An integrated border security protection system and method based on trusted access
By introducing trusted access authentication modules and integrated boundary security protection equipment into the boundary protection system, the linkage between network boundary security, service access security and data content security is achieved, the problem of passive protection of existing boundary protection equipment is solved, and a more comprehensive and reliable edge protection system is provided.
Patent Information
- Application Number
- CN202211048820.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-08-30
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2042-08-30
AI Technical Summary
The existing border protection equipment has the problem of passive protection, and it is difficult to link the functions of edge secure access, strong access control, active defense, security behavior monitoring, content auditing, etc. to form an integrated edge protection system.
It adopts an integrated boundary security protection system based on trusted access, including an integrated boundary security protection device deployed at the network edge of the service bearer network, and a trusted access authentication module installed on the service terminal or server in the bearer network. This system provides network layer boundary security, service access security, data content security check and full protocol monitoring by integrating different access processing of data and business types.
It effectively guarantees the credibility and business compliance of entities across network boundaries, solves the problem of passive protection of boundary protection equipment, and provides integrated security protection methods, which are suitable for different business network boundaries.
Smart Images

Figure CN115426158B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of communication technology, and in particular relates to an integrated border security protection system and method based on trusted access. Background Art
[0002] As part of the overall protection of information security, network security undertakes the overall protection of the information transmission network environment, including network penetration, Trojan attacks, DDOS attacks, abnormal access, data-in-the-middle attacks, data theft and other security risks. Border security protection is the last access protection of network security. Its security is directly related to the possibility of external attacks in a business network, as well as the security of how the business network communicates with external businesses. How to ensure the security and reliability of business intercommunication between different networks requires border security protection equipment to provide reliable, secure and auditable services. At present, commercial border protection equipment mainly includes firewalls, IPS, IDS, network gates and other equipment. Such equipment has its limitations and the combination of multiple devices. How to link edge security access, strong access control, active defense, security behavior monitoring, content auditing and other functions to form an edge protection system, so it is necessary to propose an integrated border security protection system and method based on trusted access. Summary of the invention
[0003] In view of the above-mentioned deficiencies in the prior art, the present invention provides an integrated border security protection system and method based on trusted access, which solves the problem of passive protection of network border protection equipment.
[0004] In order to achieve the above purpose, the technical solution adopted by the present invention is:
[0005] This solution provides an integrated border security protection system based on trusted access, including an integrated border security protection device deployed on the network edge of the service bearer network, and a trusted access authentication module installed on the service terminal or server in the bearer network;
[0006] The integrated border security protection device is used to protect network layer border security, protect business access security, check data content security and provide full protocol monitoring;
[0007] The trusted access authentication module is used to provide trusted authentication services, data content and protocol layer marking services, business access functions, and host security baseline inspection services to the integrated border security protection device.
[0008] The beneficial effects of the present invention are as follows: the present invention effectively ensures the trustworthiness of entities crossing network boundaries and business compliance by integrating heterogeneous processing of network boundary security devices when different data classes and business classes are accessed, and solves the passive protection of network boundary protection devices; the present invention can be applied to different business network boundaries to provide integrated security protection measures.
[0009] Furthermore, the integrated border security protection device includes:
[0010] The network layer boundary security protection module is used to protect the network transmission layer, penetration and virus attacks, protocol strategies and trusted access respectively;
[0011] The business model module is used to provide security protection functions for business access, as well as protocol isolation, protocol stripping and mandatory access control services, including mandatory access control, transmission proxy and transparent service functions;
[0012] Data boundary protection module, used to provide data content security inspection services, including data category labeling, data labeling inspection, data content verification and data content auditing functions;
[0013] The business boundary protection module is used to provide full protocol monitoring of the business access process, including business protocol inspection, protocol tag inspection, protocol behavior verification and protocol behavior auditing functions;
[0014] The security audit module is used to provide network layer security audit, data security audit, business security audit and management behavior audit services, including boundary security audit function.
[0015] The beneficial effect of the above further scheme is that the integrated border security protection equipment comprehensively considers network border access security, data security, transmission protocol security and attack protection, and links border security access, strong access control, active defense, security behavior detection and content auditing to solve the limitations of existing border protection equipment.
[0016] Furthermore, the trusted access authentication module includes:
[0017] A trusted authentication submodule is used to provide trusted authentication services to the integrated border security protection device;
[0018] The data tagging submodule is used to provide data content tagging services and support the security measures of the integrated border security protection equipment;
[0019] Access control binding submodule, which is used to provide protocol layer tagging services and support the security measures of integrated border security protection equipment;
[0020] The data transfer agent submodule is used to provide business access functions that safely cross network boundaries;
[0021] The main body security verification submodule is used to provide host security baseline inspection services and provide security measures for the terminal's main body security.
[0022] The beneficial effects of the above further scheme are: the trusted access authentication module provides a means of subject security inspection, which combined with trusted authentication can improve the security of business interaction; the data marking, access control binding and data transmission modules cooperate with the various functional modules of the integrated border security protection equipment to perform security checks, supporting the integrated border security protection system functions.
[0023] The present invention also provides an integrated border security protection method based on trusted access, comprising the following steps:
[0024] S1. Install a trusted access authentication module on the terminal or server in the bearer network, and use the trusted access authentication module to scan the terminal's subject security verification and check the security baseline;
[0025] S2. Based on the inspection result, the integrated border security protection device is authenticated to generate a unique identity identifier of the terminal, and the identifier is used as a trusted authentication code to penetrate the integrated border security protection device;
[0026] S3. After the integrated border security protection device completes the trusted access authentication on the terminal or server, the trusted information of the terminal or server is generated inside the integrated border security protection device;
[0027] S4. Based on the trusted information, when a terminal or server in the bearer network penetrates the network boundary to access, the trusted access authentication module obtains the type of access;
[0028] S5. When performing data access, obtain the file tag of the data file, intercept it through the data transmission proxy submodule, and use the proxy method to transmit data to the integrated border security protection device. During the transmission process, the trusted authentication code and file tag generated during terminal authentication are added to each message. When the integrated border security protection device receives the data access from the terminal or server, it performs a security check to complete the integrated border security protection;
[0029] S6. When making business-type access, obtain the business type of the business-type access, intercept the business protocol through the access control binding submodule, and use the tunnel to transmit data to the integrated border security protection device. During the transmission process, the trusted authentication code and file mark generated during terminal authentication are added to each message. When the integrated border security protection device receives the business-type access from the terminal or server, it performs a security check to complete the integrated border security protection.
[0030] The beneficial effects of the present invention are as follows: the present invention designs an effective security linkage mechanism from the perspectives of network boundary access security, data security, transmission protocol security, attack protection, etc., to form a security linkage means with trusted access, traceable data, visible protocols, controllable policies, and preventable attacks, and provides heterogeneous security access services at both the data and business levels, ensuring that no external security risks are introduced when business linkage is carried out within the network and externally, and providing effective boundary security protection services.
[0031] Furthermore, the step S5 comprises the following steps:
[0032] S501, when performing data access, the trusted access authentication module obtains the file tag of the data file;
[0033] S502, intercepting data type access data through the data transmission proxy submodule of the trusted access authentication module;
[0034] S503, adding a trusted authentication code and a file identifier to each message in the intercepted data through a trusted access authentication module;
[0035] S504, after the integrated border security protection device receives data access from the terminal or server, the basic network protocol is protected;
[0036] S505, monitor penetration and virus attack behaviors;
[0037] S506, protecting whether the data access behavior is a credible transmission protocol;
[0038] S507, judging whether the access end is a trusted authentication end, protecting against non-compliant business access, and taking the subject's trustworthiness as a prerequisite for business access;
[0039] S508, intercepting the data file content accessed by the data class through the data transmission agent submodule, and verifying the completeness of the transmitted data file;
[0040] S509, perform tag detection on the data file, and determine whether the data file complies with the tag security policy according to the tag detection result. If so, proceed to step S510; otherwise, discard the data file, perform boundary behavior audit record, and proceed to step S511;
[0041] S510, detecting the content of the data file, and judging whether the content of the data file has abnormal content according to the detection result, if yes, proceeding to step S511, otherwise, proceeding to step S511;
[0042] S511. Audit the contents of statistical data files to complete integrated border security protection.
[0043] The beneficial effect of the above further scheme is: based on the above steps, data content security inspection services such as data marking, data inspection, and data content verification can be provided for data-related services, which can ensure the security of data content transmitted at the network boundary.
[0044] Furthermore, step S6 includes the following steps:
[0045] S601, when performing a business access, obtaining a business type of the business access;
[0046] S602, intercepting the business protocol through the access control binding submodule;
[0047] S603, encapsulating a tunnel for the service data, and adding a trusted authentication code and a file mark generated during terminal authentication to each message;
[0048] S604, when the integrated border security protection device receives a service access from a terminal or a server, the basic network protocol is protected;
[0049] S605, monitor penetration and virus attack behaviors;
[0050] S606, protecting whether the business access behavior is a trusted transmission protocol;
[0051] S607, judging whether the access end is a trusted authentication end, protecting against non-compliant business access, and taking the subject's trustworthiness as a prerequisite for business access;
[0052] S608. Implement the network transmission protocol through the transparent service function in the business model;
[0053] S609, perform an upper layer protocol format check on the application layer protocol, and determine whether the application layer protocol of this type of service meets the conditions during transmission based on the check result, block and audit abnormal application layer protocols, and notify the abnormal application layer protocol to the network layer boundary security protection module for protocol policy protection;
[0054] S610, checking the application layer protocol tags, discarding abnormal application layer protocol tags, and auditing boundary behaviors;
[0055] S611. Check the application layer protocol behavior, determine the service access behavior, and conduct an audit;
[0056] S612. Collect audits of border behaviors and complete integrated border security protection.
[0057] The beneficial effect of the above further scheme is: it provides protocol inspection, protocol tag inspection, protocol behavior verification, protocol behavior audit and other service access process authorization protocol monitoring functions for business data, which can ensure the security of network boundary transmission protocols. BRIEF DESCRIPTION OF THE DRAWINGS
[0058] Figure 1 This is a schematic diagram of the system deployment network of the present invention.
[0059] Figure 2 It is a schematic diagram of the functional component modules of the integrated border security protection equipment in the present invention.
[0060] Figure 3 It is a schematic diagram of the composition of the trusted access authentication module in the present invention.
[0061] Figure 4 The figure is a flow chart of the method of the present invention.
[0062] Figure 5 The figure is a schematic diagram of the data class access boundary security protection process in the present invention.
[0063] Figure 6 It is a schematic diagram of the business class access boundary security protection process in the present invention. DETAILED DESCRIPTION
[0064] The specific implementation modes of the present invention are described below so that those skilled in the art can understand the present invention. However, it should be clear that the present invention is not limited to the scope of the specific implementation modes. For those of ordinary skill in the art, as long as various changes are within the spirit and scope of the present invention as defined and determined by the attached claims, these changes are obvious, and all inventions and creations utilizing the concept of the present invention are protected.
[0065] Example 1
[0066] When a business network is constructed and planned, it is "secure" from the beginning of design and construction. The introduction of security risks is mainly caused by the access of external businesses and the introduction of external networks. Figure 1 As shown, the present invention provides an integrated border security protection system based on trusted access, including an integrated border security protection device deployed on the network edge of a service bearer network, and a trusted access authentication module installed on a service terminal or server in the bearer network;
[0067] The integrated border security protection device is used to protect network layer border security, protect business access security, check data content security and provide full protocol monitoring;
[0068] The trusted access authentication module is used to provide trusted authentication services, data content and protocol layer marking services, business access functions, and host security baseline inspection services to the integrated border security protection device.
[0069] In this embodiment, the integrated border security protection device includes:
[0070] The network layer boundary security protection module is used to protect the network transmission layer, penetration and virus attacks, protocol strategies and trusted access respectively;
[0071] The business model module is used to provide security protection functions for business access, as well as protocol isolation, protocol stripping and mandatory access control services, including mandatory access control, transmission proxy and transparent service functions;
[0072] Data boundary protection module, used to provide data content security inspection services, including data category labeling, data labeling inspection, data content verification and data content auditing functions;
[0073] The business boundary protection module is used to provide full protocol monitoring of the business access process, including business protocol inspection, protocol tag inspection, protocol behavior verification and protocol behavior auditing functions;
[0074] The security audit module is used to provide network layer security audit, data security audit, business security audit and management behavior audit services, including boundary security audit function.
[0075] In this embodiment, Figure 2As shown, the functional components of the integrated border security protection equipment mainly include: network layer border security protection module, business model module, data type border protection module, business class border protection module and security audit module. The specific functions are decomposed as follows: Network layer border security protection module: including network transmission layer protection, penetration and virus attack protection, protocol policy protection and trusted access protection functions; Business model module: including forced access control, transmission agent and transparent service functions, which mainly provides security protection functions for business access, and provides protocol isolation, protocol stripping and mandatory access control services; Data class border protection module: including data class tag, data tag check, data content verification and data content audit functions, providing data content security check services to ensure the security of data content transmitted at the network boundary; Business class border protection module: including business class protocol check, protocol tag check, protocol behavior verification and protocol behavior audit functions, providing full protocol monitoring of the business access process to ensure the security of network boundary transmission protocols; Security audit module: including border security audit functions, providing network layer security audit, data class security audit, business class security audit and management behavior audit services.
[0076] In this embodiment, the trusted access authentication module includes:
[0077] A trusted authentication submodule is used to provide trusted authentication services to the integrated border security protection device;
[0078] The data tagging submodule is used to provide data content tagging services and support the security measures of the integrated border security protection equipment;
[0079] Access control binding submodule, which is used to provide protocol layer tagging services and support the security measures of integrated border security protection equipment;
[0080] The data transfer agent submodule is used to provide business access functions that safely cross network boundaries;
[0081] The main body security verification submodule is used to provide host security baseline inspection services and provide security measures for the terminal's main body security.
[0082] In this embodiment, Figure 3As shown, the functional components of the trusted access authentication module mainly include: trusted authentication submodule, data marking submodule, access control binding submodule, data transmission agent submodule and subject security verification module. The specific functions are decomposed as follows: trusted authentication submodule: provides trusted authentication services to the integrated security boundary protection device. Only terminals or servers that are authenticated to the integrated security boundary protection device can have secure business interactive access with the integrated boundary security protection device and "safely cross" the network boundary; data marking submodule: provides data content marking services to support the integrated security boundary protection device to perform data inspection, content verification and other security measures; access control binding submodule: provides protocol layer marking services to support the integrated security boundary protection device to perform protocol security verification and protocol policy inspection and other security measures; data transmission agent submodule: provides business access functions for "safely crossing" the network boundary; subject security verification submodule: provides host security baseline inspection services to provide security means for the terminal's subject security.
[0083] The present invention integrates heterogeneous processing of network boundary security devices when different data and business types are accessed, effectively ensuring the trustworthiness of entities crossing network boundaries and business compliance, and solving the passive protection of network boundary protection devices; the present invention can be applied to different business network boundaries to provide an integrated security protection method.
[0084] Example 2
[0085] like Figure 4 As shown, the present invention provides an integrated border security protection method based on trusted access, and its implementation method is as follows:
[0086] S1. Install a trusted access authentication module on the terminal or server in the bearer network, and use the trusted access authentication module to scan the terminal's subject security verification and check the security baseline;
[0087] In this embodiment, a trusted access authentication module is installed on a terminal or server within the bearer network. The authentication module performs a subject security verification scan, specifically including: whether a firewall is installed, the firewall version, whether the firewall is started, the current operating system version, system patches, whether there is a user identity authentication module and other security measures for scoring. If the security baseline does not comply with the rules, no authentication service will be provided. If the security baseline complies with the rules, the software will operate normally.
[0088] S2. Based on the inspection result, the integrated border security protection device is authenticated to generate a unique identity identifier of the terminal, and the identifier is used as a trusted authentication code to penetrate the integrated border security protection device;
[0089] In this embodiment, after the security baseline check of the trusted access authentication module, a trusted authentication is performed to the integrated security boundary protection device, and a unique identity identifier of the terminal is generated through negotiation. The identifier is used to "penetrate" the trusted authentication code of the integrated boundary security protection device.
[0090] S3. After the integrated border security protection device completes the trusted access authentication on the terminal or server, the trusted information of the terminal or server is generated inside the integrated border security protection device;
[0091] In this embodiment, after the terminal or server completes the trusted access authentication process, the integrated border security protection device generates trusted information of the terminal or server inside the device.
[0092] S4. Based on the trusted information, when a terminal or server in the bearer network penetrates the network boundary to access, the trusted access authentication module obtains the type of access;
[0093] In this embodiment, when a terminal or server in the bearer network "penetrates" the network boundary to access, a trusted access authentication module installed on the terminal or server transparently obtains the type of access, whether it is service access or data access.
[0094] S5. When performing data access, obtain the file tag of the data file, intercept it through the data transmission agent submodule, and use the agent to transmit data to the integrated border security protection device. During the transmission process, the trusted authentication code and file tag generated during terminal authentication are added to each message. When the integrated border security protection device receives the data access from the terminal or server, it performs a security check to complete the integrated border security protection. The implementation method is as follows:
[0095] S501, when performing data access, the trusted access authentication module obtains the file tag of the data file;
[0096] S502, intercepting data type access data through the data transmission proxy submodule of the trusted access authentication module;
[0097] S503, adding a trusted authentication code and a file identifier to each message in the intercepted data through a trusted access authentication module;
[0098] S504, after the integrated border security protection device receives data access from the terminal or server, the basic network protocol is protected;
[0099] S505, monitor penetration and virus attack behaviors;
[0100] S506, protecting whether the data access behavior is a credible transmission protocol;
[0101] S507, judging whether the access end is a trusted authentication end, protecting against non-compliant business access, and taking the subject's trustworthiness as a prerequisite for business access;
[0102] S508, intercepting the data file content accessed by the data class through the data transmission agent submodule, and verifying the completeness of the transmitted data file;
[0103] S509, perform tag detection on the data file, and determine whether the data file complies with the tag security policy according to the tag detection result. If so, proceed to step S510; otherwise, discard the data file, perform boundary behavior audit record, and proceed to step S511;
[0104] S510, detecting the content of the data file, and judging whether the content of the data file has abnormal content according to the detection result, if yes, proceeding to step S511, otherwise, proceeding to step S511;
[0105] S511. Audit the contents of statistical data files to complete integrated border security protection.
[0106] In this embodiment, when data access is performed, the file mark of the data file is first obtained, such as confidential, internal, public, non-confidential, or unmarked, and then the data is intercepted through the data transmission agent module, and the data is transmitted to the integrated border security protection device in an agent manner, and the trusted authentication code and file mark generated during the terminal authentication are added to each message during the transmission process.
[0107] In this embodiment, Figure 5 As shown in the figure, when the integrated border security protection device receives data access from the terminal or server, it performs security checks through various security function modules. The internal steps of the device are as follows:
[0108] Perform basic network protocol protection, including DDOS monitoring, port traversal detection, vulnerability scanning, etc. of the basic network; monitor penetration and virus attack behaviors, and protect against middleman data smuggling, transmission protocol middleman heterogeneity, virus enhancement, and active attack control during transmission; control transmission protocol policies to protect whether the access behavior is a trusted transmission protocol. Only specific transmission protocols and application layer protocols can be used for business access, minimizing the limit on protocol private settings for unexpected penetration and attacks; determine whether the access end is a trusted authentication end, protect against non-compliant business access, and take subject trust as a prerequisite for business access; through the data transmission agent module, the data accessed by the data class The file content is completely implemented and the completion of the transferred file is verified. After the transferred file is implemented, a file tag check is performed and checked according to the file tag security policy. If the transferred file tag complies with the tag security policy, subsequent processing is performed. If the transferred file tag does not comply with the tag security policy, it is discarded and audit records are made. After the file tag check, a data file content check is performed to check whether the file content contains abnormal content such as data entity inclusion and virus infection, and audit statistics are performed. Then, file content audit statistics are performed to audit the file name, file size, transmission time, transmission subject, receiving subject and other information to provide audit data elements for the administrator. Then, audit statistics are performed.
[0109] S6. When performing business class access, obtain the business type of the business class access, and intercept the business protocol through the access control binding submodule, and use the tunnel to transmit data to the integrated border security protection device, and add the trusted authentication code and file mark generated during the terminal authentication to each message during the transmission process. When the integrated border security protection device receives the business class access from the terminal or server, it performs a security check to complete the integrated border security protection. The implementation method is as follows:
[0110] S601, when performing a business access, obtaining a business type of the business access;
[0111] S602, intercepting the business protocol through the access control binding submodule;
[0112] S603, encapsulating a tunnel for the service data, and adding a trusted authentication code and a file mark generated during terminal authentication to each message;
[0113] S604, when the integrated border security protection device receives a service access from a terminal or a server, the basic network protocol is protected;
[0114] S605, monitor penetration and virus attack behaviors;
[0115] S606, protecting whether the business access behavior is a trusted transmission protocol;
[0116] S607, judging whether the access end is a trusted authentication end, protecting against non-compliant business access, and taking the subject's trustworthiness as a prerequisite for business access;
[0117] S608. Implement the network transmission protocol through the transparent service function in the business model;
[0118] S609, perform an upper layer protocol format check on the application layer protocol, and determine whether the application layer protocol of this type of service meets the conditions during transmission based on the check result, block and audit abnormal application layer protocols, and notify the abnormal application layer protocol to the network layer boundary security protection module for protocol policy protection;
[0119] S610, checking the application layer protocol tags, discarding abnormal application layer protocol tags, and auditing boundary behaviors;
[0120] S611. Check the application layer protocol behavior, determine the service access behavior, and conduct an audit;
[0121] S612. Collect audits of border behaviors and complete integrated border security protection.
[0122] In this embodiment, when a service access is performed, the service type of the service access is first obtained, such as email service, instant messaging service, web service, etc., and then the service protocol is intercepted by accessing the access control binding submodule in the trusted access authentication software, and the tunnel is used to transmit data to the integrated border security protection device, and the trusted authentication code and file mark generated during the terminal authentication are added to each message during the transmission process. Figure 6 As shown in the figure, when the integrated border security protection device receives a business access from a terminal or server, it performs a security check through each security function module. The steps inside the device are as follows:
[0123] Perform basic network protocol protection, including DDOS monitoring, port traversal detection, vulnerability scanning, etc. of the basic network; monitor penetration and virus attack behaviors, and protect against middleman data smuggling, transmission protocol middleman heterogeneity, virus enhancement, and active attack control during transmission; control transmission protocol policies to protect whether the access behavior is a trusted transmission protocol. Only specific transmission protocols and application layer protocols can be used for business access, minimizing the limit on protocol private settings for unexpected penetration and attacks; determine whether the access end is a trusted authentication end, protect against non-compliant business access, and take subject trust as a prerequisite for business access; implement network transmission protocols through transparent service modules, including Including the implementation of IP layer protocol and TCP\UDP layer protocol; after the transmission protocol is implemented, the upper layer protocol format of the application layer protocol is checked to determine whether the application layer protocol of this type of business meets the requirements during the transmission process, and abnormal application protocols are blocked and audited, and abnormal protocols are notified to the protocol policy protection module; after the application layer protocol format check, the protocol tag is checked again, and abnormal application tags are discarded and audited; after the protocol layer inspection, the protocol behavior is analyzed to determine the access behavior of the business, and the behavior review is conducted, including downloading, uploading, obtaining and other actions. Compliant behaviors can be released, abnormal behaviors are blocked and audited; finally, a unified process audit is collected.
[0124] Through the above design, the present invention proposes an integrated border security protection method based on trusted access. The method designs an effective security linkage mechanism from the perspectives of network border access security, data security, transmission protocol security, attack protection, etc., forming a security linkage means with trusted access, traceable data, visible protocols, controllable policies, and preventable attacks, and provides heterogeneous security access services at both the data and business levels, ensuring that no external security risks are introduced when the network is linked to the outside world. Provide effective border security protection services.
Claims
1. An integrated border security protection system based on trusted access, characterized in that: It includes integrated border security protection equipment deployed on the network edge of the service bearer network, and trusted access authentication modules installed on service terminals or servers within the bearer network; The integrated border security protection device is used to protect network layer border security, protect business access security, check data content security and provide full protocol monitoring; The trusted access authentication module is used to provide trusted authentication services, data content and protocol layer marking services, business access functions and host security baseline inspection services to the integrated border security protection device. The implementation method is as follows: Install a trusted access authentication module on the terminal or server in the bearer network, and use the trusted access authentication module to scan the terminal's subject security verification and check the security baseline; Based on the inspection results, the integrated border security protection device is authenticated to generate a unique identity of the terminal, and the identity is used as a trusted authentication code to penetrate the integrated border security protection device; After the integrated border security protection device completes the trusted access authentication on the terminal or server, the trusted information of the terminal or server is generated inside the integrated border security protection device; Based on the trusted information, when a terminal or server in the bearer network penetrates the network boundary to access, the trusted access authentication module obtains the type of access; When performing data access, the file tag of the data file is obtained, and the data transmission agent submodule is used to intercept it, and the data is transmitted to the integrated border security protection device in an agent manner. During the transmission process, the trusted authentication code and file tag generated during terminal authentication are added to each message. When the integrated border security protection device receives the data access from the terminal or server, it performs a security check to complete the integrated border security protection; When making business-type access, the business type of the business-type access is obtained, and the business protocol is intercepted through the access control binding sub-module, and the data is transmitted to the integrated border security protection device through a tunnel. During the transmission process, the trusted authentication code and file mark generated during terminal authentication are added to each message. When the integrated border security protection device receives the business-type access from the terminal or server, it performs a security check to complete the integrated border security protection.
2. The integrated border security protection system based on trusted access according to claim 1 is characterized in that: The integrated border security protection equipment includes: The network layer boundary security protection module is used to protect the network transmission layer, penetration and virus attacks, protocol strategies and trusted access respectively; The business model module is used to provide security protection functions for business access, as well as protocol isolation, protocol stripping and mandatory access control services, including mandatory access control, transmission proxy and transparent service functions; Data boundary protection module, used to provide data content security inspection services, including data category labeling, data labeling inspection, data content verification and data content auditing functions; The business boundary protection module is used to provide full protocol monitoring of the business access process, including business protocol inspection, protocol tag inspection, protocol behavior verification and protocol behavior auditing functions; The security audit module is used to provide network layer security audit, data security audit, business security audit and management behavior audit services, including boundary security audit function.
3. The integrated border security protection system based on trusted access according to claim 2 is characterized in that: The trusted access authentication module includes: A trusted authentication submodule is used to provide trusted authentication services to the integrated border security protection device; The data tagging submodule is used to provide data content tagging services and support the security measures of the integrated border security protection equipment; Access control binding submodule, which is used to provide protocol layer tagging services and support the security measures of integrated border security protection equipment; The data transfer agent submodule is used to provide business access functions that safely cross network boundaries; The main body security verification submodule is used to provide host security baseline inspection services and provide security measures for the terminal's main body security.
4. The integrated border security protection method of the integrated border security protection system based on trusted access according to any one of claims 1 to 3, characterized in that: The following steps are involved: S1. Install a trusted access authentication module on the terminal or server in the bearer network, and use the trusted access authentication module to scan the terminal's subject security verification and check the security baseline; S2. Based on the inspection result, the integrated border security protection device is authenticated to generate a unique identity identifier of the terminal, and the identifier is used as a trusted authentication code to penetrate the integrated border security protection device; S3. After the integrated border security protection device completes the trusted access authentication on the terminal or server, the trusted information of the terminal or server is generated inside the integrated border security protection device; S4. Based on the trusted information, when a terminal or server in the bearer network penetrates the network boundary to access, the trusted access authentication module obtains the type of access; S5. When performing data access, obtain the file tag of the data file, intercept it through the data transmission proxy submodule, and use the proxy method to transmit data to the integrated border security protection device. During the transmission process, the trusted authentication code and file tag generated during terminal authentication are added to each message. When the integrated border security protection device receives the data access from the terminal or server, it performs a security check to complete the integrated border security protection; S6. When making business-type access, obtain the business type of the business-type access, intercept the business protocol through the access control binding submodule, and use the tunnel to transmit data to the integrated border security protection device. During the transmission process, the trusted authentication code and file mark generated during terminal authentication are added to each message. When the integrated border security protection device receives the business-type access from the terminal or server, it performs a security check to complete the integrated border security protection.
5. The integrated border security protection method according to claim 4, characterized in that: The step S5 comprises the following steps: S501, when performing data access, the trusted access authentication module obtains the file tag of the data file; S502, intercepting data type access data through the data transmission proxy submodule of the trusted access authentication module; S503, adding a trusted authentication code and a file identifier to each message in the intercepted data through a trusted access authentication module; S504, after the integrated border security protection device receives data access from the terminal or server, the basic network protocol is protected; S505, monitor penetration and virus attack behaviors; S506, protecting whether the data access behavior is a credible transmission protocol; S507, judging whether the access end is a trusted authentication end, protecting against non-compliant business access, and taking the subject's trustworthiness as a prerequisite for business access; S508, intercepting the data file content accessed by the data class through the data transmission agent submodule, and verifying the completeness of the transmitted data file; S509, perform tag detection on the data file, and determine whether the data file complies with the tag security policy according to the tag detection result. If so, proceed to step S510; otherwise, discard the data file, perform boundary behavior audit record, and proceed to step S511; S510, detecting the content of the data file, and if there is abnormal content in the data file according to the detection result, performing file content audit statistics, and proceeding to step S11; S511. Audit the contents of statistical data files to complete integrated border security protection.
6. The integrated border security protection method according to claim 5, characterized in that: The step S6 comprises the following steps: S601, when performing a business access, obtaining a business type of the business access; S602, intercepting the business protocol through the access control binding submodule; S603, encapsulating a tunnel for the service data, and adding a trusted authentication code and a file mark generated during terminal authentication to each message; S604, when the integrated border security protection device receives a service access from a terminal or a server, the basic network protocol is protected; S605, monitor penetration and virus attack behaviors; S606, protecting whether the business access behavior is a trusted transmission protocol; S607, judging whether the access end is a trusted authentication end, protecting against non-compliant business access, and taking the subject's trustworthiness as a prerequisite for business access; S608. Implement the network transmission protocol through the transparent service function in the business model; S609, perform an upper layer protocol format check on the application layer protocol, and determine whether the application layer protocol of this type of service meets the conditions during transmission based on the check result, block and audit abnormal application layer protocols, and notify the abnormal application layer protocol to the network layer boundary security protection module for protocol policy protection; S610, checking the application layer protocol tags, discarding abnormal application layer protocol tags, and auditing boundary behaviors; S611. Check the application layer protocol behavior, determine the service access behavior, and conduct an audit; S612. Collect audits of border behaviors and complete integrated border security protection.
Citation Information
Patent Citations
Security boundary management system and management method
CN106888189A