A method of using a computer network firewall
Patent Information
- Application Number
- CN202111303317.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-11-05
- Publication Date
- 2025-07-01
- Estimated Expiration
- 2041-11-05
AI Technical Summary
The existing firewalls on the market cannot provide good protection during the virus scanning and killing process, resulting in low security for computer network use.
By implementing the input, link verification, risk analysis and access protection processes in the computer network firewall, including web page structure analysis, data asset comparison, real-time protection, traffic sorting and pop-up window processing, risk analysis is performed using blacklists, corpora, knowledge maps, etc. and protection, and resolve the domain name to the high-defense IP for cleaning and filtering during the access process to ensure the stability of the origin site IP.
It improves the security of the computer network, enhances the protection against viruses and malicious attacks through real-time detection and protection measures, and ensures the integrity and security of user data and information.
Smart Images

Figure CN113992423B8_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of computer network security technology, specifically to a highly secure computer network firewall and its usage method. Background Technology
[0002] Firewall technology is a technology that organically combines various software and hardware devices used for security management and screening to help computer networks build a relatively isolated protective barrier between their internal and external networks, thereby protecting the security of user data and information. The main function of firewall technology is to promptly detect and handle potential security risks and data transmission problems that may exist during the operation of computer networks. The handling measures include isolation and protection, and it can also record and detect various operations in computer network security to ensure the security of computer network operation, protect the integrity of user data and information, and provide users with a better and safer computer network experience.
[0003] With the advent of the information age, people are paying more and more attention to network security. However, existing firewalls on the market do not have high security performance and cannot play a good protective role in the process of virus detection and removal, which is not conducive to the security of computer network use. Summary of the Invention
[0004] The purpose of this invention is to provide a highly secure computer network firewall and its usage method. It has the advantage of high security and solves the problem that existing firewalls on the market do not have a high level of security and cannot play a good protective role in the process of virus detection and removal, which is not conducive to the security of computer network use.
[0005] To solve the above-mentioned technical problems, the present invention provides the following technical solution:
[0006] A highly secure computer network firewall has the following specific process: input, link verification, risk analysis, access protection, and access; users enter links through a client or click on external links to access the network, outputting commands through the external network interface. The firewall retrieves the IP address of the accessed link, stores the information in the network node's memory, and retrieves the firewall's built-in blacklist for comparison. If an anomaly is detected, a pop-up alarm is triggered. After the blacklist comparison is successful, the firewall directly analyzes the data source's address and protocol type, determining whether access is permitted.
[0007] The following are further optimizations of the above technical solution by the present invention:
[0008] After complying with firewall standards, access risk analysis is conducted. Access risk analysis first includes webpage structure parsing and data asset comparison. Webpage structure parsing includes a rule layer and a risk perception layer. The rule layer includes list identification, malicious code detection, illegal domain name identification, and hidden content identification.
[0009] Further optimization: The risk perception layer includes structured matching of sensitive word rules and extraction of sensitive text fragments. After structural parsing, the data is stored and analyzed one by one by retrieving the corpus, knowledge graph, risk graph, malicious JS code library, illegal domain name library and list library.
[0010] Further optimization: During the access process, real-time protection is implemented by resolving the domain name to the high-defense IP through the firewall, and forwarding rules are set on the high-defense IP. All public network traffic will go through the high-defense IP, and user access will be forwarded to the origin IP through port protocol forwarding. At the same time, malicious attack traffic is cleaned and filtered on the high-defense IP and normal traffic is returned to the origin IP, thereby ensuring stable access protection service for the origin IP.
[0011] Further optimization: During internet access and browsing, traffic usage is analyzed in the backend. In case of abnormal packet loss or abnormal traffic usage, the source address is checked through the firewall to detect usage risks.
[0012] Further optimization: When an abnormal pop-up occurs during internet access and browsing, the firewall will repeatedly perform connection verification and risk analysis steps to check the pop-up address. If the risk level is high, it will be directly added to the blacklist and blocked before the next pop-up. If the risk level is low, a pop-up window in the lower right corner of the computer will remind the user to manually enable or select trust.
[0013] Further optimization: When a request to access computer data via a background link is received during computer use, the firewall will repeat the link verification and risk analysis steps to check the link address. If the risk level is high, the link will be directly added to the blacklist. If the risk level is low, a pop-up window in the lower right corner of the computer will remind the user to manually enable or select trust.
[0014] Further optimization: During computer use, manually select or automatically enable real-time online data updates.
[0015] This invention also provides a method for using a highly secure computer network firewall. The user can set the firewall to start automatically at boot or manually enable it at boot. The firewall can automatically update its database and virus definitions via pop-up windows, or the user can manually update the database and virus definitions periodically. Once enabled, the firewall periodically reminds the user to scan for Trojans or set up automatic virus removal via pop-up windows. The user can also manually set trusted software and addresses, and the firewall will perform real-time detection and pop-up reminders when downloading software or browsing web pages.
[0016] This invention employs the aforementioned technical solution, which is ingeniously conceived. Users can configure a firewall to start automatically on computer startup or manually enable it at startup. The firewall automatically displays pop-up windows allowing users to access and update its database and virus definitions in real-time. Alternatively, users can manually update the database and virus definitions periodically. Once enabled, the firewall periodically reminds users to scan for Trojans or set up automatic virus removal. Users can also manually configure trusted software and addresses. Real-time detection and pop-up alerts are provided during software downloads and web browsing. This solves the problem that existing firewalls on the market lack high security and fail to provide adequate protection during virus scanning, thus hindering computer network security.
[0017] The present invention will be further described below with reference to the accompanying drawings and embodiments. Attached Figure Description
[0018] Figure 1 This is a schematic diagram of the overall structure in an embodiment of the present invention;
[0019] Figure 2 This is a schematic diagram illustrating the principle of access risk analysis in an embodiment of the present invention;
[0020] Figure 3 This is a flowchart of the link verification process in an embodiment of the present invention;
[0021] Figure 4 This is a flowchart illustrating real-time protection in an embodiment of the present invention;
[0022] Figure 5 This is a flowchart of risk monitoring in an embodiment of the present invention;
[0023] Figure 6 This is a flowchart illustrating the access protection process in an embodiment of the present invention.
[0024] Figure 7 This is a flowchart illustrating the access protection process in an embodiment of the present invention. Detailed Implementation
[0025] Example: Please refer to Figure 1-7A highly secure computer network firewall, whose specific process includes: input, connection verification, risk analysis, access protection, and access control.
[0026] Users can access the system by entering a link in the client or clicking on an external link, and output commands through the external network interface. The firewall retrieves the IP address of the accessed link, stores the information in the network node's storage, and retrieves and compares it with the firewall's built-in blacklist. If any abnormality is detected, a pop-up alarm will be triggered.
[0027] After the blacklist comparison is successful, the firewall directly analyzes the data source's address and protocol type, and determines whether it can pass through.
[0028] After complying with firewall standards, an access risk analysis is conducted.
[0029] Access risk analysis first includes webpage structure analysis and data asset comparison. Webpage structure analysis includes a rule layer and a risk perception layer. The rule layer includes list identification, malicious code detection, illegal domain name identification, and hidden content identification.
[0030] The risk perception layer includes structured matching of sensitive word rules and extraction of sensitive text fragments. After structural parsing, the data is stored and analyzed one by one by accessing corpora, knowledge graphs, risk graphs, malicious JS code libraries, illegal domain name libraries, and list libraries.
[0031] During access, real-time protection is implemented by resolving the domain name to the high-defense IP via the firewall and setting forwarding rules on the high-defense IP. All public network traffic will go through the high-defense IP, and user access will be forwarded to the origin IP via port protocol forwarding. At the same time, malicious attack traffic is cleaned and filtered on the high-defense IP and normal traffic is returned to the origin IP, thereby ensuring stable access from the origin IP.
[0032] During internet access and browsing, traffic usage is analyzed in the backend. If abnormal packet loss or abnormal traffic usage occurs, the source address is checked through the firewall to detect the usage risk.
[0033] If an abnormal pop-up occurs during internet access and browsing, the firewall will repeatedly perform connection verification and risk analysis steps to check the pop-up address. If the risk level is high, it will be directly added to the blacklist and blocked before the next pop-up. If the risk level is low, a pop-up window in the lower right corner of the computer will remind the user to manually enable or select trust.
[0034] When a request to access computer data via a background link is received during computer use, the firewall repeatedly performs link verification and risk analysis steps to check the link address. If the risk level is high, the link is directly added to the blacklist; if the risk level is low, a pop-up window in the lower right corner of the computer prompts the user to manually enable or select trust.
[0035] During computer use, manually select or automatically enable real-time online data updates.
[0036] This invention also provides a method for using a highly secure computer network firewall, by having the user set the firewall to start automatically at boot or manually enable the firewall at boot on the computer terminal.
[0037] The firewall can automatically pop up a window to select whether to update the database and virus definitions online in real time, or allow users to manually update the database and virus definitions periodically.
[0038] Once the firewall is enabled, it periodically reminds users to scan for and remove Trojans or set up automatic virus removal via pop-up windows, allowing users to manually set trusted software and addresses.
[0039] Real-time monitoring and pop-up alerts are provided when downloading software and browsing web pages.
[0040] When using it, the user can set the firewall to start automatically at boot or manually enable the firewall at boot on the computer terminal.
[0041] The firewall can automatically pop up a window to select whether to update the database and virus definitions online in real time, or allow users to manually update the database and virus definitions periodically.
[0042] Once the firewall is enabled, it periodically reminds users to scan for and remove Trojans or set up automatic virus scanning. Users can manually set trusted software and addresses, and the firewall performs real-time detection and pop-up reminders when downloading software and browsing the web.
[0043] It solves the problem that existing firewalls on the market lack high security and cannot provide adequate protection during virus detection, thus hindering computer network security.
[0044] Although embodiments of the invention have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the appended claims and their equivalents.
Claims
1. A highly secure computer network firewall, characterized in that: The specific process includes: input, link verification, risk analysis, access protection, and access; access is achieved through client-side link input or external link clicking, command output through external network interface, the firewall retrieves the IP address of the access link, stores the information in the network node storage, and retrieves the firewall's built-in blacklist for comparison, with an alert popping up directly if an anomaly is detected; after passing the blacklist comparison, the firewall directly analyzes the data source address and protocol type characteristics, and determines whether access is permitted.
2. The highly secure computer network firewall according to claim 1, characterized in that: After complying with firewall standards, access risk analysis is conducted. Access risk analysis first includes webpage structure parsing and data asset comparison. Webpage structure parsing includes a rule layer and a risk perception layer. The rule layer includes list identification, malicious code detection, illegal domain name identification, and hidden content identification.
3. A highly secure computer network firewall according to claim 2, characterized in that: The risk perception layer includes structured matching of sensitive word rules and extraction of sensitive text fragments. After structural parsing, the data is stored and analyzed one by one by accessing corpora, knowledge graphs, risk graphs, malicious JS code libraries, illegal domain name libraries, and list libraries.
4. A highly secure computer network firewall according to claim 3, characterized in that: During access, real-time protection is implemented by resolving the domain name to the high-defense IP via the firewall and setting forwarding rules on the high-defense IP. All public network traffic will go through the high-defense IP, and user access will be forwarded to the origin IP via port protocol forwarding. At the same time, malicious attack traffic is cleaned and filtered on the high-defense IP and normal traffic is returned to the origin IP, thereby ensuring stable access from the origin IP.
5. A highly secure computer network firewall according to claim 4, characterized in that: During internet access and browsing, traffic usage is analyzed in the backend. If abnormal packet loss or abnormal traffic usage occurs, the source address is checked through the firewall to detect the usage risk.
6. A highly secure computer network firewall according to claim 5, characterized in that: If an abnormal pop-up occurs during internet access and browsing, the firewall will repeatedly perform connection verification and risk analysis steps to check the pop-up address. If the risk level is high, it will be directly added to the blacklist and blocked before the next pop-up. If the risk level is low, a pop-up window in the lower right corner of the computer will remind the user to manually enable or select trust.
7. A highly secure computer network firewall according to claim 6, characterized in that: When a request to access computer data via a background link is received during computer use, the firewall repeatedly performs link verification and risk analysis steps to check the link address. If the risk level is high, the link is directly added to the blacklist; if the risk level is low, a pop-up window in the lower right corner of the computer prompts the user to manually enable or select trust.
8. A highly secure computer network firewall according to claim 7, characterized in that: During computer use, manually select or automatically enable real-time online data updates.
9. A method of using a highly secure computer network firewall as described in any one of claims 1-8, characterized in that: Users can configure the firewall to start automatically at boot or manually enable it at boot on their computer terminal. The firewall can automatically update its database and virus definitions online in real time via a pop-up window, or users can manually update the database and virus definitions periodically.
10. The method of using a highly secure computer network firewall according to claim 9, characterized in that: Once the firewall is enabled, it periodically reminds users to scan for and remove Trojans or set up automatic virus scanning. Users can manually set trusted software and addresses, and the firewall performs real-time detection and pop-up reminders when downloading software and browsing the web.
Citation Information
Patent Citations
WEB site security protection method and system
CN106713318A
A network application layer security protection system
CN109167754A
Network security protection method, device and system
CN112351012A
System and method for implementing a web application firewall as a customized service
US20210036991A1