CN110413305A - The loophole remediation management method, apparatus and electronic equipment of fining - Google Patents

The loophole remediation management method, apparatus and electronic equipment of fining Download PDF

Info

Publication number
CN110413305A
CN110413305A CN201910493173.4A CN201910493173A CN110413305A CN 110413305 A CN110413305 A CN 110413305A CN 201910493173 A CN201910493173 A CN 201910493173A CN 110413305 A CN110413305 A CN 110413305A
Authority
CN
China
Prior art keywords
setting
patch
loophole
mode
restarted
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
CN201910493173.4A
Other languages
Chinese (zh)
Inventor
吴定波
刘鹏华
王晓胜
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Netshen Information Technology (beijing) Co Ltd
Qianxin Technology Group Co Ltd
Secworld Information Technology Beijing Co Ltd
Original Assignee
Netshen Information Technology (beijing) Co Ltd
Qianxin Technology Group Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Netshen Information Technology (beijing) Co Ltd, Qianxin Technology Group Co Ltd filed Critical Netshen Information Technology (beijing) Co Ltd
Priority to CN201910493173.4A priority Critical patent/CN110413305A/en
Publication of CN110413305A publication Critical patent/CN110413305A/en
Pending legal-status Critical Current

Links

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/50Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
    • G06F21/57Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities
    • G06F21/577Assessing vulnerabilities and evaluating computer system security
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F8/00Arrangements for software engineering
    • G06F8/60Software deployment
    • G06F8/65Updates
    • G06F8/658Incremental updates; Differential updates

Landscapes

  • Engineering & Computer Science (AREA)
  • General Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Software Systems (AREA)
  • Theoretical Computer Science (AREA)
  • Computer Hardware Design (AREA)
  • Physics & Mathematics (AREA)
  • General Physics & Mathematics (AREA)
  • Computing Systems (AREA)
  • Stored Programmes (AREA)

Abstract

The loophole remediation management method, apparatus and electronic equipment of a kind of fining are provided in the embodiment of the present invention, belongs to field of information security technology, this method comprises: setting loophole repair time;And/or the software type that category setting is repaired;And/or the loophole range repaired by rank setting;And/or setting excludes the patch for having compatibling problem or the only patch of installation provision;And/or the loophole reparation limitation of setting terminal;And/or setting patch downloads erection sequence;And/or setting patch installs the mode that back operation system is restarted.Using this programme, while improving fining control of the user to the whole network loophole repair process, the requirement that network management works to administrative staff is reduced, the efficiency and validity of enterprise's the whole network loophole repair is improved, has greatly saved the network management job costs of enterprise.

Description

The loophole remediation management method, apparatus and electronic equipment of fining
Technical field
The present invention relates to field of information security technology more particularly to a kind of loophole remediation management method, apparatus of fining And electronic equipment.
Background technique
Currently, the continuous development of computer technology at any time, many rogue program (such as computer virus, backdoor programs, wooden horses Deng) be implanted in target program using loophole, so as to cause target program paralysis, make troubles to user job, or cause The leakage of user's personal information, brings hidden danger to the personal property of user.Therefore, each enterprises and institutions all attach great importance to being at present The reparation of system.This demand is answered, the rich and varied loophole that each safety equipment manufacturer is also proposed oneself one after another repairs product, such as eventually Loophole is held to repair product, server end loophole reparation product.For group, corporate client, repaired using server end loophole It reproduces product and the working efficiency that loophole reparation effectively increases client is carried out to the whole network, so that administrator is not had to terminal one by one and successively carry out Vulnerability scanning, reparation, alleviate workload.But it is all more extensive that these existing loopholes, which repair the management function that product provides, , i.e., in addition to end item (such as repair time) can by user configuration management other than entire loophole repair process be all by system by Default behavior is automatically performed, and user can not participate in the management of repair process, this is caused to user, especially enterprise, group customer Inconvenience, make enterprise, group administrative staff can not loophole repair process to the whole network refined just like manually to end End carries out the management as loophole reparation.
Summary of the invention
In view of this, the embodiment of the present invention provides the loophole remediation management method, apparatus and electronic equipment of a kind of fining, At least partly solve problems of the prior art.
In a first aspect, a kind of loophole remediation management method of fining provided in an embodiment of the present invention, including server end Correcting strategy, terminal downloads and conversation strategy configuration are configured, the configuration of terminal loads strategy is simultaneously repaired according to Policy Filtering patch Multiple, wherein server end configuration correcting strategy includes:
Loophole repair time is set;
And/or the software type that category setting is repaired;
And/or the loophole range repaired by rank setting;
And/or setting excludes the patch for having compatibling problem or the only patch of installation provision;
And/or the loophole reparation limitation of setting terminal;
And/or setting patch downloads erection sequence;
And/or setting patch installs the mode that back operation system is restarted.
A kind of specific implementation according to an embodiment of the present invention, the setting loophole repair time are in a manner of selecting one Selection the following terms simultaneously carries out corresponding configuration:
It closes and repairs;
It is automatically repaired mode;
Periodically repair mode and regular maintenance frequency and time setting;
Mode and the setting of self defined time section are repaired according to the time period.
A kind of specific implementation according to an embodiment of the present invention, the software type that the category setting is repaired is with more The software that the mode of choosing selects following loophole to repair type and its covered:
Operating system class;
Microsoft Office class;
Third party software.
A kind of specific implementation according to an embodiment of the present invention, the loophole range repaired by rank setting is with more The mode of choosing selects following loophole rank:
It is high-risk;
It is optional high-risk;
Other and functional patch.
A kind of specific implementation according to an embodiment of the present invention, the setting exclude the patch for having compatibling problem or only pacify Patch as defined in filling, comprising:
Open or close patch limitation function;And it when opening patch limitation function, selects to exclude in a manner of selecting one List includes list;And when selecting Exclude Lists, the problematic list of patches to be excluded is set;And when selection packet The list of patches of only installation provision is arranged in when containing list.
The loophole reparation of a kind of specific implementation according to an embodiment of the present invention, the setting terminal is limited to multiselect Mode select following prohibitive behavior:
Forbid in terminal disregards patch;
Forbid in the manual patching bugs of terminal;And when selection is forbidden in the manual patching bugs of terminal, with the side of multiselect Formula selects and configures the following contents:
Forbid according to the time period;When choosing this option, the period is set;
Forbid the loophole rank repaired: high-risk, optional high-risk or other and functional patch.
A kind of specific implementation according to an embodiment of the present invention, the setting patch downloading erection sequence is to select one Mode selects the following terms:
It the downloading of patch and installation while carrying out;
After patch has all been downloaded, then install one by one.
A kind of specific implementation according to an embodiment of the present invention, the setting patch install the side that back operation system is restarted Formula is to choose whether setting operating system to restart mode, and when selection is, the following terms is selected in a manner of selecting one:
Prompting is restarted;
It is restarted automatically.
A kind of specific implementation according to an embodiment of the present invention is further selected when having selected the prompting to restart Primary or Interval Reminder is reminded, when having selected the Interval Reminder, the Interval Reminder time is further set.
A kind of specific implementation according to an embodiment of the present invention is further arranged when having selected described be restarted automatically The count down time restarted.
A kind of specific implementation according to an embodiment of the present invention, the setting patch install the side that back operation system is restarted Formula is to choose whether setting operating system to restart mode, when selection is, if further including that patch is completed to be already expired when installation Same day reboot time, then be arranged the period S restarted at the appointed time section, and after setting, system can be in second day weight Period S is opened to be restarted automatically.
A kind of specific implementation according to an embodiment of the present invention, the disclosure further include depositing after having carried out above-mentioned setting The corresponding setting of storage.
A kind of specific implementation according to an embodiment of the present invention, the disclosure further include whole lockings, all unlock and it is extensive The option of multiple default policy, when all locking in choosing, above-mentioned all configuration items will no longer be able to modify, and prevent maloperation or evil Meaning operation bring reparation loss;When all unlocking in choosing, above-mentioned all configuration items locked will open modification function, permit Perhaps normal modification;When restoring default policy in choosing, above-mentioned all configuration items will revert to preset default configuration.
Second aspect, the embodiment of the invention provides a kind of loophole remediation management devices of fining, comprising:
Component is arranged in repair time, for allowing administrator setting loophole repair time;
And/or component is arranged in loophole type, the software type for allowing the setting of administrator's category to repair;
And/or component is arranged in loophole rank, the loophole range for allowing administrator to repair by rank setting;
And/or patch limitation setting component, it is advised for allowing administrator setting exclusion to have the patch of compatibling problem or only install Fixed patch;
And/or terminal loophole reparation limits component, for allowing the loophole reparation of administrator setting terminal to limit;
And/or component is arranged in patch downloading erection sequence, for allowing the downloading erection sequence of administrator setting patch;
And/or patch installation back operation system restarts setting component, for operating system after allowing administrator setting patch to install The mode that system is restarted.
The third aspect, the embodiment of the invention also provides a kind of electronic equipment, which includes:
At least one processor;And
The memory being connect at least one processor communication;Wherein,
The memory is stored with the instruction that can be executed by least one processor, and the instruction is by least one processor It executes, so that at least one processor is able to carry out one in any implementation of aforementioned first aspect or first aspect The loophole remediation management method of kind fining.
Fourth aspect, the embodiment of the invention also provides a kind of non-transient computer readable storage medium, the non-transient meters Calculation machine readable storage medium storing program for executing stores computer instruction, and the computer instruction is for making the computer execute aforementioned first aspect or the The loophole remediation management method of one of any implementation of one side fining.
5th aspect, the embodiment of the invention also provides a kind of computer program product, which includes The calculation procedure being stored in non-transient computer readable storage medium, the computer program include program instruction, when the program When instruction is computer-executed, the computer is made to execute one of aforementioned first aspect or any implementation of first aspect The loophole remediation management method of fining.
Beneficial effect
Compare the prior art, the loophole remediation management method of one of embodiment of the present invention fining, by providing use Family is to the peace after loophole repair time, software type, loophole rank, patch limitation, the loophole reparation limitation of terminal, patch downloading The mode that dress sequence, patch installation back operation system are restarted is configured, and then whole network equipment carries out loophole according to setting rule It repairs, effective technological means is provided to the fining control of enterprise's the whole network loophole repair process for enterprise administrator, makes pipe Reason person can accomplish that, to the very delicate configuration of loophole repair process, the client that helps is with most suitably used mode patching bugs, and prevention is eventually End is by vulnerability exploit attack, the safety of guarantee terminal.Meanwhile using present invention also reduces network management work to want to administrative staff It asks, reduces the number that administrator solves terminal problem to terminal filed one by one, improve the effect of enterprise's the whole network loophole repair Rate and validity have greatly saved the network management job costs of enterprise.
Detailed description of the invention
In order to illustrate the technical solution of the embodiments of the present invention more clearly, below will be to needed in the embodiment attached Figure is briefly described, it should be apparent that, drawings in the following description are only some embodiments of the invention, for this field For those of ordinary skill, without creative efforts, it can also be obtained according to these attached drawings other attached drawings.
Fig. 1 is a kind of loophole remediation management method schematic diagram of fining provided in an embodiment of the present invention;
Fig. 2 is setting loophole repair time schematic diagram provided in an embodiment of the present invention;
Fig. 3 is the software type schematic diagram that category provided in an embodiment of the present invention setting is repaired;
Fig. 4 is the loophole range schematic diagram provided in an embodiment of the present invention repaired by rank setting;
Fig. 5 is that patch provided in an embodiment of the present invention limits list setting schematic diagram, and (a) is patch limitation setting signal Figure (b) is patch Exclude Lists schematic diagram;
Fig. 6 is that terminal loophole reparation provided in an embodiment of the present invention limits schematic diagram;
Fig. 7 is that another terminal loophole reparation provided in an embodiment of the present invention limits schematic diagram;
Fig. 8 is that setting patch provided in an embodiment of the present invention downloads erection sequence schematic diagram;
Fig. 9 is that setting patch provided in an embodiment of the present invention installs the schematic diagram that back operation system is restarted;
Figure 10 is locking, unlock and the functional schematic for restoring default setting provided in an embodiment of the present invention;
Figure 11 is the loophole remediation management schematic device of fining provided in an embodiment of the present invention;
Figure 12 is electronic equipment schematic diagram provided in an embodiment of the present invention.
Specific embodiment
The embodiment of the present invention is described in detail with reference to the accompanying drawing.
Illustrate embodiment of the present disclosure below by way of specific specific example, those skilled in the art can be by this specification Disclosed content understands other advantages and effect of the disclosure easily.Obviously, described embodiment is only the disclosure A part of the embodiment, instead of all the embodiments.The disclosure can also be subject to reality by way of a different and different embodiment It applies or applies, the various details in this specification can also be based on different viewpoints and application, in the spirit without departing from the disclosure Lower carry out various modifications or alterations.It should be noted that in the absence of conflict, the feature in following embodiment and embodiment can To be combined with each other.Based on the embodiment in the disclosure, those of ordinary skill in the art are without creative efforts Every other embodiment obtained belongs to the range of disclosure protection.
It should be noted that the various aspects of embodiment within the scope of the appended claims are described below.Ying Xian And be clear to, aspect described herein can be embodied in extensive diversified forms, and any specific structure described herein And/or function is only illustrative.Based on the disclosure, it will be understood by one of ordinary skill in the art that one described herein Aspect can be independently implemented with any other aspect, and can combine the two or both in these aspects or more in various ways. For example, carry out facilities and equipments in terms of any number set forth herein can be used and/or practice method.In addition, can make With other than one or more of aspect set forth herein other structures and/or it is functional implement this equipment and/or Practice the method.
It should also be noted that, diagram provided in following embodiment only illustrates the basic structure of the disclosure in a schematic way Think, component count, shape and the size when only display is with component related in the disclosure rather than according to actual implementation in schema are drawn System, when actual implementation kenel, quantity and the ratio of each component can arbitrarily change for one kind, and its assembly layout kenel can also It can be increasingly complex.
In addition, in the following description, specific details are provided for a thorough understanding of the examples.However, fields The skilled person will understand that the aspect can be practiced without these specific details.
The embodiment of the present disclosure provides a kind of loophole remediation management method of fining.The leakage of fining provided in this embodiment Hole remediation management method can be executed by a computing device, which can be implemented as software, or be embodied as software With the combination of hardware, which, which can integrate, is arranged in server, terminal device etc..
Terminal in the embodiment of the present disclosure can include but is not limited to such as mobile phone, laptop, digital broadcasting Receiver, PDA (personal digital assistant), PAD (tablet computer), PMP (portable media player), car-mounted terminal (such as Vehicle mounted guidance terminal) etc. mobile terminal and such as number TV, desktop computer, file server, database server Etc. fixed terminal.
Referring to Fig. 1, a kind of loophole remediation management method of fining provided in an embodiment of the present invention, including server end are matched Correcting strategy, terminal downloads and conversation strategy configuration are set, the configuration of terminal loads strategy is simultaneously repaired according to Policy Filtering patch, Wherein server end configuration correcting strategy includes following content:
(1) loophole repair time is set.
In general, the loophole repair time setting that administrator can participate in is only fixed period frequency, it is desirable to provide more Flexibly meet the management requirement of complicated enterprise to the management talent of repair time.As a specific example, such as Fig. 2 It is shown, flexible repair time configuration is provided, to select the following terms in a manner of selecting one and carrying out corresponding configuration:
It closes and repairs;
It is automatically repaired mode;
Periodically repair mode and regular maintenance frequency and time setting;
Mode and the setting of self defined time section are repaired according to the time period.
When selected close repair when, system will close loophole repair function, meet user in some scenarios no longer into The needs of row loophole reparation.When having selected to be automatically repaired mode, system can choose right times patching bugs automatically.When selection Mode is periodically repaired, system will carry out loophole reparation to system according to maintenance frequency set by user and time.When having selected to press Period repairs mode, and user can customize setting multiple repair times, system will according to maintenance frequency set by user and when Between section loophole reparation is carried out to system, e.g., carry out loophole between 17:00 to second days 8:00 of daily non-working time section and repair It is multiple.
(2) and/or the software type repaired is arranged in category.
The software for needing to repair is distinguished according to software category, and administrator can be made to repair in software difference level to terminal loophole It is managed again.As a specific example, configured as shown in figure 3, providing flexible software type of repairing, for multiselect The software that mode selects following loophole to repair type and its covered:
Operating system class;
Microsoft Office class;
Third party software.
(3) and/or by rank setting the loophole range repaired.
According to the loophole range that the setting of loophole rank needs to repair, administrator can be made to repair on different stage to the whole network loophole It is managed again.As a specific example, flexibly match by the loophole range that rank setting is repaired as shown in figure 4, providing It sets, to select following loophole rank in a manner of multiselect:
It is high-risk;
It is optional high-risk;
Other and functional patch.
Certainly, one skilled in the art will appreciate that it is without being limited thereto, to the division of loophole range can also by it is important, weight It wants, is inessential etc. to be divided.
(4) and/or setting excludes the patch for having compatibling problem or the only patch of installation provision.
In actual use, it is frequently encountered after being mounted with some patch since to bring system unavailable for compatibility issue, Cause vocational work to be stopped, brings massive losses for group, enterprise, at this point, net administrator's body, which enters terminal filed, goes investigation problem, it is extensive Complex system wastes net administrator's a large amount of time.For this purpose, administrator can be made to leakage by allowing administrator setting patch to limit list Hole, which is repaired, carries out finer control, makes the whole network only all benefits of the patch of installation provision or installation in addition to the patch of exclusion Fourth avoids the occurrence of above situation.As a specific example, as shown in Fig. 5 (a), provides flexible patch limitation list and set It sets, to open or close patch limitation function;And when opening patch limitation function, Exclude Lists are selected in a manner of selecting one Or include list;And when selecting Exclude Lists, the problematic list of patches to be excluded is set, such as Fig. 5 (b);And work as When selection is comprising list, the list of patches of only installation provision is set.
(5) and/or the loophole reparation of setting terminal limits.
In the practice of network management, often meets terminal user and cancel the whole network loophole reparation situation that net administrator carries out, make Terminal is obtained because ignoring loophole reparation for a long time as network security weak spot, is constituted a serious threat to enterprise network security;Or terminal Patch of the patch bring because being mounted with compatibling problem caused by not knowing about to patch situation is repaired manually, causes operation system Situation that is abnormal, influencing work;Or terminal at work between section repair manually patch influence vocational work situation;When these feelings Shape can reduce the validity of loophole reparation when appearance;To these situations, it is desirable to provide administrator is able to carry out the skill of control Art means enable an administrator to limit the loophole reparation of terminal.As a specific example, as shown in fig. 6, providing The loophole of multiplicity repairs limited option, to select following prohibitive behavior in a manner of multiselect:
Forbid preventing terminal user from ignoring loophole in violation of rules and regulations, leaving security risk in terminal disregards patch;
Forbid in the manual patching bugs of terminal;And when selection is forbidden in the manual patching bugs of terminal, with the side of multiselect Formula selects and configures the following contents:
Forbid according to the time period;When choosing this option, the period is set;Forbid user to repair according to the time period, prevents terminal from using Patch is installed at family oneself during office hours influences office;
Forbid the loophole rank repaired: high-risk, optional high-risk or other and functional patch;Prevent terminal user oneself Installing risky patch influences office.
It, can be with as shown in fig. 7, when having selected self defined time section as the specific example forbidden according to the time period Any time period setting that the round-the-clock period or administrator for adding workaday disable time section or nonworkdays need, mentions Administrator has been supplied flexibly to manage means.
(6) and/or setting patch downloads erection sequence.
The sequence that installation is planted under patch will impact the use of system, therefore it provides technological means allows administrator It can independently select the downloading erection sequence of patch particularly important.As a specific example, as shown in figure 8, providing as follows The patch of two kinds of mutual exclusions downloads erection sequence option:
It the downloadings of 6.1 patches and installation while carrying out;
After 6.2 patches have all been downloaded, then install one by one.
Option 1 can effectively save the time of loophole reparation, and CPU when downloading can be greatly decreased in option 2 is occupied, administrator It can be selected according to the actual situation.
(7) and/or setting patch installs the mode that back operation system is restarted.
It is understood that requiring to restart system after the installation of many patches can just come into force in practice, but some terminal users do not have Shutdown habit or the terminal having are unattended daily, all can cause patch that cannot come into force in time, therefore system weight whether is arranged It opens, or which kind of mode to allow system reboot that administrator can be allowed sufficiently to control above situation using.As a specific example, such as Shown in Fig. 9, it is to choose whether setting operating system to restart mode that setting patch, which installs the mode that back operation system is restarted, works as selection When being, the following terms is selected in a manner of selecting one:
Prompting is restarted;
It is restarted automatically.
It is alternatively described to remind a kind of specific implementation restarted, it can further select that primary or interval to be reminded to mention It wakes up, when having selected the Interval Reminder, the Interval Reminder time is further set.Remind primary design that can reduce to terminal User's bothers.The design of Interval Reminder can urge terminal user to restart in time.
The alternatively a kind of specific implementation being restarted automatically, when the countdown restarted can be further set Between, i.e., it is restarted automatically at the appointed time, is suitable for unattended, common terminal, server, reboot time is controllable, more surely It is appropriate.
As a kind of specific implementation, it is to choose whether setting behaviour that patch, which is arranged, to install the mode that back operation system is restarted Make system reboot mode, when selection is, if further including that patch completes that same day reboot time has been already expired when installation, sets Set the period S restarted at the appointed time section, after setting, system can second day reboot time section S be restarted automatically with Patch is set to come into force.
As a kind of specific implementation, the disclosure further includes storing corresponding setting after having carried out above-mentioned setting.Institute The corresponding setting of storage is stated, as a kind of specific implementation, the setting can be stored into database, it can also be by institute It states and is provided as configuration file storage into file system.
As a kind of specific implementation, as shown in Figure 10, the disclosure further includes that whole lockings, all unlock and recovery are silent Recognize the option of strategy, when all locking in choosing, above-mentioned all configuration items will no longer be able to modify, and prevent maloperation or malice from grasping Make bring reparation loss;When all unlocking in choosing, above-mentioned all configuration items locked will open modification function, allow just Often modification, resets administrator according to practical O&M situation, to meet continually changing need of work, such as Patch b before having new patch a to solve the problems, such as, then delete b from Exclude Lists, be automatically installed it;Restore in elected When default policy, above-mentioned all configuration items will revert to preset default configuration, mitigate the configuration work amount of administrator.
As a kind of specific implementation, terminal is as follows according to the process that above-mentioned strategy carries out loophole reparation:
(1) judge whether current time is loophole repair time, is, turn (2);It is no, terminate;
(2) all patch numbers to be repaired of current time are downloaded to according to the time of last loophole reparation, and to each Patch executes (3)-(9) process, until all patches are disposed, judges to download whether erection sequence is that patch has all been downloaded Afterwards, then one by one it installs, is, patch is installed one by one until all patches install;Turn (10);
(3) whether in Exclude Lists, be, turn (2), handle next patch if judging current patch;It is no, turn (4);
(4) whether in comprising list, be, turn (7) if judging current patch;It is no, turn (5);
(5) judge current patch whether be administrator setting loophole repair type, be, turn (6);It is no, turn (2), processing Next patch;
(6) judge current patch whether be administrator setting loophole repair rank, be, turn (7);It is no, turn (2), processing Next patch;
(7) current patch is downloaded;
(8) judge to download whether erection sequence is downloading and installation while carrying out, be to turn (9);It is no, turn (2), under processing One patch;
(9) patch is installed;Turn (2), handles next patch;
(10) judge whether system reboot mode is to remind to restart, and is to turn (11);It is no, turn (12);
(11) pop-up dialog box reminds terminal user to restart, if user feedback is, turns (13);It is no, terminate;
(12) judge whether system reboot mode is to be restarted automatically and set count down time and reboot time, is, it is full Lumping weight turns (13) after opening condition;
(13) system is restarted so that patch comes into force.
As a kind of specific implementation, when terminal user is intended to utilize client software, such as 360 assistants, progress loophole When reparation, according to the improper activity of the loophole reparation limitation project control user of terminal in the strategy of above-mentioned administrator setting, such as Do not allow its at work between section carry out loophole reparation in case influence vocational work, forbid it that patch to be installed in software prompt When selection ignore.
Corresponding with above method embodiment, referring to Figure 11, the embodiment of the invention provides a kind of loopholes of fining to repair Multiple managing device 11, comprising:
Component 111 is arranged in repair time, for allowing administrator setting loophole repair time;
And/or component 112 is arranged in loophole type, the software type for allowing the setting of administrator's category to repair;
And/or component 113 is arranged in loophole rank, the loophole range for allowing administrator to repair by rank setting;
And/or patch limitation setting component 114, it patch for allowing administrator setting to exclude to have compatibling problem or only installs Defined patch;
And/or terminal loophole reparation limits component 115, for allowing the loophole reparation of administrator setting terminal to limit;
And/or component 116 is arranged in patch downloading erection sequence, for allowing the downloading erection sequence of administrator setting patch;
And/or patch installation back operation system restarts setting component 117, for being operated after allowing administrator setting patch to install The mode of system reboot.
The scheme of the application enables to loophole remediation management finer, so that administrator can be with:
1. the customized setting period, it can be set to different multiple periods every day.
2. according to loophole type, (major class is divided into: " Windows/Office/ third party software ", group is divided into " windows Each each version of version/office ") and loophole rank patching bugs.
3. excluding the patch for having compatibling problem.
4. the only patch of installation provision.
5. section installation patch influences normal office work between preventing terminal user at work.
A) it supports to control whether to allow the manual patching bugs of terminal according to the period.
B) it supports to control whether to allow the manual patching bugs of terminal according to loophole rank.
C) it supports to control whether to allow the manual patching bugs of terminal according to grouping.
6. terminal user is forbidden to ignore high-risk loophole, security risk is left.
7. patch is allowed to come into force in time.
Terminal user is reminded to restart a) patch is installed after.
B) it is restarted automatically after patch being installed.
It can realize that administrator to the Precise control of loophole repair process management, reduces network management using the scheme of the application Work requirement to administrative staff, reduces network management maintenance work amoun, improve enterprise's the whole network loophole repair efficiency and Validity has saved the network management job costs of enterprise.
Referring to Figure 12, the embodiment of the invention also provides a kind of electronic equipment 60, which includes:
At least one processor;And
The memory being connect at least one processor communication;Wherein,
The memory is stored with the instruction that can be executed by least one processor, and the instruction is by least one processor It executes, so that at least one processor is able to carry out the loophole remediation management method refined in preceding method embodiment.
The embodiment of the invention also provides a kind of non-transient computer readable storage medium, the non-transient computer is readable to be deposited Storage media stores computer instruction, and the computer instruction is for executing the computer in preceding method embodiment.
The embodiment of the invention also provides a kind of computer program product, the computer program product is non-temporary including being stored in Calculation procedure on state computer readable storage medium, the computer program include program instruction, when the program instruction is calculated When machine executes, the loophole remediation management method for the fining for executing the computer in preceding method embodiment.
The method that Figure 11 shown device can execute Fig. 1-10 illustrated embodiment, the part that the present embodiment is not described in detail, It can refer to the related description to Fig. 1-10 illustrated embodiment.Details are not described herein.
Below with reference to Figure 12, it illustrates the structural representations for the electronic equipment 60 for being suitable for being used to realize the embodiment of the present disclosure Figure.Electronic equipment in the embodiment of the present disclosure can include but is not limited to such as mobile phone, laptop, digital broadcasting and connect Receive device, PDA (personal digital assistant), PAD (tablet computer), PMP (portable media player), car-mounted terminal (such as vehicle Carry navigation terminal) etc. mobile terminal and such as number TV, desktop computer etc. fixed terminal.Electricity shown in Figure 12 Sub- equipment is only an example, should not function to the embodiment of the present disclosure and use scope bring any restrictions.
As shown in figure 12, electronic equipment 60 may include processing unit (such as central processing unit, graphics processor etc.) 601, random access can be loaded into according to the program being stored in read-only memory (ROM) 602 or from storage device 608 Program in memory (RAM) 603 and execute various movements appropriate and processing.In RAM 603, it is also stored with electronic equipment Various programs and data needed for 60 operations.Processing unit 601, ROM 602 and RAM 603 are connected with each other by bus 604. Input/output (I/O) interface 605 is also connected to bus 604.
In general, following device can connect to I/O interface 605: including such as touch screen, touch tablet, keyboard, mouse, figure As the input unit 606 of sensor, microphone, accelerometer, gyroscope etc.;Including such as liquid crystal display (LCD), loudspeaking The output device 607 of device, vibrator etc.;Storage device 608 including such as tape, hard disk etc.;And communication device 609.It is logical T unit 609 can permit electronic equipment 60 and wirelessly or non-wirelessly be communicated with other equipment to exchange data.Although Figure 11 shows The electronic equipment 60 with various devices is gone out, it should be understood that being not required for implementing or having all devices shown. It can alternatively implement or have more or fewer devices.
Particularly, in accordance with an embodiment of the present disclosure, it may be implemented as computer above with reference to the process of flow chart description Software program.For example, embodiment of the disclosure includes a kind of computer program product comprising be carried on computer-readable medium On computer program, which includes the program code for method shown in execution flow chart.In such reality It applies in example, which can be downloaded and installed from network by communication device 609, or from storage device 608 It is mounted, or is mounted from ROM 602.When the computer program is executed by processing unit 601, the embodiment of the present disclosure is executed Method in the above-mentioned function that limits.
It should be noted that the above-mentioned computer-readable medium of the disclosure can be computer-readable signal media or meter Calculation machine readable storage medium storing program for executing either the two any combination.Computer readable storage medium for example can be --- but not Be limited to --- electricity, magnetic, optical, electromagnetic, infrared ray or semiconductor system, device or device, or any above combination.Meter The more specific example of calculation machine readable storage medium storing program for executing can include but is not limited to: have the electrical connection, just of one or more conducting wires Taking formula computer disk, hard disk, random access storage device (RAM), read-only memory (ROM), erasable type may be programmed read-only storage Device (EPROM or flash memory), optical fiber, portable compact disc read-only memory (CD-ROM), light storage device, magnetic memory device, Or above-mentioned any appropriate combination.In the disclosure, computer readable storage medium can be it is any include or storage journey The tangible medium of sequence, the program can be commanded execution system, device or device use or in connection.And at this In open, computer-readable signal media may include in a base band or as the data-signal that carrier wave a part is propagated, In carry computer-readable program code.The data-signal of this propagation can take various forms, including but not limited to Electromagnetic signal, optical signal or above-mentioned any appropriate combination.Computer-readable signal media can also be computer-readable and deposit Any computer-readable medium other than storage media, the computer-readable signal media can send, propagate or transmit and be used for By the use of instruction execution system, device or device or program in connection.Include on computer-readable medium Program code can transmit with any suitable medium, including but not limited to: electric wire, optical cable, RF (radio frequency) etc. are above-mentioned Any appropriate combination.
Above-mentioned computer-readable medium can be included in above-mentioned electronic equipment;It is also possible to individualism, and not It is fitted into the electronic equipment.
Above-mentioned computer-readable medium carries one or more program, when said one or multiple programs are by the electricity When sub- equipment executes, so that the electronic equipment: obtaining at least two internet protocol addresses;Send to Node evaluation equipment includes institute State the Node evaluation request of at least two internet protocol addresses, wherein the Node evaluation equipment is internet from described at least two In protocol address, chooses internet protocol address and return;Receive the internet protocol address that the Node evaluation equipment returns;Its In, the fringe node in acquired internet protocol address instruction content distributing network.
Alternatively, above-mentioned computer-readable medium carries one or more program, when said one or multiple programs When being executed by the electronic equipment, so that the electronic equipment: receiving the Node evaluation including at least two internet protocol addresses and request; From at least two internet protocol address, internet protocol address is chosen;Return to the internet protocol address selected;Wherein, The fringe node in internet protocol address instruction content distributing network received.
The calculating of the operation for executing the disclosure can be write with one or more programming languages or combinations thereof Machine program code, above procedure design language include object oriented program language-such as Java, Smalltalk, C+ +, it further include conventional procedural programming language-such as " C " language or similar programming language.Program code can Fully to execute, partly execute on the user computer on the user computer, be executed as an independent software package, Part executes on the remote computer or executes on a remote computer or server completely on the user computer for part. In situations involving remote computers, remote computer can pass through the network of any kind --- including local area network (LAN) Or wide area network (WAN)-is connected to subscriber computer, or, it may be connected to outer computer (such as utilize Internet service Provider is connected by internet).
Flow chart and block diagram in attached drawing are illustrated according to the system of the various embodiments of the disclosure, method and computer journey The architecture, function and operation in the cards of sequence product.In this regard, each box in flowchart or block diagram can generation A part of one module, program segment or code of table, a part of the module, program segment or code include one or more use The executable instruction of the logic function as defined in realizing.It should also be noted that in some implementations as replacements, being marked in box The function of note can also occur in a different order than that indicated in the drawings.For example, two boxes succeedingly indicated are actually It can be basically executed in parallel, they can also be executed in the opposite order sometimes, and this depends on the function involved.Also it to infuse Meaning, the combination of each box in block diagram and or flow chart and the box in block diagram and or flow chart can be with holding The dedicated hardware based system of functions or operations as defined in row is realized, or can use specialized hardware and computer instruction Combination realize.
Being described in unit involved in the embodiment of the present disclosure can be realized by way of software, can also be by hard The mode of part is realized.Wherein, the title of unit does not constitute the restriction to the unit itself under certain conditions, for example, the One acquiring unit is also described as " obtaining the unit of at least two internet protocol addresses ".
It should be appreciated that each section of the invention can be realized with hardware, software, firmware or their combination.
The above description is merely a specific embodiment, but scope of protection of the present invention is not limited thereto, any In the technical scope disclosed by the present invention, any changes or substitutions that can be easily thought of by those familiar with the art, all answers It is included within the scope of the present invention.Therefore, protection scope of the present invention should be subject to the protection scope in claims.

Claims (29)

1. a kind of loophole remediation management method of fining, including server end configure correcting strategy, terminal downloads simultaneously save plan Slightly, terminal loads strategy is simultaneously repaired according to Policy Filtering patch, which is characterized in that the server end configures correcting strategy Include:
Loophole repair time is set;
And/or the software type that category setting is repaired;
And/or the loophole range repaired by rank setting;
And/or setting excludes the patch for having compatibling problem or the only patch of installation provision;
And/or the loophole reparation limitation of setting terminal;
And/or setting patch downloads erection sequence;
And/or setting patch installs the mode that back operation system is restarted.
2. the method according to claim 1, wherein the setting loophole repair time is to be selected in a manner of selecting one It selects the following terms and carries out corresponding configuration:
It closes and repairs;
It is automatically repaired mode;
Periodically repair mode and regular maintenance frequency and time setting;
Mode and the setting of self defined time section are repaired according to the time period.
3. the method according to claim 1, wherein the software type that category setting is repaired is with multiselect The mode software that selects following loophole to repair type and its covered:
Operating system class;
Microsoft Office class;
Third party software.
4. the method according to claim 1, wherein the loophole range repaired by rank setting is with multiselect Mode select following loophole rank:
It is high-risk;
It is optional high-risk;
Other and functional patch.
5. the method according to claim 1, wherein the setting excludes the patch for having compatibling problem or only installs Defined patch, comprising:
Open or close patch limitation function;And when opening patch limitation function, Exclude Lists are selected in a manner of selecting one Or include list;And when selecting Exclude Lists, the problematic list of patches to be excluded is set;And when selection includes column When table, the list of patches of only installation provision is set.
6. the method according to claim 1, wherein the loophole reparation of the setting terminal is limited to multiselect Mode selects following prohibitive behavior:
Forbid in terminal disregards patch;
Forbid in the manual patching bugs of terminal;And when selection is forbidden selecting in a manner of multiselect in the manual patching bugs of terminal It selects and configures the following contents:
Forbid according to the time period;When choosing this option, the period is set;
Forbid the loophole rank repaired: high-risk, optional high-risk or other and functional patch.
7. the method according to claim 1, wherein it is the side to select one that the setting patch, which downloads erection sequence, Formula selects the following terms:
It the downloading of patch and installation while carrying out;
After patch has all been downloaded, then install one by one.
8. the method according to claim 1, wherein the setting patch installs the mode that back operation system is restarted Mode is restarted to choose whether setting operating system, and when selection is, the following terms is selected in a manner of selecting one:
Prompting is restarted;
It is restarted automatically.
9. according to the method described in claim 8, it is characterized in that, further selection mentions when having selected the prompting to restart The Interval Reminder time is further arranged when having selected the Interval Reminder in primary or Interval Reminder of waking up.
10. according to the method described in claim 8, it is characterized in that, further setting is heavy when having selected described be restarted automatically The count down time opened.
11. according to the method described in claim 8, it is characterized in that, the setting patch installs the side that back operation system is restarted Formula is to choose whether setting operating system to restart mode, when selection is, if further including that patch is completed to be already expired when installation Same day reboot time, then be arranged the period S restarted at the appointed time section, and after setting, system can be in second day weight Period S is opened to be restarted automatically.
12. the method according to claim 1, wherein further including whole lockings, all unlock and recovery default plan Option slightly, when all locking in choosing, above-mentioned all correcting strategy configuration items will no longer be able to modify, and prevent maloperation or evil Meaning operation bring reparation loss;When all unlocking in choosing, above-mentioned all configuration items locked will open modification function, permit Perhaps normal modification;When restoring default policy in choosing, above-mentioned all configuration items will revert to preset default configuration.
13. -12 any method according to claim 1, which is characterized in that further include carrying out the claim 1- After the setting of 12 any the methods, corresponding setting is stored.
14. a kind of loophole remediation management device of fining characterized by comprising
Component is arranged in repair time, for allowing administrator setting loophole repair time;
And/or component is arranged in loophole type, the software type for allowing the setting of administrator's category to repair;
And/or component is arranged in loophole rank, the loophole range for allowing administrator to repair by rank setting;
And/or patch limitation setting component, patch for allowing administrator setting to exclude to have compatibling problem or only installation provision Patch;
And/or terminal loophole reparation limits component, for allowing the loophole reparation of administrator setting terminal to limit;
And/or component is arranged in patch downloading erection sequence, for allowing the downloading erection sequence of administrator setting patch;
And/or patch installation back operation system restarts setting component, for allowing administrator setting patch to install back operation system weight The mode opened.
15. device according to claim 14, which is characterized in that the setting loophole repair time is in a manner of selecting one Selection the following terms simultaneously carries out corresponding configuration:
It closes and repairs;Or
It is automatically repaired mode;Or
Periodically repair mode and regular maintenance frequency and time setting;Or
Mode and the setting of self defined time section are repaired according to the time period.
16. device according to claim 14, which is characterized in that the software type that the category setting is repaired is with more The software that the mode of choosing selects following loophole to repair type and its covered:
Operating system class;
Microsoft Office class;
Third party software.
17. device according to claim 14, which is characterized in that the loophole range repaired by rank setting is with more The mode of choosing selects following loophole rank:
It is high-risk;
It is optional high-risk;
Other and functional patch.
18. device according to claim 14, which is characterized in that the setting excludes the patch for having compatibling problem or only pacifies Patch as defined in filling, comprising:
Open or close patch limitation function;And when opening patch limitation function, Exclude Lists are selected in a manner of selecting one Or include list;And when selecting Exclude Lists, the problematic list of patches to be excluded is set;And when selection includes column When table, the list of patches of only installation provision is set.
19. device according to claim 14, which is characterized in that the loophole reparation of the setting terminal is limited to multiselect Mode select following prohibitive behavior:
Forbid in terminal disregards patch;
Forbid in the manual patching bugs of terminal;And when selection is forbidden selecting in a manner of multiselect in the manual patching bugs of terminal It selects and configures the following contents:
Forbid according to the time period;When choosing this option, the period is set;
Forbid the loophole rank repaired: high-risk, optional high-risk or other and functional patch.
20. device according to claim 14, which is characterized in that the setting patch downloading erection sequence is to select one Mode selects the following terms:
It the downloading of patch and installation while carrying out;
After patch has all been downloaded, then install one by one.
21. device according to claim 14, which is characterized in that the setting patch installs the side that back operation system is restarted Formula is to choose whether setting operating system to restart mode, and when selection is, the following terms is selected in a manner of selecting one:
Prompting is restarted;
It is restarted automatically.
22. device according to claim 21, which is characterized in that when having selected the prompting to restart, further select Primary or Interval Reminder is reminded, when having selected the Interval Reminder, the Interval Reminder time is further set.
23. device according to claim 21, which is characterized in that when having selected described be restarted automatically, be further arranged The count down time restarted.
24. device according to claim 14, which is characterized in that the setting patch installs the side that back operation system is restarted Formula is to choose whether setting operating system to restart mode, when selection is, if further including that patch is completed to be already expired when installation Same day reboot time, then be arranged the period S restarted at the appointed time section, and after setting, system can be in second day weight Period S is opened to be restarted automatically.
25. device according to claim 14, which is characterized in that further include whole lockings, all unlock and recovery default The function button of strategy, when clicking whole lock function buttons, modification function is will not be provided in above-mentioned all components, is prevented Maloperation or malicious operation bring reparation loss;When clicking whole unlocking function buttons, above-mentioned all groups locked Part will be opened and modify function, and normal modification is allowed;When clicking recovery default policy function button, above-mentioned all components content Preset default configuration will be reverted to.
26. any device of 4-25 according to claim 1, which is characterized in that further include carrying out the claim After the setting of any described device of 14-25, corresponding setting is stored.
27. a kind of electronic equipment, which is characterized in that the electronic equipment includes:
At least one processor;And
The memory being connect at least one described processor communication;Wherein,
The memory is stored with the instruction that can be executed by least one described processor, and described instruction is by described at least one It manages device to execute, so that at least one described processor is able to carry out a kind of fining described in aforementioned any claim 1-13 Loophole remediation management method.
28. a kind of non-transient computer readable storage medium, which is characterized in that non-transient computer readable storage medium storage Computer instruction, the computer instruction is for making the computer execute a kind of fining described in aforementioned any claim 1-13 Loophole remediation management method.
29. a kind of computer program product, which is characterized in that including the meter being stored in non-transient computer readable storage medium Program is calculated, which includes program instruction, when the program instruction is computer-executed, executes the computer aforementioned A kind of loophole remediation management method of fining described in any claim 1-13.
CN201910493173.4A 2019-06-06 2019-06-06 The loophole remediation management method, apparatus and electronic equipment of fining Pending CN110413305A (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201910493173.4A CN110413305A (en) 2019-06-06 2019-06-06 The loophole remediation management method, apparatus and electronic equipment of fining

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201910493173.4A CN110413305A (en) 2019-06-06 2019-06-06 The loophole remediation management method, apparatus and electronic equipment of fining

Publications (1)

Publication Number Publication Date
CN110413305A true CN110413305A (en) 2019-11-05

Family

ID=68358448

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201910493173.4A Pending CN110413305A (en) 2019-06-06 2019-06-06 The loophole remediation management method, apparatus and electronic equipment of fining

Country Status (1)

Country Link
CN (1) CN110413305A (en)

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN112286571A (en) * 2020-09-25 2021-01-29 长沙市到家悠享网络科技有限公司 Vulnerability repairing method and device and storage medium
WO2021259109A1 (en) * 2020-06-24 2021-12-30 中兴通讯股份有限公司 Patch loading method, network element, and computer-readable storage medium

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20050005159A1 (en) * 2003-07-01 2005-01-06 Oliphant Brett M. Vulnerability and remediation database
CN107463428A (en) * 2017-06-29 2017-12-12 北京北信源软件股份有限公司 A kind of patch management method and apparatus being used under virtualized environment
CN108363926A (en) * 2017-10-19 2018-08-03 北京安天网络安全技术有限公司 A kind of loophole defence method and system

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20050005159A1 (en) * 2003-07-01 2005-01-06 Oliphant Brett M. Vulnerability and remediation database
CN107463428A (en) * 2017-06-29 2017-12-12 北京北信源软件股份有限公司 A kind of patch management method and apparatus being used under virtualized environment
CN108363926A (en) * 2017-10-19 2018-08-03 北京安天网络安全技术有限公司 A kind of loophole defence method and system

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
学建筑的桃桃: "怎么关闭360漏洞修复", 《HTTPS://JINGYAN.BAIDU.COM/ARTICLE/6B97984DF241541CA2B0BF94.HTML》 *

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2021259109A1 (en) * 2020-06-24 2021-12-30 中兴通讯股份有限公司 Patch loading method, network element, and computer-readable storage medium
CN112286571A (en) * 2020-09-25 2021-01-29 长沙市到家悠享网络科技有限公司 Vulnerability repairing method and device and storage medium

Similar Documents

Publication Publication Date Title
US10275343B2 (en) Application programming interface for providing access to computing platform definitions
EP2210206B1 (en) License activation and management
CN1842031B (en) Data processing method and system
CN103299314B (en) Real-time APP privacy control panel based on cloud
KR101562445B1 (en) Dynamic device configuration using predicates
US10469315B2 (en) Using computing platform definitions to provide segmented computing platforms in a computing system
US8843122B1 (en) Mobile phone controls preprocessor
US9477530B2 (en) Automated provisioning and management of cloud services
CN104462961A (en) Mobile terminal and privacy permission optimizing method thereof
US20090113414A1 (en) Computer administration deployment system
CN106504088A (en) A kind of method and system that realizes quantifying transaction in removable computing device
CN110413305A (en) The loophole remediation management method, apparatus and electronic equipment of fining
CN108804175A (en) Multilingual adaptation method, mobile terminal and computer readable storage medium
CN102164179B (en) Method and system for arranging terminal application based on network
CN110175178A (en) A kind of method of data processing, node device and system
CN109766103A (en) Method and apparatus for handling information
CN110008694A (en) A kind of application security control method, device, equipment and readable storage medium storing program for executing
CN101963913B (en) Method for online evolution of component based on transactions
US7523506B1 (en) Approach for managing functionalities within a system
CN109542432A (en) Air control rule editing method and terminal device
Brucker et al. A framework for secure service composition
CN109241727B (en) Permission setting method and device
CN107368735A (en) One kind applies installation method, mobile terminal and computer-readable recording medium
US20070185792A1 (en) Method and system for assisting in compiling employee tax deduction
Bott Introducing Windows 10 for IT Professionals

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication
SE01 Entry into force of request for substantive examination
SE01 Entry into force of request for substantive examination
RJ01 Rejection of invention patent application after publication

Application publication date: 20191105

RJ01 Rejection of invention patent application after publication