DNS resolution-based secure access control method, system, device, and equipment
Through the collaborative work of the cloud security management platform and the security access service edge node, secure access control based on DNS resolution is achieved, which solves the problem of high difficulty in maintaining security equipment in existing technologies and improves network security and user experience.
Patent Information
- Application Number
- CN202111110888.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-09-18
- Publication Date
- 2025-09-19
- Estimated Expiration
- 2041-09-18
AI Technical Summary
In the existing technology, in order to ensure the security of Internet access, enterprises or individuals need to deploy multiple security devices, such as DDoS, WAF, IDS, IPS, etc., which makes maintenance difficult and costly.
Configure the traffic diversion strategy and security resolution strategy through the cloud security management platform, and send them to the security access service edge node and target terminal respectively. Use the security access service edge node to control the domain name resolution request according to the resolution strategy to achieve secure access control.
It reduces the maintenance difficulty and cost of security equipment, improves the security of network communications, supports personalized security management in multi-user scenarios, reduces network latency, and improves user experience.
Smart Images

Figure CN115826444B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular to a DNS resolution-based security access control method, system, device, computer-readable storage medium, and electronic device. Background Art
[0002] The DNS system, or Domain Name System, is a core service on the internet. Any access requires DNS resolution to locate the corresponding service IP address before the corresponding resource can be retrieved. Therefore, the DNS resolution result directly determines the host the user accesses. To ensure the security of internet access, businesses and individuals currently deploy various security devices, such as DDoS, WAF, IDS, IPS, and online behavior management, for secure access control. However, these devices require maintenance, which is difficult and costly. Therefore, reducing the maintenance difficulty and cost of security devices while ensuring the security of internet access has become a pressing technical challenge. Summary of the Invention
[0003] In order to solve the problems existing in the prior art, at least one embodiment of the present invention provides a method, system, device, computer-readable storage medium and electronic device for secure access control based on DNS resolution.
[0004] In a first aspect, an embodiment of the present invention provides a secure access control method based on DNS resolution, which is applied to a secure access service edge node. The method includes:
[0005] Determining, based on a domain name resolution request from a target terminal, identification information of the target terminal and a target domain name to be resolved;
[0006] Determining, based on the identification information of the target terminal, a security parsing policy associated with a target user corresponding to the target terminal;
[0007] According to the security resolution policy, the target domain name is resolved and controlled.
[0008] In a second aspect, an embodiment of the present invention provides a secure access control method based on DNS resolution, which is applied to a cloud security management platform. The method includes:
[0009] Configure traffic diversion strategies and security resolution strategies for domain name resolution requests for target users;
[0010] Sending the traffic diversion strategy to the secure access service edge node and the target terminal corresponding to the target user, respectively, so that the target terminal sends a domain name resolution request to the secure access service edge node according to the traffic diversion strategy;
[0011] The security resolution policy is sent to the security access service edge node, so that the security access service edge node performs resolution control on the target domain name to be resolved in the domain name resolution request according to the security resolution policy.
[0012] In a third aspect, an embodiment of the present invention provides a secure access control method based on DNS resolution, which is applied to a target terminal. The method includes:
[0013] Obtaining a traffic diversion strategy for a domain name resolution request, the traffic diversion strategy including an address of a secure access service edge node that provides a domain name resolution service and is allocated to the target terminal;
[0014] According to the traffic diversion strategy, the generated domain name resolution request is sent to the secure access service edge node;
[0015] Receive response information sent by the secure access service edge node, where the response information is generated by the secure access service edge node performing resolution control on the domain name resolution request according to a security resolution policy, wherein the security resolution policy is associated with a target user corresponding to the target terminal.
[0016] In a fourth aspect, an embodiment of the present invention provides a secure access control system based on DNS resolution, wherein the system includes:
[0017] The cloud security management platform is used to configure a traffic diversion strategy and a security resolution strategy for a target user's domain name resolution request, and send the traffic diversion strategy to a secure access service edge node and a target terminal corresponding to the target user, and send the security resolution strategy to the secure access service edge node;
[0018] The secure access service edge node is configured to perform resolution control on a target domain name to be resolved in a domain name resolution request from the target terminal according to the secure resolution policy.
[0019] In a fifth aspect, an embodiment of the present invention provides a secure access control device based on DNS resolution, which is provided at a secure access service edge node, and the device includes:
[0020] A request analysis module, configured to determine identification information of the target terminal and a target domain name to be resolved based on a domain name resolution request from the target terminal;
[0021] a policy determination module, configured to determine, based on the identification information of the target terminal, a security parsing policy associated with a target user corresponding to the target terminal;
[0022] The resolution control module is used to perform resolution control on the target domain name according to the security resolution policy.
[0023] In a sixth aspect, an embodiment of the present invention provides a secure access control device based on DNS resolution, which is provided on a cloud security management platform and is characterized by comprising:
[0024] The policy configuration module is used to configure the traffic diversion strategy and security resolution strategy for domain name resolution requests for target users;
[0025] A first sending module is configured to send the traffic diversion strategy to the secure access service edge node and the target terminal corresponding to the target user, so that the target terminal sends a domain name resolution request to the secure access service edge node according to the traffic diversion strategy;
[0026] The second sending module is configured to send the security resolution policy to the security access service edge node, so that the security access service edge node performs resolution control on the target domain name to be resolved in the domain name resolution request according to the security resolution policy.
[0027] In a seventh aspect, an embodiment of the present invention provides a secure access control device based on DNS resolution, which is provided at a target terminal and includes:
[0028] A policy acquisition module, configured to acquire a traffic diversion policy for a domain name resolution request, wherein the traffic diversion policy includes an address of a secure access service edge node that provides a domain name resolution service and is allocated to the target terminal;
[0029] A request sending module, configured to send the generated domain name resolution request to the secure access service edge node according to the traffic diversion strategy;
[0030] A response receiving module is used to receive response information sent by the secure access service edge node, where the response information is generated by the secure access service edge node by performing resolution control on the domain name resolution request according to a security resolution policy, wherein the security resolution policy is associated with a target user corresponding to the target terminal.
[0031] In an eighth aspect, an embodiment of the present invention provides a computer-readable storage medium on which a computer program is stored. When the program is executed by a processor, a secure access control method based on DNS resolution as described in the first, second or third aspect above is implemented.
[0032] In a ninth aspect, an embodiment of the present invention provides an electronic device, comprising:
[0033] processor;
[0034] a memory for storing instructions executable by the processor;
[0035] The processor is configured to execute the instructions to implement a secure access control method based on DNS resolution as described in the first aspect, the second aspect or the third aspect.
[0036] Compared with the prior art, the above technical solution of the present invention has the following beneficial effects:
[0037] 1. The present invention configures a diversion strategy and a security resolution strategy for a target user through a cloud security management platform, and sends the diversion strategy to a security access service edge node and a target terminal corresponding to the target user, respectively, so that the target terminal can divert the domain name resolution request to the security access service edge node according to the diversion strategy, and at the same time send the security resolution strategy to the security access service edge node, so that the security access service edge node can perform resolution control on the target domain name to be resolved in the domain name resolution request according to the security resolution strategy, thereby realizing a new and efficient domain name access security management mode; compared with the existing technology, this domain name access security management mode does not require the configuration and management of numerous security devices, and improves the security of network communications at a lower cost.
[0038] 2. In an embodiment of the present invention, the cloud security management platform serves as a management center, configuring personalized traffic diversion strategies and security resolution strategies for each target user. As a management center for a secure cloud gateway for multiple users, it has strong elasticity and business expansion capabilities, is suitable for domain name access in a variety of scenarios, and can simultaneously meet the requirements for security and convenience of domain name access.
[0039] 3. In an embodiment of the present invention, the target terminal sends the domain name resolution request directly to the secure access service edge node according to the diversion strategy. The secure access service edge node checks and filters the category of the target domain name to be resolved in the domain name resolution request, and then takes different disposal methods to respond, thereby realizing secure access control of the domain name, and the operation is simple and efficient.
[0040] 4. In an embodiment of the present invention, each distributed node in the CDN network can provide DNS resolution services for the target user, that is, each distributed node can perform domain name resolution on the domain name resolution request sent by the target terminal, and can perform resolution control on the domain name resolution request, thereby ensuring the security of the target terminal's Internet access.
[0041] 5. In the embodiments of the present invention, the deployment of distributed secure access service edge nodes allows the target terminal to access the nearest secure access service edge node, significantly reducing the time delay for information to reach the secure access service edge node, thereby greatly improving the user experience. BRIEF DESCRIPTION OF THE DRAWINGS
[0042] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0043] Figure 1 This is a schematic diagram of the composition of a secure access control system based on DNS resolution provided by an embodiment of the present invention;
[0044] Figure 2 yes Figure 1 The system shown is a schematic diagram of the interactive process of implementing a secure access control method based on DNS resolution;
[0045] Figure 3 The embodiment of the present invention shows the settings of different handling methods according to different threat categories;
[0046] Figure 4 The embodiment of the present invention shows the setting contents of different processing methods according to different content categories;
[0047] Figure 5 The following shows the settings of the target user's traffic diversion strategy and security analysis strategy according to an embodiment of the present invention;
[0048] Figure 6 yes Figure 1 A schematic diagram of the composition of a secure access service edge node in the system shown;
[0049] Figure 7 yes Figure 2 Schematic diagram of the process of determining the target user in the secure access control method based on DNS resolution shown;
[0050] Figure 8 FIG. 4 is a schematic diagram of the composition of an electronic device according to an embodiment of the present invention. DETAILED DESCRIPTION
[0051] To make the objectives, technical solutions, and advantages of the embodiments of the present invention more clear, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts shall fall within the scope of protection of the present invention.
[0052] like Figure 1As shown, this embodiment provides a secure access control system based on DNS resolution, which mainly includes a cloud security management platform 10, a secure access service edge node 20 and a target terminal 30, wherein:
[0053] The cloud security management platform 10 is used to configure a traffic diversion strategy and a security resolution strategy for a target user's domain name resolution request, and send the traffic diversion strategy to the secure access service edge node 20 and the target terminal 30 corresponding to the target user, and send the security resolution strategy to the secure access service edge node 20;
[0054] The secure access service edge node 20 is used to perform resolution control on the target domain name to be resolved in the domain name resolution request from the target terminal 30 according to the security resolution policy provided by the cloud security management platform 10 .
[0055] The target terminal 30 is configured to send the domain name resolution request to the secure access service edge node 20 according to the traffic diversion strategy.
[0056] The target terminal 30 may be office equipment in a branch office, such as a desktop computer, or a BYOD (Bring Your Own Device) device, whereby an enterprise employee brings their own device to work, such as a personal computer, mobile phone, or tablet computer, without being restricted by time, location, equipment, personnel, or network environment. By installing the enterprise's application software on their personal device, the employee can access relevant enterprise resources. The target terminal 30 may also be a personal mobile terminal, such as a smartphone, which is not specifically limited in this application.
[0057] Figure 2 This is a schematic diagram of the interactive process of the above system implementing the secure access control method based on DNS resolution. Figure 2 As shown, the interaction process is completed by the cloud security management platform 10, the secure access service edge node 20 and the target terminal 30. The method mainly includes the following steps:
[0058] 101, the cloud security management platform 10 configures a traffic diversion strategy and a security resolution strategy for the domain name resolution request for the target user;
[0059] 102, the cloud security management platform 10 sends the traffic diversion policy to the secure access service edge node 20 and the target terminal 30 corresponding to the target user;
[0060] 103, the cloud security management platform 10 sends the security parsing policy to the secure access service edge node 20;
[0061] 104. The target terminal 30 receives a traffic diversion strategy for the domain name resolution request provided by the cloud security management platform, wherein the traffic diversion strategy includes the address of the secure access service edge node 20 that provides the domain name resolution service and is allocated to the target terminal 30.
[0062] 105 , the target terminal 30 sends the generated domain name resolution request to the secure access service edge node 20 according to the traffic diversion strategy;
[0063] 106, the secure access service edge node 20 receives the domain name resolution request sent by the target terminal 30;
[0064] 107, the secure access service edge node 20 determines the identification information of the target terminal 30 and the target domain name to be resolved according to the domain name resolution request;
[0065] 108. The secure access service edge node 20 determines the target user corresponding to the target terminal 30 based on the identification information of the target terminal 30, and then determines the security resolution policy associated with the target user corresponding to the target terminal 30 based on the correspondence between the target user and the security resolution policy pre-provided by the cloud security management platform 10.
[0066] 109, the secure access service edge node 20 performs resolution control on the target domain name according to the secure resolution policy;
[0067] 110, the secure access service edge node 20 feeds back to the target terminal 30 the response information generated by performing resolution control on the domain name resolution request;
[0068] 111, the secure access service edge node 20 outputs a parsing log to the cloud security management platform 10, where the parsing log records the parsing result of the target domain name;
[0069] 112 , the cloud security management platform 10 receives the parsing log sent by the secure access service edge node 20 , and analyzes and / or visualizes the parsing results in the parsing log.
[0070] The following describes in detail the various steps of the above method and the optional or alternative implementations thereof.
[0071] In the embodiment of the present invention, the target user can be understood as the smallest unit that needs to implement the security analysis strategy. Figure 1As shown, in this embodiment, the target user can be, for example, an enterprise, a home network, or an individual user. Typically, each target user has a corresponding user account, which can be registered by the user themselves or assigned by operators through the cloud security management platform 10. It should be understood that a target user can correspond to at least one target terminal. The term "at least one" in this application can mean any number of one, two, or more than two. For example, an enterprise can have one or more terminal devices, or a home network can have one or more terminal devices.
[0072] In some embodiments, before configuring the diversion strategy and security resolution strategy for the target user, the cloud security management platform 10 can also respond to the access request sent by the target terminal 30, verify the target terminal based on the access request, and allow the target terminal to access only after the verification is passed. It also queries the diversion strategy and security resolution strategy corresponding to the target user for the target terminal, and then sends the queried diversion strategy to the secure access service edge node 20 and the target terminal 30 corresponding to the target user, and sends the security resolution strategy to the secure access service edge node 20.
[0073] It should be noted that the secure access service edge node 20 can be a distributed node in a distributed network that provides various services. In one example, the distributed network can be a CDN (Content Delivery Network) network, which can include multiple distributed nodes (i.e., edge nodes). In an embodiment of the present invention, each distributed node in the CDN network can provide DNS resolution services for the target user, that is, each distributed node can perform domain name resolution on the domain name resolution request sent by the target terminal, and can perform resolution control on the domain name resolution request, thereby ensuring the security of the target terminal's Internet access. In addition, the distributed node can also provide other services, such as access control services, firewalls, DDoS, WAF, IDS, IPS, and Internet behavior management.
[0074] In other embodiments, the distributed network may also be an SD-WAN network. In addition, the distributed network may also be a server cluster composed of multiple servers in a distributed architecture, and the distributed node is any server in the server cluster.
[0075] In another example, the distributed network can also be an edge cloud network, which can be a cloud computing platform built on edge infrastructure based on the core and edge computing capabilities of cloud computing technology to form an elastic cloud platform with comprehensive computing, networking, storage, security and other capabilities at the edge. The edge cloud network can include multiple edge nodes (i.e., distributed nodes) to provide services at the edge of the network closer to the terminal. It should be noted that the embodiments of the present application do not limit the specific type of network that the distributed network is, and any network with a distributed architecture consisting of multiple computing devices is applicable to the present application.
[0076] In some embodiments, the access request sent by the user to the cloud security management platform 10 through the target terminal 30 may include the identity information of the target terminal, so that the cloud security management platform 10 can configure the corresponding diversion strategy through query according to the identity information of the target terminal. It should be noted that the identity information of the target terminal can be the identity information corresponding to the target terminal, and the corresponding target terminal can be determined based on the identity information. For example, the identity information of the target terminal can be information such as the IP address, MAC address or device number of the target terminal. In other examples, the identity information of the target terminal can also be the identity information of the user using the target terminal, such as the user's contact number, ID number, social account and other information, and this application does not specifically limit this.
[0077] In an exemplary embodiment of the present application, the diversion strategy may include the domain name information (i.e., service domain name) of the security access service edge node assigned to the target user. In this way, the subsequent security access service edge node can determine the target user corresponding to the domain name based on the correspondence between the identity information of the target terminal and the service domain name of the security access service edge node. Specifically, the cloud security management platform can assign a corresponding security access service edge node to each target user, and generate a DNS resolution service domain name of the security access service edge node for the target user. It should be understood that the service domain name is in a one-to-one correspondence with the target user, so that the target user can be determined based on the DNS resolution service domain name of the security access service edge node accessed by the target user.
[0078] It should be noted that a secure access service edge node can have multiple service domain names for multiple target users, that is, it can have a different DNS resolution service domain name corresponding to each target user. Therefore, a secure access service edge node can serve multiple target users, and can also provide multiple services for a target user, thereby improving the resource utilization of the secure access service edge node.
[0079] Alternatively, in some embodiments, the access request sent by the target terminal 30 to the cloud security management platform 10 includes not only the target terminal's identity information but also the traffic diversion policy set by the target user for domain name resolution requests. That is, it also includes the address of the secure access service edge node 20 that provides domain name resolution services, which the target user specifies. In other words, the traffic diversion policy can be set by the target user themselves or configured by operators on the cloud security management platform 10 for the target user. This is not specifically limited in the present invention.
[0080] It should be noted that the target terminals belonging to the same target user can correspond to the same diversion strategy and security resolution strategy. In some cases, the target terminals belonging to the same target user may also correspond to different diversion strategies or security resolution strategies. For example, an employee belonging to a branch is on a business trip. According to the location information of the target terminal used by the employee, the security access service edge node closest to the target terminal or with the best network quality is determined to be different from the security access service edge node in the diversion strategy corresponding to the branch. In this case, the diversion strategy can be modified accordingly, and the original security access service edge node is replaced with the actual closest or best security access service edge node to ensure the access quality of the target terminal.
[0081] When operators configure a traffic diversion strategy for a target user on the cloud security management platform 10, the security access service edge node 20 providing the domain name resolution service in the traffic diversion strategy can preferably be a security access service edge node that is geographically located in the same region as the target terminal and closest to the target terminal, thereby reducing the time delay for information to reach the security access service edge node, thereby significantly improving the user experience. In addition, the security access service edge node 20 can also be a security access service node with the best or relatively good network quality between it and the target terminal, thereby reducing the network delay for information to reach the security service edge node.
[0082] It should also be noted that the ways in which the cloud security management platform 10 sends down the diversion strategy and the security resolution strategy may include active sending or passive sending, as well as direct sending or indirect sending. For example, the cloud security management platform 10 may actively send down the diversion strategy and the security resolution strategy to the security access service edge node 20, or the cloud security management platform 10 may passively send down the diversion strategy to the target terminal 30 in response to the access request sent by the target user through the target terminal 30. Alternatively, the cloud security management platform 10 may directly send down the diversion strategy and the security resolution strategy to the security access service edge node 20, or the cloud security management platform 10 may first send down the diversion strategy and the security resolution strategy to the configuration manager 40, and then the configuration manager 40 sends it down to the security access service edge node 20 (i.e., indirectly). In short, the present invention does not impose any special restrictions on the ways in which the diversion strategy and the security resolution strategy are sent down.
[0083] It should be noted that the cloud security management platform 10 and the configuration manager 40 can be independent servers. The cloud security management platform 10 can send the configured traffic diversion strategy and security parsing strategy information to the configuration management server 40, so that the configuration management server 40 can send it to the corresponding security access service edge node 20 and target terminal. In another embodiment, the cloud security management platform 10 and the configuration manager 40 can also be the same server or in the same system, that is, the user or administrator can configure the relevant configuration information of the corresponding traffic diversion strategy and security parsing strategy in the interface provided by the cloud security management platform 10. After receiving the relevant configuration information, the interface provided by the cloud security management platform 10 can send the relevant configuration information to the configuration manager 40 for storage, so that the relevant configuration information can be sent to the corresponding security access service edge node 20 and target terminal at a later time.
[0084] In addition, it should be noted that the target terminal 30 corresponding to the target user can be either the network exit of the branch office or the terminal device of an individual user (hereinafter referred to as the user terminal device). The user terminal device may include but is not limited to one or more electronic devices with network connection functions and data access functions, such as smart phones, tablet computers, laptops, desktop computers, smart wearable devices or Internet of Things devices. Therefore, the identification information of the target terminal 30 can be either the public network exit address of the branch office or the virtual address of the client in the established diversion tunnel, that is, the target terminal can establish a diversion tunnel between the target terminal and the secure access service edge node based on the received diversion strategy, such as based on the GRE protocol, IPsec protocol, etc., so as to ensure the accuracy and security of the diversion results.
[0085] In some practicable embodiments, the cloud security management platform 10 may further display a target user configuration interface in response to a configuration request for a target user, wherein the configuration interface includes multiple information configuration options; and then, based on the edited information received from the multiple information configuration options, determine the target user's corresponding public network exit address, intranet address, traffic diversion strategy, and security resolution strategy. The intranet address is used to establish a traffic diversion tunnel. For example, for a branch office, a traffic diversion tunnel is established based on the branch office's intranet address and the address of the secure access service edge node assigned to the branch office to achieve traffic diversion.
[0086] In an embodiment of the present invention, a plurality of distributedly deployed secure access service edge nodes 20 form a secure cloud. Each secure access service edge node 20 can be connected to at least one target terminal 30, and each secure access service edge node 20 pre-stores a diversion strategy and a secure resolution strategy configured for each target user obtained from the cloud security management platform 10. In addition, each secure access service edge node 20 runs secure DNS software, and the secure DNS software supports multiple types of DNS resolution protocols, which may include but are not limited to one or more of UDP, TCP, DoT (DNS over TLS) and DoH (DNS over HTTPS), that is, the secure DNS software may only support one of the above-mentioned DNS resolution protocols, or may support any number of two or more of the above-mentioned DNS resolution protocols, and this application does not make any special restrictions on this. As a result, the secure access service edge node can support the processing of domain name resolution requests from multiple types of target terminals, has greater flexibility, can adapt to the needs of different application scenarios, and is compatible with various different DNS protocols, thereby obtaining the benefits of more accurate resolution or higher security.
[0087] When the secure access service edge node 20 receives a domain name resolution request from a target terminal 30, the domain name resolution request can be sent directly by the target terminal to the secure access service edge node, or it can be sent indirectly by the target terminal to the secure access service edge node through an intermediate server, where the intermediate server can be a gateway server, Local DNS, etc. Based on the domain name resolution request, the identification information of the target terminal 30 and the target domain name to be resolved are determined. In an embodiment of the present invention, the identification information of a target terminal 30 can include at least one of the public network exit address of the target terminal 30 and the request method of the domain name resolution request. Through the identification information of the target terminal 30, the secure access service edge node 20 can determine which target terminal 30 the received domain name resolution request comes from, thereby determining the target user corresponding to the target terminal 30, and then determining the security resolution policy associated with the target user. Because the secure access service edge node 20 pre-stores a mapping relationship between the identification information of the target terminal 30 and the target user corresponding to the target terminal 30, when the secure access service edge node 20 receives a domain name resolution request from the target terminal 30, it obtains the identification information of the target terminal 30 and then obtains the target user corresponding to the target terminal 30 from the mapping relationship. The security resolution policy pre-stored on the secure access service edge node 20 is associated with the target user corresponding to the target terminal 30. Therefore, once the target user is determined, the security resolution policy for the target user corresponding to the target terminal 30 can be obtained.
[0088] In an exemplary embodiment of the present application, the identification information of the target terminal may include both the public network egress address of the target terminal and the request method of the domain name resolution request. In this case, in step 108, the secure access service edge node determines the target user corresponding to the target terminal based on the identification information of the target terminal, including at least three of the following methods:
[0089] If the domain name resolution request mode is DoT or DoH, determine the target user corresponding to the target terminal according to the service domain name of the secure access service edge node;
[0090] If the request mode for sending the resolution request is not DoT or DoH, and the public network exit address of the target terminal is an IPv4 address, determine the target user corresponding to the target terminal according to the public network exit address of the target terminal;
[0091] If the request mode for sending the resolution request is not DoT or DoH, and the public network exit address of the target terminal is not an IPv4 address, the target user corresponding to the target terminal is determined according to the IPv6 address of the secure access service edge node allocated to the target terminal.
[0092] Therefore, setting different target user determination strategies for different situations can ensure the accuracy of target user determination and avoid the problem of unrecognized special situations. At the same time, DNS resolution based on secure access to service edge nodes can obtain the corresponding service node based on the real address of the target terminal, ensuring the accuracy of the resolution result and avoiding the traditional DNS resolution strategy of resolving the address information of the Local DNS server corresponding to the target terminal, which can easily cause deviations in the resolution result. For example, if the Local DNS server corresponding to the target terminal in area A fails, the DNS resolution request of the target terminal will be sent to the Local DNS server in the neighboring area B for resolution, which will cause the resolution result to be more relevant to area B, thereby affecting the service quality for the target terminal.
[0093] In some embodiments, the security resolution policy includes at least one of a domain name classification resolution policy, a security threat resolution policy, and a custom resolution policy. It should be noted that regardless of domain name classification resolution policy, security threat resolution policy, or custom resolution policy, they can all contain multiple rules, each of which corresponds to a matching condition and a handling action. When the matching condition is met, the secure access service edge node executes the corresponding handling action.
[0094] When the security resolution policy includes a domain name classification resolution policy, the secure access service edge node performs resolution control on the target domain name according to the domain name classification resolution policy, including:
[0095] Determining the content category corresponding to the target domain name based on a pre-stored domain name classification database;
[0096] According to the content category, the disposal method for the target domain name is determined, and the disposal method includes allowing the target domain name to be resolved. When the secure access service edge node provides cache service, the secure access service edge node can return the resolved target node IP after resolving the target domain name. The target node IP can be the IP of the current secure access service edge node or the IP of other secure access service edge nodes. When the secure access service edge node does not provide cache service or does not store the resources corresponding to the target domain name, the secure access service edge node can further query and access the IP address of the original server corresponding to the target domain name. The original server can be the source server corresponding to the target domain name or the server that stores the resources corresponding to the target domain name, etc. The disposal method also includes prohibiting the resolution of the target domain name or observing the resolution of the target domain name. The observation of the resolution of the target domain name means allowing the resolution of the target domain name and recording the resolution log of the time.
[0097] The beneficial effect of this is that before the DNS server responds with the resolution result, it analyzes and determines the type of the requested domain name, and adopts different handling methods according to different types (that is, responds to different resolution results), thereby achieving secure access control of the domain name, and the operation is simple and efficient.
[0098] When the security resolution policy includes a security threat resolution policy, the secure access service edge node performs resolution control on the target domain name according to the security threat resolution policy, including:
[0099] Determine the threat category corresponding to the target domain name based on a pre-stored security threat database;
[0100] Determine a handling method for the target domain name based on the threat category. The handling method includes allowing resolution of the target domain name, prohibiting resolution of the target domain name, or observing resolution of the target domain name. Observing resolution of the target domain name means allowing resolution of the target domain name and recording a resolution log.
[0101] The beneficial effect of this is that by judging whether the target domain name to be resolved belongs to threat categories such as viruses, C2, phishing emails, mining, etc., the disposal method for such domain names (such as blocking access to such domain names) can be implemented to meet the security requirements for domain name access.
[0102] When the security resolution policy includes a custom resolution policy, the secure access service edge node performs resolution control on the target domain name according to the custom resolution policy, including:
[0103] Determining whether the target domain name belongs to a custom domain name type in a pre-stored custom domain name database;
[0104] According to the judgment result, a disposal method for the target domain name is determined, where the disposal method includes allowing the target domain name to be resolved, prohibiting the target domain name from being resolved, or replacing the target domain name.
[0105] The beneficial effect of this is that it can configure personalized access resolution strategies, achieve strong elasticity and scalability, and meet domain name access needs in various scenarios.
[0106] In this embodiment, a diversion strategy and a security resolution strategy are configured for the target user through the cloud security management platform, and the diversion strategy is sent to the security access service edge node and the target terminal corresponding to the target user respectively, so that the target terminal diverts the domain name resolution request to the security access service edge node according to the diversion strategy, and at the same time, the security resolution strategy is sent to the security access service edge node, so that the security access service edge node performs resolution control on the target domain name to be resolved in the domain name resolution request according to the security resolution strategy, thereby realizing a new and efficient domain name access security management mode; compared with the existing technology, this domain name access security management mode does not require the configuration and management of numerous security devices, and improves network communication security at a lower cost.
[0107] Example 2
[0108] In order to enable those skilled in the art to have a deeper understanding of the working principle of the edge node in the above embodiment, the system structure and workflow are explained below with reference to a specific application example.
[0109] In this embodiment, a multi-tenant cloud security access control system has a cloud security management platform, multiple distributed security access service edge nodes DNS, and multiple target terminals of different types.
[0110] To achieve secure management of domain name resolution, the cloud security management platform operator or the target user's security manager first establishes at least one of the following databases on the cloud security management platform: a domain name classification database, a security threat database, and a custom domain name database. The domain name classification database records the categories of each domain name, the security threat database records the security threat types of domain names, and the custom domain name database records custom information about domain names. After establishing these databases, operators can modify the data in these databases as necessary. For example, they can add, delete, or modify domain names and domain categories in the domain name classification database and update the security threat database based on the latest threat intelligence.
[0111] In addition, the operator or the security manager of the target user can also set a corresponding security resolution policy for the target user on the cloud security management platform. Here, the target user can be understood as an organization (such as an enterprise, group or individual) identified on the cloud security management platform, which is the smallest unit for which the security resolution policy needs to be implemented. In this embodiment, the target user can be, for example, an enterprise organization, a home network or an individual user. Accordingly, due to the different characteristics of each target user, it is necessary to set up corresponding security resolution policies for each of these target users. The security resolution policy includes at least one of a domain name classification resolution policy, a security threat resolution policy and a custom resolution policy. For example, taking the domain name classification resolution policy as an example, a security resolution policy can be set for a home network to help parents prevent minors from browsing the content of bad websites (such as pornographic websites). Taking the security threat resolution policy as an example, a security resolution policy can be set for an enterprise organization to avoid the threat of phishing emails and ransomware viruses, and a security resolution policy can be set for an individual user's mobile device to avoid the threat of DNS hijacking. Taking the custom resolution policy as an example, a special security resolution policy can be set for an enterprise organization to prohibit access to specific URLs to obtain resources.
[0112] The following table shows the security parsing strategy adopted in this embodiment.
[0113] Figure 3 and Figure 4 The following is an example of a security parsing strategy for this embodiment. Figure 3 Shows different handling methods according to different threat categories; Figure 4 Different handling methods are shown according to different content categories.
[0114] In the security resolution strategy of this embodiment, different handling methods are adopted according to different threat categories, content categories, etc., and the handling methods include allowing, prohibiting, and observing (allowing resolution but recording the resolution log at that time). For example, allowing: office applications, information applications, office365; prohibiting: video applications, game applications, high-bandwidth download applications, virus, trojan, and phishing domain names. In addition, the security resolution strategy of this embodiment also includes custom resolution strategies. For example, corresponding handling methods are adopted for custom domain name classifications, and the handling methods include releasing, blocking, and rewriting. For example, www.example.com is resolved to cname.demo.com through domain name rewriting.
[0115] Table 1
[0116]
[0117]
[0118] After establishing the database and security parsing policy, the cloud security management platform operator or the target user's security manager will synchronize the established database and security parsing policy to the security access service edge node so that the security access service edge node can perform parsing control according to the security parsing policy.
[0119] like Figure 5 As shown, in addition to the aforementioned security resolution policies, operators or target user security managers also need to set up corresponding traffic diversion policies for each target user. In other words, operators or target user security managers also need to assign the address of a secure access service edge node that provides domain name resolution services to each target user, so that domain name resolution requests initiated by the target user can be diverted to the corresponding secure access service edge node for resolution control.
[0120] In this embodiment, the cloud security management platform responds to the configuration request for the target user and displays the following Figure 5 The target user configuration interface shown in the figure includes a plurality of information configuration options; then, based on the plurality of information configuration options, the editing information is received to determine the public network exit address, intranet address, diversion strategy and security resolution strategy corresponding to the target user. Among them, the intranet address is used to establish a diversion tunnel. For example, for a certain branch, based on the intranet address of the branch and the address of the security access service edge node assigned to the branch, a diversion tunnel is established to achieve diversion from the branch to the security access service edge node. In other words, the branch sends the newly generated domain name resolution request through the established diversion tunnel to the corresponding security access service edge node for resolution control.
[0121] In another example, when the branch office needs to send the generated domain name resolution request to the corresponding secure access service edge node, the DNS server address corresponding to the branch office can also be pointed to the address of the corresponding secure access service edge node, and then the generated domain name resolution request is sent to the secure access service edge node according to the address of the secure access service edge node.
[0122] For example, the addresses allocated to an enterprise organization include IPv4 addresses (such as 134.43.34.1), IPv6 addresses (such as 2a03:54c1:34::310c), or a domain name (such as kjfaueo.xiueorijl-gateway.com, through which the domain name can be further resolved to the secure access service edge node that provides domain name resolution services).
[0123] After setting up the diversion strategy, the operator or the security manager of the target user will synchronize the set diversion strategy to the security access service edge node and the target terminal used by the target user, so that the domain name resolution request sent by the target user through the target terminal can be diverted to the corresponding security access service edge node for resolution control, that is, to realize the diversion of the domain name resolution request.
[0124] It should be noted that in the above steps, although the operator or the target user's administrator manually configures the traffic diversion strategy and security resolution strategy for the target user on the cloud security management platform, the technical solution of the present invention is not limited to this. For example, the cloud security management platform can also automatically match the traffic diversion strategy and security resolution strategy suitable for the target user based on the target user's characteristics or identity through queries. This will not be elaborated here.
[0125] The system of this embodiment includes a plurality of distributedly deployed secure access service edge nodes (hereinafter referred to as secure edge nodes). Generally, secure DNS software is run on each secure edge node to implement secure access control of DNS resolution. The secure DNS software supports multiple types of DNS resolution protocols, such as UDP, TCP, DoT (DNS over TLS), and DoH (DNS over HTTPS), and can support the processing of domain name resolution requests from multiple types of target terminals. In addition, the system of this embodiment also includes a configuration manager for configuring secure edge nodes. In this system, the target user configuration interface of the cloud security management platform first sends the latest database, security resolution policy, and diversion policy information received to the configuration manager, and then the configuration manager sends the database, security resolution policy, and diversion policy information issued by the cloud security management platform to each secure access service edge node, and issues the diversion policy to the corresponding target terminal. Here, a more beneficial approach is that before performing resolution control on the target domain name to be resolved according to the security resolution policy, the configuration manager updates the database and / or security resolution policy stored on each service edge node accordingly based on the update information for the database and / or security resolution policy received from the target user configuration interface of the cloud security management platform.
[0126] In this embodiment, the database issued by the cloud security management platform includes at least one of a domain name classification database, a security threat database, and a custom domain name database. The information on the security resolution policy and diversion policy issued by the cloud security management platform often records multiple target users and the security resolution policy and diversion policy corresponding to each target user. The security resolution policy includes at least one of a domain name classification resolution policy, a security threat resolution policy, and a custom resolution policy. The diversion policy includes the address of the security access service edge node that provides domain name resolution services assigned by the cloud security management platform to the target user.
[0127] like Figure 6 As shown, each secure access service edge node can include a load balancer and at least one security server. The load balancer is used to forward domain name resolution requests to one of the security servers. Each security server runs a protocol processing module, a threat identification module, a domain name grouping module, a custom resolution module, and a policy engine module.
[0128] The functions and effects of each module on the security server are described in detail below.
[0129] The policy engine module receives configuration information from the configuration manager and provides the configuration information to other functional modules. The configuration information includes information such as the database, security resolution policy, and diversion policy sent to the configuration manager by the cloud security management platform. The other functional modules perform corresponding domain name resolution control processing on the domain name resolution request based on this configuration information.
[0130] The protocol processing module supports various types of DNS resolution protocols, such as UDP, TCP, DoT (DNS over TLS), and DoH (DNS over HTTPS). It can resolve domain name resolution requests from various types of target terminals (such as user terminals or network exits of branches) according to the DNS resolution protocol, thereby determining which target terminal (target user) sends the domain name resolution request and the target domain name to be resolved.
[0131] In this embodiment, upon receiving a domain name resolution request from a user via a target terminal, the protocol processing module of the security server first resolves the domain name resolution request to determine the identification information of the target terminal that sent the domain name resolution request and the target domain name to be resolved, wherein the identification information of the target terminal includes the target terminal's public network exit address and / or the request method of the domain name resolution request. The protocol processing module of the security server then determines the target user corresponding to the target terminal based on the identification information of the target terminal, and then determines the security resolution policy associated with the target user corresponding to the target terminal based on the correspondence between each target user and the security resolution policy obtained from the policy engine module.
[0132] In this embodiment, if Figure 7 As shown, when the identification information of the target terminal includes the public network exit address of the target terminal and / or the request mode of the domain name resolution request, the protocol processing module of the security server determines the target user corresponding to the target terminal according to the identification information of the target terminal, including the following steps:
[0133] ① When resolution is performed through DoH or DoT, the security server determines the target user based on the service domain name (such as the HTTPS domain name) of the requested secure access service edge node, otherwise it proceeds to ② or ③;
[0134] ② When the request method for sending the resolution request is not DoT or DoH, and the public network exit address of the target terminal is an IPv4 address, the security server determines the target user based on the public network exit IP v4 address of the target terminal;
[0135] ③ When the request method for sending the resolution request is not DoT or DoH, and the public network exit address of the target terminal is not an IPv4 address, the security server determines the target user based on the IPv6 address of the secure access service edge node assigned to the target user.
[0136] The threat identification module identifies the threat category of the target domain name to be resolved based on a pre-stored security threat database, that is, determines whether the target domain name to be resolved belongs to a threat category such as virus, C2, phishing email, mining, etc., and implements a disposal method for such domain names based on the security threat resolution policy in the security resolution policy associated with the target user; wherein, the disposal method includes allowing the target domain name to be resolved, prohibiting the target domain name from being resolved, or observing the resolution of the target domain name, wherein observing the resolution of the target domain name means allowing the target domain name to be resolved and recording the resolution log at that time.
[0137] The domain name classification module loads the domain name classification data (i.e., the data of the domain name classification database) issued by the cloud security management platform through the policy engine module, and identifies the content category of the target domain name to be requested (such as entertainment, information, games, etc.) through an efficient data search method, and then implements the disposal method for such domain names based on the classification resolution strategy in the security resolution policy associated with the target user; wherein, the disposal method includes allowing the resolution of the target domain name, prohibiting the resolution of the target domain name, or observing the resolution of the target domain name, and observing the resolution of the target domain name means allowing the resolution of the target domain name and recording the resolution log at that time.
[0138] The custom resolution module determines, based on a pre-stored custom domain name database, whether the target domain name to be resolved belongs to a custom domain name category in the custom domain name database, and implements a disposal method for such domain name based on the determination result and the custom resolution policy in the security resolution policy associated with the target user; wherein the disposal method includes allowing the target domain name to be resolved, prohibiting the target domain name from being resolved, or replacing the target domain name.
[0139] There are two ways to change the target domain name:
[0140] 1. The secure access service edge node returns a CNAME record to the target terminal. The record value is the new domain name. The target terminal then initiates a domain name resolution request based on the new domain name.
[0141] 2. The security service edge node directly resolves the new domain name and returns the resolution result of the new domain name to the target terminal, such as the IP address obtained by resolving the new domain name.
[0142] In addition, when necessary, the security server will feedback the response information generated by the resolution control of the domain name resolution request to the target terminal. For example, when the handling method is to prohibit the resolution of the domain name, the security server sends a prompt message to the target terminal to prompt the prohibition of resolution.
[0143] In addition to the above steps, the secure access service edge node 20 may also output a parsing log to the cloud security management platform 10 . The parsing log records the parsing result of the target domain name. The format of the parsing log is configurable.
[0144] For example, the DNS server outputs the resolution log shown in the table below. By default, only request logs that hit the blocking mode are recorded. Other logs are not recorded by default due to their large volume. Statistics are aggregated and output at a certain time interval (such as once every 5 minutes). Logs can be recorded for requests in the allow and observe modes. Each log contains, but is not limited to, the following fields:
[0145] Table 2
[0146] Field Name meaning request_id The unique identifier of the request, such as f5e50d9d8785d6db09d99475cc5426a4 node_id The identifier of the edge node, such as dx-zhejiang-jinhua-8 timestamp Request timestamp, such as 2021-06-04 12:34:09 server_addr Edge Node VIP remote_addr Client public network exit IP location_id Branch logo enterprise_id Company ID rule_id The ID of the access control rule action Disposition action (allow, prohibit, observe) request_time Time taken to process the request qmethod DNS resolution methods, such as tcp, udp, dot, doh qname Domain name to be resolved qtype The requested record type, such as A, AAAA, TXT, MX, etc. domain_category Domain name grouping type
[0147] On the other hand, after receiving the parsing log sent by the secure access service edge node 20 , the cloud security management platform 10 may analyze and / or visualize the parsing results in the parsing log.
[0148] For example, a cloud security management platform can aggregate, compile, and analyze these logs across various dimensions, displaying visual analysis views of each dimension on the platform to facilitate intuitive understanding of attack and threat situations and connect corresponding threat events to the SIEM platform. The cloud security management platform provides, but is not limited to, the types of data analysis and visualization shown in Table 3 below:
[0149] Table 3
[0150]
[0151] Example 3
[0152] The following are embodiments of the apparatus of the present invention, which can be used to implement the method embodiments of the present invention. For details not disclosed in the apparatus embodiments of the present invention, please refer to the method embodiments of the present invention.
[0153] This embodiment provides a secure access control device based on DNS resolution, which is provided on a secure access service edge node. The device has the function of executing the above-mentioned method example, which can be implemented by hardware or by hardware executing corresponding software. The device may include:
[0154] A request analysis module, configured to determine identification information of the target terminal and a target domain name to be resolved based on a domain name resolution request from the target terminal;
[0155] a policy determination module, configured to determine, based on the identification information of the target terminal, a security parsing policy associated with a target user corresponding to the target terminal;
[0156] The resolution control module is used to perform resolution control on the target domain name according to the security resolution policy.
[0157] Example 4
[0158] The following are embodiments of the apparatus of the present invention, which can be used to implement the method embodiments of the present invention. For details not disclosed in the apparatus embodiments of the present invention, please refer to the method embodiments of the present invention.
[0159] This embodiment provides a secure access control device based on DNS resolution, which is provided in a target terminal and is characterized by comprising:
[0160] A policy acquisition module, configured to acquire a traffic diversion policy for a domain name resolution request, wherein the traffic diversion policy includes an address of a secure access service edge node that provides a domain name resolution service and is allocated to the target terminal;
[0161] A request sending module, configured to send the generated domain name resolution request to the secure access service edge node according to the traffic diversion strategy;
[0162] A response receiving module is used to receive response information sent by the secure access service edge node, where the response information is generated by the secure access service edge node by performing resolution control on the domain name resolution request according to a security resolution policy, wherein the security resolution policy is associated with a target user corresponding to the target terminal.
[0163] Example 5
[0164] This embodiment provides a computer-readable medium having a computer program stored thereon. When the program is executed by a processor, the steps of the secure access control method based on DNS resolution as described in the above embodiment are implemented.
[0165] It should be noted that the present invention can implement all or part of the processes in the above-mentioned embodiment method by instructing the relevant hardware through a computer program. The computer program can be stored in a computer-readable storage medium. When the computer program is executed by a processor, it can implement the steps of the above-mentioned various method embodiments. The computer program includes computer program code, which can be in source code form, object code form, executable file or some intermediate form. The computer-readable medium may include: any entity or device capable of carrying the computer program code, recording medium, USB flash drive, mobile hard disk, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electric carrier signal, telecommunication signal and software distribution medium. Of course, there are other types of readable storage media, such as quantum memory, graphene memory, etc. It should be noted that the content contained in the computer-readable medium can be appropriately increased or decreased according to the requirements of legislation and patent practice in the jurisdiction. For example, in some jurisdictions, according to legislation and patent practice, computer-readable media do not include electric carrier signals and telecommunication signals.
[0166] Example 6
[0167] Figure 8 FIG. 1 is a schematic diagram of the structure of an electronic device according to an embodiment of the present invention. Figure 8As shown, at the hardware level, the electronic device includes a processor and, optionally, an internal bus, a network interface, and memory. The memory may include internal memory, such as high-speed random-access memory (RAM), and may also include non-volatile memory, such as at least one disk storage device. Of course, the electronic device may also include other hardware required for its services.
[0168] The processor, network interface, and memory can be interconnected via an internal bus, which can be an ISA (Industry Standard Architecture) bus, a PCI (Peripheral Component Interconnect) bus, or an EISA (Extended Industry Standard Architecture) bus. The bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 8 Only line segments are used to represent the bus, but this does not mean that there is only one bus or one type of bus.
[0169] The memory is used to store programs. Specifically, the program may include program code, which includes computer operating instructions. The memory may include internal memory and non-volatile memory, and provides instructions and data to the processor. The processor reads the corresponding computer program from the non-volatile memory into the internal memory and then runs it. The processor executes the program stored in the memory to perform the following operations: Figure 2 All steps in a secure access control method based on DNS resolution are shown.
[0170] The communication bus mentioned in the above devices may be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus. This communication bus can be divided into address buses, data buses, control buses, etc. For ease of illustration, only one thick line is used in the figure, but this does not mean that there is only one bus or only one type of bus. The communication interface is used for communication between the above electronic devices and other devices.
[0171] Bus comprises hardware, software or both, for above-mentioned parts are coupled together.For example, bus can comprise accelerated graphics port (AGP) or other graphics bus, enhanced industry standard architecture (EISA) bus, front side bus (FSB), hypertransport (HT) interconnection, industry standard architecture (ISA) bus, infinite bandwidth interconnection, low pin count (LPC) bus, memory bus, micro channel architecture (MCA) bus, peripheral component interconnection (PCI) bus, PCI-Express (PCI-X) bus, serial advanced technology attachment (SATA) bus, video electronics standard association local (VLB) bus or other suitable bus or two or more above these combinations.In suitable case, bus can comprise one or more buses.Although the embodiment of the present invention describes and shows specific bus, the present invention considers any suitable bus or interconnection.
[0172] The memory may include random access memory (RAM) or non-volatile memory (NVM), such as at least one disk storage. Alternatively, the memory may be at least one storage device located away from the processor.
[0173] The memory may include a large capacity memory for data or instructions. By way of example and not limitation, the memory may include a hard disk drive (HDD), a floppy disk drive, a flash memory, an optical disk, a magneto-optical disk, a magnetic tape, or a universal serial bus (USB) drive, or a combination of two or more of these. Where appropriate, the memory may include a removable or non-removable (or fixed) medium. In a specific embodiment, the memory is a non-volatile solid-state memory. In a specific embodiment, the memory includes a read-only memory (ROM). Where appropriate, the ROM may be a mask-programmed ROM, a programmable ROM (PROM), an erasable PROM (EPROM), an electrically erasable PROM (EEPROM), an electrically rewritable ROM (EAROM), or a flash memory, or a combination of two or more of these.
[0174] The above-mentioned processor can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, and discrete hardware components.
[0175] It should be noted that those skilled in the art can clearly understand that for the convenience and brevity of description, only the division of the above-mentioned functional units and modules is used as an example for illustration. In actual applications, the above-mentioned functions can be distributed and completed by different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above. The functional units and modules in the embodiment can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above-mentioned integrated unit can be implemented in the form of hardware or in the form of software functional units. In addition, the specific names of the functional units and modules are only for the convenience of distinguishing each other, and are not used to limit the scope of protection of the present invention. The specific working process of the units and modules in the above-mentioned system can refer to the corresponding process in the aforementioned method embodiment, and will not be repeated here.
[0176] The devices, apparatuses, systems, modules, or units described in the above embodiments may be implemented by computer chips or entities, or by products having certain functions. A typical implementation device is a computer. Specifically, the computer may be, for example, a personal computer, a laptop computer, an in-vehicle human-computer interaction device, a cellular phone, a camera phone, a smartphone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or a combination of any of these devices.
[0177] Although the present invention provides method operation steps as described in the embodiments or flowcharts, more or fewer operation steps may be included based on conventional or non-inventive means. The order of steps listed in the embodiments is only one way of executing the order of many steps and does not represent the only execution order. When an actual device or terminal product is executed, it can be executed in sequence or in parallel according to the method shown in the embodiments or the drawings (for example, in a parallel processor or multi-threaded processing environment, or even a distributed data processing environment).
[0178] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowcharts and / or block diagrams, as well as combinations of processes and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowcharts and / or block diagrams. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0179] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.
[0180] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.
[0181] It should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or apparatus. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of additional identical elements in the process, method, article, or apparatus comprising the element.
[0182] Each embodiment in this specification is described in a related manner. Similar portions between the various embodiments can be referenced to each other. Each embodiment focuses on the differences from other embodiments. In particular, the device, electronic device, and readable storage medium embodiments are generally similar to the method embodiments, so their descriptions are relatively simple. For related portions, reference can be made to the descriptions of the method embodiments.
[0183] The above description is only a preferred embodiment of the present invention and is not intended to limit the scope of protection of the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present invention are included in the scope of protection of the present invention.
Claims
1. A secure access control method based on DNS resolution, applied to a secure access service edge node, the method comprising: Receive a domain name resolution request from a target terminal, wherein the domain name resolution request is directed to the secure access service edge node according to a pre-set traffic diversion strategy; Determining, based on a domain name resolution request from a target terminal, identification information of the target terminal and a target domain name to be resolved; Determining, based on the identification information of the target terminal, a security parsing policy associated with a target user corresponding to the target terminal; Performing resolution control on the target domain name according to the security resolution policy; The identification information of the target terminal includes at least one of a public network exit address of the target terminal and a request method of the domain name resolution request; Determining, based on the identification information of the target terminal, a security parsing policy associated with a target user corresponding to the target terminal, including: Determining a target user corresponding to the target terminal according to the identification information of the target terminal; Determining a security parsing policy associated with a target user corresponding to the target terminal according to a pre-stored correspondence between the target user and the security parsing policy; The method is characterized in that, determining a target user corresponding to the target terminal according to the identification information of the target terminal includes: If the domain name resolution request mode is DoT or DoH, determine the target user corresponding to the target terminal according to the service domain name of the secure access service edge node; If the request mode for sending the resolution request is not DoT or DoH, and the public network exit address of the target terminal is an IPv4 address, determine the target user corresponding to the target terminal according to the public network exit address of the target terminal; If the request mode for sending the resolution request is not DoT or DoH, and the public network exit address of the target terminal is not an IPv4 address, the target user corresponding to the target terminal is determined according to the IPv6 address of the secure access service edge node allocated to the target terminal.
2. The method according to claim 1, characterized in that The target terminal includes a user terminal and / or a network exit of a branch office; the diversion strategy includes the address of a secure access service edge node that provides domain name resolution services and is allocated by the cloud security management platform to the target terminal, so that the domain name resolution request sent by the target terminal is diverted to the secure access service edge node for resolution control.
3. The method according to claim 1, characterized in that Performing resolution control on the target domain name according to the security resolution policy includes: Determine the threat category corresponding to the target domain name based on a pre-stored security threat database; Determine a handling method for the target domain name based on the threat category. The handling method includes allowing resolution of the target domain name, prohibiting resolution of the target domain name, or observing resolution of the target domain name. Observing resolution of the target domain name means allowing resolution of the target domain name and recording a resolution log.
4. The method according to claim 1, wherein Performing resolution control on the target domain name according to the security resolution policy includes: Determining the content category corresponding to the target domain name based on a pre-stored domain name classification database; According to the content category, a disposal method for the target domain name is determined, where the disposal method includes allowing the target domain name to be resolved, prohibiting the target domain name from being resolved, or observing the resolution of the target domain name. Observing the resolution of the target domain name means allowing the target domain name to be resolved and recording a resolution log.
5. The method according to claim 1, wherein Performing resolution control on the target domain name according to the security resolution policy includes: Determining whether the target domain name belongs to a custom domain name type in a pre-stored custom domain name database; According to the judgment result, a disposal method for the target domain name is determined, where the disposal method includes allowing the target domain name to be resolved, prohibiting the target domain name from being resolved, or replacing the target domain name.
6. The method according to any one of claims 3 to 5, characterized in that Before performing resolution control on the target domain name according to the security resolution policy, the method further includes: The pre-stored security parsing policy is updated according to the update information for the security parsing policy from the cloud security management platform.
7. The method according to any one of claims 3 to 5, characterized in that After determining the disposal method for the target domain name, the method further includes: When the handling method is to prohibit the resolution of the domain name, a prompt message for prohibiting the resolution is sent to the target terminal.
8. The method according to claim 1, further comprising: Output a parsing log to the cloud security management platform, wherein the parsing log records the parsing result of the target domain name.
9. A secure access control method based on DNS resolution, applied to a cloud security management platform, comprising: Configure traffic diversion strategies and security resolution strategies for domain name resolution requests for target users; Sending the traffic diversion strategy to the secure access service edge node and the target terminal corresponding to the target user, respectively, so that the target terminal sends a domain name resolution request to the secure access service edge node according to the traffic diversion strategy; Sending the security resolution policy to the security access service edge node, so that the security access service edge node performs resolution control on the target domain name to be resolved in the domain name resolution request according to the security resolution policy; The following steps are applied at the secure access service edge node: Receive a domain name resolution request from a target terminal, wherein the domain name resolution request is directed to the secure access service edge node according to a pre-set traffic diversion strategy; Determining, based on a domain name resolution request from a target terminal, identification information of the target terminal and a target domain name to be resolved; Determining, based on the identification information of the target terminal, a security parsing policy associated with a target user corresponding to the target terminal; Performing resolution control on the target domain name according to the security resolution policy; The identification information of the target terminal includes at least one of a public network exit address of the target terminal and a request method of the domain name resolution request; Determining, based on the identification information of the target terminal, a security parsing policy associated with a target user corresponding to the target terminal, including: Determining a target user corresponding to the target terminal according to the identification information of the target terminal; Determining a security parsing policy associated with a target user corresponding to the target terminal according to a pre-stored correspondence between the target user and the security parsing policy; The method is characterized in that, determining a target user corresponding to the target terminal according to the identification information of the target terminal includes: If the domain name resolution request mode is DoT or DoH, determine the target user corresponding to the target terminal according to the service domain name of the secure access service edge node; If the request mode for sending the resolution request is not DoT or DoH, and the public network exit address of the target terminal is an IPv4 address, determine the target user corresponding to the target terminal according to the public network exit address of the target terminal; If the request mode for sending the resolution request is not DoT or DoH, and the public network exit address of the target terminal is not an IPv4 address, the target user corresponding to the target terminal is determined according to the IPv6 address of the secure access service edge node allocated to the target terminal.
10. The method according to claim 9, characterized in that The configuration of the traffic diversion strategy and security resolution strategy for the domain name resolution request for the target user includes: In response to a configuration request for a target user, displaying a target user configuration interface, the configuration interface including a plurality of information configuration options; Based on the edit information received from the plurality of information configuration options, the public network exit address, intranet address, traffic diversion strategy and security resolution strategy corresponding to the target user are determined.
11. The method according to claim 9, characterized in that The target terminal includes a user terminal and / or a network exit of a branch office; the diversion strategy includes the address of a secure access service edge node that provides domain name resolution services and is allocated by the cloud security management platform to the target terminal, so that the domain name resolution request sent by the target terminal is diverted to the secure access service edge node for resolution control.
12. The method according to claim 9, characterized in that The security resolution strategy includes at least one of a domain name classification resolution strategy, a security threat resolution strategy, and a custom resolution strategy.
13. The method according to claim 12, characterized in that The method further comprises: Establish at least one of a domain name classification database, a security threat database, and a custom domain name database, and synchronize the database to the secure access service edge node so that the secure access service edge node can perform resolution control on the target domain name according to the database.
14. The method according to claim 9, characterized in that The method further comprises: Receive the parsing log sent by the secure access service edge node, and analyze and / or visualize the parsing results in the parsing log.
15. A secure access control method based on DNS resolution, applied to a target terminal, the method comprising: Obtaining a traffic diversion strategy for a domain name resolution request, the traffic diversion strategy including an address of a secure access service edge node that provides a domain name resolution service and is allocated to the target terminal; According to the traffic diversion strategy, the generated domain name resolution request is sent to the secure access service edge node; receiving a response message sent by the secure access service edge node, the response message being generated by the secure access service edge node by performing resolution control on the domain name resolution request according to a security resolution policy, wherein the security resolution policy is associated with a target user corresponding to the target terminal; The following steps are applied at the secure access service edge node: Receive a domain name resolution request from a target terminal, wherein the domain name resolution request is directed to the secure access service edge node according to a pre-set traffic diversion strategy; Determining, based on a domain name resolution request from a target terminal, identification information of the target terminal and a target domain name to be resolved; Determining, based on the identification information of the target terminal, a security parsing policy associated with a target user corresponding to the target terminal; Performing resolution control on the target domain name according to the security resolution policy; The identification information of the target terminal includes at least one of a public network exit address of the target terminal and a request method of the domain name resolution request; Determining, based on the identification information of the target terminal, a security parsing policy associated with a target user corresponding to the target terminal, including: Determining a target user corresponding to the target terminal according to the identification information of the target terminal; Determining a security parsing policy associated with a target user corresponding to the target terminal according to a pre-stored correspondence between the target user and the security parsing policy; The method is characterized in that, determining a target user corresponding to the target terminal according to the identification information of the target terminal includes: If the domain name resolution request mode is DoT or DoH, determine the target user corresponding to the target terminal according to the service domain name of the secure access service edge node; If the request mode for sending the resolution request is not DoT or DoH, and the public network exit address of the target terminal is an IPv4 address, determine the target user corresponding to the target terminal according to the public network exit address of the target terminal; If the request mode for sending the resolution request is not DoT or DoH, and the public network exit address of the target terminal is not an IPv4 address, the target user corresponding to the target terminal is determined according to the IPv6 address of the secure access service edge node allocated to the target terminal.
16. The method according to claim 15, characterized in that The target terminal includes a user terminal and / or a network exit of a branch office.
17. The method according to claim 15, characterized in that Obtain the traffic diversion strategy for domain name resolution requests, including: Sending an access request to the cloud security management platform, wherein the access request includes the identity information of the target terminal; Receive a traffic diversion strategy for a domain name resolution request sent by the cloud security management platform, where the traffic diversion strategy is obtained by the cloud security management platform through querying the identity information of the target terminal.
18. The method according to claim 17, characterized in that According to the traffic diversion strategy, the generated domain name resolution request is sent to the secure access service edge node, including: Point the DNS server address corresponding to the target terminal to the address of the secure access service edge node; According to the address of the secure access service edge node, the generated domain name resolution request is sent to the secure access service edge node.
19. A secure access control system based on DNS resolution, characterized in that: The system comprises: The cloud security management platform is used to configure a traffic diversion strategy and a security resolution strategy for a target user's domain name resolution request, and send the traffic diversion strategy to a secure access service edge node and a target terminal corresponding to the target user, and send the security resolution strategy to the secure access service edge node; The secure access service edge node using the secure access control method based on DNS resolution as claimed in claim 1 is used to perform resolution control on the target domain name to be resolved in the domain name resolution request from the target terminal according to the secure resolution policy.
20. The system according to claim 19, wherein: The system further comprises: The target terminal is configured to send the domain name resolution request to the secure access service edge node according to the traffic diversion strategy.
21. A secure access control device based on DNS resolution, arranged at a secure access service edge node applying the secure access control method based on DNS resolution as claimed in claim 1, characterized in that: The device comprises: A request analysis module, configured to determine identification information of the target terminal and a target domain name to be resolved based on a domain name resolution request from the target terminal; a policy determination module, configured to determine, based on the identification information of the target terminal, a security parsing policy associated with a target user corresponding to the target terminal; The resolution control module is used to perform resolution control on the target domain name according to the security resolution policy.
22. A DNS resolution-based security access control device, provided on a cloud security management platform that applies the DNS resolution-based security access control method according to claim 9, characterized in that: include: The policy configuration module is used to configure the traffic diversion strategy and security resolution strategy for domain name resolution requests for target users; A first sending module is configured to send the traffic diversion strategy to the secure access service edge node and the target terminal corresponding to the target user, so that the target terminal sends a domain name resolution request to the secure access service edge node according to the traffic diversion strategy; The second sending module is configured to send the security resolution policy to the security access service edge node, so that the security access service edge node performs resolution control on the target domain name to be resolved in the domain name resolution request according to the security resolution policy.
23. A secure access control device based on DNS resolution, provided on a target terminal to which the secure access control method based on DNS resolution as claimed in claim 15 is applied, characterized in that: include: A policy acquisition module, configured to acquire a traffic diversion policy for a domain name resolution request, wherein the traffic diversion policy includes an address of a secure access service edge node that provides a domain name resolution service and is allocated to the target terminal; A request sending module, configured to send the generated domain name resolution request to the secure access service edge node according to the traffic diversion strategy; A response receiving module is used to receive response information sent by the secure access service edge node, where the response information is generated by the secure access service edge node by performing resolution control on the domain name resolution request according to a security resolution policy, wherein the security resolution policy is associated with a target user corresponding to the target terminal.
24. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, a secure access control method based on DNS resolution as described in any one of claims 1 to 18 is implemented.
25. An electronic device, characterized in that: It includes: processor; a memory for storing instructions executable by the processor; The processor is configured to execute the instructions to implement a secure access control method based on DNS resolution as described in any one of claims 1 to 18.
Citation Information
Patent Citations
Service system access method and system based on cloud computing
CN107124423A