Method for realizing Portal authentication server attack prevention and broadband access server

An access server and authentication server technology, applied in the field of Portal authentication server attack prevention and broadband access server, can solve the problems of Portal server attack, affect PortalServer performance, waste Portal authentication server resources, etc., and achieve the effect of avoiding attacks.

Active Publication Date: 2012-10-03
NEW H3C TECH CO LTD
View PDF2 Cites 19 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

For the BAS device, it is impossible to distinguish whether the Http request it receives is an Internet access request from the user browser or business traffic from a non-browser application program. As long as it is an Http request message, it will be redirected, that is, the The sender of the message responds with a redirection message, telling the sender to access the Portal server, which will cause a large number of Http messages from non-browser applications to be sent to the Portal authentication server, which seriously affects the performance of the Portal Server and causes a de facto attack
[0005] like figure 2 As shown, a large number of Http requests are sent to the Portal authentication server after being redirected by the BAS, and the Portal Server will respond one by one; for the Http requests sent by non-browser applications, the Portal Server will also respond one by one. The program does not have the browser's ability to parse pages and provide user identity information in an interactive manner. It cannot respond after receiving the response message from the Portal Server. These response messages are eventually discarded by the client's non-browser application. Wasted Portal authentication server resources
[0006] Since the BAS device cannot effectively distinguish between the Internet access request from the client browser and the business traffic generated by the non-browser application, the Portal server is finally attacked.

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Method for realizing Portal authentication server attack prevention and broadband access server
  • Method for realizing Portal authentication server attack prevention and broadband access server
  • Method for realizing Portal authentication server attack prevention and broadband access server

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0024] In order to make the purpose, technical solution and advantages of the present application clearer, the present application will be described in detail below through specific embodiments and with reference to the accompanying drawings.

[0025] This application adopts the Http authentication mechanism supported by all browsers to authenticate and protect the Http request for users to access the external network; only after the authentication is passed, will the client respond to a redirection message containing the URL address of the Portal server; otherwise, the client cannot Obtain the real address of the Portal server.

[0026] At the same time, when the client that has obtained the URL address of the Portal server accesses the Portal server, the Portal server will push the authentication page to the client. In this way, the client actually needs to pass the secondary authentication, which more strictly guarantees the authentication of the access user. safety. This ...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

PUM

No PUM Login to view more

Abstract

The invention discloses a method for realizing Portal authentication server attack prevention. The method comprises the following steps of: acquiring, by a broadband access server BAS, an HTTP request message which does not pass Portal authentication from a client; establishing TCP (Transmission Control Protocol) connection; transmitting an inquiry authentication request message to the client; after receiving, by the BAS, an inquiry authentication response message returned by a browser of the client, analyzing the inquiry authentication response message and performing identity authentication on the inquiry authentication response message; and when the authentication is successful, transmitting to the browser of the client a redirect message comprising Portal server URL (Uniform Resource Locator). The invention also discloses the broadband access server BAS. According to the method and the broadband access server, before redirect message transmission, inquiry authentication is introduced to the obtained Http request by the BAS, the traffic flow produced by a non-browser application program of a client can be shielded, and the Portal server is prevented from being attacked; and meanwhile, after the inquiry authentication is introduced, the client actually needs to pass secondary authentication, and the safety of an accessed user is more strictly guaranteed.

Description

technical field [0001] The application relates to the technical field of server anti-attack, in particular to a method for realizing Portal authentication server anti-attack and a broadband access server. Background technique [0002] Currently, the Web-based Portal access authentication solution is widely used in campus networks and carrier broadband access because it does not involve clients and is easy to deploy. Typical networking for Portal access authentication based on Web figure 1 As shown, the basic principle is: when the Portal authentication is not passed, the Http request of the user to access the external network will be redirected by the BAS device, and the authentication page will be pushed to the user through the Portal server. After the user enters the correct account and password information, continue Subsequent authentication and billing process, after the authentication is passed, the user can normally access external network resources. [0003] like f...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

Application Information

Patent Timeline
no application Login to view more
Patent Type & Authority Applications(China)
IPC IPC(8): H04L29/06H04L29/08
Inventor 高平利
Owner NEW H3C TECH CO LTD
Who we serve
  • R&D Engineer
  • R&D Manager
  • IP Professional
Why Eureka
  • Industry Leading Data Capabilities
  • Powerful AI technology
  • Patent DNA Extraction
Social media
Try Eureka
PatSnap group products