An Interception Method for Cracking Behavior and a Security Gateway Device

By monitoring service traffic in the security gateway, intercepting and forging login messages, recording usernames and passwords, and recording them on the IP blacklist, the existing security gateway cannot defend against attackers from changing IP addresses and logging in again, significantly improving the security of user information.

CN115314285BActive Publication Date: 2025-05-30BEIJING TOPSEC NETWORK SECURITY TECH +2
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210938534.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-08-05
Publication Date
2025-05-30
Estimated Expiration
2042-08-05

AI Technical Summary

Technical Problem

After detecting brute-force cracking, the existing security gateway cannot effectively defend against the attacker's login behavior after changing the IP address to the successfully brute-forced username and password, resulting in poor security of user information.

Method used

By monitoring the traffic of each service, identifying cracking behavior and intercepting the attacker's first login message, forging response messages makes the attacker mistakenly think that the login is successful, recording the user name and password, and blacklisting the attacker's IP address to prevent the attacker from changing the IP address and logging in again.

Benefits of technology

Effectively prevent attackers from logging in with the username and password that has been successfully brute-down by changing their IP addresses, improving the security of user information and ensuring early identification and blocking of malicious login behavior.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115314285B_ABST
    Figure CN115314285B_ABST
Patent Text Reader

Abstract

The present application provides a method for intercepting cracking behavior and a security gateway device. By monitoring the traffic of each service, violent cracking behavior is detected. When violent cracking behavior is detected, the currently obtained first login message is intercepted and a response message indicating successful login of the first login message is forged, and the forged response message is sent to the attacker to mislead the attacker. Moreover, the first login username and the first password of the first login message are recorded, aiming to quickly identify the malicious login behavior of the attacker when the attacker changes the IP and attempts to log in using the first login username and the first password. Therefore, the behavior of the attacker attacking by changing to other IP addresses can be blocked as early as possible. Finally, the IP address of the attacker is recorded in the IP blacklist to prevent the attacker from continuing to perform cracking behavior.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security technology. Specifically, it relates to a method for intercepting cracking behaviors and a security gateway device. Background Art

[0002] Brute force cracking is a common attack method used by attackers. Without knowing the username and password, the attack software uses a dictionary file to sequentially try the username and password, and finally cracks the username or password. The commonly used attack methods for brute force cracking are default passwords, empty passwords, or weak passwords. This kind of attack often has good results. After continuous attempts for a period of time, the username and password that can be logged in successfully are finally found.

[0003] Existing security gateways discover brute force cracking behaviors through message frequencies and message contents, but do not play a defensive role in the subsequent login behaviors of the successfully cracked usernames and passwords. Since from the start of the attacker's attack to the discovery and blocking by the security gateway, during this time difference, the attacker has often made a certain number of attempts for usernames and passwords; and the attacker can still continue to try to crack through other IP addresses. Eventually, the attacker may still obtain the username and password that can be logged in successfully. If the IP is changed later to try to log in with the successfully cracked username and password, this malicious login behavior cannot be detected, and the security of user information is relatively poor. Summary of the Invention

[0004] The purpose of the embodiments of this application is to provide a method for intercepting cracking behaviors and a security gateway device, so as to solve the problem that existing security gateways discover brute force cracking behaviors through message frequencies and message contents, but do not play a defensive role in the subsequent login behaviors of the successfully cracked usernames and passwords, resulting in the inability to detect the login behavior of the attacker changing the IP to try the successfully cracked username and password, and the security of user information is relatively poor.

[0005] A method for intercepting cracking behaviors provided by the embodiments of this application is applied to a security gateway. The method includes:

[0006] Monitor the traffic of each service to identify cracking behaviors. When a cracking behavior for the first service is detected, perform the following steps:

[0007] Obtain the first login message sent by the attacker corresponding to the cracking behavior, and intercept the first login message;

[0008] For the first login message, forge a corresponding response message and send it to the attacker;

[0009] Record the first login username and the first password in the first login message; and record the attacker's IP address in the IP blacklist, and discard the first login message.

[0010] In the above technical solution, brute - force cracking behavior is detected by monitoring the traffic of each service. When brute - force cracking behavior is detected, the currently obtained first login message is intercepted, and a response message indicating successful login of the first login message is forged and sent to the attacker, causing the attacker to misjudge. Moreover, the first login username and the first password of the first login message are recorded. The purpose is to quickly identify the malicious login behavior of the attacker when the attacker changes the IP and attempts to log in using the first login username and the first password. Therefore, the behavior of the attacker changing to other IP addresses for attack can be blocked as early as possible. Finally, the IP address of the attacker is recorded in the IP blacklist to prevent the attacker from continuing to perform cracking behavior.

[0011] In some alternative embodiments, the method further includes:

[0012] Obtain a second login message for the first service;

[0013] Determine whether the second login username and the second password of the second login message are the same as the first login username and the first password;

[0014] If so, identify the sender of the second login message as the attacker, record the IP address of the sender in the IP blacklist, and discard the second login message.

[0015] In the above technical solution, since when brute - force cracking behavior is detected, the first login username and the first password in the attacker's first login message are recorded, and a response message that makes the attacker think the login is successful is replied to the first login message. Therefore, if the attacker changes the IP address and attempts to log in using the first login username and the first password, it will be quickly identified by the security gateway, and thus the IP address currently used by the attacker will be recorded in the IP blacklist, quickly blocking the attacker's attack behavior.

[0016] In some alternative embodiments, for the first login message, forging a corresponding response message and sending it to the attacker includes:

[0017] Construct the layer - 2 header of the forged message. The destination MAC address of the forged message is the source MAC of the first login message, and the source MAC address of the forged message is the destination MAC of the first login message;

[0018] Construct the layer - 3 header of the forged message. The source IP address of the forged message is the IP address of the first service, the destination IP address of the forged message is the IP address of the attacker, and the protocol of the forged message is the TCP protocol;

[0019] Construct the TCP header of the forged packet. The source port number of the forged packet is the port number of the first service, the destination port number of the forged packet is the port number of the attacker, the seq of the forged packet is the ack of the login packet, and the ack of the forged packet is the seq of the login packet plus the length of the login packet;

[0020] The content of the application layer of the forged packet constructed is the content of successful login of the application layer protocol.

[0021] In the above technical solution, the forged response packet is sent to the attacker, making the attacker think that the brute force cracking is successful. Since the current IP address is recorded in the IP blacklist, the attacker is very likely to change the IP address and use the first login username and the first password obtained by mistakenly thinking that the brute force cracking is successful to try to log in. Therefore, subsequently, the security gateway only needs to monitor whether there is a behavior of trying to log in using the first login username and the first password, and then it can determine and identify the attack behavior of the attacker.

[0022] In some alternative embodiments, before recording the first login username and the first password in the first login packet, the method further includes:

[0023] Construct a service pseudo-account table, which is used to store the first login username and the first password, as well as the IP and port number of the first service.

[0024] In the above technical solution, in the service pseudo-account table, the key is the IP and port number of the attacked service, the value is the login username, password, and the timeout time of the table entry; if the attacker changes the IP address to try to log in, the malicious login behavior can be detected through the "service pseudo-account table", and at the same time, the user information security can be protected by disrupting the attacker's brute force cracking behavior.

[0025] In some alternative embodiments, after recording the attacker's IP address in the IP blacklist, the method further includes:

[0026] Record the behavior of recording the attacker's IP address in the IP blacklist into the alarm log.

[0027] In the above technical solution, recording the behavior of recording the attacker's IP address in the IP blacklist into the alarm log enables users or maintenance personnel to judge whether there is a false alarm of cracking behavior by querying the alarm log, or to manually unblock these IPs under the condition of ensuring information security.

[0028] A security gateway device provided by an embodiment of the present application, the device includes:

[0029] A monitoring module, configured to monitor the traffic of each service to identify cracking behavior;

[0030] The first interception module is used to perform the following steps when a cracking behavior against the first service is detected:

[0031] Obtain the first login message sent by the attacker corresponding to the cracking behavior, and intercept the first login message;

[0032] For the first login message, forge a corresponding response message and send it to the attacker;

[0033] Record the first login username and the first password in the first login message; and record the attacker's IP address in the IP blacklist, and discard the first login message.

[0034] In the above technical solution, the monitoring module is used to monitor the traffic of each service to detect brute-force cracking behavior. When brute-force cracking behavior is detected, the first interception module intercepts the currently obtained first login message and forges a response message indicating that the first login message has been successfully logged in, and sends the forged response message to the attacker to mislead the attacker. Also, the first login username and the first password of the first login message are recorded, aiming to quickly identify the attacker's malicious login behavior when the attacker changes the IP and tries to log in using the first login username and the first password. Therefore, the behavior of the attacker changing to other IP addresses for attack can be blocked as early as possible. Finally, the first interception module records the attacker's IP address in the IP blacklist to prevent the attacker from continuing to perform cracking behavior.

[0035] In some optional embodiments, the device further includes:

[0036] The second interception module is used to obtain the second login message for the first service;

[0037] Judge whether the second login username and the second password in the second login message are the same as the first login username and the first password;

[0038] If so, identify the sender of the second login message as the attacker, record the IP address of the sender in the IP blacklist, and discard the second login message.

[0039] In the above technical solution, since when brute-force cracking behavior is detected, the first login username and the first password in the attacker's first login message are recorded, and a response message that makes the attacker think that the login is successful is replied to the first login message. Therefore, if the attacker changes the IP address and tries to log in using the first login username and the first password, the second interception module can quickly identify the attacker's attack behavior, thereby recording the currently used IP address of the attacker in the IP blacklist and quickly blocking the attacker's attack behavior.

[0040] In some optional embodiments, the first interception module is further used to:

[0041] Construct the Layer 2 header of the forged packet. The destination MAC address of the forged packet is the source MAC of the first login packet, and the source MAC address of the forged packet is the destination MAC of the first login packet;

[0042] Construct the Layer 3 header of the forged packet. The source IP address of the forged packet is the IP address of the first service, the destination IP address of the forged packet is the attacker's IP address, and the protocol of the forged packet is the TCP protocol;

[0043] Construct the TCP header of the forged packet. The source port number of the forged packet is the port number of the first service, the destination port number of the forged packet is the attacker's port number, the seq of the forged packet is the ack of the login packet, and the ack of the forged packet is the seq of the login packet plus the length of the login packet;

[0044] Construct the application layer content of the forged packet as the content of successful login of the application layer protocol.

[0045] In the above technical solution, use the first interception module to send the forged response packet to the attacker, so that the attacker thinks that the brute force attack is successful. And because the current IP address is recorded in the IP blacklist, the attacker is very likely to change the IP address and try to log in using the first login username and the first password obtained by the supposed successful brute force attack. Thus, subsequently, the security gateway only needs to monitor whether there is a behavior of trying to log in using the first login username and the first password, and then it can determine and identify the attack behavior of the attacker.

[0046] In some alternative embodiments, the device further includes:

[0047] A table construction module, configured to construct a service pseudo-account table, which is used to store the first login username and the first password, as well as the IP and port number of the first service.

[0048] In the above technical solution, in the service pseudo-account table constructed by the table construction module, the key is the IP and port number of the attacked service, and the value is the login username, password, and the timeout time of the table entry; if the attacker changes the IP address and tries to log in, the malicious login behavior can be detected through the "service pseudo-account table", and at the same time, the user information security can be protected by disrupting the attacker's brute force attack behavior.

[0049] In some alternative embodiments, the device further includes:

[0050] An alarm log module, configured to record the behavior of recording the attacker's IP address in the IP blacklist to the alarm log.

[0051] In the above technical solution, the behavior of recording the IP address of the attacker into the IP blacklist by the alarm log module is recorded in the alarm log, so that users or maintenance personnel can judge whether there is a false alarm of cracking behavior by querying the alarm log, or manually lift the blockade of these IPs while ensuring information security.

[0052] An electronic device provided by an embodiment of the present application includes: a processor and a memory. The memory stores machine-readable instructions executable by the processor. When the machine-readable instructions are executed by the processor, the method described in any one of the above is executed.

[0053] A computer-readable storage medium provided by an embodiment of the present application has a computer program stored thereon. When the computer program is run by a processor, the method described in any one of the above is executed. Description of the Drawings

[0054] To more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required to be used in the embodiments of the present application will be briefly introduced below. It should be understood that the following drawings only show some embodiments of the present application, and therefore should not be regarded as limiting the scope. For those of ordinary skill in the art, other related drawings can be obtained based on these drawings without creative efforts.

[0055] Figure 1 It is a flowchart of the steps of an interception method for cracking behavior provided by an embodiment of the present application;

[0056] Figure 2 It is a flowchart of the steps of another interception method provided by an embodiment of the present application;

[0057] Figure 3 It is a functional module diagram of a security gateway device provided by an embodiment of the present application;

[0058] Figure 4 It shows a possible structure of the electronic device provided by an embodiment of the present application.

[0059] Icons: 1 - Monitoring module, 2 - First interception module, 3 - Second interception module, 4 - Table construction module, 5 - Alarm log module, 61 - Processor, 62 - Memory, 63 - Communication interface, 64 - Communication bus. Detailed Embodiments

[0060] Next, the technical solutions in the embodiments of the present application will be described in conjunction with the drawings in the embodiments of the present application.

[0061] Please refer to Figure 1 , Figure 1The flowchart of the steps of an interception method for cracking behavior provided by an embodiment of the present application is applied to a security gateway. The method includes:

[0062] Step 100: Monitor the traffic of each service (such as ftp / telnet / smtp, etc.) to identify cracking behavior. When detecting cracking behavior against the first service, execute the following steps 200-500:

[0063] Step 200: Obtain the first login packet sent by the attacker corresponding to the cracking behavior, and intercept the first login packet;

[0064] Step 300: Forge a corresponding response packet for the first login packet and send it to the attacker;

[0065] Step 400: Record the first login username and the first password in the first login packet; and

[0066] Step 500: Record the attacker's IP address in the IP blacklist and discard the first login packet.

[0067] In the embodiment of the present application, brute-force cracking behavior is detected by monitoring the traffic of each service. When detecting brute-force cracking behavior, the currently obtained first login packet is intercepted and a response packet indicating successful login of the first login packet is forged, and the forged response packet is sent to the attacker to mislead the attacker. In addition, the first login username and the first password of the first login packet are recorded, so as to quickly identify the malicious login behavior of the attacker when the attacker changes the IP and tries to log in using the first login username and the first password. Therefore, the behavior of the attacker to change to other IP addresses for attack can be blocked as early as possible. Finally, the attacker's IP address is recorded in the IP blacklist to prevent the attacker from continuing to perform cracking behavior.

[0068] In some optional embodiments, please refer to Figure 2 , Figure 2 The flowchart of the steps of another interception method provided by an embodiment of the present application. The method further includes:

[0069] Step 600: Obtain the second login packet for the first service;

[0070] Step 700: Determine whether the second login username and the second password in the second login packet are the same as the first login username and the first password; if so, enter step 800;

[0071] Step 800: Identify the sender of the second login packet as the attacker, record the IP address of the sender in the IP blacklist, and discard the second login packet.

[0072] In the embodiments of the present application, since when a brute-force cracking behavior is detected, the first login username and the first password in the attacker's first login message are recorded, and a response message that makes the attacker think that the login is successful is replied to the first login message. Therefore, if the attacker changes the IP address and tries to log in using the first login username and the first password, it will be quickly recognized by the security gateway, and thus the IP address currently used by the attacker will be recorded in the IP blacklist, quickly blocking the attacker's attack behavior.

[0073] In some alternative embodiments, before step 600, the traffic of the first service is also monitored to identify cracking behaviors.

[0074] If no cracking behavior against the first service is detected, then step 600 is executed to identify whether this login behavior is an attack behavior in which the attacker changes the IP address and uses the first login username and the first password.

[0075] If a cracking behavior against the first service is detected, then steps 200-500 are executed to record the current login username and password so that when the attacker changes the IP address and tries to log in, it can be identified.

[0076] In some alternative embodiments, for the first login message, forging a corresponding response message and sending it to the attacker includes:

[0077] Construct the data link layer header of the forged message. The destination MAC address of the forged message is the source MAC of the first login message, and the source MAC address of the forged message is the destination MAC of the first login message.

[0078] Construct the network layer header of the forged message. The source IP address of the forged message is the IP address of the first service, the destination IP address of the forged message is the IP address of the attacker, and the protocol of the forged message is the TCP protocol.

[0079] Construct the TCP header of the forged message. The source port number of the forged message is the port number of the first service, the destination port number of the forged message is the port number of the attacker, the seq of the forged message is the ack of the login message, and the ack of the forged message is the seq of the login message plus the length of the login message; where seq represents the offset of the data sent this time, ack represents the amount of data that has been received and replied, seq can prevent out-of-order, duplicate data, etc., and ack can reply to the received data, and the peer will send data from the offset position of ack next time to prevent data loss.

[0080] Construct the application layer content of the forged message as the content of successful login of the application layer protocol, such as the FTP protocol: 230 User logged in.

[0081] In the embodiments of the present application, a forged response message is sent to the attacker, causing the attacker to mistakenly believe that the brute-force attack is successful. Since the current IP address is recorded in the IP blacklist, the attacker is very likely to change the IP address and attempt to log in using the first login username and the first password obtained by mistakenly believing that the brute-force attack is successful. Thus, subsequently, the security gateway only needs to monitor whether there is an attempt to log in using the first login username and the first password to determine and identify the attack behavior of the attacker.

[0082] In some alternative embodiments, before recording the first login username and the first password in the first login message, the method further includes: constructing a service pseudo-account table for storing the first login username and the first password, as well as the IP and port number of the first service.

[0083] In the embodiments of the present application, in the service pseudo-account table, the key is the IP and port number of the attacked service, and the value is the login username, password, and the timeout time of the table entry. If the attacker changes the IP address and attempts to log in, malicious login behavior can be detected through the "service pseudo-account table", and at the same time, the user information security can be protected by disrupting the attacker's brute-force attack behavior.

[0084] In some alternative embodiments, after recording the attacker's IP address in the IP blacklist, the method further includes: recording the act of recording the attacker's IP address in the IP blacklist in the alarm log.

[0085] In the embodiments of the present application, recording the act of recording the attacker's IP address in the IP blacklist in the alarm log enables users or maintenance personnel to determine whether there is a false alarm of cracking behavior by querying the alarm log, or to manually unblock these IPs while ensuring information security.

[0086] Please refer to Figure 3 , Figure 3 which is a functional module diagram of a security gateway device provided by the embodiments of the present application. The device includes a monitoring module 1 and a first interception module 2.

[0087] Among them, the monitoring module 1 is used to monitor the traffic of each service to identify cracking behavior. The first interception module 2 is used to, when detecting cracking behavior against the first service, perform the following steps: obtain the first login message sent by the attacker corresponding to the cracking behavior and intercept the first login message; forge a corresponding response message for the first login message and send it to the attacker; record the first login username and the first password in the first login message; and record the attacker's IP address in the IP blacklist and discard the first login message.

[0088] In the embodiments of the present application, the monitoring module 1 is used to monitor the traffic of each service to detect brute-force cracking behavior. When brute-force cracking behavior is detected, the first interception module 2 intercepts the currently obtained first login message and forges a response message indicating that the first login message has been successfully logged in, and sends the forged response message to the attacker to mislead the attacker. Moreover, the first login username and the first password of the first login message are also recorded, aiming to quickly identify the malicious login behavior of the attacker when the attacker changes the IP and attempts to log in using the first login username and the first password. Therefore, the behavior of the attacker to attack by changing to other IP addresses can be blocked as early as possible. Finally, the first interception module 2 records the IP address of the attacker in the IP blacklist to prevent the attacker from continuing to perform cracking behavior.

[0089] In some alternative embodiments, the device further includes: a second interception module 3, configured to obtain a second login message for the first service; determine whether the second login username and the second password of the second login message are the same as the first login username and the first password; if so, identify the sender of the second login message as the attacker, record the IP address of the sender in the IP blacklist, and discard the second login message.

[0090] In the embodiments of the present application, since when brute-force cracking behavior is detected, the first login username and the first password in the first login message of the attacker are recorded, and a response message that makes the attacker think that the login is successful is replied to the first login message. Therefore, if the attacker changes the IP address and attempts to log in using the first login username and the first password, the second interception module 3 can quickly identify the attack behavior of the attacker, and thus record the currently used IP address of the attacker in the IP blacklist to quickly block the attack behavior of the attacker.

[0091] In some alternative embodiments, the first interception module 2 is further configured to: construct the layer 2 header of the forged message, the destination MAC address of the forged message is the source MAC of the first login message, and the source MAC address of the forged message is the destination MAC of the first login message; construct the layer 3 header of the forged message, the source IP address of the forged message is the IP address of the first service, the destination IP address of the forged message is the IP address of the attacker, and the protocol of the forged message is the TCP protocol; construct the TCP header of the forged message, the source port number of the forged message is the port number of the first service, the destination port number of the forged message is the port number of the attacker, the seq of the forged message is the ack of the login message, and the ack of the forged message is the seq of the login message plus the length of the login message; construct the application layer content of the forged message as the content indicating successful login of the application layer protocol.

[0092] In the embodiments of the present application, by using the first interception module 2, a forged response message is sent to the attacker, making the attacker think that the brute force attack is successful. Since the current IP address is recorded in the IP blacklist, it is very likely that the attacker will change the IP address and try to log in using the first login username and the first password obtained by the supposed successful brute force attack. Thus, subsequently, the security gateway only needs to monitor whether there is a behavior of trying to log in using the first login username and the first password, and then it can determine and identify the attack behavior of the attacker.

[0093] In some alternative embodiments, the device further includes: a table construction module 4, configured to construct a service pseudo-account table, which is used to store the first login username and the first password, as well as the IP and port number of the first service.

[0094] In the embodiments of the present application, in the service pseudo-account table constructed by the table construction module 4, the key is the IP and port number of the attacked service, and the value is the login username, password, and the timeout time of the table entry. If the attacker changes the IP address and tries to log in, the malicious login behavior can be detected through the "service pseudo-account table", and at the same time, the user information security can be protected by disrupting the attacker's brute force attack behavior.

[0095] In some alternative embodiments, the device further includes: an alarm log module 5, configured to record the behavior of recording the attacker's IP address in the IP blacklist into the alarm log.

[0096] In the embodiments of the present application, by using the alarm log module 5 to record the behavior of recording the attacker's IP address in the IP blacklist into the alarm log, the user or maintenance personnel can determine whether there is a false alarm of cracking behavior by querying the alarm log, or manually unblock these IPs while ensuring information security.

[0097] Figure 4 Shows a possible structure of the electronic device provided by the embodiments of the present application. Referring to Figure 4 , the electronic device includes: a processor 61, a memory 62, and a communication interface 63. These components are interconnected and communicate with each other through a communication bus 64 and / or other forms of connection mechanisms (not shown).

[0098] Among them, the memory 62 includes one or more (only one is shown in the figure), which can be, but is not limited to, random access memory (RAM), read only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), etc. The processor 61 and other possible components can access the memory 62, read and / or write the data therein.

[0099] The processor 61 includes one or more (only one is shown in the figure), which can be an integrated circuit chip with signal processing capabilities. The above-mentioned processor 61 can be a general-purpose processor, including a central processing unit (CPU), a microcontroller unit (MCU), a network processor (NP), or other conventional processors; it can also be a dedicated processor, including a neural-network processing unit (NPU), a graphics processing unit (GPU), a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components. Moreover, when there are multiple processors 61, a part of them can be general-purpose processors, and another part can be dedicated processors.

[0100] The communication interface 63 includes one or more (only one is shown in the figure), which can be used to communicate directly or indirectly with other devices for data interaction. The communication interface 63 can include interfaces for wired and / or wireless communication.

[0101] One or more computer program instructions can be stored in the memory 62, and the processor 61 can read and run these computer program instructions to implement the interception method provided by the embodiments of the present application.

[0102] It can be understood that Figure 4 The structure shown is only for illustration, and the electronic device may also include more or fewer components than those shown in Figure 4 or have a different structure from that shown in Figure 4 shown. Figure 4 Each component shown in can be implemented by hardware, software, or a combination thereof. The electronic device may be a physical device, such as a PC, a laptop, a tablet, a mobile phone, a server, an embedded device, etc., or may be a virtual device, such as a virtual machine, a virtualized container, etc. Moreover, the electronic device is not limited to a single device, and may also be a combination of multiple devices or a cluster composed of a large number of devices.

[0103] The embodiments of the present application also provide a computer-readable storage medium. When the computer program instructions stored on the computer-readable storage medium are read and run by a processor of a computer, the interception method provided by the embodiments of the present application is executed. For example, the computer-readable storage medium can be implemented as Figure 4 the memory 62 in the electronic device shown in.

[0104] In the embodiments provided by the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. The device embodiments described above are only illustrative. For example, the division of the units is only a logical function division, and there may be other division methods in actual implementation. For another example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the couplings or direct couplings or communication connections shown or discussed with each other can be through some communication interfaces, and the indirect couplings or communication connections of the devices or units can be in electrical, mechanical, or other forms.

[0105] In addition, the units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0106] Furthermore, in each embodiment of the present application, the functional modules can be integrated together to form an independent part, or each module can exist alone, or two or more modules can be integrated to form an independent part.

[0107] In this document, relational terms such as first and second are used solely to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations.

[0108] The above description is only for the embodiments of this application and is not intended to limit the protection scope of this application. For those skilled in the art, this application can have various modifications and changes. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of this application shall be included within the protection scope of this application.

Claims

1. An interception method for cracking behavior, characterized in that, applied to a security gateway, the method includes: Monitoring the traffic of each service to identify cracking behavior. When detecting cracking behavior against the first service, perform the following steps: Obtain the first login packet sent by the attacker corresponding to the cracking behavior and intercept the first login packet; For the first login packet, forge a corresponding response packet and send it to the attacker; Record the first login username and the first password in the first login packet; and Record the IP address of the attacker in the IP blacklist and discard the first login packet; It further includes: Obtain the second login packet for the first service; Determine whether the second login username and the second password in the second login packet are the same as the first login username and the first password; If so, identify the sender of the second login packet as the attacker, record the IP address of the sender in the IP blacklist, and discard the second login packet.

2. The method according to claim 1, characterized in that, For the first login packet, forging a corresponding response packet and sending it to the attacker includes: Construct the second-layer header of the forged packet, the destination MAC address of the forged packet is the source MAC of the first login packet, and the source MAC address of the forged packet is the destination MAC of the first login packet; Construct the third-layer header of the forged packet, the source IP address of the forged packet is the IP address of the first service, the destination IP address of the forged packet is the IP address of the attacker, and the protocol of the forged packet is the TCP protocol; Construct the TCP header of the forged packet, the source port number of the forged packet is the port number of the first service, the destination port number of the forged packet is the port number of the attacker, the SEQ of the forged packet is the ACK of the login packet, and the ACK of the forged packet is the SEQ of the login packet plus the length of the login packet; Construct the application layer content of the forged packet as the content of successful login of the application layer protocol.

3. The method according to claim 1, characterized in that, Before recording the first login username and the first password in the first login packet, the method further includes: Construct a service pseudo-account table, which is used to store the first login username and the first password, as well as the IP and port number of the first service.

4. The method according to claim 1, characterized in that, After recording the IP address of the attacker in the IP blacklist, the method further includes: Record the behavior of recording the IP address of the attacker in the IP blacklist in the alarm log.

5. A security gateway device, characterized in that, The device includes: A monitoring module for monitoring the traffic of each service to identify cracking behavior; A first interception module for, when detecting cracking behavior against the first service, performing the following steps: Obtain the first login packet sent by the attacker corresponding to the cracking behavior and intercept the first login packet; For the first login packet, forge a corresponding response packet and send it to the attacker; Record the first login username and the first password in the first login packet; and Record the IP address of the attacker in the IP blacklist and discard the first login packet; The device further includes: A second interception module, configured to obtain a second login message for a first service; Determine whether the second login username and second password in the second login message are the same as the first login username and first password; If so, identify the sender of the second login message as an attacker, record the IP address of the sender in the IP blacklist, and discard the second login message.

6. The apparatus according to claim 5, wherein, The first interception module is further configured to: Construct a two-layer header of a forged message, where the destination MAC address of the forged message is the source MAC of the first login message, and the source MAC address of the forged message is the destination MAC of the first login message; Construct a three-layer header of the forged message, where the source IP address of the forged message is the IP address of the first service, the destination IP address of the forged message is the IP address of the attacker, and the protocol of the forged message is the TCP protocol; Construct a TCP header of the forged message, where the source port number of the forged message is the port number of the first service, the destination port number of the forged message is the port number of the attacker, the SEQ of the forged message is the ACK of the login message, and the ACK of the forged message is the SEQ of the login message plus the length of the login message; Construct the application layer content of the forged message as the content indicating successful login of the application layer protocol.

7. The apparatus according to claim 5, wherein, The apparatus further includes: A table construction module, configured to construct a service pseudo-account table, where the service pseudo-account table is used to store the first login username and first password, as well as the IP and port number of the first service.

8. A computer-readable storage medium, wherein, A computer program is stored on the storage medium, and when the computer program is run by a processor, it executes the method according to any one of claims 1-4.

Citation Information

Patent Citations

  • Security defense method for Web server

    CN109347794A

  • Malicious user interception method and system

    CN111723361A