A method and system for fast attack surface convergence under heavy protection mode

By setting up a critical protection mode in the control center and utilizing encrypted long connections and multi-gateway policies to establish a secure encrypted tunnel, the problems of slow switching of critical protection policies, large port exposure, insufficient hierarchical protection, and synchronization delay of multi-gateway policies are solved. This enables rapid convergence of the attack surface and improves the network security protection capability.

CN122372337APending Publication Date: 2026-07-10HANGZHOU HUFU NETWORK CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
HANGZHOU HUFU NETWORK CO LTD
Filing Date
2026-06-08
Publication Date
2026-07-10

AI Technical Summary

Technical Problem

In critical network security scenarios, existing technologies suffer from problems such as slow switching of critical protection policies, large port exposure, insufficient hierarchical protection, and synchronization delay of multiple gateway policies. They are unable to quickly converge the attack surface, are difficult to resist targeted penetration, and cannot meet the core protection needs of critical protection scenarios.

Method used

By acquiring target data through the control center, setting up a critical protection mode, determining the policy scheduling template, and utilizing encrypted long connections and multi-gateway policies, a secure encrypted tunnel is established to control the transmission of target data, thereby achieving rapid convergence of the attack surface.

Benefits of technology

It enables rapid switching of critical protection strategies, reduces the port exposure surface, enhances hierarchical protection capabilities, reduces multi-gateway synchronization latency, resists targeted penetration, and meets the core protection needs of critical protection scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122372337A_ABST
    Figure CN122372337A_ABST
Patent Text Reader

Abstract

This invention provides a method and system for rapid attack surface convergence under a critical protection mode, relating to the field of network security technology. The method includes: acquiring target data; setting a critical protection mode; selecting the critical protection mode corresponding to the target data through a control center; determining a policy scheduling template based on the critical protection mode; obtaining multi-gateway policies through encrypted long connections based on the policy scheduling template; performing multi-verification on the terminal based on the multi-gateway policies; establishing a secure encrypted tunnel by combining the verified terminal and gateway nodes; and controlling the transmission of target data to target data through the secure encrypted tunnel. This invention precisely adapts to the protection needs of critical protection scenarios, strictly controlling access security through multi-dimensional terminal verification, ensuring the security of target data transmission through an encrypted tunnel, significantly converging the network attack surface, effectively blocking unauthorized access, improving the accuracy, timeliness, and security of network protection in critical protection scenarios, and ensuring the compliance and controllability of core data transmission and access.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network security technology, and in particular to a method and system for rapid attack surface convergence under a critical protection mode. Background Technology

[0002] In critical cybersecurity protection scenarios, it is necessary to quickly converge the attack surface, accurately block unauthorized access, ensure business continuity and data security, and meet compliance requirements such as the Cybersecurity Law and the Data Security Law. Therefore, a set of efficient, flexible, and collaborative protection solutions for critical cybersecurity protection is required.

[0003] Current mainstream protection relies mainly on traditional security strategy configuration and zero-trust architecture, depending on manual switching of critical protection modes, opening of general business ports, weak identity authentication, and limited hierarchical management capabilities, to achieve basic access and policy distribution in multi-gateway and multi-regional environments.

[0004] However, existing solutions suffer from problems such as slow switching of critical protection policies, large port exposure, insufficient hierarchical protection, and synchronization delay of multiple gateway policies. In addition, they cannot quickly converge the attack surface, making it difficult to resist targeted penetration and meet the core protection needs of critical protection scenarios. Summary of the Invention

[0005] In view of the shortcomings of the prior art, the purpose of this invention is to provide a method and system for rapid attack surface convergence in the critical protection mode, which can solve the problems of slow switching of critical protection policies, large port exposure surface, insufficient hierarchical protection, and multi-gateway policy synchronization delay in the prior art; in addition, it can also solve the technical problems of being unable to quickly converge the attack surface, making it difficult to resist targeted penetration and meet the core protection requirements of critical protection scenarios.

[0006] A first aspect of this invention proposes a method for fast attack surface convergence under a critical protection mode, comprising: S1: Obtain the target data.

[0007] S2: Set up critical protection mode.

[0008] S3: Select the protection mode corresponding to the target data through the control center.

[0009] S4: Determine the strategy scheduling template based on the critical protection mode.

[0010] S5: By using encrypted long-lived connections, a multi-gateway policy is obtained based on the policy scheduling template.

[0011] S6: Perform multiple verifications on the terminal based on the multi-gateway policy.

[0012] S7: Combine the verified terminal and gateway node to establish a secure encrypted tunnel.

[0013] S8: Controls the transmission of target data through a secure encrypted tunnel to comprehensively reduce the attack surface.

[0014] A second aspect of this invention provides a fast attack surface convergence system under a critical protection mode, comprising: a processor and a memory; The memory stores programs or instructions that can run on the processor, which, when executed by the processor, implement the steps of the attack surface fast convergence method in the heavy protection mode as described in the first aspect.

[0015] A third aspect of the present invention provides a readable storage medium on which a program or instructions are stored, wherein when the program or instructions are executed by a processor, the steps of the attack surface fast convergence method in the heavy protection mode as described in the first aspect are implemented.

[0016] The beneficial effects of the technical solutions provided in the embodiments of the present invention include at least the following: In this embodiment of the invention, the heavy protection mode, encrypted long connection and multi-gateway strategy can quickly switch heavy protection strategies, reduce the port exposure surface, improve hierarchical protection capabilities and reduce multi-gateway synchronization latency; through the secure encrypted tunnel, the transmission of the target data is controlled to comprehensively converge the attack surface, resist targeted penetration and meet the core protection requirements of heavy protection scenarios. Attached Figure Description

[0017] The accompanying drawings are for illustrative purposes only and are not intended to limit the invention. Throughout the drawings, the same reference numerals denote the same parts. Obviously, the drawings described below are merely some embodiments of the present invention, and those skilled in the art can obtain other drawings based on these drawings without any creative effort.

[0018] Figure 1 This is a flowchart illustrating a fast attack surface convergence method under a critical protection mode provided in an embodiment of the present invention.

[0019] Figure 2 This is a schematic diagram of the structure of a fast attack surface convergence system under a heavy protection mode provided in an embodiment of the present invention. Detailed Implementation

[0020] To enable those skilled in the art to better understand the technical solutions in the embodiments of the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. It should be understood that these descriptions are merely exemplary and are not intended to limit the scope of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.

[0021] The attack surface fast convergence method under the protection mode provided by the present invention will be described in detail below with reference to the accompanying drawings, through specific embodiments and application scenarios.

[0022] Reference manual attached Figure 1 The diagram shows a flowchart of a fast attack surface convergence method under a critical protection mode provided by an embodiment of the present invention.

[0023] This invention provides a method for fast attack surface convergence in a critical protection mode, which may include the following steps: S1: Obtain the target data.

[0024] S2: Set up critical protection mode.

[0025] Specifically, the protection modes include: basic enhancement mode, deep enhancement mode, and extreme enhancement mode.

[0026] In this embodiment of the invention, by centrally setting a unified activation of the critical protection mode, the traditional manual configuration barrier is broken, and the standardization and global consistency of the protection strategy are achieved. This ensures that the protection strategy across the entire network is consistent and unbiased during high-risk periods, providing a unified core benchmark for subsequent precise attack surface convergence.

[0027] S3: Select the protection mode corresponding to the target data through the control center.

[0028] Specifically, the three-tiered protection model architecture includes: designing a three-tiered control mechanism of basic enhancement mode, deep enhancement mode, and extreme enhancement mode, which allows administrators to switch between modes with one click based on attack intensity and activity importance.

[0029] The basic enhanced mode specifically disables enterprise activation codes and email activation methods, allowing only terminals with bound device certificates to access the system via certificate knocking, while retaining the emergency channel for manual activation by administrators.

[0030] The deep enhancement mode specifically means: disabling the administrator's manual activation channel, supporting only device certificate activation, and simultaneously enabling mandatory terminal compliance verification, directly blocking non-compliant terminals.

[0031] The ultimate enhancement mode specifically means: based on the deep enhancement mode, enabling sensitive data access restrictions and internet isolation functions, opening access permissions only to core business functions, and comprehensively reducing the attack surface.

[0032] In this embodiment of the invention, the corresponding critical protection mode can be flexibly matched according to the importance level, security requirements and protection strength of the target data, so as to achieve precise protection by classification and grading, avoid over-protection or under-protection, and improve the adaptability and effectiveness of the overall security strategy.

[0033] S4: Determine the strategy scheduling template based on the critical protection mode.

[0034] Specifically, the policy scheduling template includes: port stealth rules, access verification rules, and sensitive data monitoring rules.

[0035] In this embodiment of the invention, the corresponding port stealth, access verification, and sensitive data monitoring rules can be automatically matched according to different levels of protection modes, so as to realize the templated and standardized generation of policies, eliminate repeated configuration, improve the efficiency of policy distribution, and ensure that the protection rules are unified, complete, and reusable.

[0036] S5: By using encrypted long-lived connections, a multi-gateway policy is obtained based on the policy scheduling template.

[0037] In one possible implementation, S5 specifically includes sub-steps S501 to S506: S501: Standardize and integrate the policy scheduling template and encapsulate it into a JSON format data packet.

[0038] Among them, JSON format data packets refer to data packets organized in a lightweight, structured, and universal data format, which are used to uniformly store policy information.

[0039] Specifically, the JSON format data packet includes: pattern type, policy ID, and timestamp.

[0040] It should be noted that by encapsulating diverse protection rules into a structured, cross-platform compatible JSON data packet, the policy information format is standardized, facilitating transmission, parsing, and verification, and effectively improving policy processing efficiency and data interaction stability.

[0041] S502: Uses the SHA-256 algorithm to perform hash operations on JSON format data packets and generate a message digest.

[0042] The SHA-256 algorithm is a cryptographically secure hash algorithm that can generate a fixed-length 256-bit hash value (message digest) from input data of arbitrary length through one-way hashing. It has the characteristics of collision resistance, irreversibility, and detectable data tampering. It is used to verify that data has not been illegally tampered with during transmission and to ensure data integrity.

[0043] It should be noted that by using the tamper-resistant and irreversible characteristics of the SHA-256 algorithm to generate message digests, the integrity of data packets can be verified throughout the transmission process, effectively preventing the policy from being illegally tampered with, and greatly improving the security and reliability of policy transmission.

[0044] S503: Concatenate JSON format data packets and message digests into a data body.

[0045] It should be noted that integrating the policy content and integrity verification information into a unified data body binds the policy and the digest together, which facilitates subsequent encrypted transmission and integrity verification, ensuring that the policy data can be effectively verified during transmission.

[0046] S504: Encrypts the data body using a two-layer encryption algorithm.

[0047] Specifically, the two-layer encryption algorithm includes: AES-256-GCM (symmetric) algorithm and RSA-2048 (asymmetric) algorithm.

[0048] Specifically, the control center randomly generates a session key and initialization vector that are only used for this policy push. After concatenating the data packet and digest into a data body, the ciphertext and authentication tag are generated using the session key and initialization vector.

[0049] It should be noted that a two-layer encryption algorithm combining symmetric and asymmetric encryption is used to encrypt the data body, balancing encryption efficiency and key security. This achieves end-to-end encryption protection for policy data transmission, effectively preventing data theft, tampering, and forgery, and significantly improving transmission security.

[0050] S505: Combine the encryption key packet, authentication tag, control center RSA signature, and encrypted data body to obtain the final encryption packet.

[0051] It should be noted that integrating the key, integrity identifier, identity signature, and ciphertext data into a complete encryption package not only ensures secure transmission but also verifies the source and integrity of the data, significantly improving the anti-attack capability and trustworthiness of policy transmission.

[0052] S506: By using an encrypted long connection, the final encrypted packet is pushed to the gateway node to obtain the multi-gateway policy.

[0053] It should be noted that by relying on the pre-established encrypted long connection to securely push encrypted packets, policies can be quickly distributed and synchronized with the entire gateway, ensuring consistent, delay-free, and uncompromising policies across multiple nodes, significantly improving the timeliness and coordination of attack surface convergence.

[0054] In one possible implementation, S506 specifically includes sub-steps S5061 and S5062: S5061: The final encrypted packet is synchronized with the region corresponding to the gateway node via multicast protocol.

[0055] Among them, multicast protocol refers to a one-to-many network transmission protocol. The control center or main gateway only needs to send one piece of data to transmit it to multiple authorized slave gateways at the same time. It has the characteristics of high transmission efficiency, fast policy synchronization and low network occupation, and can realize the global fast and consistent distribution of policies among multiple gateways.

[0056] It should be noted that the use of multicast protocol to achieve one-to-many policy synchronous distribution means that multiple gateway devices can be covered with a single transmission, reducing network bandwidth consumption, greatly improving the policy distribution speed, and ensuring that the protection rules of gateways in the same area are consistent in real time and without security blind spots.

[0057] S5062: Determine if the synchronization was successful. If yes, return an acknowledgment packet to the control center. Otherwise, return to step S5061.

[0058] In this embodiment of the invention, policy templates are quickly distributed to each gateway by relying on encrypted long connections, so as to achieve unified effectiveness of the protection policy across the entire domain, avoid the delay and error caused by manual configuration, and strengthen the cross-regional collaborative protection capability.

[0059] In one possible implementation, after S5, the following steps are also included: updating firewall rules, authentication configurations, and access control configurations according to the multi-gateway policy, and returning the execution results to the control center.

[0060] Specifically, policy rules are encapsulated into JSON data packets and a SHA-256 digest is generated. Then, a final encrypted packet is formed using double encryption with AES-256-GCM and RSA-2048. Based on encrypted long connections, master-slave push and multicast synchronization are used to achieve rapid policy distribution across multiple gateways. Gateways load the policy after decryption, integrity verification, and validity checks. The control center uniformly confirms the execution results and synchronizes logs, achieving full-domain collaboration, security, reliability, and rapid activation of critical protection policies.

[0061] In this embodiment of the invention, firewall rules, authentication configurations, and access control configurations are automatically updated according to multi-gateway policies, and the execution results are returned to the control center in real time. This enables the policies to be automatically implemented and take effect after being issued, reducing manual intervention, improving configuration accuracy and execution efficiency, and ensuring real-time synchronization of the overall security status.

[0062] S6: Perform multiple verifications on the terminal based on the multi-gateway policy.

[0063] In one possible implementation, S6 specifically includes sub-steps S601 to S506: S601: Receives encrypted SPA data packets sent by the terminal through the gateway node.

[0064] It should be noted that using encrypted SPA data packets to pre-encrypt the transmission of terminal identity and access requests can complete security verification before establishing a connection, effectively reducing the risk of port exposure and improving the security and concealment of terminal access.

[0065] S602: Parse the encrypted SPA data packet and extract the terminal ID.

[0066] It should be noted that by securely parsing encrypted SPA data packets to obtain the unique identifier of the terminal, the identity of the access terminal can be accurately identified, providing a reliable basis for subsequent permission verification and access control, and improving the accuracy and security of identity authentication.

[0067] S603: Determine if the terminal ID is in a normal state. If yes, proceed to step S604. Otherwise, discard the encrypted SPA data packet and end the verification.

[0068] It should be noted that real-time verification of terminal ID status during the initial access phase can quickly intercept abnormal or illegal terminals, prevent unauthorized access behavior in advance, effectively reduce the subsequent processing pressure on the gateway, and enhance the overall security protection capabilities of the system.

[0069] S604: Extract the terminal's certificate from the encrypted SPA data packet and determine its validity based on the multi-gateway policy. If valid, proceed to step S605. Otherwise, discard the encrypted SPA data packet and end the verification process.

[0070] It should be noted that the validity of terminal certificates is verified based on a unified multi-gateway policy, ensuring consistent certificate authentication standards, accurately filtering invalid or forged certificates, strengthening terminal access security, and preventing unauthorized requests from entering subsequent processes.

[0071] S605: Extract the digital signature value and plaintext service segment from the encrypted SPA data packet, and determine whether the digital signature value and plaintext service segment conform to preset rules according to the multi-gateway policy. If yes, trigger terminal access control. Otherwise, discard the encrypted SPA data packet and end the verification.

[0072] It should be noted that by combining a unified policy across multiple gateways to verify the validity of terminal certificates, strong identity authentication based on digital certificates is achieved, further filtering unauthorized access requests, ensuring terminal access security and consistent policy execution.

[0073] In one possible implementation, the preset rule is specifically: calculate the hash value of the digital signature value and the hash value of the business plaintext segment, and determine whether the hash value of the digital signature value and the hash value of the business plaintext segment are equal.

[0074] It should be noted that those skilled in the art can set preset rules according to actual needs, and this invention does not limit such settings.

[0075] In this embodiment of the invention, a multi-level security verification is implemented on the terminal based on a unified multi-gateway strategy, a coherent and reliable access defense line is built, the strength of identity authentication is effectively improved, unauthorized access is blocked from the source, and the security of system access is ensured.

[0076] S7: Combine the verified terminal and gateway node to establish a secure encrypted tunnel.

[0077] In this embodiment of the invention, a secure encrypted tunnel is established only after the terminal passes multiple verifications, providing an encrypted communication channel only for legitimate terminals, which greatly reduces the attack surface and ensures that data transmission is secure, reliable, and protected against eavesdropping and tampering throughout the entire process.

[0078] S8: Controls the transmission of target data through a secure encrypted tunnel to comprehensively reduce the attack surface.

[0079] Specifically, an SSL encrypted tunnel is established using the TLS 1.3 protocol and an encryption key of 2048 bits or more. Terminals access authorized service resources through this tunnel, and if verification fails, they can re-initiate access according to the compliance repair guidelines. In deep enhancement mode, after triple verification and access control, the terminal sequentially performs TLS 1.3 handshake initialization, identity authentication and ECDH key negotiation, and HKDF session key derivation. After both parties confirm the integrity of the handshake through a Finished message, they encrypt and transmit service traffic using the AES-256-GCM algorithm and the corresponding session key. The tunnel is maintained through heartbeat keep-alive and session ticketing mechanisms. In case of an anomaly or active disconnection, the tunnel is securely terminated and the key is cleared, achieving highly secure and efficient encrypted communication.

[0080] Specifically, in the enhanced sensitive data protection process, when a terminal accesses the business system through an encrypted tunnel, the gateway captures the data traffic in real time and identifies sensitive information using a preset keyword library and regular expressions through the sensitive data monitoring module. When abnormal behavior such as high-frequency access to sensitive data or cross-regional download of sensitive files is detected, the gateway will automatically block access and freeze the terminal's permissions. At the same time, the control center will generate alarm information in real time and push it to the administrator via email and DingTalk. The administrator will then perform unfreezing or extension of control operations based on the verification results.

[0081] It should be noted that those skilled in the art can set up a preset keyword library according to actual needs, and this invention does not limit this.

[0082] In this embodiment of the invention, the target data is transmitted and controlled throughout the entire process by relying on a secure encrypted tunnel, thereby achieving refined protection of data access and transmission, significantly reducing the system's exposure surface at the communication link level, and significantly improving the overall security defense capability.

[0083] In one possible implementation, after S8, the following is also included: Through the control center, a policy restoration command is issued to all gateway nodes. The gateways restore normal access rules, the whitelist is automatically cleared, and the terminal clients simultaneously disable the protection-related configurations and return to normal access mode.

[0084] Specifically, the control center issues a policy restoration command to each gateway node, loads the normal mode policy template, and clears the temporary critical protection rules. The gateway restores normal access rules, opens standard ports, disables critical protection-specific policies and functions, and clears the dynamic whitelist. Terminals simultaneously disable critical protection configurations and revert to normal access mode. After all gateways complete the process, they return confirmation information to the control center. The control center records the operation log and synchronizes it to the audit module, achieving secure, closed-loop exit from critical protection mode.

[0085] In this embodiment of the invention, by centrally issuing policy restoration commands through the control center, the configuration of all network gateways and terminals can be restored with one click, the temporary whitelist can be automatically cleared and the system can exit the critical protection mode, which greatly reduces the cost of manual operation, avoids the security risks caused by policy residues, and ensures that the system can quickly, uniformly and securely return to the normal operating state.

[0086] The attack surface fast convergence method in the protection mode provided in this application embodiment can be executed by an attack surface fast convergence device in the protection mode. This application embodiment uses the execution of the attack surface fast convergence method in the protection mode by an attack surface fast convergence device in the protection mode as an example to illustrate the attack surface fast convergence device in the protection mode provided in this application embodiment.

[0087] Reference manual attached Figure 2 The diagram shows a structural schematic of an attack surface fast convergence system under a critical protection mode provided by an embodiment of the present invention.

[0088] This invention provides an attack surface fast convergence system 20 in a critical protection mode, comprising: a processor 201 and a memory 202; The memory 202 stores programs or instructions that can run on the processor 201. When the program or instructions are executed by the processor 201, they implement the steps of the attack surface fast convergence method in the above-mentioned heavy protection mode and can achieve the same technical effect. To avoid repetition, the present invention will not elaborate further.

[0089] It should be understood that the processor 201 in this embodiment of the invention may be a central processing unit (CPU), or it may be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor.

[0090] It should also be understood that the memory 202 in the embodiments of the present invention can be volatile memory or non-volatile memory, or may include both volatile and non-volatile memory. The non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. The volatile memory can be random access memory (RAM), which is used as an external cache. By way of example, but not limitation, many forms of random access memory are available, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), and direct memory bus RAM (DR RAM).

[0091] The above embodiments can be implemented, in whole or in part, by software, hardware (such as circuits), firmware, or any other combination thereof. When implemented using software, the above embodiments can be implemented, in whole or in part, as a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer programs are loaded or executed on a computer, all or part of the processes or functions described in the embodiments of the present invention are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more sets of available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium. A semiconductor medium can be a solid-state drive.

[0092] It should be understood that, in various embodiments of the present invention, the order of the above-mentioned process numbers does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.

[0093] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of this invention.

[0094] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the devices, apparatuses, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0095] In the several embodiments provided by this invention, it should be understood that the disclosed devices, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another device, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between devices or units may be electrical, mechanical, or other forms.

[0096] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0097] In addition, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.

[0098] If the aforementioned functions are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this invention, essentially, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0099] This invention provides a readable storage medium comprising: storing a program or instructions on the readable storage medium, wherein when the program or instructions are executed by a processor, the program or instructions implement the steps of the above-described attack surface fast convergence method under the protection mode, and can achieve the same technical effect. To avoid repetition, this invention will not elaborate further.

[0100] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the embodiments of the present invention, and are not intended to limit them. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention. Any changes or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in the present invention should be included within the protection scope of the present invention.

Claims

1. A method for fast attack surface convergence under a critical protection mode, characterized in that, include: S1: Obtain target data; S2: Set up critical protection mode; S3: Select the protection mode corresponding to the target data through the control center; S4: Determine the strategy scheduling template based on the aforementioned critical protection mode; S5: Obtain the multi-gateway strategy by using an encrypted long connection and scheduling the template according to the strategy. S6: Perform multiple verifications on the terminal according to the multi-gateway strategy; S7: Combine the verified terminal and the gateway node to establish a secure encrypted tunnel; S8: Control the transmission of the target data through the secure encrypted tunnel to comprehensively reduce the attack surface.

2. The attack surface fast convergence method under the heavy protection mode according to claim 1, characterized in that, The enhanced protection modes include: basic enhancement mode, deep enhancement mode, and extreme enhancement mode.

3. The method for fast attack surface convergence under the heavy protection mode according to claim 1, characterized in that, The policy scheduling template includes: port stealth rules, access verification rules, and sensitive data monitoring rules.

4. The attack surface fast convergence method under the heavy protection mode according to claim 1, characterized in that, S5 specifically includes: S501: Standardize and integrate the policy scheduling template and encapsulate it into a JSON format data packet; S502: Perform a hash operation on the JSON format data packet using the SHA-256 algorithm to generate a message digest; S503: Concatenate the JSON format data packet and the message digest into a data body; S504: Encrypt the data body using a two-layer encryption algorithm; S505: Combining the encryption key packet, authentication tag, control center RSA signature, and encrypted data body, the final encryption packet is obtained; S506: The final encrypted packet is pushed to the gateway node through the encrypted long connection to obtain the multi-gateway strategy.

5. The attack surface fast convergence method under the heavy protection mode according to claim 4, characterized in that, Specifically, S506 includes: S5061: Synchronize the region corresponding to the gateway node to the final encrypted packet via multicast protocol; S5062: Determine whether the synchronization result is successful; if yes, return an acknowledgment packet to the control center; otherwise, return to step S5061.

6. The method for fast attack surface convergence under the heavy protection mode according to claim 1, characterized in that, Following S5, the process further includes: updating firewall rules, authentication configuration, and access control configuration according to the multi-gateway policy, and returning the execution result to the control center.

7. The method for fast attack surface convergence under the heavy protection mode according to claim 1, characterized in that, S6 specifically includes: S601: Receive the encrypted SPA data packet sent by the terminal through the gateway node; S602: Parse the encrypted SPA data packet and extract the terminal ID; S603: Determine whether the status of the terminal ID is normal; if yes, proceed to step S604; otherwise, discard the encrypted SPA data packet and end the verification. S604: Extract the terminal's certificate from the encrypted SPA data packet, and determine whether the certificate is valid according to the multi-gateway policy; if yes, proceed to step S605; otherwise, discard the encrypted SPA data packet and end the verification. S605: Extract the digital signature value and the service plaintext segment from the encrypted SPA data packet, and determine whether the digital signature value and the service plaintext segment conform to the preset rules according to the multi-gateway policy; if yes, trigger the terminal access detection; otherwise, discard the encrypted SPA data packet and end the verification.

8. The method for fast attack surface convergence under the heavy protection mode according to claim 7, characterized in that, The preset rule specifically involves determining whether the hash value of the digital signature value is equal to the hash value of the business plaintext segment.

9. The method for fast attack surface convergence under the protection mode according to claim 1, characterized in that, Following S8, it also includes: Through the control center, a policy restoration command is issued to all gateway nodes. The gateways restore normal access rules, the whitelist is automatically cleared, and the terminal clients simultaneously disable the protection-related configurations and return to normal access mode.

10. A fast attack surface convergence system under a critical protection mode, characterized in that, include: Processor and memory; The memory stores programs or instructions that can run on the processor, which, when executed by the processor, implement the steps of the attack surface fast convergence method in the heavy protection mode as described in any one of claims 1 to 9.