AI Chat Paper
Note: Please note that the following content is generated by AMiner AI. SciOpen does not take any responsibility related to this content.
{{lang === 'zh_CN' ? '文章概述' : 'Summary'}}
{{lang === 'en_US' ? '中' : 'Eng'}}
Chat more with AI
PDF (2.5 MB)
Collect
Submit Manuscript AI Chat Paper
Show Outline
Outline
Show full outline
Hide outline
Outline
Show full outline
Hide outline
Research Article | Open Access

Design and implementation of a computer endpoint security baseline verification system based on MLPS 2.0

Fan MiaoYaQiong Xu( )ZiYang WanYingJie ZhuangYang LiJiaPeng Ren
China Academy of Railway Sciences Corporation Limited, Institute of Computing Technologies, Beijing, China
Show Author Information

Abstract

Purpose

Amidst an increasingly severe cybersecurity landscape, the widespread adoption of Xinchuang endpoints has become a strategic imperative. Governments and enterprises have established terminal localization as a critical objective, aiming for comprehensive indigenous replacement through rapid technological iteration. Consequently, Xinchuang systems and Windows platforms are expected to coexist over an extended period. This study seeks to establish an automated verification framework for multi-version operating systems and validate the efficacy of baseline hardening in mitigating security risks.

Design/methodology/approach

Based on the Classified Protection 2.0 framework and relevant national standards for endpoint security, this study proposes an endpoint security baseline verification scheme applicable to multiple operating systems. The scheme addresses divergent security policies and implementation methodologies across heterogeneous environments. It automates the inspection of core baselines, including account password complexity, default shared service status and patch installation status. Furthermore, a comprehensive scoring model is established by incorporating differentiated weights for account security, patch management and log auditing, ultimately generating visualized risk reports to facilitate remediation prioritization.

Findings

This study reveals that baseline configuration serves as the fundamental prerequisite in endpoint security practices. Through a scalable detection engine and quantitative scoring model, the system can promptly identify and remediate potential risks, thereby reducing the attack surface and mitigating intrusion risks. However, on certain domestic chip architectures, compatibility issues persist in detecting specific configuration items. Further improvement in hardware–software co-adaptation for domestic platforms is required to advance the development of localized security protection systems.

Originality/value

Through in-depth research on security baseline configurations across multiple operating systems, this study implements an automated and visualized baseline verification methodology. This approach significantly strengthens the security posture of domestic operating systems and supports the establishment of a more robust, national-level cybersecurity defense framework.

References

【1】
【1】
 
 
Railway Sciences
Pages 136-152

{{item.num}}

Comments on this article

Go to comment

< Back to all reports

Review Status: {{reviewData.commendedNum}} Commended , {{reviewData.revisionRequiredNum}} Revision Required , {{reviewData.notCommendedNum}} Not Commended Under Peer Review

Review Comment

Close
Close
Cite this article:
Miao F, Xu Y, Wan Z, et al. Design and implementation of a computer endpoint security baseline verification system based on MLPS 2.0. Railway Sciences, 2026, 5(1): 136-152. https://doi.org/10.1108/RS-08-2025-0031

403

Views

2

Downloads

0

Crossref

0

Scopus

Received: 01 September 2025
Revised: 22 September 2025
Accepted: 23 September 2025
Published: 01 February 2026
© Fan Miao, YaQiong Xu, ZiYang Wan, YingJie Zhuang, Yang Li and JiaPeng Ren. Published in Railway Sciences.

This article is published under the Creative Commons Attribution (CC BY 4.0) licence. Anyone may reproduce, distribute, translate and create derivative works of this article (for both commercial and non-commercial purposes), subject to full attribution to the original publication and authors. The full terms of this licence may be seen at Link to the terms of the CC BY 4.0 licence.