Implementation method and system for intranet penetration

Through the collaborative work of center services and gateway services, intranet IP is automatically discovered and managed, which solves the high maintenance costs and security risks of intranet penetration solutions in the existing technology, and achieves low-cost and high-security intranet penetration.

CN115118502BActive Publication Date: 2025-07-25ZHEJIANG YINGYUN TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210745048.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-06-27
Publication Date
2025-07-25
Estimated Expiration
2042-06-27

AI Technical Summary

Technical Problem

In the prior art, the intranet penetration scheme requires the establishment of a large number of port bindings between the intranet IP and the external IP, resulting in high maintenance costs and low security in the intranet environment.

Method used

By setting up center services and gateway services, different connection methods are established based on different operating systems. Gateway services act as a jumper to realize intranet penetration, automatically scan the intranet IP and report it to the central service. The central service stores all connected intranet IPs, and the external network obtains all accessible intranet IPs through the central service.

Benefits of technology

It realizes open external network port mapping without the need for intranet environments, reduces maintenance costs and improves the security of intranet environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115118502B_ABST
    Figure CN115118502B_ABST
Patent Text Reader

Abstract

The present application discloses a method and system for implementing intranet penetration, which relates to the technical field of intranet penetration. The method for implementing intranet penetration includes the following steps: setting up a central service, running the gateway service of any device in the intranet environment, obtaining different operating systems based on the intranet IP to be connected, establishing different connection methods based on different operating systems, and after the information to be verified passes the verification, the central service communicates the corresponding intranet IP with the external network based on the success instruction. The beneficial effect is that intranet penetration is achieved by using the gateway service as a jumper, without the need to open external network port mapping in the intranet environment, with low maintenance costs and high security of the intranet environment. The gateway service can scan the intranet IP and automatically discover the connectable IPs in the intranet environment. The central service stores all the connectable intranet IPs. The external network can obtain all the accessible intranet IPs in the intranet environment by connecting to the central service.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application belongs to the technical field of intranet penetration. More specifically, this application relates to a method and system for implementing intranet penetration. Background Art

[0002] Traditional intranet penetration technology is to convert a dedicated network address (such as an enterprise internal network Internet) into a public address (such as the Internet Internet), thereby hiding the internal management IP address from the outside. By using unregistered IP addresses internally and converting them into a small number of externally registered IP addresses, the cost of IP address registration is reduced and the currently increasingly scarce address space is saved. However, the current technical solutions have the following defects:

[0003] It is necessary to establish a port binding between the intranet IP and the extranet IP. If there are too many intranet IPs, the corresponding number of bound ports will also be required to be too large, resulting in too high maintenance costs. At the same time, opening too many ports to the extranet poses a great potential safety hazard to the intranet environment. Summary of the Invention

[0004] The purpose of this application is to provide a method and system for implementing intranet penetration to solve the technical problem in the above-mentioned existing technology that opening too many ports to the extranet poses a great potential safety hazard to the intranet environment.

[0005] To achieve the above technical purpose, the technical solution adopted by this application is as follows:

[0006] A method for implementing intranet penetration includes the following steps:

[0007] Set up a central service, and run the gateway service of any device in the intranet environment. The gateway service and the central service establish a connection with each other;

[0008] The extranet transmits the intranet IP to be connected and the information to be verified to the gateway service through the central service. Based on the intranet IP to be connected, different operating systems are obtained, and different connection methods are established based on different operating systems;

[0009] After the information to be verified passes the verification, the gateway service transmits a success instruction to the central service, and the central service communicates the corresponding intranet IP with the extranet based on the success instruction.

[0010] Preferably, it further includes the step of:

[0011] After the gateway service and the central service establish a connection with each other, the gateway service automatically scans the intranet IPs in the intranet environment;

[0012] After any of the internal network IPs is successfully connected, the gateway service reports the internal network IP and the corresponding port to the central service until the central service obtains all the connectable internal network IPs in the internal network environment.

[0013] Preferably, the external network transmits the internal network IP to be connected and the information to be verified to the gateway service through the central service, which specifically includes the following steps:

[0014] The external network establishes a connection with the central service through the KCP protocol, and the external network transmits the internal network IP to be connected and the information to be verified to the central service;

[0015] The central service transmits the received internal network IP to be connected and the information to be verified to the gateway service.

[0016] Preferably, different operating systems are obtained based on the internal network IP to be connected, and different connection methods are established based on different operating systems, which specifically includes the following steps:

[0017] When the operating system is a Linux system, the gateway service establishes an SSH connection with the corresponding internal network IP and transmits the information to be verified to the corresponding internal network IP for verification;

[0018] The information to be verified includes the login username and login password.

[0019] Preferably, different operating systems are obtained based on the internal network IP to be connected, and different connection methods are established based on different operating systems, which specifically includes the following steps:

[0020] When the operating system is a Windows system, the gateway service establishes an RDP connection with the corresponding internal network IP and transmits the information to be verified to the corresponding internal network IP for verification;

[0021] The information to be verified includes the login username and login password.

[0022] Preferably, after the information to be verified passes the verification, the gateway service transmits a success instruction to the central service, which specifically includes the following steps:

[0023] The internal network IP verifies the information to be verified, generates the success instruction after passing the verification, and transmits it to the gateway service;

[0024] The gateway service transmits the success instruction to the central service, and the gateway service transmits the communication data corresponding to the internal network IP to the central service.

[0025] Preferably, the central service communicates the corresponding internal network IP with the external network based on the success instruction, which specifically includes the following steps:

[0026] The central service receives the success instruction transmitted by the gateway service, and based on the success instruction, the central service transmits the communication data of the corresponding internal network IP to the external network;

[0027] The external network communicates based on the communication data and the corresponding internal network IP, and controls the devices with the internal network IP based on different connection methods.

[0028] An implementation system for internal network penetration includes:

[0029] A first connection module, which is used to set up a central service and run the gateway service of any device in the internal network environment, and the gateway service and the central service establish a connection with each other;

[0030] A second connection module, which is used for the external network to transmit the internal network IP to be connected and the information to be verified to the gateway service through the central service, obtain different operating systems based on the internal network IP to be connected, and establish different connection methods based on different operating systems;

[0031] A third connection module, which is used after the information to be verified passes the verification, the gateway service transmits a success instruction to the central service, and the central service communicates the corresponding internal network IP with the external network based on the success instruction.

[0032] An electronic device includes a memory and a processor, and the memory is used to store one or more computer instructions, wherein the one or more computer instructions are executed by the processor to implement an implementation method for internal network penetration as described above.

[0033] A computer-readable storage medium stores computer instructions, and when the computer instructions are executed by a processor, the steps of the above method are implemented.

[0034] The beneficial effects provided by this application are as follows:

[0035] 1. By setting up a central service, running the gateway service of any device in the internal network environment, establishing different connection methods based on different operating systems, and the central service communicating the corresponding internal network IP with the external network based on the success instruction. The internal network penetration is achieved by using the gateway service as a jumper, without the need to open the external network port mapping in the internal network environment, with low maintenance cost and high security of the internal network environment.

[0036] 2. After the gateway service and the central service of this application establish a connection with each other, the gateway service automatically scans the internal network IPs in the internal network environment. After any internal network IP is successfully connected, the gateway service reports the internal network IP and the corresponding port to the central service. The gateway service can scan the internal network IPs, automatically discover the connectable IPs in the internal network environment, and send the connectable internal network IPs to the central service. The central service stores all the connectable internal network IPs. The external network can obtain all the accessible internal network IPs in the internal network environment by connecting to the central service. BRIEF DESCRIPTION OF THE DRAWINGS

[0037] To more clearly illustrate the technical solutions in the embodiments of this application, the following will briefly introduce the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings in the following description are only some embodiments of this application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0038] Figure 1 It is a timing diagram of the implementation method of internal network penetration. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0039] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the following will clearly and completely describe the technical solutions in the embodiments of this application with reference to the drawings in the embodiments of this application. Obviously, the described embodiments are some, but not all, of the embodiments of this application. Usually, the components of the embodiments of this application described and illustrated in the drawings here can be arranged and designed in various different configurations.

[0040] Therefore, the following detailed description of the embodiments of this application provided in the drawings is not intended to limit the scope of this application that is required to be protected, but merely represents the selected embodiments of this application. Based on the embodiments in this application, all other embodiments obtained by those of ordinary skill in the art without creative efforts fall within the scope of protection of this application.

[0041] Embodiment 1:

[0042] As Figure 1 shown, this embodiment includes an implementation method of internal network penetration, which includes the following steps: Set up a central service, run the gateway service of any device in the internal network environment, and establish a connection between the gateway service and the central service. The external network transmits the internal network IP to be connected and the information to be verified to the gateway service through the central service, obtain different operating systems based on the internal network IP to be connected, and establish different connection methods based on different operating systems. After the information to be verified passes the verification, the gateway service transmits a successful instruction to the central service, and the central service communicates the corresponding internal network IP with the external network based on the successful instruction.

[0043] The technical solution of this application uses the gateway service as a jump machine to achieve intranet penetration. At the same time, the gateway service can scan the intranet IP, automatically discover the connectable IPs in the intranet environment, send the connectable intranet IPs to the central service, and the central service stores all the connectable intranet IPs. The external network can obtain all the accessible intranet IPs in the intranet environment by connecting to the central service, without opening the external network port mapping in the intranet environment, with low maintenance cost and high security of the intranet environment.

[0044] It also includes the steps: after the gateway service and the central service establish a connection with each other, the gateway service automatically scans the intranet IPs in the intranet environment. After any intranet IP connection is successful, the gateway service reports the intranet IP and the corresponding port to the central service until the central service obtains all the connectable intranet IPs in the intranet environment.

[0045] In this embodiment, the central service is a connection service that opens the KCP protocol, can connect to multiple gateway services, and is a microservice program. The central service is deployed in the linux environment and in the external network environment.

[0046] After the gateway service and the central service establish a connection with each other, the gateway service uses the telnet technology to periodically traverse and connect to the intranet IPs. If it can connect to any intranet IP, it means the corresponding IP is accessible, and the connectable intranet IPs are sent to the central service, and the central service stores all the connectable intranet IPs. Only the intranet IPs that can be successfully connected are reported to the central service.

[0047] After the external network connects to the central service, the central service returns all the connectable intranet IPs to the external network. The external network selects an IP, the login username, and the login password corresponding to the IP from all the connectable intranet IPs, and the external network sends the selected intranet IP, the login username, and the login password corresponding to the IP to the central service, and the central service forwards them to the gateway service. Through the above technical solution, the external network can obtain all the accessible intranet IPs in the intranet environment by connecting to the central service.

[0048] The external network transmits the intranet IP to be connected and the information to be verified to the gateway service through the central service, specifically including the following steps: the external network establishes a connection with the central service through the KCP protocol, and the external network transmits the intranet IP to be connected and the information to be verified to the central service. The central service transmits the received intranet IP to be connected and the information to be verified to the gateway service.

[0049] Obtain different operating systems based on the internal network IP to be connected, and establish different connection methods based on different operating systems, which specifically include the following steps: When the operating system is the Linux system, the gateway service establishes an SSH connection with the corresponding internal network IP, and transmits the information to be verified to the corresponding internal network IP for verification. The information to be verified includes the login username and login password. The gateway service uses multiplexing technology to establish an SSH connection with the corresponding internal network IP.

[0050] Obtain different operating systems based on the internal network IP to be connected, and establish different connection methods based on different operating systems, which specifically include the following steps: When the operating system is the Windows system, the gateway service establishes an RDP connection with the corresponding internal network IP, and transmits the information to be verified to the corresponding internal network IP for verification. The information to be verified includes the login username and login password. The gateway service uses multiplexing technology to establish an RDP connection with the corresponding internal network IP.

[0051] After the information to be verified passes the verification, the gateway service transmits the success instruction to the central service, which specifically includes the following steps: The internal network IP verifies the information to be verified. After passing the verification, a success instruction is generated and transmitted to the gateway service. The gateway service transmits the success instruction to the central service, and the gateway service transmits the communication data of the corresponding internal network IP to the central service.

[0052] The internal network IP verifies the information to be verified. In this embodiment, the information to be verified includes the login username and login password. If the login username and login password are verified successfully, a success instruction is generated and transmitted to the gateway service after passing the verification. If the login username and login password are verified incorrectly, error data is generated and transmitted to the gateway service.

[0053] The central service communicates the corresponding internal network IP with the external network based on the success instruction, which specifically includes the following steps: The central service receives the success instruction transmitted by the gateway service. Based on the success instruction, the central service transmits the communication data of the corresponding internal network IP to the external network. The external network communicates with the corresponding internal network IP based on the communication data and controls the devices of the internal network IP based on different connection methods.

[0054] If the central service receives the success instruction returned by the gateway service, it forwards the subsequent communication between the central service and the gateway service to the external network based on the success instruction. Finally, the communication between the external network and the corresponding internal network IP is realized, and the devices of the corresponding internal network IP can be directly controlled through RDP connection or SSH connection.

[0055] Embodiment 2:

[0056] This embodiment includes a system for implementing internal network penetration, including:

[0057] The first connection module is used to set up a central service and run the gateway service of any device in the intranet environment. The gateway service and the central service establish connections with each other.

[0058] The second connection module is used for the external network to transmit the intranet IP to be connected and the information to be verified to the gateway service through the central service, obtain different operating systems based on the intranet IP to be connected, and establish different connection methods based on different operating systems.

[0059] The third connection module is used for the gateway service to transmit a success instruction to the central service after the information to be verified passes the verification, and the central service communicates the corresponding intranet IP with the external network based on the success instruction.

[0060] The implementation system of intranet penetration in Embodiment 2 of this specification can be used as the execution subject of the above Figure 1 shown implementation method of intranet penetration. Therefore, the implementation system of intranet penetration can implement the functions realized by the method in Figure 1 See the corresponding description in Part of Embodiment 1 for relevant parts.

[0061] Embodiment 3:

[0062] An electronic device includes a memory and a processor. The memory is used to store one or more computer instructions. Among them, the one or more computer instructions are executed by the processor to implement the above-mentioned implementation method of intranet penetration.

[0063] Those skilled in the art can clearly understand that for the convenience and simplicity of description, the specific working process of the above-described electronic device can refer to the corresponding process in the foregoing method embodiment, and will not be elaborated herein.

[0064] A computer-readable storage medium stores computer instructions, and when the computer instructions are executed by a processor, the steps of the method in Embodiment 1 are implemented.

[0065] Those skilled in the art should understand that the embodiments of the present invention can be provided as methods, devices, or computer program products. Therefore, the present invention can adopt the form of an all-hardware embodiment, an all-software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0066] The present invention is described with reference to the flowcharts and / or block diagrams of methods, terminal devices (systems), and computer program products according to the present invention. It should be understood that each flow and / or block in the flowchart and / or block diagram, and the combination of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing terminal devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing terminal devices generate means for implementing the functions specified in one or more of the flows Figure 1 one or more flows and / or blocks Figure 1 or means for implementing the functions specified in one or more of the blocks.

[0067] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing terminal device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured article including instruction means, and the instruction means implement the functions specified in one or more of the flows Figure 1 one or more flows and / or blocks Figure 1 or means for implementing the functions specified in one or more of the blocks.

[0068] These computer program instructions can also be loaded onto a computer or other programmable data processing terminal device, so that a series of operation steps are executed on the computer or other programmable terminal device to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable terminal device provide steps for implementing the functions specified in one or more of the flows Figure 1 one or more flows and / or blocks Figure 1 or means for implementing the functions specified in one or more of the blocks.

[0069] It should be noted that:

[0070] The phrase "one embodiment" or "embodiment" mentioned in the specification means that the specific features, structures, or characteristics described in combination with the embodiment are included in at least one embodiment of the present application. Therefore, the phrases "one embodiment" or "embodiment" that appear throughout the specification do not necessarily all refer to the same embodiment.

[0071] Although the preferred embodiments of the present application have been described, those skilled in the art can make additional changes and modifications to these embodiments once they know the basic creative concept. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of the present application.

[0072] In addition, it should be noted that for the specific embodiments described in this specification, the shapes and names of the components can be different. Any equivalent or simple changes made to the structure, features, and principles according to the inventive concept of this patent application are included in the protection scope of this patent application. Those skilled in the technical field to which this application pertains can make various modifications, supplements, or use similar methods for substitution to the specific embodiments described, as long as they do not deviate from the structure of this application or exceed the scope defined by this claim book, they should all fall within the protection scope of this application.

Claims

1. A method for implementing intranet penetration, characterized in that, It includes the following steps: Set up a central service to run the gateway service of any device in the intranet environment, and establish a connection between the gateway service and the central service; The external network transmits the intranet IP to be connected and the information to be verified to the gateway service through the central service, obtains different operating systems based on the intranet IP to be connected, and establishes different connection methods based on different operating systems; After the information to be verified passes the verification, the gateway service transmits a success instruction to the central service, and the central service communicates the corresponding intranet IP with the external network based on the success instruction; After the gateway service and the central service establish a connection with each other, the gateway service automatically scans the intranet IPs in the intranet environment; After any of the intranet IPs is successfully connected, the gateway service reports the intranet IP and the corresponding port to the central service until the central service obtains all the connectable intranet IPs in the intranet environment; Obtain different operating systems based on the intranet IP to be connected, and establish different connection methods based on different operating systems, which specifically include the following steps: When the operating system is the Linux system, the gateway service establishes an SSH connection with the corresponding intranet IP and transmits the information to be verified to the corresponding intranet IP for verification; When the operating system is the Windows system, the gateway service establishes an RDP connection with the corresponding intranet IP and transmits the information to be verified to the corresponding intranet IP for verification; The central service is a connection service that has opened the KCP protocol and can be connected to multiple gateway services. The central service is deployed in the Linux environment and in the external network environment.

2. The implementation method of intranet penetration according to claim 1, characterized in that, The external network transmits the intranet IP to be connected and the information to be verified to the gateway service through the central service, which specifically includes the following steps: The external network establishes a connection with the central service through the KCP protocol, and the external network transmits the intranet IP to be connected and the information to be verified to the central service; The central service transmits the received intranet IP to be connected and the information to be verified to the gateway service.

3. The implementation method of internal network penetration according to claim 1, characterized in that, The information to be verified includes the login username and login password.

4. The implementation method of intranet penetration according to claim 1, characterized in that After the information to be verified passes the verification, the gateway service transmits a success instruction to the central service, which specifically includes the following steps: The intranet IP verifies the information to be verified, generates the success instruction after passing the verification, and transmits it to the gateway service; The gateway service transmits the success instruction to the central service, and the gateway service transmits the communication data corresponding to the intranet IP to the central service.

5. The implementation method of internal network penetration as described in claim 1, characterized in that, The central service communicates the corresponding intranet IP with the external network based on the success instruction, which specifically includes the following steps: The central service receives the success instruction transmitted by the gateway service, and based on the success instruction, the central service transmits the communication data of the corresponding intranet IP to the external network; The external network communicates with the corresponding intranet IP based on the communication data and controls the devices of the intranet IP based on different connection methods.

6. An implementation system for intranet penetration, characterized in that, Applying the method according to any one of claims 1-5, comprising: A first connection module, which is used to set up a central service and run the gateway service of any device in the intranet environment, and the gateway service and the central service establish a connection with each other; A second connection module, which is used for the external network to transmit the intranet IP to be connected and the information to be verified to the gateway service through the central service, obtain different operating systems based on the intranet IP to be connected, and establish different connection methods based on different operating systems; A third connection module, which is used for the gateway service to transmit a success instruction to the central service after the information to be verified passes the verification, and the central service communicates the corresponding intranet IP with the external network based on the success instruction.

7. An electronic device, characterized in that, Comprising a memory and a processor, the memory is used to store one or more computer instructions, wherein the one or more computer instructions are executed by the processor to implement a method for realizing intranet penetration as described in any one of claims 1 to 5.

8. A readable storage medium, on which a computer program is stored, characterized in that, When the computer program is executed by the processor, the steps of the method as described in any one of claims 1 to 5 are implemented.

Citation Information

Patent Citations

  • Enterprise intranet access method based on reverse connection and application layer tunnel

    CN108600204A

  • Internet-of-things gateway intranet penetration method based on reverse proxy

    CN110611724A