Server port security configuration method and device and server

By configuring one or a few open ports on the server and generating legitimate tags through user authentication and adding them to the rule port whitelist, the problem of poor server port security is solved, achieving efficient security and flexible access control.

CN120956490APending Publication Date: 2025-11-14SHANGHAI SINOXUAN INTELLECTUAL PROPERTY CONSULTING SERVICES CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511156896.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-19
Publication Date
2025-11-14

AI Technical Summary

Technical Problem

In existing technologies, server port security is poor, traditional security measures are labor-intensive and prone to security vulnerabilities, VPNs affect performance and rely on third parties, and SSO offers limited improvement.

Method used

A server port security configuration method is adopted, which configures only one or a few open ports. After verification through the user login authentication interface, a valid tag is generated and added to the rule port whitelist to achieve fine-grained access control and dynamic security management.

Benefits of technology

It greatly reduces security risks and maintenance costs, improves server port security, and enables fine-grained access control and dynamic security management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120956490A_ABST
    Figure CN120956490A_ABST
Patent Text Reader

Abstract

The invention discloses a server port security configuration method and device and a server, and relates to the technical field of network services. The method comprises the steps that an open port and a rule port are obtained through configuration, the open port is a port which can be actively accessed, the open port comprises a user login identity verification interface, and the rule port is a port which cannot be actively accessed; obtaining a white list of the rule port based on the white list rule configuration of the rule port, wherein the white list rule of the rule port comprises that the request end passing the verification of the user login identity verification interface of the open port is allowed to access the rule port; the device is a computer readable storage medium in which a program is stored, and the steps in the method are implemented when the program is executed by a processor. The server is obtained according to the configuration of the method; and for the request end which does not pass verification, the rule port is hidden, so that the security of the server port is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network service technology, and in particular to a method, apparatus and server for configuring secure server ports. Background Technology

[0002] In today's era of internet development, people primarily interact with the world through communication between personal terminals such as PCs and mobile phones and servers. To improve server utilization efficiency, a server deployed on the internet often opens multiple ports to provide various services to users. Common website servers typically open database service ports and HTTP ports simultaneously. Enterprise office servers, in particular, also provide services such as OA / ERP / BPM / CRM / financial systems to internal employees located in different locations. The increase in the number of open ports means an increase in risk. Traditional port security measures mainly involve implementing separate security measures for each port, which often leaves enterprise operations and security personnel exhausted.

[0003] There are currently three main security defense strategies for server ports, which are detailed below.

[0004] 1. Technique 1: Harden each port individually and add port access rules. This approach is labor-intensive and requires a high level of technical skill from the program developers and maintainers. Slight negligence could leave security vulnerabilities on a port, giving hackers an opportunity to exploit them.

[0005] 2. Technology Two: VPN. VPNs are the most common approach used by businesses today. A VPN creates a virtual, encrypted private network on the internet, helping users achieve secure data transmission in insecure network environments. The working principle of a VPN involves three steps: First, the user connects to the VPN server through a VPN client; second, data is transmitted encrypted between the VPN client and the VPN server; third, the user's network requests are forwarded to the target website or service through the VPN server, and the website's response data is also transmitted back to the user through the VPN server. However, VPN technology has limitations: First, VPN relays add extra encryption and decryption calculations, affecting performance, and also increase network latency, impacting the user experience; second, since user network requests and responses are relayed through the VPN server, data security and privacy depend on the VPN service provider; third, VPN configuration is complex.

[0006] 3. Technology Three: Single Sign-On (SSO). It's an authentication mechanism that allows users to log in to multiple applications or websites using a single set of credentials, such as a username and password, without needing to log in separately for each application. SSO primarily addresses: First, optimizing user experience: reducing the number of passwords users need to remember and improving operational efficiency. Second, security management: centrally managing user identities and reducing the risk of password leaks. Third, system integration: simplifying authentication processes between different systems. While SSO improves security primarily through centralized user authentication management and reduced operational complexity, its fundamental security enhancement is limited.

[0007] Therefore, the high cost and poor security of server port security maintenance have become urgent technical problems that need to be solved. Summary of the Invention

[0008] This invention provides a method, apparatus, and server for configuring secure server ports, thereby solving the technical problem of poor server port security.

[0009] To solve the above-mentioned technical problems, the technical solution adopted by the present invention is as follows:

[0010] A method for configuring server port security includes the following steps: Step 1: Configure and obtain open ports and rule ports, where open ports are ports that can be actively accessed and include user login authentication interfaces, and rule ports are ports that cannot be actively accessed; Configure and obtain a whitelist of rule ports based on whitelist rules of rule ports, where the whitelist rules of rule ports include allowing requesting clients that have passed authentication through the user login authentication interface of open ports to access rule ports.

[0011] A further technical solution is that, in step 1, the number of open ports is one.

[0012] A further technical solution is that, in step 1, the number of open ports is small.

[0013] A further technical solution is that, in step 1, the whitelist rule for the rule port also includes allowing access to the corresponding rule port based on the user role identity of the verified requesting end.

[0014] A further technical solution is that, in step 1, the open port also includes a functional interface.

[0015] A further technical solution is that, in step 1, the whitelist rule for the rule port also includes allowing access to the corresponding functional interface based on the user role identity of the verified requesting end.

[0016] A further technical solution includes step 2 after step 1. In step 2, when the requesting end passes the user login authentication interface verification without the open port, the requesting end only has access to the user login authentication interface. When the requesting end passes the user login authentication interface verification with the open port, a valid tag is generated and sent to the requesting end, and the IP of the requesting end is added to the whitelist of the rule port. When the requesting end carries a valid tag and the IP of the requesting end is in the whitelist of the rule port, the rule port allows the requesting end to access.

[0017] A further technical solution is that, in step 2, the requesting end only has access to the user login authentication interface, that is, the function interfaces and rule ports other than the user login authentication interface in the open port are all denied access by the requesting end.

[0018] A further technical solution includes step 3 after step 2: clean up the whitelist of the rule port based on the triggering conditions for cleaning up the whitelist.

[0019] A further technical solution is as follows: In step 3, the trigger condition for cleaning the whitelist is a processing cycle setting value or a server load threshold. The cleaning is either initialization or targeted cleaning. Initialization is to delete all verified IPs, and targeted cleaning is to delete all verified IPs outside the trust table.

[0020] A server port security configuration device is a computer-readable storage medium storing a computer program that, when executed by a processor, implements the corresponding steps in the aforementioned server port security configuration method.

[0021] A server is configured according to the above-described server port security configuration method. The server is configured with open ports and rule ports. Requests that pass the user login authentication interface on the open ports are allowed to access the rule ports.

[0022] A further technical solution is that the number of open ports on the server is one.

[0023] A further technical solution is that the server has only one open port that can be actively accessed, and the server's rule ports cannot be actively accessed.

[0024] The beneficial effects of adopting the above technical solution are as follows:

[0025] First, a method for configuring server port security includes the following steps: Step 1: Configure and obtain open ports and rule ports. Open ports are ports that can be actively accessed, including user login authentication interfaces. Rule ports are ports that cannot be actively accessed. Configure and obtain a whitelist of rule ports based on whitelist rules. The whitelist rules for rule ports include allowing requests that have passed authentication via the user login authentication interface of the open ports to access the rule ports. For requests that have not passed authentication, the rule ports are hidden, thus improving the security of the server ports.

[0026] Secondly, the number of open ports is limited to one, which greatly reduces security risks and also lowers the cost of security maintenance.

[0027] Third, the number of open ports is small, which reduces security risks and also lowers the cost of security maintenance.

[0028] Fourth, the whitelist rules for rule ports also include allowing access to the corresponding rule ports or function interfaces based on the user role identity of the verified requesting party, thus achieving fine-grained access control and enhancing security.

[0029] Fifth, open ports also include functional interfaces. With more functional interfaces, more functions can be implemented, and applications can be more flexible and convenient.

[0030] Sixth, based on step 2, when the requesting client passes the user login authentication interface without accessing the open port, the requesting client only has access to the user login authentication interface, hiding other interfaces and rule ports, thus improving server security. When the requesting client carries a valid identifier and its IP address is in the rule port's whitelist, the rule port allows the requesting client to access it, achieving conditional access permission under controlled conditions and protecting server security.

[0031] Seventh, based on step 3, the whitelist of rule ports is cleaned up according to the trigger conditions for cleaning up the whitelist, so as to realize dynamic security control and ensure the security of the server in dynamic use.

[0032] Eighth, the trigger condition for cleaning the whitelist is the processing cycle setting or the server load threshold. The cleaning can be either initial or targeted, which can flexibly meet the needs of use while also ensuring security.

[0033] Ninth, a server port security configuration device, wherein the device is a computer-readable storage medium storing a computer program, and the computer program, when executed by a processor, implements the corresponding steps in the aforementioned server port security configuration method. Based on the technical means of allowing access to the rule port to requesting clients that have passed authentication via an open port's user login authentication interface, the rule port is hidden for unauthenticated requesting clients, thereby improving server port security.

[0034] Tenth, a server, configured according to the above-mentioned server port security configuration method, the server is configured with open ports and rule ports. Requests that pass the user login authentication interface of the open port are allowed to access the rule ports. For requests that fail authentication, the rule ports are hidden, thereby improving the security of the server ports. Attached Figure Description

[0035] Figure 1 This is a state diagram showing that the user has not been authenticated;

[0036] Figure 2 This is a state diagram showing that the user has been authenticated. Detailed Implementation

[0037] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. The following description of at least one exemplary embodiment is merely illustrative and is in no way intended to limit this application or its application or use. All other embodiments obtained by those skilled in the art based on the embodiments of this application without creative effort are within the scope of protection of this application.

[0038] Many specific details are set forth in the following description in order to provide a full understanding of this application. However, this application may also be implemented in other ways different from those described herein. Those skilled in the art can make similar extensions without departing from the spirit of this application. Therefore, this application is not limited to the specific embodiments disclosed below.

[0039] Example 1:

[0040] This invention discloses a method for configuring server port security, comprising the following steps:

[0041] Step 1: Determine the rule port and open ports, and create a whitelist rule for the rule port.

[0042] Configure open ports and rule ports. There is one open port, which can be actively accessed and includes both user login authentication and functional interfaces. There are multiple rule ports, which cannot be actively accessed. Configure a whitelist based on the rule ports to obtain a whitelist of rule ports. The whitelist rule allows requests that pass authentication via the user login authentication interface of the open port to access the rule port. Details are as follows.

[0043] like Figure 1 As shown, assuming an enterprise management server deploys seven types of services, each service type corresponds to a service port, with open port OP1 and rule ports RP1 to RP6 (first to sixth rules). Open port OP1 provides OA (Office Automation) services; rule port RP1 provides CRM (Customer Relationship Management); rule port RP2 provides PDM (Product Document Management); rule port RP3 provides DB (Database) services; rule port RP4 provides ERP (Enterprise Resource Planning) services; rule port RP5 provides PM (Project Management); and rule port RP6 provides RDP (Remote Procedure Call). Open port OP1 includes a user login authentication interface API, function interfaces API1, API2, and so on up to function interface APIn. `userLogin` is the interface function of the user login authentication interface API. Function interface API1 is used to receive requested pending task data, and function interface API2 is used to allow users to view procurement and contract data based on their permissions.

[0044] RP indicates that the port is a rule port, meaning that a rule is set for this port to allow only IP terminals that meet the rule to access the port. Port rules can be set through firewall whitelists or through server-side programmatic control. Considering that the rule will need to be programmed later, it is not recommended to use third-party firewall software.

[0045] Setting up a firewall whitelist is relatively easy. Taking a Windows Server 2022 server as an example, the PowerShell script to set up a whitelist for port 8080 is as follows.

[0046] New-NetFirewallRule -DisplayName "8080InboundRule" -Direction Inbound-Action Allow -Protocol TCP -LocalPort 8080.

[0047] To verify the validity of rule 8080InboundRule: Open the Windows Defender Firewall Advanced Security window, click Inbound Rules in the left navigation pane, find 8080InboundRule in the right-hand list, right-click, and click Properties in the context menu. In the Properties window, click the Scope tab, select the following IP addresses in the Remote IP address field, and click the Add button on the right. In the pop-up IP address window, enter the remote IP addresses allowed to access this port, and click OK. Return to the Properties window and click OK again. Now, use the telnet command on the client PC to test connectivity. If clients with internet IPs in the whitelist can connect while clients with other IPs cannot connect to this port, then the rule is effective.

[0048] OP indicates that the port is open to the outside world. No rules are set for this port, and any IP can connect. The user login authentication interface API provided on this port, userLogin(username,password), will verify the data submitted by the client and limit the frequency of access from the same IP.

[0049] Taking a Node.js server as an example, assuming OP1 is on port 8082, the server starts listening on port 8082:

[0050] app.use(logger.logger)

[0051] / / Configure the rate limiter in memory

[0052] const rateLimiter = new RateLimiterMemory({

[0053] points: 150, / / The maximum number of points allowed per IP address within a given time period.

[0054] duration: 1, / / The length of a time window (in seconds)

[0055] / / There are other configurable options.

[0056] });

[0057] app.listen(8082,()=>{

[0058] console.log('start server successfully!');

[0059] });

[0060] complete.

[0061] Step 2: Open port security verification and linkage operation of rule ports.

[0062] When a requesting client successfully authenticates via the user login authentication interface on an open port, it only has access to that interface. Access to other functional interfaces and rule ports on the open port is denied. Once the requesting client successfully authenticates via the user login authentication interface on the open port, the server generates a valid identifier, adds the requesting client's IP address to the rule port's whitelist, allows access, and sends the valid identifier to the requesting client. Details are as follows.

[0063] Without successful API:userLogin authentication, a user only has access to the API:userLogin interface on port OP1; access to other APIs on port OP1 and other RP ports is denied to the user.

[0064] The following is the Node.js server-side code that restricts access to API1, API2, and other interfaces on port OP1 to only those with a valid token:

[0065] app.use(expressJWT({

[0066] secret: key, / / The signing key or PublicKey

[0067] algorithms: ['HS256'],

[0068] }).unless({

[0069] path: [' / user / login'] / / Specifies the path that does not require token parsing, meaning the request can proceed normally even without a token in the request header.

[0070] }) );

[0072] complete.

[0073] A legitimate user within the enterprise accesses the API on port OP1: https: / / hostIP:OP1 / userLogin, providing the correct username and password. The server receives the submitted data, retrieves the user's IP address, verifies the user's legitimacy, generates a token, and returns it to the client (the requesting end). Simultaneously, the server adds the user's IP address to the whitelist of relevant ports. At this point, the user's IP address gains access rights to other related ports. The server can then further refine access control for these ports based on the user's role.

[0074] The server adds the user's IP address to the whitelist of the corresponding rule port based on the logged-in user's identity, role, and permissions, thereby granting the user access to the corresponding rule port and achieving fine-grained control over access permissions and enhanced security.

[0075] For example, by adding only the user's IP address to the rule set for port RP6, the user can only access ports OP1 and RP6, thus refining port access control.

[0076] For example, if a user is from the company's project department and logs into the server primarily to use the PM project management system, the server program on the OP port will add their IP address to the whitelist of the corresponding PM port based on the user's permissions. At this point, the user can access the PM's functions, but will still be unable to access functions on other ports. If a user is in finance, their IP address will be added to the whitelist of the finance-related port after logging in. If a user is in sales, their IP address will be added to the whitelist of the CRM customer management system port after logging in. These rules can be flexibly defined, achieving fine-grained access control and enhanced security.

[0077] Using PowerShell code as an example, the script to add client IP addresses to the rule port whitelist is as follows:

[0078] #Note: IP address passed from outside the script

[0079] Param(

[0080] [Parameter(Mandatory=$true)]

[0081] [string]$IP1 )

[0083] #Note: $ips = @('192.168.2.15','192.168.2.17','192.168.100.15')

[0084] #Note: The passed IP address is placed into an array variable.

[0085] $ips=@($IP1)

[0086] #Note: Retrieves the list of allowed IPs for firewall rule "Firewall Rule 1".

[0087] $current_ips = (Get-NetFirewallRule -DisplayName 'Firewall Rule 1'| Get-NetFirewallAddressFilter).RemoteAddress

[0088] #If the passed IP address is already in the list, do nothing.

[0089] if($current_ips -contains $IP1){

[0090] Write-Host 'FireWall Script IP existed:'$IP1

[0091] }else{

[0092] #If the passed IP is not in the list, then add it.

[0093] $current_ips += $ips

[0094] #Remove duplicate IPs from the list

[0095] $ips1=$current_ips | Sort-Object -Unique

[0096] # Set the IPs in the new set to the set of IPs allowed for connections in the firewall rules.

[0097] Get-NetFirewallrule -DisplayName 'Firewall rule 1'|Set-NetFirewallRule -RemoteAddress $ips1

[0098] Write-Host 'FireWall Script IP Add:'$IP1

[0099] }

[0100] complete.

[0101] The server program can perform operations on port rules by calling this PowerShell script.

[0102] In practice, user access to ports such as PDM also requires authentication and authorization. In this case, the server can resubmit the login data submitted by the user to the login interface of the application such as PDM, obtain the Token_PDM issued by the corresponding interface, and return it to the logged-in user.

[0103] like Figure 2 As shown, after receiving the corresponding token issued by the server, the user carries the token with each access request to the server. In this way, if API1 and API2 on port OP1 verify that the user role has the access rights, the user can access API1 / API2 and other interfaces to obtain the corresponding data.

[0104] Step 3: Regularly clean up the rule port whitelist.

[0105] The server initializes the whitelist of rule ports based on the processing cycle setting. Details are as follows.

[0106] To prevent unauthorized credential stuffing attacks and improve the performance of the program's handling of rule-based port whitelists, the whitelist should be initialized periodically. The processing cycle is set to one day. Initialization involves deleting all verified IPs, requiring re-verification.

[0107] Taking a Node.JS server program as an example, a scheduled task can be created when the service starts, which is scheduled to call a PowerShell script at 1:01:30 AM every day to initialize the whitelist of the corresponding rule ports.

[0108] app.listen(8082,()=>{

[0109] console.log('start server successfully!');

[0110] / / The rule initialization task is executed at 1:01:30 AM every day. It can also be set to execute the rule port whitelist initialization task at other times according to the server load.

[0111] schedule.scheduleJob('30 1 1 * * *', () => {

[0112] try {

[0113] execPowerShell.execPowerShell('C:\\PowerShellScript\\initFireWall.ps1')

[0114] } catch(e) {

[0115] console.log('Rule initialization error:' + e);

[0116] }

[0117] })

[0118] });

[0119] The initFireWall.ps1 script called in the above code is as follows:

[0120] #Initial values ​​for firewall whitelist

[0121] $ips = @('127.0.0.1','192.168.0.1','10.66.1.88')

[0122] #Initialize firewall whitelist

[0123] Get-NetFirewallrule -DisplayName 'Firewall rule 1'|Set-NetFirewallRule -RemoteAddress $ips

[0124] complete.

[0125] In Example 1, the trigger condition for cleaning the whitelist is a processing cycle setting value. The whitelist of the rule port is cleaned based on the processing cycle setting value. The processing cycle setting value is one day, and the whitelist of the rule port is initialized at 1:01:30 AM every day.

[0126] In summary, this application provides a technical architecture that exposes only one port with secure authentication through a multi-port security contraction defense strategy. After the user passes the security authentication of the open port, the backend will link up with other relevant rule ports to add the user's IP to the whitelist of the corresponding rule port, thus realizing port contraction defense of multi-port servers and fine-grained access control of ports and interfaces.

[0127] Compared to Embodiment 1, this application can also adopt another technical architecture, which uses a multi-port security contraction defense strategy to expose only a small number of ports with secure authentication, that is, the number of exposed open ports is a small number of ports, such as two, three or four ports with secure authentication.

[0128] In theory, if a server has n ports providing services externally, n-1 open ports can be configured. For example, consider two ports corresponding to services developed internally by the company's developers, who are confident in the security of these two ports and see no need to hide them. However, other ports correspond to services provided by third-party software vendors, such as PDM or OA systems. The company's internal maintenance personnel are unfamiliar with the technical details of these third-party software and lack confidence in their security, so they must be hidden. In this case, the number of open ports can be considered small.

[0129] Previously, with multiple ports open on a server, a lot of effort had to be put into improving the security of each port. Now, only one or a few open ports need to be maintained, which reduces maintenance costs.

[0130] Compared to Example 1, the processing cycle setting value can be set according to actual safety needs, such as one hour, four hours, one week, etc. In a specific example, the processing cycle setting value is a fixed value.

[0131] Compared to Example 1, the trigger condition for clearing the whitelist is the server load threshold. The trigger condition for clearing the whitelist can also be set according to the actual situation such as server load. When the server load is high, it can be controlled in time to ensure the security of the server.

[0132] For example, when the server load is greater than or equal to the server load threshold, the whitelist of rule ports is cleaned up. The server load threshold is 60%, and the trigger condition for cleaning up the whitelist is that when the server load reaches or exceeds 60% of the server's capacity, the whitelist of rule ports is initialized.

[0133] The server load threshold can also be designed to take values ​​according to actual needs, such as 70% or 80%.

[0134] Compared to Example 1, targeted cleanup can also be used. The steps of targeted cleanup are to retain a number of trusted IPs and delete all IPs other than these trusted ones. The server is an enterprise server, and the departments within the enterprise are internal departments. The IPs of these internal departments can be known in advance, and multiple IPs from these departments can be designated as trusted IPs. Targeted cleanup operations can better balance server security and the needs of internal enterprise use.

[0135] You can also designate multiple specific external IPs as trusted IPs, that is, multiple IPs of third parties that are known in advance as trusted IPs, so that the server can provide services to the specified third party requesting party while taking into account the server's security.

[0136] The company's internal department IPs and specific external IPs form a trust table. Multiple IPs in the trust table are considered trustworthy. The trust table is added to the whitelist of the rule port. During targeted cleanup, all verified IPs not in the trust table are deleted.

[0137] The triggering conditions for cleaning the whitelist can also be a combination of processing cycle settings and server load thresholds. For example, in a specific embodiment, the whitelist of the rule port is cleaned at 1:01:30 a.m. every day. The whitelist of the rule port is cleaned when the server load is greater than or equal to the server load threshold.

[0138] Compared to Implementation Example 1, the open port can contain only the user login authentication interface, which can make the server port more secure and solve the technical problem of poor security.

[0139] The above mainly describes how to manipulate Windows Firewall rules using PowerShell scripts on a Windows Server platform and how to whitelist port rules by calling PowerShell scripts from a Node.js server. The following outlines the general steps for other methods of implementing this technical solution.

[0140] Example 2:

[0141] This invention discloses a method for configuring server port security, comprising the following steps:

[0142] Implemented using C# programming on the Windows Server platform.

[0143] Take server port 8080 as an example.

[0144] Step 1: Create a whitelist for port 8080.

[0145] / / Note: Create a whitelist for port 8080. This whitelist can be stored in a local database.

[0146] private static List <string>whiteListOfRP8080 = new List <string>{ "192.168.1.1", "127.0.0.1"};

[0147] complete.

[0148] Step 2: Listen for TCP connection requests on port 8080. If the connection is already in the whitelist, allow it; otherwise, refuse it.

[0149] TcpListener listener = new TcpListener(IPAddress.Any, 8080);

[0150] listener.Start();

[0151] TcpClient client = listener.AcceptTcpClient();

[0152] IPEndPoint clientEndPoint = (IPEndPoint)client.Client.RemoteEndPoint;

[0153] string clientIp = clientEndPoint.Address.ToString();

[0154] if (whiteListOfRP8080.Contains(clientIp))

[0155] {

[0156] Console.WriteLine($"{clientIp} is already in the whitelist");

[0157] / / Post-connection operations such as reading data, etc.

[0158] }

[0159] else

[0160] {

[0161] Console.WriteLine($"{clientIp} violates whitelist rules");

[0162] client.Close(); / / Close the connection

[0163] }

[0164] complete.

[0165] Step 3: By opening the port, add the IP address of the already authenticated client to the whitelist of port 8080.

[0166] whiteListOfRP8080.add(clientIp);

[0167] complete.

[0168] Example 3:

[0169] This invention discloses a method for configuring server port security, comprising the following steps:

[0170] Implemented using IPTables on the Linux platform.

[0171] Take server port 8080 as an example.

[0172] Step 1: Ensure that iptables is installed.

[0173] yum install -y iptables-services

[0174] systemctl enable iptables

[0175] start service iptables

[0176] complete.

[0177] Step 2: Create a whitelist set for port 8080.

[0178] ipset create whitelist hash:ip

[0179] complete.

[0180] Step 3: Add port 8080 to the firewall and deny all IP access.

[0181] iptables -I INPUT -p tcp --dport 8080 -j DROP

[0182] complete.

[0183] Step 4: Add this whitelist to the set of allowed accesses for port 8080.

[0184] iptables -A INPUT -p tcp --dport 8080 -m set --match-set whitelistsrc -j ACCEPT

[0185] complete.

[0186] Step 5: By opening the port, add the IP of the already authenticated client to the whitelist of port 8080.

[0187] ipset add whitelist 192.168.50.81

[0188] complete.

[0189] Step 6: Periodically initialize the rule whitelist.

[0190] sudo ipset destroy whitelist

[0191] complete.

[0192] Example 4:

[0193] This invention discloses a method for configuring server port security, comprising the following steps:

[0194] Firewalld is implemented using programming methods on the Linux platform.

[0195] Take server port 8080 as an example.

[0196] Step 1: Install and start firewalld.

[0197] sudo yum install firewalld

[0198] sudo systemctl start firewalld

[0199] sudo systemctl enable firewalld

[0200] complete.

[0201] Step 2: Open port 8080.

[0202] firewall-cmd --zone=public --add-port=8080 / tcp --permanent

[0203] firewall-cmd --reload

[0204] complete.

[0205] Step 3: By opening the port, add the IP address of the already authenticated client to the whitelist of port 8080.

[0206] firewall-cmd --permanent --add-rich-rule="rule family="ipv4" sourceaddress="192.168.50.81" port protocol="tcp" port="8080" accept"

[0207] complete.

[0208] Step 4: Periodically initialize the rule whitelist.

[0209] firewall-cmd --permanent --remove-source=0.0.0.0 / 0

[0210] complete.

[0211] Example 5:

[0212] This invention discloses a server port security configuration device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. The memory and the processor form an electronic terminal, and the processor executes the computer program to implement the steps of Embodiment 1.

[0213] Example 6:

[0214] The present invention discloses a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the steps in Embodiment 1.

[0215] The research and development concept is summarized and explained as follows.

[0216] To address the troublesome issue of multi-port security defense, this application proposes a defense contraction strategy that can greatly reduce the cost of maintaining server port security and enhance server security.

[0217] This application addresses the problem that existing technologies or products of the same type need to solve: for multi-service enterprise management servers, as the server functions increase, the number of open ports also increases, and the security risks also increase.

[0218] Inventive concept: This application enables legitimate individuals to access other services by providing only one or a few authentication interfaces to the outside world, thereby greatly improving the security of enterprise servers.

[0219] The innovative points are explained below.

[0220] 1. Port contraction defense strategy for servers with open ports. Unauthenticated users can only access the user login verification interface provided by one or a few ports on the server. After successful verification, the server will link the corresponding rule port to the whitelist, thereby granting access to other ports and interfaces, thus improving server security performance.

[0221] 2. Fine-grained control over port and interface access. The server determines which ports or interfaces to open to a verified user based on the user's identity and role, thereby limiting the access scope of legitimate users.

[0222] 3. This application proposes a security and access control model that can be implemented through various programming languages ​​and technical frameworks and has a wide range of applications.

[0223] The advantages of this application compared to the prior art are detailed below.

[0224] 1. It has low implementation and maintenance costs, and can be implemented through various technical frameworks and programming languages.

[0225] 2. Significantly improves server security performance.

[0226] 3. It features the convenience of Single Sign-On (SSO) technology, allowing users to access all authorized services with a single login.

[0227] 4. Flexibility: Fine-grained control of access permissions for any service can be achieved simply by describing specific rules.

[0228] 5. Wide coverage: This technology can enhance the security of various service-oriented servers.< / string> < / string>

Claims

1. A method for configuring server port security, characterized in that: The steps include the following: Step 1: Configure and obtain open ports and rule ports. Open ports are ports that can be actively accessed, including the user login authentication interface. Rule ports are ports that cannot be actively accessed. The whitelist of a rule port is obtained by configuring the whitelist rule based on the rule port. The whitelist rule for the rule port includes requests that have been verified by the user login authentication interface of the open port and are allowed to access the rule port.

2. The server port security configuration method according to claim 1, characterized in that: In step 1, the number of open ports is one.

3. The server port security configuration method according to claim 1, characterized in that: In step 1, the number of open ports is small.

4. The server port security configuration method according to claim 1, characterized in that: In step 1, the whitelist rule for the rule port also includes allowing access to the corresponding rule port based on the user role identity of the verified requesting end.

5. A server port security configuration method according to claim 1, characterized in that: In step 1, the open port also includes a functional interface.

6. A server port security configuration method according to claim 1, characterized in that: It also includes step 2 after step 1. Step 2: When the requesting end passes the user login authentication interface without being verified by the open port, the requesting end only has the right to access the user login authentication interface; when the requesting end passes the user login authentication interface of the open port, a valid tag is generated and sent to the requesting end, and the IP of the requesting end is added to the whitelist of the rule port. When the requesting end carries a valid tag and the IP of the requesting end is in the whitelist of the rule port, the rule port allows the requesting end to access.

7. A server port security configuration method according to claim 6, characterized in that: It also includes step 3 after step 2. Step 3: Clean up the whitelist of the rule port based on the trigger conditions for cleaning up the whitelist.

8. A server port security configuration method according to claim 7, characterized in that: In step 3, the trigger condition for cleaning the whitelist is a processing cycle setting or a server load threshold. The cleaning is either initialization or targeted cleaning. Initialization means deleting all verified IPs, while targeted cleaning means deleting all verified IPs outside the trust table.

9. A server port security configuration device, the device being a computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by the processor, it implements the corresponding steps in the server port security configuration method according to any one of claims 1 to 8.

10. A server, characterized in that: According to any one of claims 1 to 8, a server port security configuration method is used to configure an obtained server, and an open port and a rule port are configured on the server. Requests that pass the user login authentication interface of the open port are allowed to access the rule port.