A method and system for judging the legality of a local area network terminal device
By acquiring fixed and dynamic features of terminal devices to generate feature fingerprints and using fuzzy matching algorithms for comparison, the vulnerability of local area network terminal device legitimacy determination in existing technologies is solved, achieving more efficient legitimacy assessment and network security protection.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-03-25
- Publication Date
- 2026-03-27
AI Technical Summary
In existing technologies, the methods for determining the legitimacy of local area network terminal devices ignore the forgery of MAC addresses, and existing algorithms lack universality and cannot effectively identify dynamic changes in various terminal characteristics, making it easy for unauthorized devices to access the power grid operating company's network and threatening power grid security.
By acquiring fixed features and dynamic behavioral features of terminal devices at fixed time intervals, feature fingerprints are generated. The legitimacy of the terminal device is determined by comparing them with pre-stored behavioral fingerprint samples using a fuzzy matching algorithm. Combining multiple fixed features as access credentials improves the credibility and universality of legitimacy assessment.
It improves the accuracy and universality of identifying the legitimacy of LAN terminal devices, reduces the threat of counterfeit terminal access, enhances the security of power grid operating company networks, and is applicable to various access terminal devices.
Smart Images

Figure CN111585953B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The application belongs to the technical field of power information security, and particularly relates to a LAN terminal device network access legality discrimination method and system. BACKGROUND
[0002] As a key information infrastructure, the power system has always been one of the key attack targets of "cyber war". In order to prevent various network security attacks and ensure the safe and stable operation of the power grid, the power grid operator has carried out long-term and effective work in network security protection. However, with the construction and operation of the data communication backbone network and the terminal access network, various types of intelligent terminal devices, especially marketing field business terminals, are massively accessed to the network of the power grid operator or even directly accessed to the backbone network. Since the field terminal device itself has weak protection and the environment is uncontrollable, once it is illegally used, it will directly affect the overall security protection system of the power grid operator and pose a great security threat.
[0003] The reason for analyzing the terminal impersonation and attack on the internal network of the power grid operator is that the marketing field fails to discriminate the legality of the devices accessing the field LAN, thereby allowing illegal devices to access the field LAN, thereby further endangering the internal network system of the power grid operator. Therefore, developing a terminal access method and system that can discriminate the legality of the terminal identity is imminent for protecting the information security of the company. At present, the terminal access technology products and research in the market and research field mainly discriminate the identity legality by judging the MAC address of the terminal device. Although this method discriminates the terminal identity legality by using the global uniqueness of the MAC address, it ignores the forgery of the MAC address. Some scholars have also researched the terminal access technology of the Android system and proposed a single-factor fuzzy matching algorithm. However, this method is only applicable to the case where only one terminal characteristic changes, and lacks the universality of terminal types. SUMMARY
[0004] In order to overcome the shortcomings of the prior art, the application provides a LAN terminal device network access legality discrimination method, which has the following improvements:
[0005] At a fixed time interval, the behavior characteristics of the terminal device are acquired based on the fixed characteristics of the terminal device accessing the working LAN.
[0006] The feature fingerprint of the terminal device is generated based on the behavior characteristics.
[0007] The legality of the terminal device behavior is determined based on the comparison between the feature fingerprint of the terminal and the behavior fingerprint sample pre-stored in the terminal.
[0008] Preferably, the fixed features of the access working LAN terminal device are used to obtain the behavior features of the terminal device, including:
[0009] The dynamic behavior of the terminal device is sampled based on the fixed features of the terminal device, to obtain dynamic behavior data;
[0010] According to the dynamic behavior data, the behavior features of the terminal device are obtained.
[0011] Preferably, the fixed features of the terminal device are determined by the terminal type.
[0012] Preferably, before the behavior features of the terminal device are obtained, the method further includes:
[0013] Judging whether the terminal device is allowed to access the working LAN:
[0014] When the multiple fixed features of the terminal device all respectively meet the pre-stored fixed feature samples, the terminal device is allowed to access the working LAN; otherwise, the terminal device is not allowed to access the working LAN.
[0015] Preferably, the legality of the terminal device behavior is determined based on the comparison between the feature fingerprint of the terminal and the behavior fingerprint sample pre-stored by the terminal, including:
[0016] The similarity between the feature fingerprint of the terminal and the behavior fingerprint sample pre-stored by the terminal is calculated by using a fuzzy matching algorithm;
[0017] Judging whether the similarity is greater than a given threshold value: if yes, the terminal device behavior is judged to be legal and the feature fingerprint is used to update the behavior fingerprint sample; otherwise, the terminal device behavior is judged to be illegal.
[0018] Preferably, the calculation formula of the similarity is as follows:
[0019] S=S'+w i *S i
[0020] In the formula, S i represents the similarity degree corresponding to the i-th behavior feature, w i represents the weight of the i-th behavior feature, S' represents the similarity before considering the i-th behavior feature, and S represents the similarity after considering the i-th behavior feature; the initial value of S is 0.
[0021] Preferably, the calculation formula of the similarity degree S i corresponding to the i-th behavior feature is as follows:
[0022]
[0023] In the formula, Ai-last a mean value representing the i-th behavior feature in the behavior fingerprint sample, B i-last a standard deviation representing the i-th behavior feature in the behavior fingerprint sample; A i-new a mean value representing the i-th dynamic behavior feature, B i-new a standard deviation representing the i-th behavior feature.
[0024] Preferably, the setting of the initial value of the terminal device behavior fingerprint sample comprises:
[0025] sampling the dynamic behavior of the terminal device within a preset time length after the terminal device accesses a working local area network for the first time to obtain initial dynamic behavior data;
[0026] obtaining the initial value of the behavior feature of the terminal device according to the initial dynamic behavior data;
[0027] generating the initial value of the terminal device behavior fingerprint sample according to the initial value of the behavior feature of the terminal device.
[0028] Based on the same inventive concept, the application further provides a local area network terminal device network access legality judgment system, characterized by comprising a behavior feature module, a feature fingerprint module and a legality judgment module.
[0029] The behavior feature module is configured to acquire the behavior feature of the terminal device based on fixed features of terminal devices accessing a working local area network at fixed time intervals.
[0030] The feature fingerprint module is configured to generate a feature fingerprint for the terminal device based on the behavior feature.
[0031] The legality judgment module is configured to determine the legality of the behavior of the terminal device based on a comparison between the feature fingerprint of the terminal and a behavior fingerprint sample previously stored by the terminal.
[0032] Preferably, the legality judgment module comprises a similarity unit and a legality unit.
[0033] The similarity unit is configured to calculate the similarity between the feature fingerprint of the terminal and the behavior fingerprint sample previously stored by the terminal by using a fuzzy matching algorithm.
[0034] The legality unit is configured to determine whether the similarity is greater than a given threshold value: if yes, it is determined that the behavior of the terminal device is legal and the feature fingerprint is used to update the behavior fingerprint sample; if no, it is determined that the behavior of the terminal device is illegal.
[0035] Compared with the closest prior art, the application has the following beneficial effects:
[0036] The application provides a LAN terminal device network access legality discrimination method and system, comprising: at a fixed time interval, obtaining the behavior characteristics of a terminal device based on the fixed characteristics of an access working LAN terminal device; generating a characteristic fingerprint for the terminal device based on the behavior characteristics; and determining the legality of the terminal device behavior based on the comparison of the characteristic fingerprint of the terminal with the behavior fingerprint sample pre-stored by the terminal.
[0037] Compared with the traditional access system, the application uses multiple fixed characteristic factors as the credentials for device access, improves the vulnerability of using only MAC address as access credentials, and effectively enhances the credibility of terminal legality judgment.
[0038] Compared with the current research status in the research field, the fuzzy matching algorithm used in the application can be applied to the scenario where multiple dynamic behavior characteristics of the access terminal change at the same time, effectively improving the application scenario of the same type of algorithm in the current research field which only supports one characteristic changing, and improving the universality and matching accuracy of the algorithm.
[0039] Compared with the current research status in the research field, the terminal to be tested applicable to the application is no longer limited to Android system terminal, but supports all terminals accessing the working LAN in the power marketing field. BRIEF DESCRIPTION OF DRAWINGS
[0040] Figure 1 A LAN terminal device network access legality discrimination method flowchart is provided for the application;
[0041] Figure 2 A LAN terminal device network access legality discrimination method flowchart is provided for the application;
[0042] Figure 3 A LAN terminal device network access legality discrimination method flowchart is provided for the application;
[0043] Figure 4 A LAN terminal device network access legality discrimination system basic structure diagram is provided for the application;
[0044] Figure 5 A LAN terminal device network access legality discrimination system detailed structure diagram is provided for the application. DETAILED DESCRIPTION
[0045] The specific embodiments of the application will be further described in detail below with reference to the accompanying drawings.
[0046] Embodiment 1
[0047] A flowchart of a LAN terminal device network access feature fingerprint legality discrimination method provided by the present application is shown in Figure 1 as shown, comprising:
[0048] Step 1: At a fixed time interval, based on the fixed features of the access working LAN terminal device, the behavior features of the terminal device are acquired;
[0049] Step 2: Based on the behavior features, the feature fingerprint of the terminal device is generated;
[0050] Step 3: Based on the comparison of the feature fingerprint of the terminal with the behavior fingerprint sample pre-stored by the terminal, the legality of the terminal device behavior is determined.
[0051] First, in the selection of device features, the present application lists the fixed features and dynamic behaviors contained in the marketing site terminal device, and selects the sampling method and sampling strategy for the corresponding features, which are active, passive or a combination of active and passive; second, by matching the fixed features of the device, the terminal device is allowed to access the local area network, and a certain right is reserved for observation, and the device information that fails to match the fixed features is delivered to the audit module for decision; third, within the access period or after formal access, the behavior features of the terminal are investigated by using a fuzzy approximate matching algorithm, and if it is found that the behavior of a terminal exceeds the threshold range allowed by the algorithm within a period of time, the terminal is determined to be a problem terminal; finally, the problem terminal is disconnected by using isolation VLAN (Virtual Local Area Network) and TCP (Transmission Control Protocol) blocking technology, and the information of the problem terminal is delivered to the audit module for auditing. The LAN terminal device network access feature fingerprint legality discrimination method and system provided by the present application improves the ability of power marketing site terminal legality discrimination, greatly reduces the threat of counterfeit and illegal terminal access to the site network, thereby further protecting the internal network from malicious network attacks, and has wide engineering practical value. The audit module decides again whether the terminal is allowed to access the local area network according to the pre-defined rules or the judgment of the administrator.
[0052] Specifically, the present application provides a LAN terminal device network access feature fingerprint legality discrimination method based on a fuzzy approximate matching algorithm. The method improves the ability of power marketing site terminal legality discrimination, greatly reduces the threat of counterfeit and illegal terminal access to the site network, thereby further protecting the company internal network from malicious network attacks, and has wide engineering practical value. The method comprises the following steps:
[0053] Step 101: Obtain a list of terminal types by investigating the types of terminals included in the power marketing site.
[0054] Step 102: Select appropriate terminal fixed features for each type of terminal in the list of terminal types. For example, under the premise of assigning static IP to the device, when a computer accesses the local area network, the computer's local IP address, MAC address, computer local name, operating system version, and browser information should be collected; when a printer accesses the local area network, its local IP address, MAC address, device name, operating system version, printer built-in web title, and printer special protocol port should be collected. The purpose of collecting and analyzing terminal fixed features is to provide access permission for the terminal to be accessed. When a new terminal needs to connect to the on-site work local area network, the terminal's fixed features need to be pre-entered through the access system. If the terminal needs to be online after being offline, each fixed feature of the terminal needs to be accurately matched. The terminal fixed features and their sampling methods are shown in the following table.
[0055] Table 1 Terminal fixed features and their sampling methods
[0056]
[0057] Step 103: Select appropriate terminal dynamic behavior features, i.e., behavior features, for each type of terminal in the list of terminal types. For example, for power marketing and payment terminals in the power business hall, the following dynamic features should be monitored at all times: access destination address of communication messages, data traffic per unit time, port open list during operation, application layer protocol usage, and whether the terminal is turned on and off according to working hours; for video monitoring terminals, the following dynamic features should be collected: video protocol traffic stability indicators, video message transmission destination address, port open list, and whether the terminal works 24 hours a day. The purpose of collecting and analyzing terminal dynamic behavior features is to provide modeling of legal behavior and discovery of illegal behavior for authorized terminals. The terminal dynamic behavior features and their sampling methods are shown in the following table.
[0058] Table 2 Terminal dynamic behavior features and their sampling methods
[0059]
[0060] Step 104: Once it is determined that each fixed feature of the terminal to be accessed has successfully completed the matching process, the terminal is given the right to access the work local area network. If the fixed feature matching of the terminal to be accessed fails, the terminal information is delivered to the system verification module, and the terminal is blocked or released according to the actual situation.
[0061] Step 105: After a newly added legitimate terminal accesses the local area network for the first time, the access control system shall collect, record and analyze the terminal behavior within a certain period of time after the terminal accesses the network, combine the calculated values of various dynamic behavior features to form an initial terminal dynamic feature fingerprint, and enter the fingerprint into the fingerprint database.
[0062] Step 106: After successful fingerprint initialization, the access control system should periodically detect the behavioral characteristics of the terminal device, generate new behavioral feature fingerprints and record them in the fingerprint database, and use a fuzzy matching algorithm to compare the new fingerprints with the initial fingerprints. If the similarity between the new fingerprint and the initial fingerprint is greater than the threshold given in the algorithm, it is determined to be a legitimate terminal, and the initial behavioral feature fingerprint in the fingerprint database is updated; otherwise, the fingerprint matching fails, the terminal has performed an illegal operation or is an illegal counterfeit terminal, and the terminal information is delivered to the system verification module for decision-making.
[0063] In step 106, the implementation process of the fuzzy matching algorithm is as follows: Figure 3 As shown, W is the type feature weight matrix of the device to be admitted, and N is the number of type features. i Let be the weight coefficient of the i-th item of the equipment type to be admitted. More important features are assigned larger weight coefficients. In actual use, the weights of each indicator can be adjusted as needed. Matrix W satisfies:
[0064] W = [w1, w2, ..., w N ], and w1+w2+...+w N =1
[0065] A i-last B represents the mean value of the i-th dynamic behavioral feature recorded in the fingerprint database. i-last A represents the standard deviation of the i-th dynamic behavioral feature value collected in the fingerprint database. i-last B i-last The two points together form P in the coordinate system. i-last Point; A i-new B represents the mean value of the i-th dynamic behavioral feature collected over a certain period of time. i-new A represents the standard deviation of the i-th dynamic behavioral feature collected over a certain period of time. i-new B i-new The two points together form P in the coordinate system. i-new Point. S i The similarity between the measured value of the i-th indicator and the value stored in the fingerprint database is calculated by formula (1); S represents the similarity between the device fingerprint calculated after measuring all indicators and the fingerprint recorded by the device in the fingerprint database.
[0066]
[0067] The similarity S and each Si Initialize to 0, and start comparing the P values of each dynamic behavioral feature sequentially from i=1. i-last Point and P i-new Point: If P of any dynamic behavioral characteristic i-last and P i-new Similarity between S i If the value is not greater than the first threshold, then clear all P values. i-new The value of S determines whether the device is behaving abnormally, and the process ends if S... i If the value is greater than the first threshold, the value of S is updated using formula (2) and the comparison of the next dynamic behavioral feature begins, until all dynamic behavioral features have been compared and judged. Where S' represents the similarity before the update.
[0068] S = S' + w i *S i (2)
[0069] After comparing and judging all dynamic behavioral features, determine whether the similarity S between the device fingerprint and the fingerprint recorded in the fingerprint database for that device is greater than or equal to the second threshold: if not, clear all P values. i-new The value of S is used to determine if the device's behavior is abnormal, and the process ends; otherwise, the values of P for each dynamic behavior characteristic are calculated. i-last and P i-new The midpoint P i-m And use the midpoint P of each dynamic behavioral characteristic respectively i-m Replace P in the fingerprint database i-last Then it ends.
[0070] The first threshold can be set to 0.8, and the second threshold can be set to 0.85.
[0071] Example 2:
[0072] The following is in conjunction with the appendix Figure 2 An embodiment of a method for determining the legitimacy of network access fingerprints for local area network terminal devices is given.
[0073] The process for determining the legitimacy of network access fingerprints for LAN terminal devices, after it begins, includes:
[0074] Step 201: Terminal type classification.
[0075] Step 202: Selection of strategies for fixed terminal features and dynamic behavior features.
[0076] That is, for each type of terminal in the terminal type list, select appropriate fixed terminal features for them.
[0077] Step 203: Wait for the device to join the network.
[0078] The device in this embodiment is also known as the terminal.
[0079] Step 204: Determine whether there is a device being on-boarded: if yes, go to step 205, otherwise go to step 203.
[0080] Step 205: Query the terminal MAC address.
[0081] Step 206: Determine whether the MAC address has been registered in the admission library: if yes, go to step 207, otherwise go to step 215.
[0082] Step 207: Perform accurate matching of the device fixed features.
[0083] Step 208: Determine whether the matching of the device fixed features is successful: if yes, go to step 209, otherwise go to step 215.
[0084] Step 209: The device passes the admission, periodically collects dynamic behavior features and generates dynamic device fingerprints.
[0085] Step 210: Perform similarity calculation using a fuzzy matching algorithm and the initial fingerprints in the fingerprint library.
[0086] Step 211: Determine whether the similarity of the dynamic behavior feature fingerprints is greater than a threshold value: if yes, go to step 209, and perform step 219; otherwise, go to step 212.
[0087] Step 212: Submit to the review module for review.
[0088] Step 213: The review module determines whether it passes the review: if yes, go to step 209, and perform step 219; otherwise, go to step 214.
[0089] Step 214: Prevent the device from connecting, and end.
[0090] Step 215: Submit to the review module for review.
[0091] Step 216: The review module determines whether it passes the review: if yes, go to step 217, otherwise go to step 214.
[0092] Step 217: Update the admission library.
[0093] Step 218: Collect dynamic behavior features for a certain period of time, generate initial dynamic behavior feature fingerprints, and go to step 209, and perform step 219.
[0094] Step 219: Update the fingerprint library.
[0095] Example 3:
[0096] A specific embodiment of a method for judging the legality of a LAN terminal device access feature fingerprint is given below.
[0097] Step 301: Terminal type investigation is conducted for a certain power marketing site, and the investigation result shows that the terminal types include working computers, marketing payment terminals, printers, cameras, POS machines and card punching instruments, etc.
[0098] Step 302: The terminal access system using the method is deployed by bypassing at the core switch, and all data traffic passing through the core switch is mirrored through a mirror port.
[0099] Step 303: A corresponding terminal fixed feature and terminal dynamic behavior feature are configured for each type of terminal, for example, all terminal features in Table 1 and Table 2 are configured for a computer terminal.
[0100] Step 304: Two computers of the same model and operating system are prepared as test machines. Computer A is a legal terminal accessing the LAN, and its fixed features are pre-recorded in the access library, and after sampling the dynamic behavior features for a period of time, the terminal dynamic feature fingerprint is generated and recorded in the fingerprint library. Computer B is a control group, and its fixed features are not pre-recorded in the access library. Computer B is directly connected to the test LAN, and the system checking module obtains the access request of computer B from the administrator, and can block the access of computer B.
[0101] Step 305: Computer A is offline, the IP address of computer B is modified to the original IP address of computer A, the MAC address of computer B is modified to the MAC address of computer A, and the system port and service of computer B are ensured to be in the same state as computer A, then the modified computer B is connected to the test LAN to replace the role of computer A, and computer B is temporarily connected to the network successfully.
[0102] Step 306: Some illegal operation behaviors are performed on computer B, including but not limited to accessing illegal hosts and domain names, frequently pinging a host address in the LAN, opening unknown high-risk ports, installing and running disabled unknown software, etc. After a period of time, computer B is kicked out of the network and its terminal information is delivered to the system checking module for blocking decision by the administrator.
[0103] Embodiment 4
[0104] Based on the same inventive concept, the application also provides a LAN terminal device access legality discrimination system, which has similar principles to the LAN terminal device access legality discrimination method in solving technical problems, and the repeated parts will not be repeated.
[0105] The basic structure of the system is shown in Figure 4 It includes a behavior feature module, a feature fingerprint module and a legality judgment module.
[0106] The behavior feature module is configured to obtain the behavior feature of the terminal device based on the fixed features of the terminal device accessing the working LAN at fixed time intervals.
[0107] The feature fingerprint module is configured to generate a feature fingerprint of the terminal device based on the behavior feature.
[0108] The legality judgment module is configured to determine the legality of the behavior of the terminal device based on a comparison between the feature fingerprint of the terminal device and a behavior fingerprint sample previously stored by the terminal.
[0109] The LAN terminal device network access legality discrimination system has a detailed structure as shown in Figure 5
[0110] The legality judgment module includes a similarity unit and a legality unit.
[0111] The similarity unit is configured to calculate the similarity between the feature fingerprint of the terminal device and the behavior fingerprint sample previously stored by the terminal using a fuzzy matching algorithm.
[0112] The legality unit is configured to determine whether the similarity is greater than a given threshold value: if yes, it is determined that the behavior of the terminal device is legal and the behavior fingerprint sample is updated with the feature fingerprint; if no, it is determined that the behavior of the terminal device is illegal.
[0113] The behavior feature module includes a dynamic behavior data unit and a behavior feature unit.
[0114] The dynamic behavior data unit is configured to sample the dynamic behavior of the terminal device based on the fixed features of the terminal device to obtain dynamic behavior data.
[0115] The behavior feature unit is configured to obtain the behavior feature of the terminal device based on the dynamic behavior data.
[0116] The LAN terminal device network access legality discrimination system further includes a network access judgment module.
[0117] The network access judgment module is configured to determine whether the terminal device is allowed to access the working LAN: when the multiple fixed features of the terminal device all respectively meet the fixed feature sample previously stored, the terminal device is allowed to access the working LAN; otherwise, the terminal device is not allowed to access the working LAN.
[0118] The LAN terminal device network access legality discrimination system further includes a behavior fingerprint sample initialization module; the fingerprint sample initialization module includes an initial dynamic behavior data unit, a behavior feature initial value unit, and a behavior fingerprint sample initial value unit.
[0119] An initial dynamic behavior data unit, configured to sample the dynamic behavior of the terminal device within a preset time length after the terminal device initially accesses the working local area network, to obtain initial dynamic behavior data of the terminal device;
[0120] An initial behavior feature value unit, configured to obtain an initial value of the behavior feature of the terminal device according to the initial dynamic behavior data;
[0121] An initial behavior fingerprint sample value unit, configured to generate an initial value of the behavior fingerprint sample of the terminal device according to the initial value of the behavior feature of the terminal device.
[0122] Those skilled in the art will understand that embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the present application can take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROMs, optical storage, etc.) containing computer usable program code.
[0123] The present application is described with reference to flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to embodiments of the present application. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, as well as combinations of flows and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing apparatus to produce a machine, so that the instructions that are executed by the processor of the computer or other programmable data processing apparatus generate an apparatus that implements the functions specified in the flowcharts and / or block diagrams. Figure 1 The functions specified in a flow or multiple flows and / or blocks Figure 1 The functions specified in a flow or multiple flows and / or blocks
[0124] These computer program instructions can also be stored in a computer-readable memory that can direct the computer or other programmable data processing apparatus to work in a specific manner, so that the instructions stored in the computer-readable memory produce a manufactured product including instruction apparatus, which implements the functions specified in the flowcharts and / or block diagrams. Figure 1 The functions specified in a flow or multiple flows and / or blocks Figure 1 The functions specified in a flow or multiple flows and / or blocks
[0125] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus, so that a series of operation steps are performed on the computer or other programmable data processing apparatus to produce a computer-implemented process, so that the instructions executed on the computer or other programmable data processing apparatus provide a process for implementing the functions specified in the flowcharts and / or block diagrams. Figure 1 The functions specified in a flow or multiple flows and / or blocks Figure 1steps of the functions specified in the block or blocks.
[0126] Finally, it should be noted that the above examples are merely used to illustrate the technical solutions of the present application but not to limit the protection scope thereof, and although the present application has been described in detail with reference to the above examples, those of ordinary skill in the art should understand that after reading the present application, various modifications, equivalent replacements, or changes to the specific embodiments of the present application can be made, but these modifications, equivalent replacements, or changes all fall within the protection scope of the claims of the present application.
Claims
1. A method for determining the legality of network access for local area network (LAN) terminal devices, characterized in that, include: At fixed time intervals, the behavioral characteristics of the terminal devices are obtained based on fixed characteristics of the terminal devices accessing the local area network. Based on the behavioral characteristics, a feature fingerprint is generated for the terminal device; The legality of the terminal device's behavior is determined by comparing the terminal's feature fingerprint with pre-stored behavioral fingerprint samples. The method of obtaining the behavioral characteristics of the terminal device based on the fixed characteristics of the terminal device accessing the local area network includes: Based on the fixed characteristics of the terminal device, the dynamic behavior of the terminal device is sampled to obtain dynamic behavior data; Based on the dynamic behavior data, the behavioral characteristics of the terminal device are obtained; The dynamic behaviors include: traffic volume, access behavior, access time, online / offline time, open ports at runtime, and service status at runtime. The determination of the legality of the terminal device's behavior based on the comparison between the terminal's feature fingerprint and pre-stored behavioral fingerprint samples includes: The similarity between the feature fingerprint of the terminal and the behavioral fingerprint samples pre-stored in the terminal is calculated using a fuzzy matching algorithm; Determine whether the similarity is greater than a given threshold: if yes, determine that the terminal device behavior is legal and update the behavior fingerprint sample with the feature fingerprint; otherwise, determine that the terminal device behavior is illegal. The similarity is calculated as follows: S=S’+w i *S i In the formula, S i w represents the degree of similarity corresponding to the i-th behavioral feature. i S represents the weight of the i-th behavioral feature, S' represents the similarity before considering the i-th behavioral feature, and S represents the similarity after considering the i-th behavioral feature; the initial value of S is 0. The similarity S corresponding to the i-th behavioral feature i The calculation formula is as follows: In the formula, A i-last B represents the mean of the i-th behavioral feature in the behavioral fingerprint sample. i-last A represents the standard deviation of the i-th behavioral feature in the behavioral fingerprint sample; i-new B represents the mean of the i-th dynamic behavioral feature. i-new The standard deviation represents the i-th behavioral characteristic; The step of determining whether the similarity is greater than a given threshold: if yes, the terminal device behavior is deemed legal and the behavior fingerprint sample is updated using the feature fingerprint; otherwise, the terminal device behavior is deemed illegal, including: The similarity S and each S i Initialize to 0, and start comparing the P values of each dynamic behavioral feature sequentially from i=1. i-last Point and P i-new Point: If P of any dynamic behavioral characteristic i-last and P i-new Similarity between S i If the value is not greater than the first threshold, then clear all P values. i-new The value of S determines whether the device is behaving abnormally, and the process ends if S... i If the value is greater than the first threshold, update the value of S and start comparing the next dynamic behavior feature until all dynamic behavior features have been compared and judged. After comparing and judging all dynamic behavioral features, determine whether the similarity S between the device fingerprint and the fingerprint recorded in the fingerprint database for that device is greater than or equal to the second threshold: if not, clear all P values. i-new The value of S is used to determine if the device's behavior is abnormal, and the process ends; otherwise, the values of P for each dynamic behavior characteristic are calculated. i-last and P i-new The midpoint P i-m And use the midpoint P of each dynamic behavioral characteristic respectively i-m Replace P in the fingerprint database i-last Then it ends; Among them, A i-last B i-last The two points together form P in the coordinate system. i-last Point A i-new B i-new The two points together form P in the coordinate system. i-new point.
2. The method as described in claim 1, characterized in that, The fixed characteristics of the terminal device are determined by the type of terminal.
3. The method as described in claim 1, characterized in that, Before acquiring the behavioral characteristics of the terminal device, the method further includes: Determine whether the terminal device is allowed to access the work local area network: Access to the work local area network is permitted when multiple fixed features of the terminal device conform to the pre-stored fixed feature samples; otherwise, access to the work local area network is not permitted.
4. The method as described in claim 1, characterized in that, The initial value setting of the terminal device behavioral fingerprint sample includes: After the terminal device first connects to the work local area network, the dynamic behavior of the terminal device is sampled within a preset time period to obtain initial dynamic behavior data. The initial values of the behavioral characteristics of the terminal device are obtained based on the initial dynamic behavior data; The initial value of the terminal device behavior fingerprint sample is generated based on the initial value of the terminal device behavior characteristics.
5. A system for determining the legality of network access for local area network (LAN) terminal devices, characterized in that, include: Behavioral feature module, feature fingerprint module, and legality judgment module; The behavior feature module is used to obtain the behavior features of the terminal device based on the fixed features of the terminal device accessing the work local area network at fixed time intervals. The feature fingerprint module is used to generate a feature fingerprint for the terminal device based on the behavioral features; The legality determination module is used to determine the legality of the terminal device's behavior based on the comparison between the terminal's feature fingerprint and the behavior fingerprint samples pre-stored by the terminal. The behavioral feature module includes: a dynamic behavioral data unit and a behavioral feature unit; The dynamic behavior data unit is used to sample the dynamic behavior of the terminal device based on the fixed features of the terminal device to obtain dynamic behavior data. The behavior feature unit is used to obtain the behavior features of the terminal device based on dynamic behavior data; The dynamic behaviors include: traffic volume, access behavior, access time, online / offline time, open ports at runtime, and service status at runtime. The legality determination module includes: a similarity unit and a legality unit; The similarity unit is used to calculate the similarity between the feature fingerprint of the terminal and the behavioral fingerprint samples pre-stored by the terminal using a fuzzy matching algorithm; The legality unit is used to determine whether the similarity is greater than a given threshold: if yes, the terminal device behavior is determined to be legal and the behavior fingerprint sample is updated with the feature fingerprint; otherwise, the terminal device behavior is determined to be illegal. The similarity is calculated as follows: S=S’+w i *S i In the formula, S i w represents the degree of similarity corresponding to the i-th behavioral feature. i S represents the weight of the i-th behavioral feature, S' represents the similarity before considering the i-th behavioral feature, and S represents the similarity after considering the i-th behavioral feature; the initial value of S is 0. The similarity S corresponding to the i-th behavioral feature i The calculation formula is as follows: In the formula, A i-last B represents the mean of the i-th behavioral feature in the behavioral fingerprint sample. i-last A represents the standard deviation of the i-th behavioral feature in the behavioral fingerprint sample; i-new B represents the mean of the i-th dynamic behavioral feature. i-new The standard deviation represents the i-th behavioral characteristic; The step of determining whether the similarity is greater than a given threshold: if yes, the terminal device behavior is deemed legal and the behavior fingerprint sample is updated using the feature fingerprint; otherwise, the terminal device behavior is deemed illegal, including: The similarity S and each S i Initialize to 0, and start comparing the P values of each dynamic behavioral feature sequentially from i=1. i-last Point and P i-new Point: If P of any dynamic behavioral characteristic i-last and P i-new Similarity between S i If the value is not greater than the first threshold, then clear all P values. i-new The value of S determines whether the device is behaving abnormally, and the process ends if S... i If the value is greater than the first threshold, update the value of S and start comparing the next dynamic behavior feature until all dynamic behavior features have been compared and judged. After comparing and judging all dynamic behavioral features, determine whether the similarity S between the device fingerprint and the fingerprint recorded in the fingerprint database for that device is greater than or equal to the second threshold: if not, clear all P values. i-new The value of S is used to determine if the device's behavior is abnormal, and the process ends; otherwise, the values of P for each dynamic behavior characteristic are calculated. i-last and P i-new The midpoint P i-m And use the midpoint P of each dynamic behavioral characteristic respectively i-m Replace P in the fingerprint database i-last Then it ends; Among them, A i-last B i-last The two points together form P in the coordinate system. i-last Point A i-new B i-new The two points together form P in the coordinate system. i-new point.
Citation Information
Patent Citations
Internet of Things terminal network portrait and abnormal network access behavior detection method
CN109600363A