WO2017080424A1 - 一种基于局域网的安全检测方法和装置 - Google Patents

一种基于局域网的安全检测方法和装置 Download PDF

Info

Publication number
WO2017080424A1
WO2017080424A1 PCT/CN2016/104919 CN2016104919W WO2017080424A1 WO 2017080424 A1 WO2017080424 A1 WO 2017080424A1 CN 2016104919 W CN2016104919 W CN 2016104919W WO 2017080424 A1 WO2017080424 A1 WO 2017080424A1
Authority
WO
WIPO (PCT)
Prior art keywords
risk
local area
area network
rule
user terminal
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2016/104919
Other languages
English (en)
French (fr)
Inventor
江爱军
赵小宁
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Beijing Qihoo Technology Co Ltd
Beijing Qianxin Technology Co Ltd
Original Assignee
Beijing Qihoo Technology Co Ltd
Beijing Qianxin Technology Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Beijing Qihoo Technology Co Ltd, Beijing Qianxin Technology Co Ltd filed Critical Beijing Qihoo Technology Co Ltd
Publication of WO2017080424A1 publication Critical patent/WO2017080424A1/zh
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/14Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
    • H04L63/1408Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
    • H04L63/1416Event detection, e.g. attack signature detection
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/40Network security protocols
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/14Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
    • H04L63/1408Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
    • H04L63/1425Traffic logging, e.g. anomaly detection
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/14Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
    • H04L63/1433Vulnerability analysis
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/14Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
    • H04L63/1441Countermeasures against malicious traffic
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L12/00Data switching networks
    • H04L12/28Data switching networks characterised by path configuration, e.g. LAN [Local Area Networks] or WAN [Wide Area Networks]

Definitions

  • the present invention relates to the field of computer security technologies, and in particular, to a LAN-based security detection method and a LAN-based security detection device.
  • LAN With the rapid spread of the Internet, LAN has become an indispensable part of enterprise development. However, while bringing convenience to enterprises, LANs also face a variety of attacks and threats, such as confidential leakage, data loss, network abuse, identity fraud, illegal intrusion and so on.
  • the existing LAN-based security detection schemes are mostly installed on the terminals inside the enterprise network by the anti-virus software client, and the anti-virus software client discovers the number of viruses and the degree of virus damage on the terminal based on the virus signature database, and according to the internal network of the enterprise network. The number of viruses and the degree of virus damage of the terminal are evaluated for security of the enterprise network.
  • this method can reflect the security status of the enterprise network to a certain extent, because the virus signature database has a certain lag relative to the virus, the enterprise network with the virus is already in a dangerous state. In this case, the enterprise network is already a failing network environment, and scoring or detecting the failing network environment belongs to the scope of post-remediation, so the security of the enterprise network cannot be effectively guaranteed.
  • the present invention has been made in order to provide a LAN-based security detection method and a LAN-based security detection apparatus that overcome the above problems or at least partially solve the above problems.
  • a LAN-based security detection method including:
  • the control terminal acquires a risk rule input by the user
  • the control terminal sends the risk rule to the user terminal in the local area network, so that the user terminal scans the host according to the risk rule to obtain a corresponding scan result;
  • the control terminal receives the scan result reported by the user terminal in the local area network
  • the control terminal analyzes the security of the local area network according to the scan result of the user terminal in the local area network.
  • a LAN-based security detecting apparatus for controlling a terminal, including:
  • An acquisition module configured to obtain a risk rule input by a user
  • a sending module configured to send the risk rule to a user terminal in a local area network, so that the user terminal scans the host according to the risk rule to obtain a corresponding scan result
  • a receiving module configured to receive a scan result reported by a user terminal in the local area network
  • an analysis module configured to analyze security of the local area network according to a scan result of the user terminal in the local area network.
  • a local area network-based security detection method and apparatus can enable a user of a control terminal to flexibly formulate a corresponding risk rule according to the current security requirements and actual conditions of the local area network, and scan according to the risk rule. The result is analyzed to obtain the security status of the local area network.
  • the security status of the local area network may include: security, suspicious, dangerous, etc.; therefore, the embodiment of the present invention can detect the local area network more timely through risk rules than the traditional virus signature database. Unknown threats and security risks can improve the timeliness of security detection and enable effective prevention of viruses.
  • FIG. 1 is a flow chart showing the steps of a LAN-based security detection method according to an embodiment of the present invention
  • FIG. 2 illustrates a LAN-based security detection method according to an embodiment of the present invention. Step flow diagram
  • FIG. 3 is a flow chart showing the steps of a LAN-based security detection method according to an embodiment of the present invention.
  • FIG. 4 is a flow chart showing the steps of a LAN-based security detection method according to an embodiment of the present invention.
  • FIG. 5 is a flow chart showing the steps of a LAN-based security detection method according to an embodiment of the present invention.
  • FIG. 6 is a schematic structural diagram of a LAN-based security detecting apparatus according to an embodiment of the present invention.
  • FIG. 7 is a block diagram of a computing device for performing a local area network based security detection method in accordance with the present invention.
  • FIG. 8 is a storage unit for program code for maintaining or carrying a LAN-based security detection method in accordance with the present invention.
  • FIG. 1 a flow chart of steps of a LAN-based security detection method according to an embodiment of the present invention is shown, which may specifically include the following steps:
  • Step 101 The control terminal acquires a risk rule input by the user.
  • Step 102 The control terminal sends the risk rule to the user terminal in the local area network, so that the user terminal scans the host according to the risk rule to obtain a corresponding scan result.
  • Step 103 The control terminal receives the scan result reported by the user terminal in the local area network.
  • Step 104 The control terminal analyzes the security of the local area network according to the scan result of the user terminal in the local area network.
  • the embodiments of the present invention can be applied to a local area network such as an enterprise network, a government network, or a campus network;
  • the control terminal refers to a terminal in the local area network for controlling other user terminals for security detection.
  • the user terminal refers to a terminal in the local area network that responds to the control terminal and performs data interaction with the control terminal.
  • a server proxy module may be deployed in the control terminal, and a software client module may be deployed on the user terminal to implement a control function of the control terminal to the user terminal in the local area network, similar to a C/S (client/server) architecture, and , the control response and communication function of the user terminal.
  • the control terminal and the user terminal can communicate with each other through a standard protocol or a private protocol.
  • the private protocol has the advantages of high security and high security. It can be understood that the embodiment of the present invention is between the control terminal and the user terminal.
  • the specific communication method is not limited.
  • the user of the control terminal may be an advanced user with certain network security knowledge, such as a network administrator. Therefore, the user controlling the terminal can flexibly formulate corresponding risk rules according to the current security requirements and actual conditions of the local area network. Therefore, the security status of the local area network can be obtained according to the scan result corresponding to the risk rule.
  • the risk rule may specifically include: a rule related to a risk object, and the risk object may specifically include at least one of the following objects: a process, a service, a scheduled task, and an installation.
  • a process a service
  • a scheduled task a scheduled task
  • an installation Application, port, file, operating system, registry, user account, and user rights. It can be understood that the embodiments of the present invention do not limit specific risk objects and specific risk rules.
  • the foregoing risk rule may be related to an APT (Advanced Persistent Threat) attack.
  • APT Advanced Persistent Threat
  • the traditional APT attack has many variants and is updated quickly, so there is no sample for the unknown virus.
  • the user of the control terminal can determine the corresponding risk object according to the characteristics of the APT attack, thereby formulating corresponding risk rules. It can be understood that the specific basis of the risk object is not limited in the embodiment of the present invention.
  • the user of the control terminal finds that the APT attack is related to the QQ application. Therefore, if it is intended to know the usage status of the QQ in the local area network, the QQ application can be used as a risk object and a corresponding risk rule is formulated. It can be used to scan whether the host has QQ installed, the time when QQ is installed, the version where QQ is installed, and the installation path of QQ.
  • the user controlling the terminal finds that the speed of one host in the local area network is slowed down, and further research finds that an unknown service is added to the host, so the The unknown service is used as a risk object and a corresponding risk rule is set.
  • the risk rule can be used to scan whether the unknown service exists on the host, the time when the unknown service enters the host, the path of the unknown service on the host, and the like.
  • the user of the control terminal finds that the security of the local area network is related to the password of the user terminal, so the password of the user terminal can be used as a risk object and a corresponding risk rule can be formulated, and the risk rule can be used for scanning. Whether the password of the user terminal meets the complexity requirements of the preset.
  • the embodiment of the present invention may provide an input interface for a risk rule to a user, and the input interface may support a search for a search, and may support logical operations such as AND, or the like. It can be understood that the embodiment of the present invention inputs risks for the user.
  • the specific way of the rules is not limited.
  • the embodiment of the present invention can be used as an auxiliary analysis tool for security detection of a local area network.
  • the security status analyzed by the embodiment of the present invention can be used as a basis for determining an unknown virus, or the embodiment of the present invention can also be used with a conventional
  • the anti-virus software such as the virus signature database is used in combination, and the embodiment of the present invention does not limit the specific application scenario.
  • the user terminal may perform scanning on the host according to the foregoing risk rule, and the obtained scan result may specifically include: a hit result of the hit risk rule, or a fatal result of the risk rule.
  • the user terminal may report the scan result to the control terminal after obtaining the scan result, or the user terminal may report the hit result only to the control terminal, but may not report the command to the control terminal. Not the result, so you can save the transmission resources of the result.
  • the traditional virus signature database has a certain hysteresis with respect to the virus, so the unknown virus cannot be detected.
  • the embodiment of the present invention can make the user of the control terminal flexibly formulate the corresponding according to the current security requirements and actual conditions of the local area network. Risk rules, and according to the scan results corresponding to the risk rules, the security status of the local area network is obtained, and the security status of the local area network may be specifically Including: security, suspicious, dangerous, etc.; therefore, compared with the traditional virus signature database, the embodiment of the present invention can detect unknown threats and security risks of the local area network in a timely manner through risk rules, thereby improving the timeliness of security detection. And can achieve effective prevention of the virus.
  • FIG. 2 a flow chart of steps of a LAN-based security detection method according to an embodiment of the present invention is shown, which may specifically include the following steps:
  • Step 201 The control terminal acquires a risk rule input by the user.
  • Step 202 The control terminal sends the risk rule to the user terminal in the local area network, so that the user terminal scans the host according to the risk rule to obtain a corresponding scan result.
  • Step 203 The control terminal receives the scan result reported by the user terminal in the local area network.
  • Step 204 The control terminal analyzes the security of the local area network according to the scan result of the user terminal in the local area network.
  • the risk rule of the embodiment may include: a rule related to the risk object, wherein the control terminal is based on the scan result of the user terminal in the local area network, and the local area network is compared with the embodiment shown in FIG.
  • Step 204 of performing security analysis may specifically include:
  • Step 241 The control terminal analyzes the risk of the risk object according to the scan result of the user terminal in the local area network.
  • the risk object may be a granularity, and the risk of the risk object may be analyzed.
  • the risk object is an unknown service
  • the risk of the unknown service can be analyzed according to the scan result of all the user terminals in the local area network. Therefore, the embodiment of the present invention can detect the virus in a more timely manner than the traditional virus signature database. Out of the risk object of the LAN.
  • the step of the control terminal analyzing the risk of the risk object according to the scan result of the user terminal in the local area network may specifically include:
  • Step A1 The control terminal analyzes the growth trend of the risk object according to the scan result of the user terminal in the local area network in a time period;
  • Step A2 Determine the risk of the risk object according to the growth trend of the risk object.
  • a file because it has not passed the verification of MD5 (Message-Digest Algorithm 5), it is listed as a risk object;
  • MD5 Message-Digest Algorithm 5
  • the scanning result of the user terminal in a period of time indicates that the file spreads from one host to one thousand hosts in one week, so the file can be judged to be an unknown hidden danger according to the growth trend of the file.
  • the risk of the risk object can be determined according to the rate corresponding to the growth trend, the maximum value of the risk object, and the like.
  • the specific determination method of the risk of the risk object is not limited in the embodiment of the present invention.
  • the growth trend of the above risk objects can be presented in the form of tables, histograms, curves, etc., in order to improve the intuitiveness of the analysis results.
  • the above analysis results in the growth trend of the risk object only as an optional embodiment.
  • those skilled in the art can first analyze the distribution or proportion and risk of the risk object in the local area network according to the actual application requirements. The characteristics of the life cycle of the object, and then the risk of the risk object is determined according to the characteristics of the risk object.
  • the embodiment of the present invention does not limit the characteristics of the risk object.
  • FIG. 3 a flow chart of steps of a local area network-based security detection method according to an embodiment of the present invention is shown, which may specifically include the following steps:
  • Step 301 The control terminal acquires a risk rule input by the user; the risk rule may specifically include: a rule related to the risk object;
  • Step 302 The control terminal sends the risk rule to the user terminal in the local area network, so that the user terminal scans the host according to the risk rule to obtain a corresponding scan result.
  • Step 303 The control terminal receives the scan result reported by the user terminal in the local area network.
  • Step 304 The control terminal analyzes the security of the local area network according to the scan result of the user terminal in the local area network.
  • the analysis may include: the control terminal analyzes according to the scan result of the user terminal in the local area network.
  • the method in this embodiment may further include:
  • Step 305 Generate a risk rule for cleaning the risk object when the risk of the risk object meets a preset condition
  • Step 306 Step 302: The generated risk rule is input to the control terminal to deliver the risk rule to the user terminal in the local area network.
  • the preset condition of the embodiment of the present invention may be a condition preset according to the risk of the risk object, for example.
  • the preset condition may include: a condition corresponding to a risk level such as security, suspicious, dangerous, etc., wherein the preset condition corresponding to the risk level may include any one of the following conditions: The distribution or proportion of the risk object in the local area network, the life cycle of the risk object, the growth trend of the risk object in a time period, and the like, and the specific preset conditions are not limited in the embodiment of the present invention.
  • the risk rule may be used to scan whether the QQ is installed on the host, the time when the QQ is installed, the version of the installed QQ, the installation path of the QQ, etc., and the risk of the QQ application corresponding to the risk rule.
  • a risk rule for cleaning the QQ application may be generated, so that the user terminal uninstalls the QQ application on the host and deletes files and traces corresponding to the QQ application.
  • the risk rule may be used to scan whether the unknown service exists on the host, the time when the unknown service enters the host, the path of the unknown service on the host, etc., and the risk rule corresponds to When the risk of the unknown service meets the preset conditions, a risk rule for cleaning the unknown service may be generated to enable the user terminal to clean up the unknown service on its own host.
  • the risk rules of the risk object are generated and cleaned in this embodiment, and the unknown threats and security risks of the local area network are further stopped in the bud state on the basis of detecting the unknown threats and security risks of the local area network in time, thereby Improve the security of the LAN.
  • FIG. 4 a flow chart of steps of a LAN-based security detection method according to an embodiment of the present invention is shown, which may specifically include the following steps:
  • Step 401 The control terminal acquires a risk rule input by the user; the risk rule may specifically include: a rule related to the risk object;
  • Step 402 The control terminal sends the risk rule to the user terminal in the local area network, so that the user terminal scans the host according to the risk rule to obtain a corresponding scan result.
  • Step 403 The control terminal receives the scan result reported by the user terminal in the local area network.
  • Step 404 The control terminal analyzes the security of the local area network according to the scan result of the user terminal in the local area network.
  • the analysis may include: the control terminal analyzes according to the scan result of the user terminal in the local area network.
  • the method in this embodiment may further include:
  • Step 405 When the risk of the risk object meets the preset condition, track the attack source corresponding to the risk object according to the information of the risk object that first appears in the local area network.
  • the attack source of the network attack may be tracked in the case of a network attack, so as to have intelligent learning capability for a new type of network attack, and also have good recognition and control capabilities for the network attack.
  • the intrusion forensics technology can be used to track the attack source corresponding to the above risk object.
  • the software and hardware technologies of the computer can be used to identify, save, analyze, and submit digital evidence for attacks such as intrusion, destruction, fraud, and attacks of the first-ever risk object corresponding to the attack source in a manner consistent with legal norms.
  • the address of the attack source may be tracked according to the IP address and MAC address corresponding to the risk object.
  • the login trace of the attack source may be recorded according to the user login record recorded in the system log record, or may be recorded according to the firewall log.
  • the original address information of the attack source determines the address of the attack source, etc., and the specific process of tracking the attack source corresponding to the risk object is not limited in the embodiment of the present invention.
  • FIG. 5 a flow chart of steps of a LAN-based security detection method according to an embodiment of the present invention is shown, which may specifically include the following steps:
  • Step 501 The control terminal acquires a risk rule input by the user.
  • Step 502 The control terminal acquires a repair rule input by the user, where the repair rule is used for security repair when the scan result of the user terminal hits the risk rule;
  • Step 503 The control terminal sends the risk rule to the user terminal in the local area network, so that the user terminal scans the host according to the risk rule to obtain a corresponding scan result.
  • Step 504 The control terminal sends the repair rule to the user terminal in the local area network, so that the user terminal performs security repair when the scan result hits the risk rule.
  • Step 505 The control terminal receives the scan result reported by the user terminal in the local area network.
  • Step 506 The control terminal analyzes the security of the local area network according to the scan result of the user terminal in the local area network.
  • the control terminal of this embodiment can also be used for users in the local area network.
  • the terminal sends a repair rule to enable the user terminal to perform security repair when the scan result hits the risk rule; wherein the control terminal may simultaneously send the risk rule and the repair to the user terminal, so that the user terminal scans As a result, when the risk rule is hit, the security repair is performed in time.
  • the risk rule corresponding to the risk object can be used to scan whether the password of the user terminal meets the preset complexity requirement, etc., and the repair rule corresponding to the risk object includes the repair indication value.
  • the repair indication value is equal to 1, indicating that the scan result is not reported to the control terminal when the scan result fails the risk rule; the repair indication value is equal to 2, indicating that the scan result is reported to the control terminal when the scan result hits the risk rule;
  • the repair indication value is equal to 3, indicating that the user is prompted to modify the password in addition to reporting the scan result to the control terminal when the scan result hits the risk rule;
  • the repair indication value is equal to 4, indicating that the scan result is reported to the control terminal except when the scan result hits the risk rule.
  • the repair indication value may be determined according to the scan result.
  • the value of the repair indication value is determined to be 1; when the complexity of the password conforms to the second complexity condition, the determination is performed.
  • the value of the repair indication value is 2; when the complexity of the password complies with the third complexity condition, the value of the repair indication value is determined to be 3; when the complexity of the password conforms to the fourth complexity condition, the value of the repair indication value is determined. 4.
  • the complexity corresponding to the first complexity condition, the second complexity condition, the third complexity condition, and the fourth complexity condition is decreased.
  • LAN-based security detection is illustrated in accordance with one embodiment of the present invention.
  • the structural block diagram of the device may specifically include the following modules:
  • the obtaining module 601 is configured to obtain a risk rule input by the user
  • the issuing module 602 is configured to send the risk rule to the user terminal in the local area network, so that the user terminal scans the host according to the risk rule to obtain a corresponding scan result.
  • the receiving module 603 is configured to receive a scan result reported by the user terminal in the local area network.
  • the analyzing module 604 is configured to analyze the security of the local area network according to the scanning result of the user terminal in the local area network.
  • the risk rule may specifically include: a rule related to the risk object, and the analyzing module 604 may specifically include:
  • the analysis submodule is configured to analyze the risk of the risk object according to the scan result of the user terminal in the local area network.
  • the analyzing sub-module may specifically include:
  • a trend analysis unit configured to analyze a growth trend of the risk object according to a scan result of the user terminal in the local area network during a time period
  • the determining unit is configured to determine the risk of the risk object according to the growth trend of the risk object.
  • the apparatus may further include:
  • Generating a module configured to generate a risk rule for cleaning the risk object when the risk of the risk object meets a preset condition
  • An input module configured to input the generated risk rule to the delivery module.
  • the apparatus may further include:
  • the tracking module is configured to track the attack source corresponding to the risk object according to the information of the risk object first appearing in the local area network when the risk of the risk object meets the preset condition.
  • the obtaining module 601 may be further configured to acquire a repair rule input by the user, where the repair rule is used for the scan result of the user terminal to hit the risk. Security fixes at the time of the rule;
  • the sending module 602 may be further configured to send the repairing rule to the user terminal in the local area network, so that the user terminal performs security repair when the scanning result hits the risk rule.
  • the risk rule may specifically include: a rule related to a risk object, and the risk object may specifically include at least one of the following objects:
  • the description is relatively simple, and the relevant parts can be referred to the description of the method embodiment.
  • modules in the devices of the embodiments can be adaptively changed and placed in one or more devices different from the embodiment.
  • Can The modules or units or components in the embodiments are combined into one module or unit or component, and further they may be divided into a plurality of sub-modules or sub-units or sub-components.
  • any combination of the features disclosed in the specification, including the accompanying claims, the abstract and the drawings, and any methods so disclosed, or All processes or units of the device are combined.
  • Each feature disclosed in this specification may be replaced by alternative features that provide the same, equivalent or similar purpose.
  • the various component embodiments of the present invention may be implemented in hardware, or in a software module running on one or more processors, or in a combination thereof.
  • a microprocessor or digital signal processor can be used in practice to implement some or all of the components of the LAN-based security detection method and apparatus in accordance with embodiments of the present invention.
  • the invention can also be implemented as a device or device program (e.g., a computer program and a computer program product) for performing some or all of the methods described herein.
  • Such a program implementing the invention may be stored on a computer readable medium or may be in the form of one or more signals. Such signals may be downloaded from an internet platform, provided on a carrier signal, or provided in any other form.
  • Figure 7 illustrates a computing device for performing a LAN based security detection method in accordance with the present invention.
  • the computing device conventionally includes a processor 710 and a program product or readable medium in the form of a memory 720.
  • Memory 720 can be an electronic memory such as flash memory, EEPROM (Electrically Erasable Programmable Read Only Memory), EPROM, or ROM.
  • Memory 720 has a memory space 730 for program code 731 for performing any of the method steps described above.
  • storage space 730 for program code may include various program code 731 for implementing various steps in the above methods, respectively.
  • These program codes can be from one or Read or write to one or more program products in a plurality of program products.
  • These program products include program code carriers such as memory cards.
  • Such a program product is typically a portable or fixed storage unit as described with reference to FIG.
  • the storage unit may have storage segments, storage spaces, and the like that are similarly arranged to memory 720 in the computing device of FIG.
  • the program code can be compressed, for example, in an appropriate form.
  • the storage unit includes readable code 731', ie, code that can be read by a processor, such as 710, that when executed by the computing device causes the computing device to perform various steps in the methods described above .

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Small-Scale Networks (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

本发明实施例提供了一种基于局域网的安全检测方法和装置,其中的方法具体包括:控制终端获取用户输入的风险规则;控制终端向局域网内的用户终端下发所述风险规则,以使所述用户终端依据所述风险规则在主机上进行扫描,以得到相应的扫描结果;控制终端接收所述局域网内的用户终端上报的扫描结果;控制终端依据所述局域网内的用户终端的扫描结果,对所述局域网的安全性进行分析。本发明实施例能够通过风险规则更及时地检测出局域网的未知威胁和安全隐患,从而能够提高安全检测的及时性,且能够实现病毒的有效预防。

Description

一种基于局域网的安全检测方法和装置 技术领域
本发明涉及计算机安全技术领域,特别是涉及一种基于局域网的安全检测方法和一种基于局域网的安全检测装置。
背景技术
随着互联网的迅速普及,局域网已成为企业发展中必不可少的一部分。然而,在为企业带来便利的同时,局域网也面临着各种各样的进攻和威胁,如机密泄漏、数据丢失、网络滥用、身份冒用、非法入侵等。
现有基于局域网的安全检测方案大多通过在企业网内部的终端上分别安装杀毒软件客户端,由该杀毒软件客户端基于病毒特征库发现终端上的病毒数量和病毒危害程度,并依据企业网内部所述终端的病毒数量和病毒危害程度进行企业网的安全评估。
对于病毒数量和病毒危害程度而言,尽管这种方法能够在一定程度上体现出企业网的安全状况,但是由于病毒特征库相对于病毒具有一定的滞后性,存在病毒的企业网已经处于危险状态,此种情况下的企业网已经属于不及格的网络环境,而对不及格的网络环境进行评分或进行检测,属于事后补救的范畴,因此无法有效保证企业网的安全性。
发明内容
鉴于上述问题,提出了本发明以便提供一种克服上述问题或者至少部分地解决上述问题的一种基于局域网的安全检测方法和一种基于局域网的安全检测装置。
依据本发明的一个方面,提供了一种基于局域网的安全检测方法,包括:
控制终端获取用户输入的风险规则;
控制终端向局域网内的用户终端下发所述风险规则,以使所述用户终端依据所述风险规则在主机上进行扫描,以得到相应的扫描结果;
控制终端接收所述局域网内的用户终端上报的扫描结果;
控制终端依据所述局域网内的用户终端的扫描结果,对所述局域网的安全性进行分析。
根据本发明的另一方面,提供了一种基于局域网的安全检测装置,应用于控制终端,包括:
获取模块,用于获取用户输入的风险规则;
下发模块,用于向局域网内的用户终端下发所述风险规则,以使所述用户终端依据所述风险规则在主机上进行扫描,以得到相应的扫描结果;
接收模块,用于接收所述局域网内的用户终端上报的扫描结果;及
分析模块,用于依据所述局域网内的用户终端的扫描结果,对所述局域网的安全性进行分析。
根据本发明实施例的一种基于局域网的安全检测方法和装置,可以使得控制终端的用户根据局域网的当前安全需求和实际情况,灵活地制定相应的风险规则,并根据所述风险规则对应的扫描结果分析得到局域网的安全状况,上述局域网的安全状况具体可以包括:安全、可疑、危险等状况;因此,相对于传统的病毒特征库,本发明实施例能够通过风险规则更及时地检测出局域网的未知威胁和安全隐患,从而能够提高安全检测的及时性,且能够实现病毒的有效预防。
上述说明仅是本发明技术方案的概述,为了能够更清楚了解本发明的技术手段,而可依照说明书的内容予以实施,并且为了让本发明的上述和其它目的、特征和优点能够更明显易懂,以下特举本发明的具体实施方式。
附图说明
通过阅读下文可选实施方式的详细描述,各种其他的优点和益处对于本领域普通技术人员将变得清楚明了。附图仅用于示出可选实施方式的目的,而并不认为是对本发明的限制。而且在整个附图中,用相同的参考符号表示相同的部件。在附图中:
图1示出了根据本发明一个实施例的一种基于局域网的安全检测方法的步骤流程示意图;
图2示出了根据本发明一个实施例的一种基于局域网的安全检测方法的 步骤流程示意图;
图3示出了根据本发明一个实施例的一种基于局域网的安全检测方法的步骤流程示意图;
图4示出了根据本发明一个实施例的一种基于局域网的安全检测方法的步骤流程示意图;
图5示出了根据本发明一个实施例的一种基于局域网的安全检测方法的步骤流程示意图;
图6示出了根据本发明一个实施例的一种基于局域网的安全检测装置的结构示意;
图7是用于执行根据本发明的基于局域网的安全检测方法的计算设备的框图;
图8是用于为保持或者携带实现根据本发明的基于局域网的安全检测方法的程序代码的存储单元。
具体实施方式
下面将参照附图更详细地描述本公开的示例性实施例。虽然附图中显示了本公开的示例性实施例,然而应当理解,可以以各种形式实现本公开而不应被这里阐述的实施例所限制。相反,提供这些实施例是为了能够更透彻地理解本公开,并且能够将本公开的范围完整的传达给本领域的技术人员。
参照图1,示出了根据本发明一个实施例的一种基于局域网的安全检测方法的步骤流程图,具体可以包括如下步骤:
步骤101、控制终端获取用户输入的风险规则;
步骤102、控制终端向局域网内的用户终端下发所述风险规则,以使所述用户终端依据所述风险规则在主机上进行扫描,以得到相应的扫描结果;
步骤103、控制终端接收所述局域网内的用户终端上报的扫描结果;
步骤104、控制终端依据所述局域网内的用户终端的扫描结果,对所述局域网的安全性进行分析。
本发明实施例可以应用于企业网、政府网、校园网等局域网中;在上述 局域网中,所述控制终端是指局域网内用于控制其它用户终端进行安全检测的终端,所述用户终端是指局域网内响应控制终端的指令,与控制终端进行数据交互的终端。在实际应用中,可以在控制终端部署服务器代理模块,在用户终端部署软件客户端模块,以类似C/S(客户端/服务器)的架构,实现局域网内控制终端对用户终端的控制功能,以及,用户终端的控制响应及通信功能。其中,上述控制终端和上述用户终端之间可以通过标准协议或者私有协议进行通信,其中,私有协议具有封闭性和安全性高的优点;可以理解,本发明实施例对于控制终端与用户终端之间的具体通信方式不加以限制。
在实际应用中,控制终端的用户可以是网络管理员等具有一定的网络安全知识的高级用户,因此,控制终端的用户可以根据局域网的当前安全需求和实际情况,灵活地制定相应的风险规则,从而,可以根据所述风险规则对应的扫描结果分析得到局域网的安全状况。
在本发明的一种可选实施例中,所述风险规则具体可以包括:与风险对象相关的规则,所述风险对象具体可以包括如下对象中的至少一种:进程、服务、计划任务、安装应用、端口、文件、操作系统、注册表、用户账号和用户权限。可以理解,本发明实施例对于具体的风险对象和具体的风险规则不加以限制。
在本发明的一种可选实施例中,上述风险规则可以与APT(高级持续性威胁,Advanced Persistent Threat)攻击相关,传统APT攻击的变种多,更新快,故对于未知病毒而言并无样本可依,而本发明实施例中,控制终端的用户可以依据APT攻击的特性确定相应的风险对象,从而制定相应的风险规则。可以理解,本发明实施例对于风险对象的具体依据不加以限制。
在本发明的一种应用示例中,控制终端的用户发现APT攻击与QQ应用有关,故打算获知局域网内QQ的使用状态,则可以将QQ应用作为风险对象并制定相应的风险规则,该风险规则可用于扫描主机上是否安装有QQ、安装QQ的时间、安装QQ的版本、QQ的安装路径等。
在本发明的另一种应用示例中,控制终端的用户发现局域网中一台主机的速度变慢了,进一步研究发现该主机上多出了一个未知服务,故可以将该 未知服务作为风险对象并制定相应的风险规则,该风险规则可用于扫描主机上是否存在该未知服务、该未知服务进入该主机的时间、该未知服务在该主机上的路径等。
在本发明的再一种应用示例中,控制终端的用户发现局域网的安全性与用户终端的密码有关,故可以将用户终端的密码作为风险对象并制定相应的风险规则,该风险规则可用于扫描用户终端的密码是否符合预置的复杂性要求等。
可以理解,上述制定风险规则的方式只是作为示例,实际上,本领域技术人员还可以根据实际应用需求采用其他制定风险规则的方式,如依据步骤104输出的安全性分析结果制定风险规则等,本发明实施例对于风险规则的具体制定方式不加以限制。
需要说明的是,本发明实施例可以向用户提供风险规则的输入接口,该输入接口可以支持检索式的检索,且可以支持与、或等逻辑运算,可以理解,本发明实施例对于用户输入风险规则的具体方式不加以限制。
在实际应用中,本发明实施例可以作为局域网的安全检测的辅助分析工具,例如,本发明实施例分析得到的安全状况可以作为未知病毒的判定依据,或者,本发明实施例还可以与传统的病毒特征库等杀毒软件结合使用,本发明实施例对于具体的应用场景不加以限制。
在实际应用中,用户终端可以依据上述风险规则在主机上进行扫描,得到的扫描结果具体可以包括:命中风险规则的命中结果,或者,命不中风险规则的命不中结果等。在本发明的一种可选实施例中,用户终端可以在得到扫描结果后向控制终端上报上述扫描结果,或者,用户终端还可以仅仅向控制终端上报命中结果,而可以不向控制终端上报命不中结果,因此可以节省命不中结果的传输资源。
综上,由于传统的病毒特征库相对于病毒具有一定的滞后性,故无法检测出未知病毒;而本发明实施例可以使得控制终端的用户根据局域网的当前安全需求和实际情况,灵活地制定相应的风险规则,并根据所述风险规则对应的扫描结果分析得到局域网的安全状况,上述局域网的安全状况具体可以 包括:安全、可疑、危险等状况;因此,相对于传统的病毒特征库,本发明实施例能够通过风险规则更及时地检测出局域网的未知威胁和安全隐患,从而能够提高安全检测的及时性,且能够实现病毒的有效预防。
参照图2,示出了根据本发明一个实施例的一种基于局域网的安全检测方法的步骤流程图,具体可以包括如下步骤:
步骤201、控制终端获取用户输入的风险规则;
步骤202、控制终端向局域网内的用户终端下发所述风险规则,以使所述用户终端依据所述风险规则在主机上进行扫描,以得到相应的扫描结果;
步骤203、控制终端接收所述局域网内的用户终端上报的扫描结果;
步骤204、控制终端依据所述局域网内的用户终端的扫描结果,对所述局域网的安全性进行分析;
相对于图1所示实施例,本实施例的所述风险规则具体可以包括:与风险对象相关的规则,则所述控制终端依据所述局域网内的用户终端的扫描结果,对所述局域网的安全性进行分析的步骤204,具体可以包括:
步骤241、控制终端依据所述局域网内的用户终端的扫描结果,分析得到所述风险对象的风险性。
本实施例可以风险对象为粒度,分析风险对象的风险性。例如,在风险对象为未知服务时,可以根据局域网内的所有用户终端的扫描结果,分析得到该未知服务的风险性,因此,相对于传统的病毒特征库,本发明实施例能够更及时地检测出局域网的风险对象。
在本发明的一种可选实施例中,所述控制终端依据所述局域网内的用户终端的扫描结果,分析得到所述风险对象的风险性的步骤,具体可以包括:
步骤A1、控制终端依据所述局域网内的用户终端在一个时间段内的扫描结果,分析得到所述风险对象的生长趋势;
步骤A2、依据所述风险对象的生长趋势,判定所述风险对象的风险性。
对于某个文件而言,由于其未通过MD5(信息摘要算法5,Message-Digest Algorithm 5)的校验,故将其列为风险对象;假设局域网内 的用户终端在一个时间段内的扫描结果表明,该文件在一周内从一台主机扩散到一千台主机,故可以依据该文件的生长趋势,判断该文件为未知隐患。其中,可以依据生长趋势对应的速率、风险对象的最大值等参数判定风险对象的风险性,本发明实施例对于风险对象的风险性的具体判定方法不加以限制。
在实际应用中,可以表格、柱状图、曲线等形式展现上述风险对象的生长趋势,以提高分析结果的直观性。另外,可以理解,上述分析得到所述风险对象的生长趋势只是作为可选实施例,实际上,本领域技术人员还可以根据实际应用需求,首先分析得到风险对象在局域网中的分布或比例、风险对象的生命周期等特性,再依据风险对象的特性判定所述风险对象的风险性,本发明实施例对于风险对象的特性不加以限制。
参照图3,示出了根据本发明一个实施例的一种基于局域网的安全检测方法的步骤流程图,具体可以包括如下步骤:
步骤301、控制终端获取用户输入的风险规则;所述风险规则具体可以包括:与风险对象相关的规则;
步骤302、控制终端向局域网内的用户终端下发所述风险规则,以使所述用户终端依据所述风险规则在主机上进行扫描,以得到相应的扫描结果;
步骤303、控制终端接收所述局域网内的用户终端上报的扫描结果;
步骤304、控制终端依据所述局域网内的用户终端的扫描结果,对所述局域网的安全性进行分析;所述分析具体可以包括:控制终端依据所述局域网内的用户终端的扫描结果,分析得到所述风险对象的风险性;
相对于图2所示实施例,本实施例的方法还可以包括:
步骤305、在所述风险对象的风险性符合预置条件时,生成用于清理所述风险对象的风险规则;
步骤306、将所生成的风险规则输入至所述控制终端向局域网内的用户终端下发所述风险规则的步骤302。
本发明实施例的预置条件可以为依据风险对象的风险性预置的条件,例 如,在本发明的一种应用示例中,上述预置条件具体可以包括:安全、可疑、危险等风险等级对应的条件,其中,上述风险等级对应的预置条件可以包括如下条件中的任一:风险对象在局域网中的分布或比例、风险对象的生命周期、风险对象在一个时间段内的生长趋势等,本发明实施例对于具体的预置条件不加以限制。
在本发明的一种应用示例中,风险规则可用于扫描主机上是否安装有QQ、安装QQ的时间、安装QQ的版本、QQ的安装路径等,则在该风险规则对应的QQ应用的风险性符合预置条件时,可以生成用于清理QQ应用的风险规则,以使用户终端在主机上卸载QQ应用并删除QQ应用对应的文件和痕迹。
在本发明的另一种应用示例中,风险规则可用于扫描主机上是否存在该未知服务、该未知服务进入该主机的时间、该未知服务在该主机上的路径等,则在该风险规则对应的未知服务的风险性符合预置条件时,可以生成用于清理未知服务的风险规则,以使用户终端在自身的主机上清理掉该未知服务。
综上,本实施例生成并清理所述风险对象的风险规则,能够在及时地检测出局域网的未知威胁和安全隐患的基础上,进一步将局域网的未知威胁和安全隐患停止在萌芽状态,从而可以提高局域网的安全性。
参照图4,示出了根据本发明一个实施例的一种基于局域网的安全检测方法的步骤流程图,具体可以包括如下步骤:
步骤401、控制终端获取用户输入的风险规则;所述风险规则具体可以包括:与风险对象相关的规则;
步骤402、控制终端向局域网内的用户终端下发所述风险规则,以使所述用户终端依据所述风险规则在主机上进行扫描,以得到相应的扫描结果;
步骤403、控制终端接收所述局域网内的用户终端上报的扫描结果;
步骤404、控制终端依据所述局域网内的用户终端的扫描结果,对所述局域网的安全性进行分析;所述分析具体可以包括:控制终端依据所述局域网内的用户终端的扫描结果,分析得到所述风险对象的风险性;
相对于图2所示实施例,本实施例的方法还可以包括:
步骤405、在所述风险对象的风险性符合预置条件时,依据所述局域网内首次出现的风险对象的信息,对所述风险对象对应的攻击源进行追踪。
本实施例可以在遭到网络攻击的情况下,对上述网络攻击的攻击源进行追踪,以对新类型的网络攻击具有智能学习能力,并且还可以对网络攻击具有良好的识别和控制能力。
在实际应用中,可以采用入侵取证技术对上述风险对象对应的攻击源进行追踪。具体地,可以利用计算机的软硬件技术,按照符合法律规范的方式,对首次出现的风险对象对应攻击源的入侵、破坏、欺诈、攻击等攻击行为进行识别、保存、分析和提交数字证据。例如,可以依据上述风险对象对应的IP地址、MAC地址追踪攻击源的地址,又如,可以依据系统的日志记录中记录的用户登陆痕迹记录攻击源的登陆痕迹,或者,可以依据防火墙日志中记录的攻击源的原地址信息确定攻击源的地址等,本发明实施例对于对所述风险对象对应的攻击源进行追踪的具体过程不加以限制。
参照图5,示出了根据本发明一个实施例的一种基于局域网的安全检测方法的步骤流程图,具体可以包括如下步骤:
步骤501、控制终端获取用户输入的风险规则;
步骤502、控制终端获取用户输入的修复规则,所述修复规则用于用户终端的扫描结果命中所述风险规则时的安全性修复;
步骤503、控制终端向局域网内的用户终端下发所述风险规则,以使所述用户终端依据所述风险规则在主机上进行扫描,以得到相应的扫描结果;
步骤504、控制终端向局域网内的用户终端下发所述修复规则,以使所述用户终端在扫描结果命中所述风险规则时进行安全性修复;
步骤505、控制终端接收所述局域网内的用户终端上报的扫描结果;
步骤506、控制终端依据所述局域网内的用户终端的扫描结果,对所述局域网的安全性进行分析。
相对于图1所示实施例,本实施例的控制终端还可以向局域网内的用户 终端下发修复规则,以使所述用户终端在扫描结果命中所述风险规则时进行安全性修复;其中,控制终端可以向用户终端同时下发上述风险规则和上述修复,以使用户终端在扫描结果命中所述风险规则时,及时地进行安全性修复。
例如,在将用户终端的密码作为风险对象时,该风险对象对应的风险规则可用于扫描用户终端的密码是否符合预置的复杂性要求等;该风险对象对应的修复规则中包括有修复指示值;其中,修复指示值等于1,表示在扫描结果命不中风险规则时,不向控制终端上报扫描结果;修复指示值等于2,表示在扫描结果命中风险规则时,向控制终端上报扫描结果;修复指示值等于3,表示除了在扫描结果命中风险规则时向控制终端上报扫描结果外,还提示用户修改密码;修复指示值等于4,表示除了在扫描结果命中风险规则时向控制终端上报扫描结果外,锁定计算机,并强制用户修改密码。其中,上述修复指示值可以依据扫描结果确定,例如,在密码的复杂度符合第一复杂度条件时,确定修复指示值的值为1;在密码的复杂度符合第二复杂度条件时,确定修复指示值的值为2;在密码的复杂度符合第三复杂度条件时,确定修复指示值的值为3;在密码的复杂度符合第四复杂度条件时,确定修复指示值的值为4,其中,第一复杂度条件、第二复杂度条件、第三复杂度条件和第四复杂度条件对应的复杂度递减。
可以理解,上述依据修复规则进行安全性修复的过程只是作为示例,实际上本领域技术人员可以根据实际应用需求,采用风险对象或者风险规则对应的修复规则,本发明实施例对于具体的修复规则不加以限制。
对于方法实施例,为了简单描述,故将其都表述为一系列的动作组合,但是本领域技术人员应该知悉,本发明实施例并不受所描述的动作顺序的限制,因为依据本发明实施例,某些步骤可以采用其他顺序或者同时进行。其次,本领域技术人员也应该知悉,说明书中所描述的实施例均属于可选实施例,所涉及的动作并不一定是本发明实施例所必须的。
参照图6,示出了根据本发明一个实施例的一种基于局域网的安全检测 装置的结构框图,具体可以包括如下模块:
获取模块601,配置为获取用户输入的风险规则;
下发模块602,配置为向局域网内的用户终端下发所述风险规则,以使所述用户终端依据所述风险规则在主机上进行扫描,以得到相应的扫描结果;
接收模块603,配置为接收所述局域网内的用户终端上报的扫描结果;及
分析模块604,配置为依据所述局域网内的用户终端的扫描结果,对所述局域网的安全性进行分析。
在本发明的一种可选实施例中,所述风险规则具体可以包括:与风险对象相关的规则,则所述分析模块604,具体可以包括:
分析子模块,配置为依据所述局域网内的用户终端的扫描结果,分析得到所述风险对象的风险性。
在本发明的另一种可选实施例中,所述分析子模块,具体可以包括:
趋势分析单元,配置为依据所述局域网内的用户终端在一个时间段内的扫描结果,分析得到所述风险对象的生长趋势;及
判定单元,配置为依据所述风险对象的生长趋势,判定所述风险对象的风险性。
在本发明的再一种可选实施例中,所述装置还可以包括:
生成模块,配置为在所述风险对象的风险性符合预置条件时,生成用于清理所述风险对象的风险规则;
输入模块,配置为将所生成的风险规则输入至所述下发模块。
在本发明的又一种可选实施例中,所述装置还可以包括:
追踪模块,配置为在所述风险对象的风险性符合预置条件时,依据所述局域网内首次出现的风险对象的信息,对所述风险对象对应的攻击源进行追踪。
在本发明的一种可选实施例中,所述获取模块601,还可以配置为获取用户输入的修复规则,所述修复规则用于用户终端的扫描结果命中所述风险 规则时的安全性修复;
所述下发模块602,还可以配置为向局域网内的用户终端下发所述修复规则,以使所述用户终端在扫描结果命中所述风险规则时进行安全性修复。
在本发明的另一种可选实施例中,所述风险规则具体可以包括:与风险对象相关的规则,所述风险对象具体可以包括如下对象中的至少一种:
进程、服务、计划任务、安装应用、端口、文件、操作系统、注册表、用户账号和用户权限。
对于装置实施例而言,由于其与方法实施例基本相似,所以描述的比较简单,相关之处参见方法实施例的部分说明即可。
在此提供的算法和显示不与任何特定计算机、虚拟系统或者其它设备固有相关。各种通用系统也可以与基于在此的示教一起使用。根据上面的描述,构造这类系统所要求的结构是显而易见的。此外,本发明也不针对任何特定编程语言。应当明白,可以利用各种编程语言实现在此描述的本发明的内容,并且上面对特定语言所做的描述是为了披露本发明的最佳实施方式。
在此处所提供的说明书中,说明了大量具体细节。然而,能够理解,本发明的实施例可以在没有这些具体细节的情况下实践。在一些实例中,并未详细示出公知的方法、结构和技术,以便不模糊对本说明书的理解。
类似地,应当理解,为了精简本公开并帮助理解各个发明方面中的一个或多个,在上面对本发明的示例性实施例的描述中,本发明的各个特征有时被一起分组到单个实施例、图、或者对其的描述中。然而,并不应将该公开的方法解释成反映如下意图:即所要求保护的本发明要求比在每个权利要求中所明确记载的特征更多的特征。更确切地说,如下面的权利要求书所反映的那样,发明方面在于少于前面公开的单个实施例的所有特征。因此,遵循具体实施方式的权利要求书由此明确地并入该具体实施方式,其中每个权利要求本身都作为本发明的单独实施例。
本领域那些技术人员可以理解,可以对实施例中的设备中的模块进行自适应性地改变并且把它们设置在与该实施例不同的一个或多个设备中。可以 把实施例中的模块或单元或组件组合成一个模块或单元或组件,以及此外可以把它们分成多个子模块或子单元或子组件。除了这样的特征和/或过程或者单元中的至少一些是相互排斥之外,可以采用任何组合对本说明书(包括伴随的权利要求、摘要和附图)中公开的所有特征以及如此公开的任何方法或者设备的所有过程或单元进行组合。除非另外明确陈述,本说明书(包括伴随的权利要求、摘要和附图)中公开的每个特征可以由提供相同、等同或相似目的的替代特征来代替。
此外,本领域的技术人员能够理解,尽管在此所述的一些实施例包括其它实施例中所包括的某些特征而不是其它特征,但是不同实施例的特征的组合意味着处于本发明的范围之内并且形成不同的实施例。例如,在下面的权利要求书中,所要求保护的实施例的任意之一都可以以任意的组合方式来使用。
本发明的各个部件实施例可以以硬件实现,或者以在一个或者多个处理器上运行的软件模块实现,或者以它们的组合实现。本领域的技术人员应当理解,可以在实践中使用微处理器或者数字信号处理器(DSP,Digital Signal Process)来实现根据本发明实施例的基于局域网的安全检测方法和装置中的一些或者全部部件的一些或者全部功能。本发明还可以实现为用于执行这里所描述的方法的一部分或者全部的设备或者装置程序(例如,计算机程序和计算机程序产品)。这样的实现本发明的程序可以存储在计算机可读介质上,或者可以具有一个或者多个信号的形式。这样的信号可以从因特网平台上下载得到,或者在载体信号上提供,或者以任何其他形式提供。
例如,图7示出了用于执行根据本发明的基于局域网的安全检测方法的计算设备。该计算设备传统上包括处理器710和以存储器720形式的程序产品或者可读介质。存储器720可以是诸如闪存、EEPROM(电可擦除可编程只读存储器)、EPROM或者ROM之类的电子存储器。存储器720具有用于执行上述方法中的任何方法步骤的程序代码731的存储空间730。例如,用于程序代码的存储空间730可以包括分别用于实现上面的方法中的各种步骤的各个程序代码731。这些程序代码可以从一个或 者多个程序产品中读出或者写入到这一个或者多个程序产品中。这些程序产品包括诸如存储卡之类的程序代码载体。这样的程序产品通常为如参考图8所述的便携式或者固定存储单元。该存储单元可以具有与图7的计算设备中的存储器720类似布置的存储段、存储空间等。程序代码可以例如以适当形式进行压缩。通常,存储单元包括可读代码731’,即可以由例如诸如710之类的处理器读取的代码,这些代码当由计算设备运行时,导致该计算设备执行上面所描述的方法中的各个步骤。
应该注意的是上述实施例对本发明进行说明而不是对本发明进行限制,并且本领域技术人员在不脱离所附权利要求的范围的情况下可设计出替换实施例。在权利要求中,不应将位于括号之间的任何参考符号构造成对权利要求的限制。单词“包括”不排除存在未列在权利要求中的元件或步骤。位于元件之前的单词“一”或“一个”不排除存在多个这样的元件。本发明可以借助于包括有若干不同元件的硬件以及借助于适当编程的计算机来实现。在列举了若干装置的单元权利要求中,这些装置中的若干个可以是通过同一个硬件项来具体体现。单词第一、第二、以及第三等的使用不表示任何顺序。可将这些单词解释为名称。

Claims (16)

  1. 一种基于局域网的安全检测方法,包括:
    控制终端获取用户输入的风险规则;
    控制终端向局域网内的用户终端下发所述风险规则,以使所述用户终端依据所述风险规则在主机上进行扫描,以得到相应的扫描结果;
    控制终端接收所述局域网内的用户终端上报的扫描结果;
    控制终端依据所述局域网内的用户终端的扫描结果,对所述局域网的安全性进行分析。
  2. 如权利要求1所述的方法,其特征在于,所述风险规则包括:与风险对象相关的规则,则所述控制终端依据所述局域网内的用户终端的扫描结果,对所述局域网的安全性进行分析的步骤,包括:
    控制终端依据所述局域网内的用户终端的扫描结果,分析得到所述风险对象的风险性。
  3. 如权利要求2所述的方法,其特征在于,所述控制终端依据所述局域网内的用户终端的扫描结果,分析得到所述风险对象的风险性的步骤,包括:
    控制终端依据所述局域网内的用户终端在一个时间段内的扫描结果,分析得到所述风险对象的生长趋势;
    依据所述风险对象的生长趋势,判定所述风险对象的风险性。
  4. 如权利要求2或3所述的方法,其特征在于,所述方法还包括:
    在所述风险对象的风险性符合预置条件时,生成用于清理所述风险对象的风险规则;
    将所生成的风险规则输入至所述控制终端向局域网内的用户终端下发所述风险规则的步骤。
  5. 如权利要求2或3所述的方法,其特征在于,所述方法还包括:
    在所述风险对象的风险性符合预置条件时,依据所述局域网内首次出现的风险对象的信息,对所述风险对象对应的攻击源进行追踪。
  6. 如权利要求1或2或3所述的方法,其特征在于,所述方法还包括:
    控制终端获取用户输入的修复规则,所述修复规则用于用户终端的扫描 结果命中所述风险规则时的安全性修复;
    控制终端向局域网内的用户终端下发所述修复规则,以使所述用户终端在扫描结果命中所述风险规则时进行安全性修复。
  7. 如权利要求1或2或3所述的方法,其特征在于,所述风险规则包括:与风险对象相关的规则,所述风险对象包括如下对象中的至少一种:
    进程、服务、计划任务、安装应用、端口、文件、操作系统、注册表、用户账号和用户权限。
  8. 一种基于局域网的安全检测装置,应用于控制终端,包括:
    获取模块,配置为获取用户输入的风险规则;
    下发模块,配置为向局域网内的用户终端下发所述风险规则,以使所述用户终端依据所述风险规则在主机上进行扫描,以得到相应的扫描结果;
    接收模块,配置为接收所述局域网内的用户终端上报的扫描结果;及
    分析模块,配置为依据所述局域网内的用户终端的扫描结果,对所述局域网的安全性进行分析。
  9. 如权利要求8所述的装置,其特征在于,所述风险规则包括:与风险对象相关的规则,则所述分析模块,包括:
    分析子模块,配置为依据所述局域网内的用户终端的扫描结果,分析得到所述风险对象的风险性。
  10. 如权利要求9所述的装置,其特征在于,所述分析子模块,包括:
    趋势分析单元,配置为依据所述局域网内的用户终端在一个时间段内的扫描结果,分析得到所述风险对象的生长趋势;及
    判定单元,配置为依据所述风险对象的生长趋势,判定所述风险对象的风险性。
  11. 如权利要求9或10所述的装置,其特征在于,所述装置还包括:
    生成模块,配置为在所述风险对象的风险性符合预置条件时,生成用于清理所述风险对象的风险规则;
    输入模块,配置为将所生成的风险规则输入至所述下发模块。
  12. 如权利要求9或10所述的装置,其特征在于,所述装置还包括:
    追踪模块,配置为在所述风险对象的风险性符合预置条件时,依据所述局域网内首次出现的风险对象的信息,对所述风险对象对应的攻击源进行追踪。
  13. 如权利要求8或9或10所述的装置,其特征在于,所述获取模块,还配置为获取用户输入的修复规则,所述修复规则用于用户终端的扫描结果命中所述风险规则时的安全性修复;
    所述下发模块,还配置为向局域网内的用户终端下发所述修复规则,以使所述用户终端在扫描结果命中所述风险规则时进行安全性修复。
  14. 如权利要求8或9或10所述的装置,其特征在于,所述风险规则包括:与风险对象相关的规则,所述风险对象包括如下对象中的至少一种:
    进程、服务、计划任务、安装应用、端口、文件、操作系统、注册表、用户账号和用户权限。
  15. 一种程序,包括可读代码,当所述可读代码在计算设备上运行时,导致所述计算设备执行根据权利要求1至7中的任一项所述的基于局域网的安全检测方法。
  16. 一种可读介质,其中存储了如权利要求15所述的程序。
PCT/CN2016/104919 2015-11-13 2016-11-07 一种基于局域网的安全检测方法和装置 Ceased WO2017080424A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201510781407.7A CN105262777A (zh) 2015-11-13 2015-11-13 一种基于局域网的安全检测方法和装置
CN201510781407.7 2015-11-13

Publications (1)

Publication Number Publication Date
WO2017080424A1 true WO2017080424A1 (zh) 2017-05-18

Family

ID=55102282

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2016/104919 Ceased WO2017080424A1 (zh) 2015-11-13 2016-11-07 一种基于局域网的安全检测方法和装置

Country Status (2)

Country Link
CN (1) CN105262777A (zh)
WO (1) WO2017080424A1 (zh)

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN113411302A (zh) * 2021-05-11 2021-09-17 银雁科技服务集团股份有限公司 局域网设备网络安全预警方法及装置
CN116827660A (zh) * 2023-07-21 2023-09-29 中国移动通信集团江苏有限公司 账号权限安全控制方法、装置、设备及存储介质

Families Citing this family (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN105262777A (zh) * 2015-11-13 2016-01-20 北京奇虎科技有限公司 一种基于局域网的安全检测方法和装置
CN105933186A (zh) * 2016-06-30 2016-09-07 北京奇虎科技有限公司 安全检测的方法、装置及系统
CN111212035A (zh) * 2019-12-19 2020-05-29 杭州安恒信息技术股份有限公司 一种主机失陷确认及自动修复方法及基于此的系统

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2007066333A1 (en) * 2005-12-07 2007-06-14 Swartz Alon R A practical platform for high risk applications
CN101835144A (zh) * 2010-05-25 2010-09-15 中国科学技术大学 对无线网络进行安全检测的方法和装置
CN102413011A (zh) * 2011-11-18 2012-04-11 奇智软件(北京)有限公司 一种局域网安全评估的方法和系统
CN105262777A (zh) * 2015-11-13 2016-01-20 北京奇虎科技有限公司 一种基于局域网的安全检测方法和装置

Family Cites Families (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101378358B (zh) * 2008-09-19 2010-12-15 成都市华为赛门铁克科技有限公司 一种实现安全接入控制的方法及系统、服务器
CN103118003B (zh) * 2012-12-27 2015-11-18 北京神州绿盟信息安全科技股份有限公司 一种基于资产的风险扫描方法、装置及系统

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2007066333A1 (en) * 2005-12-07 2007-06-14 Swartz Alon R A practical platform for high risk applications
CN101835144A (zh) * 2010-05-25 2010-09-15 中国科学技术大学 对无线网络进行安全检测的方法和装置
CN102413011A (zh) * 2011-11-18 2012-04-11 奇智软件(北京)有限公司 一种局域网安全评估的方法和系统
CN105262777A (zh) * 2015-11-13 2016-01-20 北京奇虎科技有限公司 一种基于局域网的安全检测方法和装置

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN113411302A (zh) * 2021-05-11 2021-09-17 银雁科技服务集团股份有限公司 局域网设备网络安全预警方法及装置
CN116827660A (zh) * 2023-07-21 2023-09-29 中国移动通信集团江苏有限公司 账号权限安全控制方法、装置、设备及存储介质

Also Published As

Publication number Publication date
CN105262777A (zh) 2016-01-20

Similar Documents

Publication Publication Date Title
US12166786B1 (en) Malware detection verification and enhancement by coordinating endpoint and malware detection systems
US11936666B1 (en) Risk analyzer for ascertaining a risk of harm to a network and generating alerts regarding the ascertained risk
US11102223B2 (en) Multi-host threat tracking
US10587647B1 (en) Technique for malware detection capability comparison of network security devices
CN109067815B (zh) 攻击事件溯源分析方法、系统、用户设备及存储介质
US10454950B1 (en) Centralized aggregation technique for detecting lateral movement of stealthy cyber-attacks
JP6334069B2 (ja) 悪意のあるコードの検出の精度保証のためのシステムおよび方法
CN106650436B (zh) 一种基于局域网的安全检测方法和装置
CN109586282B (zh) 一种电网未知威胁检测系统及方法
US11949694B2 (en) Context for malware forensics and detection
US12309178B2 (en) Context profiling for malware detection
US10033745B2 (en) Method and system for virtual security isolation
US10142343B2 (en) Unauthorized access detecting system and unauthorized access detecting method
WO2014112185A1 (ja) 攻撃分析システム及び連携装置及び攻撃分析連携方法及びプログラム
US9479521B2 (en) Software network behavior analysis and identification system
US11075931B1 (en) Systems and methods for detecting malicious network activity
CN113824678A (zh) 处理信息安全事件以检测网络攻击的系统和方法
CN106341426A (zh) 一种防御apt攻击的方法及安全控制器
EP3746926A1 (en) Context profiling for malware detection
CN108234480B (zh) 入侵检测方法及装置
CN105262777A (zh) 一种基于局域网的安全检测方法和装置
CN105930740A (zh) 软体文件被修改时的来源追溯方法、监测方法、还原方法及系统
CN116170186A (zh) 基于网络流量分析的攻击代码在线检测方法和装置
Fujimoto et al. Detecting attacks leveraging vulnerabilities fixed in MS17-010 from Event Log
CN120200815A (zh) 一种基于攻击链的网络攻击分析方法、装置及电子设备

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 16863600

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 16863600

Country of ref document: EP

Kind code of ref document: A1