Unlock instant, AI-driven research and patent intelligence for your innovation.

Control method and system for efficient concurrent access based on network stealth

A control method and a technology of a control system, which are applied to the control method and system field of efficient concurrent access based on network stealth, can solve problems such as inability to add, message blocking, and message inability to receive, so as to prevent port collisions, prevent port scanning, and reduce The effect of message congestion

Inactive Publication Date: 2020-11-27
NANJING ENLINK NETWORK TECH CO LTD
View PDF4 Cites 1 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

[0003] 1. In the traditional single-package authorization service, the server side only does identity authentication, access rule records, addition, deletion and other operations are all performed through the firewall, so its deployment depends on the firewall environment, iptables, firewalld and other firewall software Causing performance gaps in single-package licensing services;
[0004] 2. The problem of repeated authorization. The same legitimate user may send multiple access authorization requests. Of course, all legitimate users can pass the authentication. However, the management of the rules is performed by the firewall software, which does not perform repeated verification, which will lead to A large number of identical and repeated rules, when the number reaches a certain scale, will affect the interaction efficiency between the single-package authorization service and the firewall;
[0005] 3. Software performance issues. Since the access rules are recorded and operated by the software firewall, when a large number of users access at the same time, the access performance will be limited by the performance of the software firewall. When the firewall rules reach as many as a thousand, the interactive performance will change. is extremely low, which causes a large delay in adding new rules, or even fails to add them;
[0006] 4. Message blocking problem. Since message processing and rule control are linear, when there are a large number of requests, some messages cannot be received and ignored during message processing. The larger the message volume, the more obvious the problem

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Control method and system for efficient concurrent access based on network stealth
  • Control method and system for efficient concurrent access based on network stealth
  • Control method and system for efficient concurrent access based on network stealth

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0042] The present invention provides an efficient method for access control services to accurately control device access rules through a database, and at the same time can more efficiently resist replay attacks, efficiently process large concurrent message applications, and solve the problem of high concurrency and large numbers of traditional single-package authorization schemes. Data packets paralyze the authorization policy business. The invention needs to be deployed on both the terminal side and the gateway side, and a database needs to be installed on the gateway side. The following two databases, Mysql and Redis, are implemented as follows:

[0043] Such as figure 1 Shown:

[0044]The invention is deployed on the client side. When the client needs to access, it collects the necessary client information, forms a packet to request authorization and authentication, sends a UDP authentication packet to the server, and the server opens a non-famous port for service monito...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

PUM

No PUM Login to View More

Abstract

The invention provides a control method and system for efficient concurrent access based on network stealth, and the method comprises the following steps that a server obtains an authorization authentication request initiated by a client, opens a non-famous port for service interception, carries out the authentication of the authorization application, and permits the authorization application after the authentication succeeds; the server deploys a database, the server compares the release rule with the database to ensure that the release rule is a new non-repetitive rule, and the release ruleis added to the database and labeled; for the repeatedly applied rules, timeout time is updated in the database; and the server checks the database regularly, deletes the new rule label after adding the new rule to the firewall from the database, and deletes the timeout rule. The performance problem in a single-packet authorization model is solved, performance reduction caused by the number of rules brought by firewall software is avoided, the maximum number of the contained rules is greatly increased, the operation speed of the firewall rules is greatly increased, and the situation that a client side feels authorization delay is avoided.

Description

technical field [0001] The invention belongs to the technical field of computer security communication, and in particular relates to a control method and system for efficient concurrent access based on network stealth. Background technique [0002] Most of the current enterprise security models basically deploy software firewalls in addition to physical firewalls. At the same time, single-package authorization is deployed on the software firewalls to protect the ports to be opened by the business, so as to avoid the danger caused by the long-term opening of business ports. . At this time, the software firewall is controlled by the single-package authorization CS service. When the client wants to access a certain service port, the corresponding service port is opened through the single-package authorization application. After the client authentication is successful, the server-side control The software firewall opens the corresponding port. This solution effectively protect...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

Application Information

Patent Timeline
no application Login to View More
IPC IPC(8): H04L29/06H04L9/32
CPCH04L9/3242H04L9/3247H04L63/0263H04L63/0435H04L63/08H04L63/108
Inventor 武晓辉张越秦益飞杨正权尹烁
Owner NANJING ENLINK NETWORK TECH CO LTD