Cyberspace Protection Method, Device and Terminal Device

By performing multiple verifications on the data to be verified for IP access requests received in the network space, the problem of the inability to detect abnormal access traffic in the prior art is solved, and the security of the network space is improved.

CN115484058BActive Publication Date: 2025-05-30FENGTAI SCI & TECH (BEIJING) CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202210949029.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-08-09
Publication Date
2025-05-30
Estimated Expiration
2042-08-09

AI Technical Summary

Technical Problem

The prior art has limitations in judging abnormal access traffic in the network space, and it is impossible to detect abnormal IP access in time, affecting network security.

Method used

By receiving IP access requests, the data to be checked, including the source IP and/or TCP packets, perform multiple verifications, including the source IP checksum and/or TCP packet content verification, and if the verification is passed, access is allowed.

Benefits of technology

It realizes timely discovery of abnormal IP access, improves the security of the network space, ensures that only IP access requests that pass the verification can access services, and effectively protect network assets.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115484058B_ABST
    Figure CN115484058B_ABST
Patent Text Reader

Abstract

This application is applicable to the field of network security technology, and provides a network space protection method, device and terminal device, including: obtaining data to be verified based on the received IP access request, where the data to be verified includes the source IP and / or TCP packet, performing multiple verifications based on the data to be verified to obtain a verification result, and the multiple verifications include source IP verification and / or TCP packet content verification. If the verification result indicates that the verification is passed, the source IP of the above IP access request is allowed to access. This application can improve the security of the network space.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application belongs to the field of network security technology, and in particular, relates to a network space protection method, apparatus, terminal equipment and computer-readable storage medium. Background Art

[0002] With the advent of the era of the Internet of Everything and the vigorous development of emerging technologies such as 5G, the Internet of Things, and blockchain, the number of networked devices in cyberspace has exploded, and cyberspace has become the fifth dimension of space after "sea, land, air, and space". Countries have invested in cyberspace construction and introduced national cyberspace strategies to seize the commanding heights. Among them, cyberspace mapping is an important part of cyberspace national defense capability construction. Through the network, holographic network maps are drawn to grasp the cyberspace situation in all directions and around the clock, providing strong support for maintaining the sovereignty, security, and development of national cyberspace. However, hackers and other national organizations use cyberspace surveys and cyberspace mapping to attack specific targets, and even obtain national confidential information such as national and regional network asset information, distribution, and vulnerability conditions, which has a serious impact on national network security.

[0003] However, the prior art usually performs statistical analysis on traffic logs to determine whether there are abnormal events / attack events, but cannot detect abnormal access traffic in a timely manner, which has certain limitations. Summary of the invention

[0004] The embodiments of the present application provide a network space protection method, apparatus and terminal equipment, which can timely detect abnormal IP access and improve the security of the network space.

[0005] In a first aspect, an embodiment of the present application provides a network space protection method, including:

[0006] Acquire the data to be verified based on the received IP access request, where the data to be verified includes the source IP and / or TCP message;

[0007] Perform multiple checks based on the data to be checked to obtain a check result, wherein the multiple checks include source IP check and / or TCP message content check;

[0008] If the above verification result indicates that the verification is passed, the source IP of the above IP access request is allowed to access.

[0009] In a second aspect, an embodiment of the present application provides a network space protection device, including:

[0010] A data acquisition module, which acquires the data to be verified based on the received IP access request, wherein the data to be verified includes a source IP and / or a TCP message;

[0011] A verification module, configured to perform multiple verifications based on the to-be-verified data described above to obtain a verification result, where the multiple verifications include whitelist verification and / or TCP packet content verification;

[0012] An access module, configured to, if the verification result indicates that the verification is passed, allow the source IP of the above IP access request to access.

[0013] In a third aspect, an embodiment of the present application provides a terminal device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the steps of the network space protection method described in the first aspect above are implemented.

[0014] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium. The computer storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the network space protection method described in the first aspect above are implemented.

[0015] In a fifth aspect, an embodiment of the present application provides a computer program product. When the computer program product runs on a terminal device, the terminal device is enabled to execute the network space protection method described in any one of the first aspects above.

[0016] The beneficial effects of the embodiments of the present application compared with the prior art are as follows: The to-be-verified data is obtained based on the received IP access request. The to-be-verified data includes the source IP and / or the TCP packet. Multiple verifications including whitelist verification and / or TCP packet verification are performed based on the to-be-verified data to obtain a verification result. If the verification result indicates that the verification is passed, the source IP of the above IP access request is allowed to access. Since source IP verification and / or TCP packet content verification are performed on the to-be-verified data, and the access traffic corresponding to the source IP is allowed to access the service only after the verification is passed, abnormal IP access requests can be detected in time before the source IP accesses the corresponding service, and only the source IP of the IP access request that passes the verification is allowed to access the service, effectively protecting the security of network assets and improving the security of network space services. Description of the Drawings

[0017] To more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings required for use in the embodiments or the description of the prior art.

[0018] Figure 1 It is a schematic flowchart of a network space protection method provided by an embodiment of the present application;

[0019] Figure 2 It is a schematic structural diagram of a network space protection device provided by an embodiment of the present application;

[0020] Figure 3 It is a schematic structural diagram of a terminal device provided by an embodiment of the present application. Detailed implementation manners

[0021] In the following description, for the purpose of illustration rather than limitation, specific details such as specific system architectures and technologies are presented to thoroughly understand the embodiments of the present application. However, those skilled in the art should clearly understand that the present application can also be implemented in other embodiments without these specific details. In other cases, detailed descriptions of well-known systems, devices, circuits, and methods are omitted to avoid unnecessary details from interfering with the description of the present application.

[0022] It should be understood that when used in the specification of the present application and the appended claims, the term "comprising" indicates the presence of the described features, wholes, steps, operations, elements, and / or components, but does not exclude the presence or addition of one or more other features, wholes, steps, operations, elements, components, and / or their combinations.

[0023] It should also be understood that the term "and / or" used in the specification of the present application and the appended claims refers to any combination and all possible combinations of one or more of the associated listed items, and includes these combinations.

[0024] In addition, in the description of the specification of the present application and the appended claims, the terms "first", "second", "third", etc. are only used for differential description and cannot be understood as indicating or implying relative importance.

[0025] The reference to "one embodiment" or "some embodiments" etc. described in the specification of the present application means that a specific feature, structure, or characteristic described in connection with the embodiment is included in one or more embodiments of the present application. Thus, the statements "in one embodiment", "in some embodiments", "in other some embodiments", "in still other embodiments", etc. that appear in different places in this specification do not necessarily refer to the same embodiment, but mean "one or more but not all embodiments", unless otherwise specifically emphasized in other ways.

[0026] Example 1:

[0027] Figure 1 A flowchart showing a network space protection method provided by an embodiment of the present invention is shown and described in detail as follows:

[0028] S101, obtain data to be verified based on the received IP access request.

[0029] Specifically, when receiving an IP (Internet Protocol) access request for a protected service, obtain the IP data packet of the above IP access request, parse the above IP data packet to obtain data such as the source IP address, destination IP address, optional fields, padding content, TCP (Transmission Control Protocol) packet, etc. corresponding to the above IP access request, and then determine the data to be verified based on the data obtained by parsing the IP data packet. Since the source IP address indicates the user information that issues the above IP access request, therefore, use the above source IP as the data to be verified for subsequent verification, or use the TCP packet containing the content information of the above IP access request as the data to be verified, or use both the above source IP and the above TCP packet as the data to be verified. Among them, the above source IP refers to the IP address that issues the above IP access request, and the above protected service refers to the service protected by the above network space protection method.

[0030] In the embodiment of the present application, based on the received IP access request, obtain corresponding data as the data to be verified. Since the source IP indicates the user information that issues the access request and the TCP packet contains the content information of the above access request, therefore, use the above source IP and / or TCP packet as the data to be verified, so as to clearly understand the information of the above IP access request, so as to confirm whether the above IP access request is credible subsequently.

[0031] S102, perform multiple verifications based on the above data to be verified to obtain a verification result, and the above multiple verifications include source IP verification and / or TCP packet content verification.

[0032] Specifically, in order to detect whether the above access request is safe and credible, perform multiple verifications based on the above data to be verified, and the above multiple verifications include source IP verification and / or TCP packet content verification. The above source IP verification is performed through a pre-set whitelist, and the above whitelist stores the IPs that users trust and are allowed to access the protected service. Since when performing source IP verification, there may be a situation where the whitelist information is not updated in a timely manner, so that a source IP that is credible during source IP verification fails the verification. Therefore, TCP packet verification can be performed based on the above data to be verified, or dual verification of source IP verification and TCP packet verification can be performed to obtain a verification result that can indicate whether the above IP access request is credible, reducing the situation where a credible IP access request fails the verification due to untimely update of whitelist information and improving the security of network space protection.

[0033] In the embodiments of the present application, since information may not be updated in a timely manner, resulting in a trusted IP access request failing the verification, multiple verifications including source IP verification and / or TCP packet verification are performed based on the above data to be verified, thereby reducing the error of the verification result and improving the security of network space services.

[0034] S103, if the above verification result indicates that the verification is passed, the source IP of the above IP access request is allowed to access.

[0035] Specifically, if the above verification result indicates that the above IP access request passes the verification, that is, if it is determined that the above IP access request is an access request sent by a trusted user, the source IP corresponding to the above IP access request is allowed to access the protected real service.

[0036] In the embodiments of the present application, when an IP access request is received, the IP data packet of the above IP access request is obtained, the data to be verified including the source IP and / or TCP packet is obtained based on the above IP data packet, and multiple verifications are performed based on the above data to be verified to obtain a verification result. If the above verification result indicates that the above IP access request passes the verification, the source IP corresponding to the above IP access request is allowed to access the protected service. Since the data to be verified is verified first before allowing the source IP of the above IP access request to access, and the source IP and / or data packet included in the data to be verified contains the user information of the IP access request and / or the content information of the IP access request, and it can be determined whether the corresponding IP access request is a trusted request based on the above data to be verified. Therefore, allowing the source IP corresponding to the above IP access request to access the protected service after the verification result indicates that the above IP access request passes the verification can improve the security of network space services.

[0037] In some embodiments, the above data to be verified further includes access traffic, and the above multiple verifications further include fingerprint verification. Correspondingly, the above step S102 further includes:

[0038] Perform fingerprint verification based on the above access traffic.

[0039] Specifically, when an IP access request is received, the access traffic of the above IP access request is simultaneously obtained as the data to be verified. Then, when performing multiple verifications on the IP access request, fingerprint verification is performed based on the above access traffic to detect whether the above access traffic contains a preset fingerprint feature, thereby determining whether the above IP access request is trusted.

[0040] In the embodiments of the present application, when performing multiple validations on an IP access request, fingerprint validation is also performed on the above IP access request based on the access traffic. Since the access traffic as a whole reflects the access information of the IP access request, therefore, performing fingerprint validation based on the above access traffic can detect whether the above access traffic meets the security requirements as a whole.

[0041] In some embodiments, the above step S102 includes:

[0042] A1. Compare the above source IP with a preset whitelist. If the above source IP is within the above whitelist, it is determined that the source IP verification is passed.

[0043] Among them, the preset whitelist records one or more IP addresses.

[0044] Specifically, compare the obtained source IP with the IP addresses in the preset whitelist. If there is an IP address in the above whitelist that is the same as the above source IP address, it indicates that the above source IP is a trusted IP. At this time, it can be determined that the IP access request corresponding to the above source IP address has passed the above source IP verification.

[0045] Optionally, when setting the above whitelist in advance, set an IP blacklist according to information such as network information and historical information of being attacked in the network space. Before comparing the above source IP with the above whitelist, or after comparing the above source IP with the above whitelist, compare the above source IP with the above blacklist. If the above source IP is in the above blacklist, it indicates that the IP access request corresponding to the above source IP is not trusted, and no further verification is performed on the data to be verified corresponding to the above IP access request, and it is determined that the multiple validations of the above IP access request fail.

[0046] A2. If the above source IP is not within the above whitelist, obtain the message header of the above TCP message. If the message header of the above TCP message contains a preset token, it is determined that the TCP message content verification is passed.

[0047] Optionally, if the above source IP is not within the above whitelist, or not within the above whitelist and the above blacklist, obtain the message header of the TCP message of the IP access request corresponding to the above source IP, and compare the above message header with a preset token. If the above message header contains the above token, it indicates that the IP access request corresponding to the above TCP message is a trusted access request, and it is determined that the above IP access request passes the above TCP message content verification.

[0048] A3. If the packet header of the above TCP packet does not contain the above preset token, extract the features of the above access traffic to obtain the traffic fingerprint features. If the above traffic fingerprint features contain the preset special fingerprint, it is determined that the above fingerprint verification fails.

[0049] Optionally, when verifying the above TCP packet, if the packet header of the above TCP packet does not contain the above preset token, obtain the access traffic of the IP access request corresponding to the above TCP packet, extract the features of the above access traffic to obtain the traffic feature fingerprint of the above access traffic, and compare the above traffic feature fingerprint with the special fingerprints in the pre-set special fingerprint library. If the above special fingerprint library contains the above traffic feature fingerprint, that is, the IP access request corresponding to the above traffic feature fingerprint is an untrusted access, it is determined that the fingerprint verification of the above IP access request fails. For example, if the extracted traffic fingerprint features contain the fingerprint features of a spider crawler and are consistent with the spider fingerprint features in the special fingerprint library, the IP access request corresponding to the above access traffic is an untrusted request, and it is determined that the above IP access request fails the fingerprint verification.

[0050] Optionally, when extracting the features of the above access traffic, use the trained neural network model to extract the traffic feature fingerprint of the above access traffic.

[0051] A4. If the above traffic fingerprint features do not contain the preset special fingerprint, obtain the physical address information corresponding to the above source IP. If the above physical address is within the preset address whitelist, it is determined that the above multiple verification passes. The above physical address information includes at least the information of the country corresponding to the above source IP.

[0052] Specifically, if the above traffic feature fingerprint does not contain the above special fingerprint, it indicates that the IP access request corresponding to the above traffic feature fingerprint is not a preset untrusted access. Then, further verify the above IP access request, obtain the source IP of the above IP access request, and obtain the corresponding physical address information according to the above source IP. If the physical address indicated by the above physical address information is within the preset address whitelist, it indicates that the IP access request corresponding to the above source IP is a trusted access, and it is determined that the above IP access request passes the above physical address verification, that is, the above IP access request passes the above multiple verification.

[0053] Optionally, when obtaining the corresponding physical address information based on the above source IP, existing services provided by a third party or a third-party database, such as GeoLiteCity, etc. are used to obtain information such as the country, region, province, city, district, county, and longitude and latitude corresponding to the above source IP as the physical address information. Due to possible information loss and other reasons, only information such as the country and region corresponding to some source IPs can be obtained, and more specific address information such as city and district cannot be obtained. Therefore, when verifying the physical address information of the above source IP, the above physical address information includes at least the country information corresponding to the above source IP, so as to verify whether the above source IP belongs to a foreign IP based on the above country information, thereby preventing IPs with foreign physical addresses from accessing the protected service and reducing the threat to network space security from other countries and organizations.

[0054] In the embodiments of the present application, since before an IP accesses the protected service, multiple verifications including source IP, TCP packet, and physical address information verification are performed on the corresponding IP access request based on verification data such as source IP, TCP packet, and access traffic, abnormal access can be detected in a timely manner, and at the same time, the situation of incorrect verification results caused by untimely update of whitelist information and other reasons can be reduced, improving the error tolerance rate.

[0055] In some embodiments, the above token is a byte segment with a fixed byte length. Correspondingly, the above step A3 includes:

[0056] A31. Obtain the information of the specified field in the packet header of the above TCP packet, and the byte length of the above specified field is equal to the above fixed byte length.

[0057] A32. Compare the information of the above specified field with the above token.

[0058] A33. If the information of the above specified field is the same as the above token, it is determined that the TCP packet content verification is passed.

[0059] Optionally, when setting the token, a byte segment with a fixed byte length can be randomly generated by using a cryptographic algorithm, etc. Since the reserved field of the TCP packet is 6 bytes, the token is generally set to the same byte length as the reserved field so as to insert the token into the reserved field of the TCP packet.

[0060] Specifically, when performing TCP packet content verification on an IP access request, obtain the TCP packet of the above IP access request, and extract the information of the specified field in the packet header of the above TCP packet, that is, the field where the token is located. Then, compare the information of the above specified field with the pre-set token. If the information of the above specified segment is exactly the same as the above token, the above IP access request is a trusted access. At this time, it is determined that the above IP access request passes the TCP packet content verification.

[0061] Optionally, in order to enhance the security of network space protection, when pre-setting the token, an encryption algorithm can be used to encrypt the token. When performing token verification on the TCP packet of the IP access request subsequently, use the corresponding encryption algorithm to encrypt the specified segment of the extracted TCP packet, or use the corresponding decryption algorithm to decrypt the above specified segment, and then compare it with the token.

[0062] In the embodiment of the present application, since the token is inserted into the packet header of the TCP packet, there is no need to perform additional encapsulation and decapsulation on the traffic packet or TCP packet of the IP access request. Therefore, while not affecting the normal functions of the IP data packet or TCP packet, it is possible to conveniently implement the token verification of the IP access request, that is, the TCP packet content verification.

[0063] In some embodiments, in order to reduce unnecessary verification, during the process of performing multiple verifications on an IP access request, if it is determined that the above IP access request passes any one verification, that is, it is determined that the above IP access request is a trusted access, then stop performing the next verification, and use the currently passed verification result as the verification result of the multiple verifications, reducing unnecessary verification in the case where it has been determined that the above IP access request is a trusted request. In some embodiments, for some protected services with relatively high security requirements, according to the requirements, the IP access request needs to pass any two verifications or all verifications of the multiple verifications before it is determined that the above IP access request is a trusted access, that is, it is determined that the IP access request passes the multiple verifications.

[0064] In some embodiments, the above network space protection method further includes:

[0065] If the above verification result indicates that the verification fails, obtain the current protection mode of the system.

[0066] If the above protection mode is the blocking mode, block the connection between the system and the above source IP, and intercept the access to the above source IP.

[0067] If the above protection mode is the deception mode, connect the above source IP to the simulation module, and the above simulation module is used to provide simulation services, and the above simulation services are different from the real services.

[0068] Optionally, a protection mode including a blocking mode and a spoofing mode is set. After multiple verifications of the above IP access request, if the verification result of the multiple verifications indicates that the above IP access fails the verification and the request is an untrusted access, the protection mode currently adopted by the system is obtained. If the current protection mode is the blocking mode, the connection between the system and the source IP corresponding to the above IP access request is blocked, the access to the above source IP is intercepted, and subsequent access requests from the above source IP are not accepted. If the current protection mode is the spoofing mode, the source IP corresponding to the above IP access request is connected to the simulation module, so that the above source IP is connected to the simulation service provided in the simulation module. The simulation service provided by the above simulation module is a simulated real service, such as a MySQL database, a web service, etc. Different from the real service, the above source IP cannot obtain real and useful information when accessing the simulation service. The simulation service confuses untrusted IP accesses, and can cooperate with security audits to count attack events, abnormal operation events, etc. of the source IP connected to the simulation service, so as to analyze and evaluate the security and threat level of the source IP.

[0069] Optionally, the simulation service provided by the above simulation module can switch the provided service at regular intervals, so that different simulation services are provided in different time periods. For example, the simulation module is currently set to switch the currently provided simulation service every hour. The simulation service provided to an IP connected to the simulation module is MySQL. Thirty minutes after the above IP is connected to the MySQL service, the current time is the hour, and the simulation module randomly switches the currently provided simulation service to the oracle service. One hour after this simulation service switch, the hour time arrives again, and the simulation service randomly switches the currently provided simulation service again, so that it is difficult for the IP connected to the simulation service to distinguish what service it is currently connected to, interfering with untrusted IP accesses, thereby achieving the effect of anti-surveying and effectively protecting real asset services.

[0070] In the embodiment of the present application, since untrusted IP access requests are intercepted or their source IPs are connected to the simulation service for spoofing, therefore, the simulation service confuses untrusted IP accesses, thereby achieving the interference effect of anti-surveying, and further effectively protecting real services.

[0071] In some embodiments, if the above verification result indicates that the IP access request fails the multiple verifications, an alarm message including information such as the source IP and source port is generated based on the above IP access request that fails the multiple verifications and sent to the user, so that the user can timely learn about the access situation of untrusted accesses, in order to better protect network space security.

[0072] In some embodiments, after generating a token, the obtained token is sent to the client of a trusted user. When the above client accesses a protected service, the token is inserted into a specified segment of the header information of the TCP packet, such as the reserved field. Then, the TCP checksum algorithm is used to modify the length of the TCP packet content, making the TCP packet with the inserted token indistinguishable from a normal TCP packet. Then, the above TCP packet is carried for access. Since the length of the TCP packet content is modified using the TCP checksum algorithm, the packet structure of the TCP packet with the inserted token is indistinguishable from that of a normal TCP packet, enabling it to be received by both a normal server and a system adopting the above network space anti-surveying method. Among them, the above TCP checksum algorithm refers to calculating the checksum of the TCP packet. By setting the checksum field to 0, the data to be checked is regarded as a series of 16-bit numbers, and the binary one's complement sum is calculated successively, and the obtained result is stored in the checksum field of the TCP packet.

[0073] It should be understood that the magnitudes of the sequence numbers of the steps in the above embodiments do not indicate the order of execution. The order of execution of each process should be determined according to its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present application.

[0074] Embodiment 2:

[0075] Corresponding to the above-mentioned network space protection method in the foregoing embodiment, Figure 2 The structural block diagram of the network space protection device provided by the embodiment of the present application is shown. For the sake of convenience of description, only the parts related to the embodiment of the present application are shown.

[0076] Referring to Figure 2 , the device includes: a data acquisition module 21, a verification module 22, and an access module 23. Among them,

[0077] The data acquisition module 21 acquires data to be verified based on the received IP access request. The above data to be verified includes the source IP and / or the TCP packet;

[0078] The verification module 22 is used to perform multiple verifications based on the above data to be verified to obtain a verification result. The above multiple verifications include whitelist verification and / or TCP packet content verification;

[0079] The access module 23 is used to, if the above verification result indicates that the verification is passed, allow the source IP of the above IP access request to access.

[0080] In an embodiment of the present application, when an IP access request is received, the IP data packet of the IP access request is obtained, the data to be verified including the source IP and / or the TCP packet is obtained based on the IP data packet, and multiple verifications are performed based on the data to be verified to obtain a verification result. If the verification result indicates that the IP access request passes the verification, that is, the IP access request is a trusted request, the source IP corresponding to the IP access request is allowed to access the protected service. Since the data to be verified is obtained and verified when the IP access request is received, therefore, it is timely confirmed whether the IP access request is trusted before the source IP corresponding to the IP access request accesses the protected service, improving the security of network space services.

[0081] In some embodiments, the above-mentioned network space protection device 2 further includes:

[0082] A fingerprint verification module, configured to perform fingerprint verification based on the access traffic.

[0083] In some embodiments, the above-mentioned verification module 22 further includes:

[0084] A source IP verification unit, configured to A1. Compare the above-mentioned source IP with a preset whitelist. If the above-mentioned source IP is within the whitelist, it is determined that the source IP verification passes.

[0085] A TCP verification unit, configured to if the above-mentioned source IP is not within the whitelist, obtain the header of the above-mentioned TCP packet. If the header of the above-mentioned TCP packet contains a preset token, it is determined that the TCP packet content verification passes.

[0086] A fingerprint verification unit, configured to if the header of the above-mentioned TCP packet does not contain the above-mentioned preset token, extract features from the above-mentioned access traffic to obtain traffic fingerprint features. If the traffic fingerprint features contain a preset special fingerprint, it is determined that the fingerprint verification fails.

[0087] A physical address verification unit, configured to if the traffic fingerprint features do not contain a preset special fingerprint, obtain the physical address information corresponding to the above-mentioned source IP. If the physical address is within a preset address whitelist, it is determined that the multiple verifications pass. The above-mentioned physical address information includes at least the information of the country corresponding to the above-mentioned source IP.

[0088] In some embodiments, the above-mentioned TCP verification unit further includes:

[0089] A field acquisition unit, configured to obtain the information of a specified field in the header of the above-mentioned TCP packet. The length of the above-mentioned specified field is a fixed byte length.

[0090] A Token comparison unit for comparing the information of the specified field with the above-mentioned token.

[0091] A determination unit for determining that the TCP packet content verification is passed if the information of the specified field is the same as the above-mentioned token.

[0092] In some embodiments, the above-mentioned verification module 22 further includes:

[0093] A verification stop unit for stopping the next verification during the process of multiple verifications of the IP access request, and using the verification result passed currently as the verification result of the multiple verifications.

[0094] In some embodiments, the above-mentioned network space protection device 2 further includes:

[0095] A mode acquisition module for acquiring the current protection mode of the system if the above-mentioned verification result indicates that the verification fails.

[0096] An interception module for blocking the connection between the system and the above-mentioned source IP and intercepting the access to the above-mentioned source IP if the above-mentioned protection mode is the blocking mode.

[0097] A deception module for connecting the above-mentioned source IP to the simulation module if the above-mentioned protection mode is the deception mode, and the simulation module is used to provide simulation services, and the simulation services are different from the real services.

[0098] In some embodiments, the above-mentioned network space protection device 2 further includes:

[0099] A simulation module for providing different types of simulation services and switching the provided simulation services regularly.

[0100] In some embodiments, the above-mentioned network space protection device 2 further includes a token insertion module applied to the client;

[0101] The above-mentioned token insertion module specifically includes:

[0102] A Token insertion unit for inserting a preset token into a specified field in the header information of the TCP packet in the access traffic.

[0103] A length modification unit for modifying the length of the above-mentioned TCP packet by using the TCP checksum algorithm.

[0104] It should be noted that for the information interaction, execution process, etc. between the above-mentioned devices / units, since they are based on the same concept as the method embodiments of the present application, their specific functions and the technical effects brought are specifically described in the method embodiment part, and will not be elaborated here.

[0105] Embodiment 3:

[0106] Figure 3 The following is a schematic structural diagram of a terminal device provided in an embodiment of the present application. As Figure 3 shown, the terminal device 3 in this embodiment includes: at least one processor 30 ( Figure 3 only one processor is shown in the figure), a memory 31, and a computer program 32 stored in the memory 31 and executable on the at least one processor 30. When the processor 30 executes the computer program 32, the steps in any of the above method embodiments are implemented.

[0107] Exemplarily, the above computer program 32 can be divided into one or more modules / units. The above one or more modules / units are stored in the memory 31 and executed by the processor 30 to complete the present application. The above one or more modules / units can be a series of computer program instruction segments capable of performing specific functions, and these instruction segments are used to describe the execution process of the above computer program 32 in the above terminal device 33. For example, the above computer program 32 can be divided into a data acquisition module 21, a verification module 22, and an access module 23. The specific functions of each module are as follows:

[0108] The data acquisition module 21 acquires data to be verified based on the received IP access request. The data to be verified includes the source IP and / or TCP packets;

[0109] The verification module 22 is used to perform multiple verifications based on the data to be verified to obtain a verification result. The multiple verifications include whitelist verification and / or TCP packet content verification;

[0110] The access module 23 is used to, if the verification result indicates that the verification is passed, allow the source IP of the above IP access request to access.

[0111] The terminal device 3 may be a computing device such as a desktop computer, a notebook, a palm computer, and a cloud server. The terminal device may include, but is not limited to, a processor 30 and a memory 31. Those skilled in the art can understand that Figure 3 merely examples of the terminal device 3 are given and do not constitute a limitation on the terminal device 3. It may include more or fewer components than shown in the figure, or combine certain components, or different components. For example, it may also include input / output devices, network access devices, etc.

[0112] The so-called processor 30 may be a Central Processing Unit (CPU), and the processor 30 may also be other general-purpose processors, Digital Signal Processors (DSPs), Application Specific Integrated Circuits (ASICs), Field-Programmable Gate Arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.

[0113] In some embodiments, the memory 31 may be an internal storage unit of the terminal device 3, such as the hard disk or memory of the terminal device 3. In other embodiments, the memory 31 may also be an external storage device of the terminal device 3, such as a plug-in hard disk, Smart Media Card (SMC), Secure Digital (SD) card, Flash Card, etc., equipped on the terminal device 3. Further, the memory 31 may also include both the internal storage unit and the external storage device of the terminal device 3. The memory 31 is used to store an operating system, application programs, a BootLoader, data, and other programs, such as the program code of the computer program, etc. The memory 31 may also be used to temporarily store data that has been output or is to be output.

[0114] Those skilled in the art can clearly understand that, for the convenience and simplicity of description, only the above division of each functional unit and module is used as an example. In actual applications, the above functions can be allocated to different functional units and modules as needed, that is, the internal structure of the device is divided into different functional units or modules to complete all or part of the functions described above. Each functional unit and module in the embodiments can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above integrated units can be implemented in the form of hardware or in the form of software functional units. Additionally, the specific names of each functional unit and module are only for the convenience of mutual distinction and do not limit the protection scope of this application. The specific working processes of the units and modules in the above system can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated herein.

[0115] An embodiment of the present application further provides a network device, which includes at least one processor, a memory, and a computer program stored in the memory and executable on the at least one processor. When the processor executes the computer program, the steps in any of the above method embodiments are implemented.

[0116] An embodiment of the present application further provides a computer-readable storage medium storing a computer program, which when executed by a processor can implement the steps in the above method embodiments.

[0117] An embodiment of the present application provides a computer program product, which when running on a terminal device enables the terminal device to implement the steps in the above method embodiments.

[0118] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, to implement all or part of the processes in the above embodiment methods of the present application, a computer program can be used to instruct relevant hardware to complete. The computer program can be stored in a computer-readable storage medium. When the computer program is executed by a processor, the steps in the above method embodiments can be implemented. Among them, the computer program includes computer program code, and the computer program code can be in the form of source code, object code, executable file, or some intermediate form, etc. The computer-readable medium can at least include: any entity or device capable of carrying the computer program code to the photographing device / terminal device, recording medium, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signal, telecommunication signal, and software distribution medium. For example, a USB flash drive, a mobile hard disk, a magnetic disk, or an optical disc, etc. In some jurisdictions, according to legislation and patent practice, the computer-readable medium cannot be an electrical carrier signal and a telecommunication signal.

[0119] In the above embodiments, the descriptions of the respective embodiments have their own emphases. For parts not detailed or recorded in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.

[0120] Those of ordinary skill in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods for each specific application to implement the described functions, but such implementation should not be considered to exceed the scope of this application.

[0121] In the embodiments provided in this application, it should be understood that the disclosed device / network device and method can be implemented in other ways. For example, the device / network device embodiments described above are merely illustrative. For example, the division of the modules or units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces. The indirect couplings or communication connections of the devices or units can be electrical, mechanical or other forms.

[0122] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place, or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0123] The above-described embodiments are only used to illustrate the technical solutions of this application, rather than to limit them; although this application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of this application, and should all be included in the protection scope of this application.

Claims

1. A method for network space protection, characterized in that, it includes: Obtaining data to be verified based on the received IP access request, where the data to be verified includes the source IP, TCP packet, and access traffic; Performing multiple verifications based on the data to be verified to obtain a verification result, where the multiple verifications include source IP verification, TCP packet content verification, fingerprint verification, and physical address verification; If the verification result indicates that the verification is passed, the source IP of the IP access request is allowed to access; Among them, the performing multiple verifications based on the data to be verified to obtain a verification result includes: Comparing the source IP with the IP blacklist. If the source IP is in the IP blacklist, it is determined that the multiple verifications fail. The IP blacklist is determined according to the historical information of being attacked; If the source IP is not in the IP blacklist, compare the source IP with a preset whitelist. Among them, if the source IP is in the preset whitelist, it is determined that the source IP verification is passed; If the source IP is not in the preset whitelist, obtain the packet header of the TCP packet. If the packet header of the TCP packet contains a preset token, it is determined that the TCP packet content verification is passed; If the packet header of the TCP packet does not contain the preset token, extract the feature of the access traffic to obtain a traffic fingerprint feature. If the traffic fingerprint feature contains a preset special fingerprint, it is determined that the fingerprint verification fails; If the traffic fingerprint feature does not contain a preset special fingerprint, obtain the physical address information corresponding to the source IP. If the physical address information is in the preset address whitelist, it is determined that the multiple verifications are passed. The physical address information at least includes the information of the country corresponding to the source IP.

2. The network space protection method according to claim 1, characterized in that, the token is a byte segment with a fixed byte length. The obtaining the packet header of the TCP packet and if the packet header of the TCP packet contains a preset token, it is determined that the TCP packet content verification is passed includes: Obtaining the information of the specified field in the packet header of the TCP packet, where the byte length of the specified field is equal to the fixed byte length; Comparing the information of the specified field with the token; If the information of the specified field is the same as the token, it is determined that the TCP packet content verification is passed.

3. The network space protection method according to claim 1, characterized in that, it further includes: If the verification result indicates that the verification fails, obtain the current protection mode of the system; If the protection mode is the blocking mode, block the connection between the system and the source IP and intercept the access to the source IP; If the protection mode is the deception mode, connect the source IP to the simulation module, and the simulation module is used to provide simulation services, and the simulation services are different from the real services.

4. A network space protection device, characterized in that, it includes: A data acquisition module that acquires data to be verified based on the received IP access request, where the data to be verified includes the source IP, TCP packet, and access traffic; A verification module for performing multiple verifications based on the data to be verified to obtain a verification result, where the multiple verifications include source IP verification, TCP packet content verification, fingerprint verification, and physical address verification; An access module for, if the verification result indicates that the verification is passed, allowing the source IP of the IP access request to access; Among them, the verification module is specifically used for: Comparing the source IP with an IP blacklist, and if the source IP is within the IP blacklist, determining that the multiple verifications fail, where the IP blacklist is determined according to historical attack information; If the source IP is not within the IP blacklist, comparing the source IP with a preset whitelist, where if the source IP is within the preset whitelist, determining that the source IP verification is passed; If the source IP is not within the preset whitelist and the IP blacklist, then obtaining the packet header of the TCP packet, and if the packet header of the TCP packet contains a preset token, determining that the TCP packet content verification is passed; If the packet header of the TCP packet does not contain the preset token, then extracting the feature of the access traffic to obtain a traffic fingerprint feature, and if the traffic fingerprint feature contains a preset special fingerprint, determining that the fingerprint verification fails; If the traffic fingerprint feature does not contain a preset special fingerprint, then obtaining the physical address information corresponding to the source IP, and if the physical address information is within a preset address whitelist, determining that the multiple verifications are passed, where the physical address information at least includes information about the country corresponding to the source IP.

5. The network space protection device according to claim 4, characterized in that, it further includes a token insertion module applied to the client, specifically used for: inserting a preset token into a specified field in the header information of the TCP packet in the access traffic; modifying the length of the above TCP packet using the TCP checksum algorithm.

6. The network space protection device according to claim 4, characterized in that, it further includes: A simulation module for providing different types of simulation services and periodically switching the provided simulation services.

7. A terminal device includes a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, when the processor executes the computer program, it implements the method according to any one of claims 1 to 3.

8. A computer-readable storage medium stores a computer program, characterized in that, when the computer program is executed by a processor, it implements the method according to any one of claims 1 to 3.

Citation Information

Patent Citations

  • Message processing method, device and equipment and computer readable storage medium

    CN112751815A

  • Gateway protection method and data labeling method

    CN113301028A

  • Access control method and device, equipment and storage medium

    CN113596033A