on the client page. The detection results include at least one of the following: a detection report indicating whether each configuration item to be detected passed or failed; warning information indicating the risk of configuration items that failed the detection; and repair information indicating the modification target for the configuration items that failed the detection. The device according to the embodiments of the present disclosure can be used to implement the security detection method according to the aforementioned embodiments. The implementation principles and technical effects are similar and will not be further described here. Figure 6 is a schematic block diagram of an electronic device according to an embodiment of the present disclosure. As shown in Figure 6, the electronic device 600 may include at least one processor 601 for implementing the security detection method according to an embodiment of the present disclosure. Optionally, the electronic device 600 also includes at least one memory 602 for storing program instructions and / or data. The memory 602 and the processor 601 are coupled. Coupling in the embodiments of the present disclosure refers to an indirect coupling or communication connection between devices, units, or modules, which can be electrical, mechanical, or other forms, and is used for information exchange between the devices, units, or modules. The processor 601 may operate in conjunction with the memory 602. The processor 601 may execute program instructions stored in the memory 602. At least one of the at least one memory may be included in the processor. Optionally, the electronic device 600 also includes a communication interface 603 for communicating with other devices via a transmission medium, thereby enabling the electronic device 600 to communicate with other devices. The communication interface 603 may be, for example, a transceiver, an interface, a bus, a circuit, or a device capable of performing transceiver functions. The processor 601 may utilize the communication interface 603 to transmit and receive data and / or information, and to implement the methods provided in the embodiments of the present disclosure. For details, please refer to the detailed description in the previous embodiments and will not be repeated here. The specific connection medium between the processor 601, memory 602, and communication interface 603 is not limited in the embodiments of the present disclosure.In FIG6 , the embodiment of the present disclosure illustrates a processor 601, a memory 602, and a communication interface 603 connected via a bus 604. Bus 604 is represented by a bold line in FIG6 , and the connections between other components are for illustrative purposes only and are not intended to be limiting. Such buses can be classified as address buses, data buses, control buses, and the like. For ease of illustration, FIG6 illustrates only one bold line, but this does not imply that there is only one bus or only one type of bus. It should be understood that the processor in the embodiment of the present disclosure can be an integrated circuit chip with signal processing capabilities. During implementation, each step of the above method embodiment can be completed by hardware integrated logic circuits in the processor or by software instructions. The processor can be a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. The methods, steps, and logic diagrams disclosed in the embodiments of this disclosure can be implemented or executed. A general-purpose processor can be a microprocessor or any conventional processor. The steps of the methods disclosed in conjunction with the embodiments of this disclosure can be directly implemented and executed by a hardware decoding processor, or by a combination of hardware and software modules within the decoding processor. The software modules can be located in a storage medium known in the art, such as random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, or registers. The storage medium is located in a memory, and the processor reads information from the memory and, in conjunction with its hardware, completes the steps of the aforementioned methods. It should also be understood that the memory in the embodiments of this disclosure can be volatile memory or non-volatile memory, or can include both volatile and non-volatile memory. Among them, the non-volatile memory can be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM) or a flash memory.The volatile memory can be random access memory (RAM), which is used as an external cache. By way of example and not limitation, many forms of RAM are available, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), and direct RAM (DR RAM). It should be noted that the memory of the systems and methods described herein is intended to include, but is not limited to, these and any other suitable types of memory. The present disclosure also provides a computer-readable storage medium storing a computer program (also referred to as code or instructions). When executed, the computer performs the method described in any of the aforementioned embodiments. The present disclosure also provides a computer program product, including a computer program. When executed by a processor, the computer program implements the method described in any of the aforementioned embodiments. Terms such as "unit," "module," and the like, used in this disclosure may refer to computer-related entities, hardware, firmware, a combination of hardware and software, software, or software in execution. Those skilled in the art will appreciate that the various illustrative logical blocks and steps described in conjunction with the embodiments disclosed herein can be implemented using electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Professionals may use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of this disclosure. In the several embodiments provided in this disclosure, it should be understood that the disclosed apparatuses, devices, and methods can be implemented in other ways.For example, the device embodiments described above are merely illustrative. For example, the division of units is merely a logical functional division. In actual implementation, other divisions may be employed. For example, multiple units or components may be combined or integrated into another system, or some features may be omitted or not implemented. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through interfaces, or indirect coupling or communication connection between devices or units, and may be electrical, mechanical, or other forms. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, i.e., they may be located in one location or distributed across multiple network units. Some or all of these units may be selected to achieve the objectives of the present embodiments based on actual needs. Furthermore, the functional units in the various embodiments of the present disclosure may be integrated into a single processing unit, each unit may exist physically separately, or two or more units may be integrated into a single unit. In the above embodiments, the functions of each functional unit may be implemented in whole or in part through software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions (programs). When the computer program instructions (programs) are loaded and executed on a computer, the processes or functions according to the embodiments of the present disclosure are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions may be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via a wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) method. The computer-readable storage medium may be any available medium that can be accessed by a computer, or a data storage device such as a server or data center that includes one or more available media. The available medium may be a magnetic medium (e.g., a floppy disk, a hard disk, or a magnetic tape), an optical medium (e.g., a digital video disc (DVD)), or a semiconductor medium (e.g., a solid-state drive (SSD)).If this function is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this disclosure, or the portion that contributes to the prior art, or the portion of this technical solution, can be embodied in the form of a software product. This computer software product, stored in a storage medium, includes instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the various embodiments of the present disclosure. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, mobile hard drives, ROM, RAM, magnetic disks, or optical disks. The user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, storage, and display, etc.) involved in this disclosure are all authorized by the user or fully authorized by all parties. The collection, use, and processing of the relevant data must comply with the relevant laws, regulations, and standards of the relevant countries and regions, and corresponding operation portals are provided for users to choose to authorize or reject. The above description is merely a specific embodiment of the present disclosure, but the scope of protection of the present disclosure is not limited thereto. Any modifications or substitutions that can be readily conceived by a person skilled in the art within the technical scope disclosed herein should be included within the scope of protection of the present disclosure. Therefore, the scope of protection of the present disclosure should be based on the scope of protection of the claims.

Claims

Claims 1. A security detection method, applied to a server, comprising: In response to a security check request, obtaining first configuration information corresponding to a configuration item to be checked, wherein the security check request is used to instruct a security check to be performed on at least one configuration item to be checked corresponding to each of some or all of the user's multiple cloud environments; checking the first configuration information based on configuration rules of each cloud environment, and outputting a test result.

2. The method according to claim 1, wherein obtaining the first configuration information corresponding to the configuration item to be detected comprises: The first configuration information is obtained through the access interface corresponding to each configuration item to be detected in each cloud environment.

3. The method according to claim 1 or 2, wherein the responding to the security detection request comprises: In response to the security detection request triggered by the user through the client page, or in response to the security detection request triggered by a scheduled task.

4. The method according to any one of claims 1 to 3, wherein outputting the test results comprises at least one of the following: outputting a test report indicating whether each configuration item to be tested corresponding to each of the plurality of cloud environments passes or fails the test; Outputting warning information, wherein the warning information is used to indicate the risk of the configuration item that failed the detection; Output repair information, where the repair information is used to indicate a modification target for the configuration item that failed the detection.

5. The method according to any one of claims 1 to 4, wherein outputting the detection result comprises: Output the test results based on the priority of each configuration item to be tested.

6. The method according to any one of claims 1 to 5, further comprising: Receive configuration rule customization information input by a user, and update the configuration rules of the cloud environment based on the configuration rule customization information.

7. A security detection method, applied to a client, comprising: Sending a security check request to the server, where the security check request is used to instruct to perform a security check on at least one configuration item to be checked corresponding to some or all of the user's multiple cloud environments; Receive a detection result sent by the server, where the detection result is obtained by detecting first configuration information based on configuration rules of each cloud environment, and the first configuration information is configuration information corresponding to the configuration item to be detected.

8. The method according to claim 7, wherein the sending of the security check request to the server comprises: In response to the user's operation on the client page, the security detection request is sent to the server, wherein the client displays the preset configuration items to be detected in all cloud environments of the user through one or more levels of pages.

9. The method according to claim 7 or 8, further comprising: The test results are displayed on a client page, and the test results include at least one of the following: a test report indicating whether each configuration item to be tested has passed or failed the test; an alarm indicating the risk of the configuration item that failed the test; Repair information is used to indicate the modification target of the configuration item that failed the detection.

10. A safety detection device, comprising: an acquisition module, configured to acquire, in response to a security check request, first configuration information corresponding to a configuration item to be checked, wherein the security check request is used to instruct a security check to be performed on at least one configuration item to be checked corresponding to each of some or all of a user's multiple cloud environments; and a detection module, configured to detect the first configuration information based on configuration rules of each cloud environment and output a detection result.

11. A safety detection device, comprising: a sending module, which sends a security detection request to the server, wherein the security detection request is used to instruct to perform a security detection on at least one configuration item to be detected corresponding to a portion of or all of the user's multiple cloud environments; The receiving module is configured to receive a detection result sent by the server, where the detection result is obtained by detecting first configuration information based on configuration rules of each cloud environment, and the first configuration information is configuration information corresponding to the configuration item to be detected.

12. An electronic device, comprising: memory and processor; The memory is used to store computer programs; The processor is configured to execute a computer program stored in the memory, and when the computer program is executed, the processor is enabled to execute the method according to any one of claims 1 to 9.

13. A computer-readable storage medium, wherein a computer program is stored in the computer-readable storage medium, and when the computer program is executed by a processor, the processor is caused to perform the method according to any one of claims 1 to 9.

14. A computer program product, comprising a computer program, wherein when the computer program is executed by a processor, the computer program implements the method according to any one of claims 1 to 9.

Citation Information

Patent Citations

  • Automatic monitoring and alarming method and system

    CN113779339A

  • Cloud product configuration inspection method based on multi-cloud management platform

    CN115174158A

  • Automatic testing method and device for cloud product monitoring alarm, equipment and medium

    CN116467170A

  • Micro-service state monitoring method and system based on multi-cloud platform

    CN116909846A