Method, device and system for enhancing safety of Telnet server

By performing username validity checks and password security checks on the Telnet server, and filtering keywords for remote sessions, the security deficiencies of the Telnet server are resolved, achieving higher security protection.

CN121000461APending Publication Date: 2025-11-21BEIJING CHANGYANG TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202511202422.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-26
Publication Date
2025-11-21

AI Technical Summary

Technical Problem

Existing Telnet servers are not very secure and are prone to unauthorized access, accidental operations, and malicious commands that could damage server data.

Method used

By acquiring the remote session between the client and the server, the system performs validity checks on usernames, security checks on password complexity and character repetition, and keyword filtering on every remote session sent from the client to the server to block malicious commands.

Benefits of technology

It improves password security, prevents unauthorized access and accidental operations, blocks malicious commands, and enhances the security of remote servers.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121000461A_ABST
    Figure CN121000461A_ABST
Patent Text Reader

Abstract

The invention discloses a method, device and system for enhancing safety of a Telnet server, and belongs to the field of network safety. The method comprises the following steps: acquiring a remote session between a client and a server, and carrying out legality detection on a user name; if the login password is legal and the login is successful, carrying out security detection on the login password based on the complexity of the password and the character repetition degree; and if the password accords with the security rule, performing keyword filtering on each remote session sent to the server by the client so as to block the malicious command. According to the scheme, the security detection is performed on the login password, so that the security of the password is improved, and misoperation is prevented; in addition, illegal user access can be prevented, damage of malicious commands to remote server data is blocked, and the safety of the remote server is improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of network security, and particularly relates to a method, device and system for enhancing the security of a Telnet server. BACKGROUND

[0002] The Telnet protocol is widely used for remote device management, server management, monitoring and auditing, etc. This remote management mode can improve efficiency and reduce the need for on-site visits. While this protocol improves management convenience, it also increases the requirements for server data security.

[0003] However, the security of existing Telnet servers is not high, and illegal access, misoperation and malicious commands can easily damage server data.

[0004] Therefore, there is an urgent need to provide a method, device and system for enhancing the security of a Telnet server. SUMMARY

[0005] In order to solve the problem of low security of existing Telnet servers, illegal access, misoperation and malicious commands damaging server data, the present application provides a method, device and system for enhancing the security of a Telnet server.

[0006] In one aspect, a method for enhancing the security of a Telnet server is provided, which is applied between a client and a server, and the method comprises: acquiring a remote session between the client and the server, and detecting the legality of a username; if the username is legal and the login is successful, detecting the security of a login password based on the complexity of the password and the repetition degree of characters; if the password meets the security rules, filtering keywords for each remote session sent by the client to the server to block malicious commands.

[0007] In another aspect, a device for enhancing the security of a Telnet server is provided, which is arranged between a client and a server, and is used to implement the steps of any method embodiment described in the specification, and the device comprises: a first detection unit configured to acquire a remote session between the client and the server, and detect the legality of a username; a second detection unit configured to, if the username is legal and the login is successful, detect the security of a login password based on the complexity of the password and the repetition degree of characters; a filtering unit configured to, if the password meets the security rules, filter keywords for each remote session sent by the client to the server to block malicious commands.

[0008] In another aspect, a system is provided, which comprises a client, a device for implementing the method steps described above and a server connected in sequence.

[0009] In another aspect, a computer readable storage medium is provided, which stores a computer program, which, when executed by a processor, implements the method steps described above.

[0010] In another aspect, a computer program product is provided, which comprises a computer program, which, when executed by a processor, implements the method steps described above.

[0011] The technical solution provided by the present application can bring at least the following beneficial effects: By obtaining the remote session between the client and the server, the legitimacy of the username is detected to prevent illegal users from accessing; by performing security detection on the login password, the security of the password is improved to prevent misoperation; by filtering the keywords of each remote session sent by the client to the server, the malicious commands are blocked to prevent the remote server data from being damaged, and the security of the remote server is improved. BRIEF DESCRIPTION OF DRAWINGS

[0012] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings needed to be used in the embodiments or the prior art description. Obviously, the drawings described below are some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor on the basis of these drawings.

[0013] Figure 1 is a method flow chart for enhancing the security of a Telnet server provided by an embodiment of the present application; Figure 2 is a device structure diagram for enhancing the security of a Telnet server provided by an embodiment of the present application; Figure 3 is a hardware architecture schematic diagram of a system provided by an embodiment of the present application. DETAILED DESCRIPTION

[0014] In order to make the purpose, technical solutions and advantages of the embodiments of the present application more clear, the technical solutions in the embodiments of the present application will be described clearly and completely below in combination with the drawings in the embodiments of the present application. Obviously, the described embodiments are some embodiments of the present application, but not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor fall within the scope of protection of the present application.

[0015] The specific implementation of the above concept will be described below.

[0016] Reference is made to Figure 1 The embodiment of the present application provides a method for enhancing the security of a Telnet server, which is applied between a client and a server, and the method comprises the following steps: Step 100: obtaining a remote session between the client and the server, and performing legitimacy detection on a username; Step 102: if the username is legitimate and the login is successful, performing security detection on a login password based on the complexity of the password and the repetition degree of characters; Step 104: if the password meets the security rules, performing keyword filtering on each remote session sent by the client to the server to block malicious commands.

[0017] In the embodiment of the present application, the remote session between the client and the server is obtained, and the legitimacy detection is performed on the username to prevent illegal users from accessing; the security detection is performed on the login password to improve the security of the password and prevent misoperation; the keyword filtering is performed on each remote session sent by the client to the server to block malicious commands from destroying the data of the remote server, thereby improving the security of the remote server, and the present application is suitable for all remote service systems to improve the security.

[0018] The following describes Figure 1 the execution mode of each step.

[0019] For step 100: In some embodiments, step 100 can comprise the following steps. Extracting the content of the remote session between the client and the server, and when detecting a login name string of a new session, identifying and storing the username string input subsequently; Matching the username string with an allowed user rule library; If the matching is successful, the message is released; If the matching fails, the subsequent operation of the session is blocked.

[0020] In the present embodiment, the content of the telnet session is extracted, the telnet session is identified based on five-tuple information such as a protocol, source and destination IP and port, and the communication state and interactive content between the client and the server are restored. When a new session is detected and a login name string of "login:" is detected, the subsequent input username is identified and stored. Taking the input of the username "test" in the character mode as an example, the telnet session content extracts "t", "e", "s", "t" which are sequentially interacted between the client and the server, and restores the username string "test" input by the user.

[0021] The username in the interaction content extracted in the previous step is subjected to rule matching. If the user is not in the allowed user rule library, the session is subjected to blocking processing.

[0022] A username set Uall is defined, and the allowed access set Uallow in the allowed user rule library is Uall, the current session username ui is Uall, and the detection formula is: If δauth(ui)=0, the blocking operation is performed.

[0023] In some embodiments, after step 100 and before step 102, the following steps are further included: If the username is legal, the password string input by the user is detected, and the login status string returned by the identification server is extracted; If the login failure string is detected, the number of login failures is recorded, and it is determined whether the number of login failures in 3 minutes reaches the set threshold value. If yes, the client IP address is added to the blacklist, and the subsequent login request is blocked. If the login success string is detected, the security of the password string is detected.

[0024] In this embodiment, if the "test" user is normally released, the subsequent "Password: " will be received, and when the telnet session content extraction process detects the string, the password input by the user is restored. The telnet session content is extracted, and the string returned by the identification server is identified, and the login status is determined. If the login failure string "Login incorrect" field is detected, it is identified that this login fails, and the number of login failures is recorded. If the number of login failures in 3 minutes reaches the set threshold value, the client IP address is added to the blacklist, and the subsequent login request is blocked. If the login success string "Last login:" and other fields indicating login success are detected, the password is subjected to security detection, that is, step 102 is performed.

[0025] For step 102: In some embodiments, step 102 can include: Based on the length of the password and the number of character types contained in the password, the complexity of the password is evaluated; Based on the repetition rate of each character in the password, the repetition degree of the password is calculated; Based on the repetition degree of the password and the maximum repetition rate of a single character in the password, the character repetition degree is evaluated; When the complexity of the password and the character repetition degree both meet the requirements, it is determined that the password meets the security rules.

[0026] In some embodiments, the repetition degree of the password is calculated by the following formula: wherein, is the repetition degree of the password, P is the password, x is each character contained in the password P, is the number of character x in the password, is the length of the password.

[0027] In the present embodiment, whether the complexity of the password meets the requirement is determined by the following method: wherein, is the length of the password, is the set minimum length, C(P) is the number of character types contained in the password, is the set minimum number of character types.

[0028] Whether the repetition degree of the character meets the requirement is determined by the following method: wherein, wherein, is the maximum repetition rate of single character in the password, Rmax is the set maximum single character repetition rate threshold, x is each character contained in the password P, is the number of character x in the password, is the length of the password, is the repetition degree of the password, Hmin is the set minimum repetition degree threshold.

[0029] Therefore, when the complexity of the password and the repetition degree of the character both meet the requirement, it is determined that the password meets the security rule.

[0030] If the password is identified as not meeting the security rule after the password security detection, an alarm message is notified to the network administrator, and the possible security risk is blocked by means of early intervention and modification of the password. The server with the security risk can also be added to an access control list to prohibit access by other clients. If there is no abnormality after the user legitimacy detection and the password security detection, the session will undergo the subsequent keyword filtering process.

[0031] For step 104: In some embodiments, step 104 can include: extracting commands from each remote session sent by the client to the server, and cutting the commands; performing keyword matching on the cut commands by using a keyword table; If the keyword matches, replace the carriage return after the keyword to block the command.

[0032] In the embodiment, the string sent by the client to the server is subjected to keyword matching, and if the keyword matches, the command is filtered by modifying the carriage return into a special character to ensure the security of the server data.

[0033] Taking the keyword "rmdir" in the keyword table as an example, when the telnet session content is extracted to the client, the command "rmdir / * -rf\r\n" is about to be executed, the extracted command is cut and subjected to keyword matching. If "rmdir" matches the keyword list, the command is blocked. Since the server will actually execute the command when receiving the "\r\n" character representing the carriage return, at this time, the "\r\n" is replaced by a control character, thereby blocking the execution of the command. After blocking the command, a related alarm message is sent to the management platform, facilitating subsequent audit and traceability processing. By modifying the carriage return into a special character to filter the command, the filtering speed can be improved and the filtering steps can be simplified.

[0034] Please refer to Figure 2 The embodiment of the present application provides a device for enhancing the security of a Telnet server, which is arranged between a client and a server and is used for implementing the steps of any method embodiment in the description. The device comprises: A first detection unit 201 is configured to acquire a remote session between the client and the server and perform legality detection on a username. A second detection unit 202 is configured to perform security detection on a login password based on the complexity of the password and the repetition degree of characters if the login is successful. A filtering unit 203 is configured to perform keyword filtering on each remote session sent by the client to the server to block malicious commands if the password meets the security rules.

[0035] It should be noted that the device for enhancing the security of a Telnet server provided in the above embodiment is only used as an example for the division of the above functional units. In actual applications, the above functions can be completed by different functional units according to needs, that is, the internal structure of the device is divided into different functional units to complete all or part of the above described functions. In addition, the device embodiment and the method embodiment belong to the same concept, and the specific implementation process is described in the method embodiment, which will not be repeated here.

[0036] The embodiment of the present application also provides a system, please refer to Figure 3 The computer device comprises a client, a device for implementing the steps of the above method embodiments and a server which are connected in sequence.

[0037] The embodiment of the present application further provides a computer readable storage medium, wherein at least one instruction, at least one program, a code set or an instruction set are stored on the computer readable storage medium, and the at least one instruction, the at least one program, the code set or the instruction set are loaded and executed by a processor to implement the method for enhancing the security of the Telnet server provided by any of the above method embodiments.

[0038] The embodiment of the present application further provides a computer program product, which comprises a computer program, and a processor of a computer device reads the computer program from a computer readable storage medium, and the processor executes the computer program, so that the computer device executes the method for enhancing the security of the Telnet server in any of the above embodiments.

[0039] For the convenience of description, the above system or device is described in various modules or units in terms of functions. Of course, the functions of the units can be implemented in the same or multiple software and / or hardware in the implementation of the present application.

[0040] From the above description of the embodiments, those skilled in the art can clearly understand that the present application can be implemented by means of software and necessary universal hardware platforms. Based on such understanding, the technical solutions of the present application can be embodied in the form of a software product, which can be stored in a storage medium, such as a ROM / RAM, a magnetic disk, an optical disk, etc., and includes a number of instructions to make a computer device (which can be a personal computer, a server, or a network device, etc.) execute the methods of the various embodiments or some parts of the embodiments.

[0041] Finally, it should be noted that, in this document, the relationship terms such as first, second, third and fourth are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply that there is any such actual relationship or order between the entities or operations. Moreover, the terms "include", "contain" or any other variants thereof are intended to cover non-exclusive inclusion, so that the processes, methods, articles or devices including a series of elements not only include those elements, but also include other elements not explicitly listed or inherent to such processes, methods, articles or devices. Without more limitations, the element defined by the statement "including a" does not exclude the presence of another identical element in the process, method, article or device including the element.

[0042] The above merely preferred embodiments of the present application, it should be noted that for those of ordinary skill in the art, without departing from the principles of the present application, can make several improvements and refinements, these improvements and refinements should also be considered as the scope of protection of the present application.

Claims

1. A method of enhancing the security of a Telnet server, characterized by, The method is applied between a client and a server, and comprises the following steps: acquiring a remote session between the client and the server, and detecting the legality of a username; if the username is legal and the login is successful, detecting the security of a login password based on the complexity and repetition degree of the password; if the password meets the security rules, filtering a keyword of each remote session sent by the client to the server to block malicious commands.

2. The method of claim 1, wherein, The step of acquiring the remote session between the client and the server and detecting the legality of the username comprises the following steps: extracting the content of the remote session between the client and the server, and identifying and storing a username string inputted subsequently when detecting a login name string of a newly-built session; matching the username string with a rule library of allowed users; if the matching is successful, releasing the message; if the matching is not successful, blocking the subsequent operation of the session.

3. The method of claim 1, wherein, After the step of detecting the legality of the username and before the step of detecting the security of the login password based on the complexity and repetition degree of the password if the username is legal, the method further comprises the following steps: detecting a password string inputted by the user and extracting a login status string returned by the server if the username is legal; if a login failure string is detected, recording the number of login failures, judging whether the number of login failures within 3 minutes reaches a set threshold, and adding the IP address of the client to a blacklist and blocking the subsequent login request if the number of login failures reaches the set threshold; if a login success string is detected, detecting the security of the password string.

4. The method of claim 1, wherein, The step of detecting the security of the login password based on the complexity and repetition degree of the password comprises the following steps: evaluating the complexity of the password based on the length of the password and the number of character types contained in the password; calculating the repetition degree of the password based on the repetition rate of each character in the password; evaluating the repetition degree of the characters based on the repetition degree of the password and the maximum repetition rate of a single character in the password; determining that the password meets the security rules when the complexity of the password and the repetition degree of the characters both meet the requirements.

5. The method of claim 4, wherein, The repetition degree of the password is calculated by the following formula: wherein is the repetitiveness of the password, P is the password, x is each character contained in the password P, is the number of characters x in the password, is the length of the password.

6. The method of claim 1, wherein, The step of filtering the keyword of each remote session sent by the client to the server to block malicious commands comprises the following steps: extracting a command of each remote session sent by the client to the server, and cutting the command; matching the cut command with a keyword table; if the matching is successful, replacing the carriage return symbol after the keyword to block the command.

7. An apparatus for enhancing the security of a Telnet server, arranged between a client and a server, for implementing the steps of the method according to any one of claims 1 to 6, characterized in that the apparatus The method comprises the following steps: a first detection unit is configured to acquire a remote session between a client and a server, and detect the legality of a username; a second detection unit is configured to detect the security of a login password based on the complexity and repetition degree of the password if the username is legal and the login is successful; a filtering unit is configured to filter a keyword of each remote session sent by the client to the server to block malicious commands if the password meets the security rules.

8. A system, characterized by The method comprises a client, a device for implementing the method steps of any one of claims 1-6 in sequence, and a server.

9. A computer-readable storage medium, characterized in that, A storage medium stores a computer program, and the computer program is executed by a processor to implement the steps of the method of any one of claims 1-6.

10. A computer program product, characterised in that, A computer program comprising computer program elements which, when executed by a processor, implement the steps of the method according to any one of claims 1 to 6.

Citation Information

Patent Citations

  • Telnet command filter method, network safety device and network safety system

    CN102546606A