CN102957566A - Enterprise intranet control server - Google Patents

Enterprise intranet control server Download PDF

Info

Publication number
CN102957566A
CN102957566A CN2012104149177A CN201210414917A CN102957566A CN 102957566 A CN102957566 A CN 102957566A CN 2012104149177 A CN2012104149177 A CN 2012104149177A CN 201210414917 A CN201210414917 A CN 201210414917A CN 102957566 A CN102957566 A CN 102957566A
Authority
CN
China
Prior art keywords
corporate intranet
project
strategy
detection result
safety detection
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Granted
Application number
CN2012104149177A
Other languages
Chinese (zh)
Other versions
CN102957566B (en
Inventor
于新卫
邓振波
苏云琳
黄鉴廷
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Qianxin Technology Group Co Ltd
Original Assignee
Beijing Qihoo Technology Co Ltd
Qizhi Software Beijing Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Beijing Qihoo Technology Co Ltd, Qizhi Software Beijing Co Ltd filed Critical Beijing Qihoo Technology Co Ltd
Priority to CN201210414917.7A priority Critical patent/CN102957566B/en
Publication of CN102957566A publication Critical patent/CN102957566A/en
Application granted granted Critical
Publication of CN102957566B publication Critical patent/CN102957566B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Images

Abstract

The invention discloses an enterprise intranet control server. The enterprise intranet control server comprises a WEB server and a database server, the WEB server is suitable for getting a safety detection result of an enterprise intranet terminal, receiving a preset safety strategy level, receiving a matching result from the database server and repairing the safety detection result by adopting a repair strategy corresponding to a repair project according to the matching result, wherein the safety strategy level comprises the repair project and the repair strategy corresponding to the repair project; and the database server is suitable for saving the safety detection result of the enterprise intranet terminal and the preset safety strategy level and matching the safety detection result of the enterprise intranet terminal with the safety strategy level, wherein the matching is used for judging whether the safety detection result of the enterprise intranet terminal has a corresponding repair project or not. The enterprise intranet control server disclosed by the invention can improve enterprise network management efficiency and reduce network management cost.

Description

The corporate intranet Control Server
Technical field
The present invention relates to the computer security technique field, be specifically related to a kind of corporate intranet Control Server.
Background technology
Along with the development of information age, increasing company information is placed in enterprise's inside and outside network environment, and network management becomes the problem that enterprise security can not be ignored.
Network management refers to plan, supervise, control the use of Internet resources and the comings and goings of network, so that the performance of network reaches optimum.In fact, network management technology is the development that is accompanied by computer, network and the communication technology, and the two complements each other.Classify from the network management category, can be divided into the management to net " road ": namely manage for backbone networks such as switch, routers; Management to access device: namely inner PC, server, switch etc. are managed; Management to behavior: i.e. use for the user manages; Management to assets: namely add up the information of IT software and hardware etc.Generally speaking, network management has five functional: failure management, configuration management, performance management, safety management and accounting management.
At present, the safety problem of all kinds that occurs in the enterprise network, need the network manager manually to repair network security problem, show the tradition leak reparation tabulation according to the present invention with reference to Fig. 1, the network manager need to understand first the description of patch, select uninstalled client computer, determine whether will repair these leaks again.To be the network manager may not know this reparation of which problem in the face of in numerous safety problems to the problem that may occur like this, repaired what risk that can occur other after which safety problem.In addition, in the situation that safety problem is many, the network manager also needs to repair one by one each safety problem, and operation is comparatively complicated and waste time and energy.
Therefore, those skilled in the art's technical problem in the urgent need to address is: a kind of corporate intranet terminal security maintenance mechanism is provided, thereby improves enterprise network management efficient, save network administration cost.
Summary of the invention
In view of the above problems, the present invention has been proposed in order to a kind of a kind of corporate intranet Control Server that overcomes the problems referred to above or address the above problem at least in part is provided.
According to the present invention, a kind of corporate intranet Control Server is provided, comprise WEB server, database server, wherein,
Described WEB server is suitable for obtaining the safety detection result of corporate intranet terminal and receives default security policy grade, and wherein, described security policy grade comprises rehablitation project and repairs accordingly strategy with rehablitation project; Reception is from the matching result of database server; Adopt according to described matching result and describedly to repair accordingly strategy with rehablitation project and repair safety detection result;
Described database server is suitable for preserving the safety detection result of described corporate intranet terminal and default security policy grade, and the safety detection result of described corporate intranet terminal is mated with the security policy grade of presetting; Wherein, whether described coupling exists corresponding rehablitation project for the safety detection result of judging described corporate intranet terminal.
Alternatively, described WEB server comprises:
Corporate intranet end results acquisition module is suitable for obtaining the safety detection result of corporate intranet terminal;
Matching module is suitable for the safety detection result of described corporate intranet terminal is mated with the security policy grade of presetting; Wherein, described security policy grade comprises that rehablitation project reaches and rehablitation project is repaired strategy accordingly, and whether described coupling exists corresponding rehablitation project for the safety detection result of judging described corporate intranet terminal, if then call the reparation module;
The reparation module is suitable for adopting described and rehablitation project is repaired strategy reparation accordingly.
Alternatively, described WEB server also comprises:
Display module is suitable for showing the reparation result of described rehablitation project.
Alternatively, described reparation strategy comprises automatic reparation strategy, and described reparation module further comprises:
Safety detection result sends submodule, is suitable for when there is corresponding rehablitation project in the safety detection result of described corporate intranet terminal, and the reparation strategy of the rehablitation project that described safety detection result is corresponding is sent to the corporate intranet terminal;
Repair the result and receive submodule, be suitable for receiving the reparation result that the corporate intranet terminal is returned, described reparation result is the result who is repaired the safety detection result corresponding with rehablitation project by the corporate intranet terminal according to described automatic reparation strategy.
Alternatively, described corporate intranet Control Server also comprises publisher server, and described publisher server is connected with described corporate intranet terminal, and what be suitable for the WEB server is issued repairs accordingly strategy with rehablitation project and be sent to the corporate intranet terminal.
Alternatively, described rehablitation project comprises the leak rehablitation project, wooden horse killing project, plug-in unit cleaning project, system safety project, security configuration project.
Alternatively, described security policy grade comprises advanced security strategy grade, intermediate security policy grade, rudimentary security policy grade and custom security strategy grade.
Alternatively, described safety detection result is the physical examination result to default project.
According to corporate intranet Control Server of the present invention the reparation strategy can be set once by the rehablitation project that is checked through for each corporate intranet terminal, solve thus the efficient that the each all problems of manual maintenance system of network manager have obtained the enterprise safety management, reduced the beneficial effect of enterprise IT management cost.
Above-mentioned explanation only is the general introduction of technical solution of the present invention, for can clearer understanding technological means of the present invention, and can be implemented according to the content of specification, and for above and other objects of the present invention, feature and advantage can be become apparent, below especially exemplified by the specific embodiment of the present invention.
Description of drawings
By reading hereinafter detailed description of the preferred embodiment, various other advantage and benefits will become cheer and bright for those of ordinary skills.Accompanying drawing only is used for the purpose of preferred implementation is shown, and does not think limitation of the present invention.And in whole accompanying drawing, represent identical parts with identical reference symbol.In the accompanying drawings:
Fig. 1 shows the tradition leak reparation tabulation according to the present invention;
Fig. 2 shows the flow chart of steps of a kind of according to an embodiment of the invention corporate intranet terminal security maintaining method embodiment 1;
Fig. 3 shows according to an embodiment of the invention security centre's Organization Chart of enterprise network;
Fig. 4 shows the according to an embodiment of the invention interaction figure at enterprise network security center;
Fig. 5 shows the flow chart of steps of a kind of according to an embodiment of the invention corporate intranet terminal security maintaining method embodiment 2;
Fig. 6 shows the structured flowchart of a kind of according to an embodiment of the invention corporate intranet terminal security attending device embodiment;
Fig. 7 shows the structured flowchart of a kind of according to an embodiment of the invention corporate intranet Control Server embodiment.
Embodiment
Exemplary embodiment of the present disclosure is described below with reference to accompanying drawings in more detail.Although shown exemplary embodiment of the present disclosure in the accompanying drawing, yet should be appreciated that and to realize the disclosure and the embodiment that should do not set forth limits here with various forms.On the contrary, it is in order to understand the disclosure more thoroughly that these embodiment are provided, and can with the scope of the present disclosure complete convey to those skilled in the art.
One of core idea of the embodiment of the invention is, with enterprise security manager software intelligent automation, the network manager is only with security policy grade once is set, arrange for the rehablitation project in the security policy grade in advance and repair strategy, server just can be repaired according to security policy grade when finding all kinds of dangerous automatically, and do not need the network manager manually to repair various safety problems, the network manager of side processes all kinds of safety problems in the enterprise network, simple efficient, intelligence makes network manager's supervising the network simpler automatically.
With reference to Fig. 2, show the flow chart of steps of a kind of according to an embodiment of the invention corporate intranet terminal security maintaining method embodiment 1, specifically can may further comprise the steps:
Step 201: the safety detection result that obtains the corporate intranet terminal;
In specific implementation, an enterprise network can comprise one or more corporate intranet terminals, each corporate intranet terminal relies on fail-safe software and regularly carries out safety detection, described safety detection is the health check-up to default project in the system, and safety detection result (physical examination result) is reported in the server.
As a kind of preferred exemplary of the present embodiment, the safety detection result of corporate intranet terminal can comprise security breaches, dangerous of wooden horse, installation difference comment whether plug-in unit, real-time protection close, the dangerous contents such as (being tampered such as homepage) of system.
Step 202: safety detection result and the security policy grade of presetting of described corporate intranet terminal are mated; Wherein, described security policy grade comprises that rehablitation project reaches and rehablitation project is repaired strategy accordingly, and whether described coupling exists corresponding rehablitation project for the safety detection result of judging described corporate intranet terminal;
Particularly, security strategy refers to network manager or CIO(Chief InformationOfficer, chief information officer) the action strategy formulated according to institutional risk and Security Target.In embodiments of the present invention, security policy grade can be divided into advanced security strategy grade, intermediate security policy grade, rudimentary security policy grade and custom security strategy grade, can comprise rehablitation project and repair accordingly strategy with rehablitation project for every kind of security policy grade, wherein, custom security strategy grade is that the keeper sets the reparation strategy for each rehablitation project in advance according to actual conditions.
As a kind of example, various rehablitation projects in advanced security strategy grade, intermediate security policy grade, the rudimentary security policy grade and repair accordingly strategy as shown in the following Table 1 with rehablitation project:
Figure BDA00002306920900051
Figure BDA00002306920900061
Figure BDA00002306920900071
Figure BDA00002306920900091
Table 1
As can be seen from Table 1, rehablitation project can comprise the leak rehablitation project, wooden horse killing project, and plug-in unit cleaning project, the system safety project, the security configuration project for every kind of rehablitation project, has concrete reparation item and reaches and a reparation corresponding reparation strategy;
Wherein, the leak reparation refers to the reparation to system vulnerability, system vulnerability refers to that operating system is in the mistake of the defective in the logical design or generation when writing, this defective or mistake can be utilized by illegal person or computer hacker, attack or control whole computer by implanting the modes such as wooden horse, virus, thereby steal capsule information and information in the computer, even destruction operating system, as a kind of preferred exemplary of the present embodiment, system vulnerability can comprise detection Loopholes of OS, office leak, third party's security update etc.;
The wooden horse killing refers to the killing to trojan horse program, trojan horse program is present popular virus document, from general viral different, it can self-reproduction, do not remove to infect alternative document " deliberately " yet, it is by pretending self to attract the user to download execution, provide and open by kind of the door of person's computer to executing kind of a wooden horse person, make and execute kind of person and can damage arbitrarily, steal by kind of person's file, even remote control is by kind of person's computer, a kind of preferred exemplary as the present embodiment, trojan horse program can comprise the detailed programs under the wooden horse killing project shown in the table 1, for example cloud security detection system key position risk, whether detect the browser shortcut is tampered, detect IE homepage relevant item risk, detect default value risk corresponding to " replacement web setting " etc.;
The plug-in unit cleaning, refer to the cleaning to plug-in unit, plug-in unit refers to the program that a kind of application programming interfaces of following certain standard are write out, some program needs the support of some plug-in units in the computer system, wherein these plug-in unit classifications are various, having some Malwares after computer is poisoned attacks computer, these malicious plugins can be downloaded Virus Info, computer system is destroyed, control etc., a kind of preferred exemplary as the present embodiment, plug-in unit can comprise the plug-in unit cleaning project shown in the table 1, for example detects dynamic load item risk, detect the poor plug-in unit risk of commenting, detect ActiveX control risk etc.;
System safety, refer within systems life cycle, use system safety engineering and system security management method, dangerous matter sources in the identification system, and take effective control measure to make it dangerous minimum, thereby make system in performance, time and the cost scope of regulation, reach best safe coefficient, as a kind of preferred exemplary of the present embodiment, system safety can comprise the system safety project shown in the table 1, such as detecting the remote desktop risk, detecting Windows self-starting item risk etc.;
Security configuration refers to affect the configuration of system safety, and as a kind of preferred exemplary of the present embodiment, security configuration can comprise the security configuration project shown in the table 1, such as opening the wooden horse fire compartment wall, opening net purchase bodyguard etc.
In specific implementation, the network manager arranges security policy grade in advance in server, server receives the safety detection result of corporate intranet terminal, the safety detection result of described corporate intranet terminal can comprise a plurality of dangerous, each dangerous item and the rehablitation project in the security policy grade of presetting are mated, judge whether the safety detection result of corporate intranet terminal exists corresponding rehablitation project.
Step 203: if there is corresponding rehablitation project in the safety detection result of described corporate intranet terminal, then adopt rehablitation project to repair accordingly strategy reparation;
In a preferred embodiment of the present invention, described reparation strategy can comprise automatic reparation strategy, and step 203 can comprise following substep:
Substep S11: if there is corresponding rehablitation project in the safety detection result of described corporate intranet terminal, the reparation strategy of the rehablitation project that described safety detection result is corresponding is sent to the corporate intranet terminal;
Substep S12: receive the reparation result that the corporate intranet terminal is returned, described reparation result is the result who is repaired the safety detection result corresponding with rehablitation project by the corporate intranet terminal according to described automatic reparation strategy.
Wherein, described automatic reparation strategy can comprise automatic reparation and automatically open.
In specific implementation, described reparation strategy can also comprise ignores strategy, if there is corresponding rehablitation project in the safety detection result of described corporate intranet terminal, and the reparation strategy of described rehablitation project is when ignoring strategy, server with described ignore the operation be sent to the network manager, repair described safety detection result by the network manager.
For example: safety detection result is to be checked through a difference to comment plug-in unit, and id is the 000328:11 plug-in unit.If it is to ignore that the detection difference of the plug-in unit killing project that arranges in security strategy is commented the reparation strategy of plug-in unit risk, then can generate information, the informing network administrator hand is cleared up described difference and is commented plug-in unit.
In fact, step 101 can be finished at the WEB server end, and step 102 can be finished in database server side, and step 103 can be finished at the publisher server end; Show according to an embodiment of the invention security centre's Organization Chart of enterprise network with reference to Fig. 3, represented that WEB server, database server, publisher server are at the framework at enterprise network security center, can find out, the network manager is by the whole enterprise network of WEB server admin, each corporate intranet terminal in the enterprise network returns the corporate intranet end message to the WEB server by publisher server, then shows the network manager.
Show the according to an embodiment of the invention interaction figure at enterprise network security center with reference to figure 4, represented that the WEB server, database server, publisher server, corporate intranet terminal, network manager of Fig. 3 are in the reciprocal process at enterprise network security center.Can find out, the network manager comes the management enterprise network security by security policy grade is set, the WEB server safety detection result security strategy of Administrator is top and the corporate intranet terminal received is kept in the database server, database server is after the safety detection result that receives each corporate intranet terminal, inquire about the security policy grade of described storage, judge that whether described safety detection result is complementary with the rehablitation project of default security policy grade, and described matching result returned in the WEB server, described matching result can comprise and have occurrence and do not have occurrence; If there is occurrence, then obtains the reparation strategy of described safety detection result in default rehablitation project, and described reparation strategy is returned in the WEB server; If repairing tactful is automatically to repair strategy, the WEB server issues automatically repairs strategy to publisher server, by publisher server described issuing repaired tactful corporate intranet terminal corresponding to safety detection result that be sent to, the corporate intranet terminal is repaired in the rehablitation project dangerous automatically according to automatic reparation strategy, and the reparation result (result) of described automatic reparation strategy reported the WEB server, the WEB server is sent to database server with the result that receives and preserves; If there is not occurrence, then the WEB server returns described safety detection result to the network manager, is manually repaired by the network manager.
For example: safety detection result is to be checked through high-risk leak a: KB231243, id is 000003, the leak type is 1, if the reparation strategy of " the detection Loopholes of OS " of the leak rehablitation project of security strategy is automatic reparation, then automatically issue the operation of this leak of reparation to the corporate intranet terminal, the corporate intranet terminal is repaired described leak after receiving described reparation strategy automatically, and result is reported to server.
With reference to Fig. 5, show the flow chart of steps of a kind of according to an embodiment of the invention corporate intranet terminal security maintaining method embodiment 2, specifically can may further comprise the steps:
Step 501: the safety detection result that obtains the corporate intranet terminal;
In specific implementation, an enterprise network can comprise one or more corporate intranet terminals, each corporate intranet terminal relies on fail-safe software and regularly carries out safety detection, described safety detection is the health check-up to default project in the system, and safety detection result (physical examination result) is reported in the server.
As a kind of preferred exemplary of the present embodiment, the safety detection result of corporate intranet terminal can comprise security breaches, dangerous of wooden horse, installation difference comment whether plug-in unit, real-time protection close, the dangerous contents such as (being tampered such as homepage) of system.
Step 502: safety detection result and the security policy grade of presetting of described corporate intranet terminal are mated; Wherein, described security policy grade comprises that rehablitation project reaches and rehablitation project is repaired strategy accordingly, and whether described coupling exists corresponding rehablitation project for the safety detection result of judging described corporate intranet terminal.
Particularly, security policy grade can be divided into advanced security strategy grade, intermediate security policy grade, rudimentary security policy grade and custom security strategy grade, can comprise rehablitation project and repair accordingly strategy with rehablitation project for every kind of security policy grade, wherein, rehablitation project can comprise the leak rehablitation project, wooden horse killing project, plug-in unit cleaning project, the system safety project, the security configuration project, for every kind of rehablitation project, have concrete reparation item and repair a corresponding strategy of repairing.
In specific implementation, the network manager arranges security policy grade in advance in server, server receives the safety detection result of corporate intranet terminal, the safety detection result of described corporate intranet terminal can comprise a plurality of dangerous, each dangerous item is mated with the rehablitation project in the security policy grade, judge whether the safety detection result of corporate intranet terminal exists corresponding rehablitation project.
Step 503: if there is corresponding rehablitation project in the safety detection result of described corporate intranet terminal, then adopt rehablitation project to repair accordingly strategy reparation;
In a preferred embodiment of the present invention, described reparation strategy can comprise automatic reparation strategy, and step 503 can comprise following substep:
Substep S21: if there is corresponding rehablitation project in the safety detection result of described corporate intranet terminal, the reparation strategy of the rehablitation project that described safety detection result is corresponding is sent to the corporate intranet terminal;
Substep S22: receive the reparation result that the corporate intranet terminal is returned, described reparation result is the result who is repaired the safety detection result corresponding with rehablitation project by the corporate intranet terminal according to described automatic reparation strategy.
Wherein, described automatic reparation strategy can comprise automatic reparation and automatically open.
In specific implementation, described reparation strategy can also comprise ignores strategy, if there is corresponding rehablitation project in the safety detection result of described corporate intranet terminal, and the reparation strategy of described rehablitation project for ignoring strategy is, server with described ignore the operation be sent to the network manager, repair described safety detection result by the network manager.
Step 504: the reparation result who shows described rehablitation project.
Particularly, described reparation result can comprise: the corporate intranet terminal number of enterprise network, project name, action name and the time etc. of carrying out each number of repairing the rehablitation project of strategy, described displaying, the corresponding reparation strategy of each corporate intranet terminal execution.
In specific implementation, described step 501,503,504 are arranged in the WEB server, described step 502 is arranged in database server, the keeper comes the management enterprise network security by security policy grade is set, the WEB server safety detection result security strategy of Administrator is top and the corporate intranet terminal received is kept in the database server, database server is after the safety detection result that receives each corporate intranet terminal, inquire about the security policy grade of described storage, judge that whether described safety detection result is complementary with the rehablitation project of default security policy grade, and described matching result returned in the WEB server, described matching result can comprise and have occurrence and do not have occurrence; If there is occurrence, then obtains the reparation strategy of described safety detection result in default rehablitation project, and described reparation strategy is returned in the WEB server; If repairing tactful is automatically to repair strategy, the WEB server issues automatically repairs strategy to publisher server, by publisher server described issuing repaired tactful corporate intranet terminal corresponding to safety detection result that be sent to, the corporate intranet terminal is repaired in the rehablitation project dangerous automatically according to automatic reparation strategy, and the reparation result (result) of described automatic reparation strategy reported the WEB server, the WEB server is sent to database server with the result that receives and preserves; If there is not occurrence, then the WEB server returns described safety detection result to the network manager, is manually repaired by the network manager, is showed by the WEB server at last and repairs the result.
Need to prove, for embodiment of the method, for simple description, therefore it all is expressed as a series of combination of actions, but those skilled in the art should know, the present invention is not subjected to the restriction of described sequence of movement, because according to the present invention, some step can adopt other orders or carry out simultaneously.Secondly, those skilled in the art also should know, the embodiment described in the specification all belongs to preferred embodiment, and related action and module might not be that the present invention is necessary.
With reference to Fig. 6, show the structured flowchart of a kind of according to an embodiment of the invention corporate intranet terminal security attending device embodiment, specifically can comprise with lower module:
Corporate intranet end results acquisition module 601 is suitable for obtaining the safety detection result of corporate intranet terminal;
As a kind of preferred exemplary of the present embodiment, the safety detection result of corporate intranet terminal can comprise security breaches, dangerous of wooden horse, installation difference comment whether plug-in unit, real-time protection close, the dangerous contents such as (being tampered such as homepage) of system.
Matching module 602 is suitable for the safety detection result of described corporate intranet terminal is mated with the security policy grade of presetting; Wherein, described security policy grade comprises that rehablitation project reaches and rehablitation project is repaired strategy accordingly, and whether described coupling exists corresponding rehablitation project for the safety detection result of judging described corporate intranet terminal, if then call the reparation module;
Particularly, security policy grade can be divided into advanced security strategy grade, intermediate security policy grade, rudimentary security policy grade and custom security strategy grade, can comprise rehablitation project and repair accordingly strategy with rehablitation project for every kind of security policy grade.
Rehablitation project can comprise the leak rehablitation project, wooden horse killing project, and plug-in unit cleaning project, the system safety project, the security configuration project for every kind of rehablitation project, has concrete reparation item and repairs a corresponding strategy of repairing.
Repair module 603, be suitable for adopting rehablitation project to repair accordingly strategy reparation.
In a preferred embodiment of the present invention, described reparation strategy can comprise automatic reparation strategy, repairs module 603 and can comprise following submodule:
Safety detection result sends submodule, is suitable for when there is corresponding rehablitation project in the safety detection result of described corporate intranet terminal, and the reparation strategy of the rehablitation project that described safety detection result is corresponding is sent to the corporate intranet terminal;
Repair the result and receive submodule, be suitable for receiving the reparation result that the corporate intranet terminal is returned, described reparation result is the result who is repaired the safety detection result corresponding with rehablitation project by the corporate intranet terminal according to described automatic reparation strategy.
In specific implementation, described reparation strategy can also comprise ignores strategy, if there is corresponding rehablitation project in the safety detection result of described corporate intranet terminal, and the reparation strategy of described rehablitation project for ignoring strategy is, server with described ignore the operation be sent to the network manager, repair described safety detection result by the network manager.
Display module 604 is suitable for showing the reparation result of described rehablitation project.
In specific implementation, corporate intranet end results acquisition module 601, reparation module 603, display module 604 are arranged in the WEB server, and described matching module 602 is arranged in database server.The keeper comes the management enterprise network security by security policy grade is set, the WEB server safety detection result security strategy of Administrator is top and the corporate intranet terminal received is kept in the database server, database server is after the safety detection result that receives each corporate intranet terminal, inquire about the security policy grade of described storage, judge that whether described safety detection result is complementary with the rehablitation project of default security policy grade, and described matching result returned in the WEB server, described matching result can comprise and have occurrence and do not have occurrence; If there is occurrence, then obtains the reparation strategy of described safety detection result in default rehablitation project, and described reparation strategy is returned in the WEB server; If repairing tactful is automatically to repair strategy, the WEB server issues automatically repairs strategy to publisher server, by publisher server described issuing repaired tactful corporate intranet terminal corresponding to safety detection result that be sent to, the corporate intranet terminal is repaired in the rehablitation project dangerous automatically according to automatic reparation strategy, and the reparation result (result) of described automatic reparation strategy reported the WEB server, the WEB server is sent to database server with the result that receives and preserves; If there is not occurrence, then the WEB server returns described safety detection result to the network manager, is manually repaired by the network manager, is showed by the WEB server at last and repairs the result.
For device embodiment shown in Figure 6, because itself and preceding method embodiment basic simlarity, so describe fairly simplely, relevant part gets final product referring to the part explanation of embodiment of the method.
With reference to Fig. 7, show the structured flowchart of a kind of according to an embodiment of the invention corporate intranet Control Server embodiment, specifically can comprise WEB server 701, database server 702, wherein,
Described WEB server 701 is suitable for obtaining the safety detection result of corporate intranet terminal and receives default security policy grade, and wherein, described security policy grade comprises rehablitation project and repairs accordingly strategy with rehablitation project; Reception is from the matching result of database server; Adopt according to described matching result and describedly to repair accordingly strategy with rehablitation project and repair safety detection result;
As a kind of preferred exemplary of the present embodiment, described safety detection result is that described rehablitation project can comprise the leak rehablitation project to the physical examination result of default project, wooden horse killing project, plug-in unit cleaning project, system safety project, security configuration project; Described security policy grade can comprise advanced security strategy grade, intermediate security policy grade, rudimentary security policy grade and custom security strategy grade.
In a preferred embodiment of the present invention, described WEB server 701 can also comprise such as lower module:
Corporate intranet end results acquisition module is suitable for obtaining the safety detection result of corporate intranet terminal;
Matching module is suitable for the safety detection result of described corporate intranet terminal is mated with the security policy grade of presetting; Wherein, described security policy grade comprises that rehablitation project reaches and rehablitation project is repaired strategy accordingly, and whether described coupling exists corresponding rehablitation project for the safety detection result of judging described corporate intranet terminal, if then call the reparation module;
The reparation module is suitable for adopting described and rehablitation project is repaired strategy reparation accordingly.
In a preferred embodiment of the present invention, described reparation strategy comprises automatic reparation strategy, and described reparation module can comprise following submodule:
Safety detection result sends submodule, is suitable for when there is corresponding rehablitation project in the safety detection result of described corporate intranet terminal, and the reparation strategy of the rehablitation project that described safety detection result is corresponding is sent to the corporate intranet terminal;
Repair the result and receive submodule, be suitable for receiving the reparation result that the corporate intranet terminal is returned, described reparation result is the result who is repaired the safety detection result corresponding with rehablitation project by the corporate intranet terminal according to described automatic reparation strategy.
In a preferred embodiment of the present invention, described WEB server 701 can also comprise
Display module is suitable for showing the reparation result of described rehablitation project.
Described database server 702 is suitable for preserving the safety detection result of described corporate intranet terminal and default security policy grade, and the safety detection result of described corporate intranet terminal is mated with the security policy grade of presetting; Wherein, whether described coupling exists corresponding rehablitation project for the safety detection result of judging described corporate intranet terminal.
In a preferred embodiment of the present invention, described corporate intranet Control Server can also comprise publisher server 703, described publisher server is connected with described corporate intranet terminal, and what be suitable for the WEB server is issued repairs accordingly strategy with rehablitation project and be sent to the corporate intranet terminal.
Particularly, the keeper comes the management enterprise network security by security policy grade is set, the WEB server safety detection result security strategy of Administrator is top and the corporate intranet terminal received is kept in the database server, database server is after the safety detection result that receives each corporate intranet terminal, inquire about the security policy grade of described storage, judge that whether described safety detection result is complementary with the rehablitation project of default security policy grade, and described matching result returned in the WEB server, described matching result can comprise and have occurrence and do not have occurrence; If there is occurrence, then obtains the reparation strategy of described safety detection result in default rehablitation project, and described reparation strategy is returned in the WEB server; If repairing tactful is automatically to repair strategy, the WEB server issues automatically repairs strategy to publisher server, by publisher server described issuing repaired tactful corporate intranet terminal corresponding to safety detection result that be sent to, the corporate intranet terminal is repaired in the rehablitation project dangerous automatically according to automatic reparation strategy, and the reparation result (result) of described automatic reparation strategy reported the WEB server, the WEB server is sent to database server with the result that receives and preserves; If there is not occurrence, then the WEB server returns described safety detection result to the network manager, is manually repaired by the network manager, is showed by the WEB server at last and repairs the result.
For embodiment illustrated in fig. 7, because itself and preceding method embodiment basic simlarity, so describe fairly simplely, relevant part gets final product referring to the part explanation of embodiment of the method.Each embodiment in this specification all adopts the mode of going forward one by one to describe, and what each embodiment stressed is and the difference of other embodiment that identical similar part is mutually referring to getting final product between each embodiment.
Intrinsic not relevant with any certain computer, virtual system or miscellaneous equipment with demonstration at this algorithm that provides.Various general-purpose systems also can be with using based on the teaching at this.According to top description, it is apparent constructing the desired structure of this type systematic.In addition, the present invention is not also for any certain programmed language.Should be understood that and to utilize various programming languages to realize content of the present invention described here, and the top description that language-specific is done is in order to disclose preferred forms of the present invention.
In the specification that provides herein, a large amount of details have been described.Yet, can understand, embodiments of the invention can be in the situation that there be these details to put into practice.In some instances, be not shown specifically known method, structure and technology, so that not fuzzy understanding of this description.
Similarly, be to be understood that, in order to simplify the disclosure and to help to understand one or more in each inventive aspect, in the description to exemplary embodiment of the present invention, each feature of the present invention is grouped together in single embodiment, figure or the description to it sometimes in the above.Yet the method for the disclosure should be construed to the following intention of reflection: namely the present invention for required protection requires the more feature of feature clearly put down in writing than institute in each claim.Or rather, as following claims reflected, inventive aspect was to be less than all features of the disclosed single embodiment in front.Therefore, follow claims of embodiment and incorporate clearly thus this embodiment into, wherein each claim itself is as independent embodiment of the present invention.
Those skilled in the art are appreciated that and can adaptively change and they are arranged in one or more equipment different from this embodiment the module in the equipment among the embodiment.Can be combined into a module or unit or assembly to the module among the embodiment or unit or assembly, and can be divided into a plurality of submodules or subelement or sub-component to them in addition.In such feature and/or process or unit at least some are mutually repelling, and can adopt any combination to disclosed all features in this specification (comprising claim, summary and the accompanying drawing followed) and so all processes or the unit of disclosed any method or equipment make up.Unless in addition clearly statement, disclosed each feature can be by providing identical, being equal to or the alternative features of similar purpose replaces in this specification (comprising claim, summary and the accompanying drawing followed).
In addition, those skilled in the art can understand, although embodiment more described herein comprise some feature rather than further feature included among other embodiment, the combination of the feature of different embodiment means and is within the scope of the present invention and forms different embodiment.For example, in the following claims, the one of any of embodiment required for protection can be used with compound mode arbitrarily.
All parts embodiment of the present invention can realize with hardware, perhaps realizes with the software module of moving at one or more processor, and perhaps the combination with them realizes.It will be understood by those of skill in the art that and to use in practice microprocessor or digital signal processor (DSP) to realize according to some or all some or repertoire of parts in the corporate intranet terminal security service equipment of the embodiment of the invention.The present invention can also be embodied as be used to part or all equipment or the device program (for example, computer program and computer program) of carrying out method as described herein.Such realization program of the present invention can be stored on the computer-readable medium, perhaps can have the form of one or more signal.Such signal can be downloaded from internet website and obtain, and perhaps provides at carrier signal, perhaps provides with any other form.
It should be noted above-described embodiment the present invention will be described rather than limit the invention, and those skilled in the art can design alternative embodiment in the situation of the scope that does not break away from claims.In the claims, any reference symbol between bracket should be configured to limitations on claims.Word " comprises " not to be got rid of existence and is not listed in element or step in the claim.Being positioned at word " " before the element or " one " does not get rid of and has a plurality of such elements.The present invention can realize by means of the hardware that includes some different elements and by means of the computer of suitably programming.In having enumerated the unit claim of some devices, several in these devices can be to come imbody by same hardware branch.The use of word first, second and C grade does not represent any order.Can be title with these word explanations.

Claims (8)

1. a corporate intranet Control Server comprises WEB server, database server, wherein,
Described WEB server is suitable for obtaining the safety detection result of corporate intranet terminal and receives default security policy grade, and wherein, described security policy grade comprises rehablitation project and repairs accordingly strategy with rehablitation project; Reception is from the matching result of database server; Adopt according to described matching result and describedly to repair accordingly strategy with rehablitation project and repair safety detection result;
Described database server is suitable for preserving the safety detection result of described corporate intranet terminal and default security policy grade, and the safety detection result of described corporate intranet terminal is mated with the security policy grade of presetting; Wherein, whether described coupling exists corresponding rehablitation project for the safety detection result of judging described corporate intranet terminal.
2. corporate intranet Control Server as claimed in claim 1, wherein, described WEB server comprises:
Corporate intranet end results acquisition module is suitable for obtaining the safety detection result of corporate intranet terminal;
Matching module is suitable for the safety detection result of described corporate intranet terminal is mated with the security policy grade of presetting; Wherein, described security policy grade comprises that rehablitation project reaches and rehablitation project is repaired strategy accordingly, and whether described coupling exists corresponding rehablitation project for the safety detection result of judging described corporate intranet terminal, if then call the reparation module;
The reparation module is suitable for adopting described and rehablitation project is repaired strategy reparation accordingly.
3. corporate intranet Control Server as claimed in claim 2, wherein, described WEB server also comprises:
Display module is suitable for showing the reparation result of described rehablitation project.
4. corporate intranet Control Server as claimed in claim 2, described reparation strategy comprises automatic reparation strategy, described reparation module further comprises:
Safety detection result sends submodule, is suitable for when there is corresponding rehablitation project in the safety detection result of described corporate intranet terminal, and the reparation strategy of the rehablitation project that described safety detection result is corresponding is sent to the corporate intranet terminal;
Repair the result and receive submodule, be suitable for receiving the reparation result that the corporate intranet terminal is returned, described reparation result is the result who is repaired the safety detection result corresponding with rehablitation project by the corporate intranet terminal according to described automatic reparation strategy.
5. corporate intranet Control Server as claimed in claim 1 also comprises publisher server, and described publisher server is connected with described corporate intranet terminal, and what be suitable for the WEB server is issued repairs accordingly strategy with rehablitation project and be sent to the corporate intranet terminal.
6. such as each described corporate intranet Control Server in the claim 1 to 5, wherein, described rehablitation project comprises the leak rehablitation project, wooden horse killing project, plug-in unit cleaning project, system safety project, security configuration project.
7. such as each described corporate intranet Control Server in the claim 1 to 6, wherein, described security policy grade comprises advanced security strategy grade, intermediate security policy grade, rudimentary security policy grade and custom security strategy grade.
8. such as each described corporate intranet Control Server in the claim 1 to 7, wherein, described safety detection result is the physical examination result to default project.
CN201210414917.7A 2012-10-25 2012-10-25 Enterprise intranet control server Active CN102957566B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201210414917.7A CN102957566B (en) 2012-10-25 2012-10-25 Enterprise intranet control server

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201210414917.7A CN102957566B (en) 2012-10-25 2012-10-25 Enterprise intranet control server

Publications (2)

Publication Number Publication Date
CN102957566A true CN102957566A (en) 2013-03-06
CN102957566B CN102957566B (en) 2016-06-22

Family

ID=47765831

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201210414917.7A Active CN102957566B (en) 2012-10-25 2012-10-25 Enterprise intranet control server

Country Status (1)

Country Link
CN (1) CN102957566B (en)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103281297A (en) * 2013-04-22 2013-09-04 北京奇虎科技有限公司 Enterprise information security management system and method

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20060277539A1 (en) * 2005-06-07 2006-12-07 Massachusetts Institute Of Technology Constraint injection system for immunizing software programs against vulnerabilities and attacks
CN101588360A (en) * 2009-07-03 2009-11-25 深圳市安络大成科技有限公司 Associated equipment and method for internal network security management
CN102750469A (en) * 2012-05-18 2012-10-24 北京邮电大学 Security detection system based on open platform and detection method thereof

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20060277539A1 (en) * 2005-06-07 2006-12-07 Massachusetts Institute Of Technology Constraint injection system for immunizing software programs against vulnerabilities and attacks
CN101588360A (en) * 2009-07-03 2009-11-25 深圳市安络大成科技有限公司 Associated equipment and method for internal network security management
CN102750469A (en) * 2012-05-18 2012-10-24 北京邮电大学 Security detection system based on open platform and detection method thereof

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103281297A (en) * 2013-04-22 2013-09-04 北京奇虎科技有限公司 Enterprise information security management system and method

Also Published As

Publication number Publication date
CN102957566B (en) 2016-06-22

Similar Documents

Publication Publication Date Title
US10216938B2 (en) Recombinant threat modeling
EP3100192B1 (en) Automated penetration testing device, method and system
CN103116722A (en) Processing method, processing device and processing system of notification board information
EP2984600A1 (en) A framework for coordination between endpoint security and network security services
CN103023905B (en) A kind of equipment, method and system for detection of malicious link
CN102932329A (en) Method and device for intercepting behaviors of program, and client equipment
CN103020524A (en) Computer virus monitoring system
Fisk Cyber security, building automation, and the intelligent building
CN102868694A (en) Method, device and system for detecting whether to control client to visit network
CN104468563A (en) Website bug protection method, device and system
CN104050417A (en) Method and device for detecting software states at mobile terminal
CN102916937A (en) Method and device for intercepting web attacks, and customer premise equipment
CN103049695A (en) Computer virus monitoring method and device
CN103294955A (en) Macro-virus searching and killing method and system
Livingston et al. Managing cyber risk in the electric power sector
CN112202704A (en) Block chain intelligent contract safety protection system
CN106027372A (en) Method for automatically processing alarm work order based on WeChat
CN102957695A (en) Enterprise intranet terminal safety maintenance method and device
CN103036896A (en) Method and system for testing malicious links
Kim et al. STRIDE‐based threat modeling and DREAD evaluation for the distributed control system in the oil refinery
Valentine et al. Software security: Application-level vulnerabilities in SCADA systems
CN102999555A (en) Webpage exception handling method and device
CN105262777A (en) Local area network (LAN)-based security detection method and device
CN104618176A (en) Website security detection method and device
CN102957566A (en) Enterprise intranet control server

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
C14 Grant of patent or utility model
GR01 Patent grant
C41 Transfer of patent application or patent right or utility model
TR01 Transfer of patent right

Effective date of registration: 20161212

Address after: 100015 Jiuxianqiao Chaoyang District Beijing Road No. 10, building 15, floor 17, layer 1701-26, 3

Patentee after: BEIJING QI'ANXIN SCIENCE & TECHNOLOGY CO., LTD.

Address before: 100088 Beijing city Xicheng District xinjiekouwai Street 28, block D room 112 (Desheng Park)

Patentee before: Beijing Qihoo Technology Co., Ltd.

Patentee before: Qizhi Software (Beijing) Co., Ltd.

CP01 Change in the name or title of a patent holder

Address after: 100015 15, 17 floor 1701-26, 3 building, 10 Jiuxianqiao Road, Chaoyang District, Beijing.

Patentee after: Qianxin Technology Group Co., Ltd.

Address before: 100015 15, 17 floor 1701-26, 3 building, 10 Jiuxianqiao Road, Chaoyang District, Beijing.

Patentee before: BEIJING QI'ANXIN SCIENCE & TECHNOLOGY CO., LTD.

CP01 Change in the name or title of a patent holder