Cloud-based internet access control method, apparatus, medium, device and system

By configuring traffic redirection and secure access control policies through a cloud security management platform, target terminals redirect traffic to edge nodes for unified inspection and filtering, solving the latency and high cost problems caused by enterprise terminal backhaul, and achieving efficient and low-cost Internet access control.

CN115567229BActive Publication Date: 2025-11-28SHANGHAI YUNDUN INFORMATION TECH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202110745342.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-06-30
Publication Date
2025-11-28
Estimated Expiration
2041-06-30

AI Technical Summary

Technical Problem

In existing technologies, when enterprise terminals access the internet, data needs to be transmitted back to the enterprise headquarters for traffic inspection and filtering. This results in high latency, network fluctuations that affect user experience, and high maintenance costs, making it difficult to adapt to the development trends of cloud computing and mobile office.

Method used

By adopting a cloud-based internet access control method, traffic diversion policies and security access control policies are configured through a cloud security management platform. The target terminal diverts traffic to edge nodes for unified inspection and filtering. Full-stack security software runs on the edge nodes for fine-grained protection, reducing the need for security device management on the target terminal.

Benefits of technology

It achieves efficient and low-cost network traffic security management, reduces maintenance and usage costs, improves user experience, and adapts to the needs of cloud computing and mobile office.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115567229B_ABST
    Figure CN115567229B_ABST
Patent Text Reader

Abstract

The application provides a cloud-based Internet access control method, system and device, a computer readable storage medium and an electronic device. The method comprises the following steps: configuring a diversion policy and a security access control policy for a target user through a cloud security management platform, sending the diversion policy to an edge node and a target terminal corresponding to the target user respectively, and sending the security access control policy to the edge node; the target terminal diverts access traffic to the corresponding edge node according to the diversion policy; the edge node obtains the network attribute of the target terminal according to the received access traffic from the target terminal, determines the security access control policy of the target user corresponding to the target terminal according to the pre-stored diversion policy and the network attribute of the target terminal, and performs security access control processing on the access traffic of the target terminal according to the security access control policy. Through the application, a brand-new and efficient security management mode of network traffic is realized.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of network security, and in particular to a cloud-based Internet access control method, system, device, computer readable storage medium and electronic equipment. BACKGROUND

[0002] With the development of Internet technology, enterprises use the Internet more and more. The connection between enterprise terminals and data centers is mostly established using the Internet. In the current technical solution, users can access the enterprise data center through MPLS or VPN, and various security devices such as DDoS, WAF, IDS, IPS, and Internet behavior management are deployed in the enterprise to ensure the security of Internet access. However, in the above process, the access traffic needs to be returned to the enterprise for inspection and filtering, which can cause large latency and network fluctuations, affecting user experience, and various security devices need to be maintained, which has high maintenance cost. Therefore, how to improve the access efficiency of Internet access and ensure the security of Internet access has become a technical problem to be solved. SUMMARY

[0003] Therefore, the purpose of the embodiments of the present application is to provide a cloud-based Internet access control method, system, device, computer readable storage medium and electronic equipment, so that the target terminal no longer needs to manage numerous security devices to achieve full-stack security management and control of the target terminal, greatly reducing the cost.

[0004] In a first aspect, the present application provides a cloud-based Internet access control method applied to an edge node, wherein the edge node is connected to at least one target terminal, and the method comprises:

[0005] According to the received access traffic from the target terminal, the network attribute of the target terminal is obtained;

[0006] According to the pre-stored diversion strategy and the network attribute of the target terminal, the security access control strategy of the target user corresponding to the target terminal is determined;

[0007] According to the security access control strategy, the access traffic from the target terminal is subjected to security access control processing.

[0008] In a second aspect, the present application provides a cloud-based Internet access control method applied to a cloud security management platform, and the method comprises:

[0009] Configuring a diversion strategy and a security access control strategy for a target user;

[0010] send the traffic steering strategy to the edge node and the target terminal corresponding to the target user respectively, so that the target terminal steers the access traffic to the edge node according to the traffic steering strategy;

[0011] send the security access control strategy to the edge node, so that the edge node performs security access control processing on the access traffic according to the security access control strategy.

[0012] In a third aspect, the present application provides a cloud-based Internet access control method applied to a target terminal, wherein the target terminal comprises a user terminal device or a network outlet of a branch office, and the method comprises:

[0013] obtain a traffic steering strategy from a cloud security management platform, wherein the traffic steering strategy is a traffic steering strategy of a target user corresponding to the target terminal;

[0014] steer the access traffic to a corresponding edge node according to the traffic steering strategy.

[0015] In a fourth aspect, the present application provides a cloud-based Internet access control system, which comprises:

[0016] a cloud security management platform configured to configure a traffic steering strategy and a security access control strategy for a target user, and send the traffic steering strategy to an edge node and a target terminal corresponding to the target user respectively, and send the security access control strategy to the edge node;

[0017] the edge node configured to perform security access control processing on the access traffic from the target terminal according to the security access control strategy.

[0018] In a fifth aspect, the present application provides a cloud-based Internet access control device arranged on an edge node, wherein the edge node is connected to at least one target terminal, and the device comprises:

[0019] an obtaining unit configured to obtain network attributes of the target terminal according to the access traffic received from the target terminal;

[0020] a determining unit configured to determine a security access control strategy of a target user corresponding to the target terminal according to a pre-stored traffic steering strategy and the network attributes of the target terminal;

[0021] a control unit configured to perform security access control processing on the access traffic from the target terminal according to the security access control strategy.

[0022] In a sixth aspect, the present application provides a cloud-based Internet access control device arranged on a cloud security management platform, which comprises:

[0023] The configuration unit is configured to configure a flow steering policy and a security access control policy for a target user;

[0024] The first sending unit is configured to send the flow steering policy to an edge node and a target terminal corresponding to the target user, respectively, so that the target terminal steers access traffic to the edge node according to the flow steering policy;

[0025] The second sending unit is configured to send the security access control policy to the edge node, so that the edge node performs security access control processing on the access traffic according to the security access control policy.

[0026] In a seventh aspect, the present application provides a cloud-based Internet access control device arranged on a target terminal, comprising:

[0027] The acquisition unit is configured to acquire a flow steering policy from a cloud security management platform, the flow steering policy being a flow steering policy of a target user corresponding to the target terminal;

[0028] The flow steering unit is configured to steer access traffic to a corresponding edge node according to the flow steering policy.

[0029] In an eighth aspect, the present application provides a computer readable storage medium having a computer program stored thereon, the program being executed by a processor to implement the cloud-based Internet access control method of the first aspect, or to implement the cloud-based Internet access control method of the second aspect, or to implement the cloud-based Internet access control method of the third aspect.

[0030] In a ninth aspect, the present application provides an electronic device comprising:

[0031] A processor;

[0032] A memory for storing instructions executable by the processor;

[0033] The processor is configured to execute the instructions to implement the cloud-based Internet access control method of the first aspect, or to implement the cloud-based Internet access control method of the second aspect, or to implement the cloud-based Internet access control method of the third aspect.

[0034] Compared with the prior art, the above technical solutions of the present application have the following beneficial effects:

[0035] 1. This invention configures traffic redirection strategies and security access control strategies for target users through a cloud security management platform. The traffic redirection strategies are then sent to edge nodes and the target terminals corresponding to the target users. This allows the target terminals to redirect access traffic to the edge nodes according to the traffic redirection strategies, while simultaneously sending the security access control strategies to the edge nodes. This enables the edge nodes to perform security access control processing on the access traffic according to the security access control strategies, achieving a novel and efficient network traffic security management model. Compared with existing technologies, this security management model eliminates the need to configure and manage numerous security devices, resulting in greater system flexibility. It is particularly in line with the development trends of cloud computing and mobile office technologies. Furthermore, since the traffic from the target terminals no longer needs to be transmitted back to headquarters for unified traffic inspection and filtering, maintenance and management costs are significantly reduced.

[0036] 2. In the embodiments of the present invention, the cloud security management platform serves as the management center, configuring personalized traffic redirection strategies and security access control strategies for each target user. As the management center of the security cloud gateway for multiple users, it possesses strong elasticity and business expansion capabilities.

[0037] 3. In the embodiments of the present invention, the edge node allows the target terminal to directly divert access traffic to the edge node according to the traffic diversion strategy for unified traffic inspection and filtering, which greatly reduces the cost of use and management. In addition, the edge node has full-stack security control capabilities and can perform full-stack fine-grained protection and control of access traffic from the corresponding target terminal according to the security access control policy, so that the target terminal no longer needs to configure a lot of security management devices, which greatly reduces costs.

[0038] 4. In the embodiments of the present invention, the deployment of distributed edge nodes allows target terminals to access edge nodes nearby, significantly reducing the time delay of information reaching edge nodes and greatly improving the user experience.

[0039] 5. In the embodiments of the present invention, the target terminal obtains the traffic diversion strategy from the cloud security management platform and diverts the access traffic directly to the corresponding edge node according to the traffic diversion strategy. This is especially suitable for application scenarios such as mobile office. For example, enterprise employees no longer rely on VPN to access enterprise applications, but can access the Internet at any time, any place, and through any network security, solving the problems of latency and bandwidth, and greatly improving work efficiency. Attached Figure Description

[0040] In order to make the technical solutions of the embodiments of the present application or the prior art clearer, the accompanying drawings needed in the embodiments or prior art description will be briefly introduced. Obviously, the accompanying drawings in the following description only need to be some embodiments of the present application, and other drawings can be obtained by those skilled in the art without any creative effort.

[0041] Figure 1 is a schematic diagram of a network communication mode between a data center of an enterprise headquarters, branch or other target terminal and the headquarters in the prior art;

[0042] Figure 2 is a schematic diagram of a cloud-based Internet access control mode provided by an embodiment of the present application;

[0043] Figure 3 is a schematic diagram of a cloud-based Internet access control method provided by an embodiment of the present application;

[0044] Figure 4 is a schematic diagram of introducing access traffic of a branch network exit into an edge node provided by an embodiment of the present application;

[0045] Figure 5 is a schematic diagram of introducing access traffic of a user terminal device into an edge node provided by an embodiment of the present application;

[0046] Figure 6 is a working principle diagram of a cloud-based Internet access control system provided by an embodiment of the present application;

[0047] Figure 7 is a structural schematic diagram of an edge node provided by an embodiment of the present application;

[0048] Figure 8 is a step flow chart of a security access control process of an edge node provided by an embodiment of the present application;

[0049] Figure 9 is a logic flow chart of HTTP / HTTPS traffic inspection provided by an embodiment of the present application;

[0050] Figure 10 is a structural schematic diagram of a cloud-based Internet access control system provided by an embodiment of the present application;

[0051] Figure 11 is a structural schematic diagram of an electronic device provided by an embodiment of the present application. DETAILED DESCRIPTION

[0052] With reference to the drawings of the embodiments of the present application, the technical solutions in the embodiments of the present application will be clearly and completely described. Obviously, the described embodiments are only a part of the embodiments of the present application, but not all the embodiments of the present application. Based on the embodiments of the present application, all the other embodiments obtained by a person of ordinary skill in the art without creative effort belong to the scope of the present application.

[0053] As shown in Figure 1 , the network communication between the data center of the enterprise headquarters, branch or other target terminal and the headquarters is usually realized through MPLS or VPN. The employees access internal resources through the intranet when they are in the enterprise, and the employees need to enter the intranet of the enterprise through the connection VPN when they access the enterprise application remotely. The traffic of the branch is first sent back to the enterprise headquarters, and various security devices such as DDoS, WAF, IDS, IPS, Internet behavior management, etc. are deployed in the enterprise headquarters to realize the centralized processing of the inspection and filtering of the outgoing and incoming traffic.

[0054] However, with the popularity of cloud computing, more and more enterprises will put applications on the cloud, and diversified mobile users and BYOD devices, the IT department needs to handle the mixed deployment of applications and provide services for the increasingly diversified and widely distributed users, while ensuring security, and this network and security structure is difficult to adapt to the new trend. At present, at least the following problems exist in the implementation scheme:

[0055] The traffic of the branch accessing the Internet needs to be transmitted to the headquarters for traffic inspection and filtering, resulting in large delay, in addition, network fluctuations will also have a large negative impact on user experience;

[0056] The enterprise needs to maintain a virtual private network (Virtual Private Network, VPN) or multiprotocol label switching (Multiprotocol Label Switching, MPLS) between the headquarters, branch and data center, and the use and management cost is high, and the expansibility is poor;

[0057] The enterprise needs to maintain independent security devices such as DDoS, WAF, IDS, IPS, etc., and the maintenance cost is high, the use is difficult, and it is difficult to implement fine access control, and this model defaults the intranet to be safe, once the intranet is invaded, it is easy to cause horizontal movement, and bring huge security risks.

[0058] Therefore, in order to adapt to the continuous development of cloud computing and the new trend of more and more applications on the cloud, the present application proposes a new and efficient cloud-based multi-user security management and control technology to meet the new challenges of the rapid development of enterprise security (such as Figure 2 ).

[0059] Embodiment one

[0060] Figure 3 is a schematic diagram of an interaction process of a cloud-based Internet control method provided by an embodiment of the present application. As shown in the figure, the interaction process is completed by three parties of a cloud security management platform, a target terminal and an edge node, and the method mainly includes the following steps: Figure 3

[0061] Step 101, the cloud security management platform configures a flow diversion policy and a security access control policy for a target user;

[0062] Step 102, the cloud security management platform sends the flow diversion policy to the edge node and the target terminal corresponding to the target user respectively, so that the target terminal can divert access traffic to the edge node according to the flow diversion policy;

[0063] Step 103, the cloud security management platform sends the security access control policy to the edge node, so that the edge node performs security access control processing on the access traffic according to the security access control policy;

[0064] Step 104, the target terminal obtains the flow diversion policy configured by the cloud security management platform for the target user corresponding to the target terminal from the cloud security management platform;

[0065] Step 105, the target terminal diverts the access traffic to the corresponding edge node according to the obtained flow diversion policy;

[0066] Step 106, the edge node obtains the network attribute of the target terminal according to the access traffic from the target terminal;

[0067] Step 107, the edge node determines the security access control policy of the target user corresponding to the target terminal according to the flow diversion policy obtained from the cloud security management platform and the network attribute of the target terminal;

[0068] Step 108, the edge node performs security access control processing on the access traffic from the target terminal according to the security access control policy.

[0069] The above method will be described in detail below, and optional or alternative embodiments thereof will be described.

[0070] As shown in the figure, steps 101 to 103 are implemented on the cloud security management platform. Figure 3

[0071] ​​In the embodiment, the target user can be a corporate user or an individual user. Generally, each target user corresponds to a user account, which can be registered by the target user or assigned by the cloud security management platform. Before configuring the target user with the steering policy and the security access control policy, the cloud security management platform can also verify the user account information sent by the target user in response to an access request sent by the target user through the target terminal, to verify the identity of the target user. Only when the identity verification is passed, the target user can be configured with the steering policy and the security access control policy, and the steering policy is issued to the edge node and the target terminal corresponding to the target user, and the security access control policy is issued to the edge node. It should be noted that the cloud security management platform can issue the steering policy and the security access control policy in the following ways: actively or passively, and directly or indirectly. For example, the cloud security management platform can actively issue the steering policy and the security access control policy to the edge node, the cloud security management platform can passively issue the steering policy to the target terminal in response to a request sent by the target user through the target terminal, the cloud security management platform can directly issue the steering policy and the security access control policy to the edge node, and the cloud security management platform can first issue the steering policy and the security access control policy to the configuration manager, and then the configuration manager issues them to the edge node (i.e. indirectly). In summary, the present application does not make special limitations on the way of issuing the steering policy and the security access control policy. It should also be noted that the target terminal corresponding to the target user can be a network exit of a branch office, or a terminal device of an individual user (hereinafter referred to as a user terminal device). The user terminal device can include, but is not limited to, one or more of a smart phone, a tablet computer, a portable computer, or a desktop computer, etc. electronic devices with network connection function and data access function, and the present application does not make special limitations.

[0072] When the target terminal is a network exit of a branch office, the steering policy includes configuration information for establishing a steering tunnel at the network exit of the branch office; when the target terminal is a user terminal device, the steering policy includes configuration information for establishing a steering tunnel through a steering application set on the user terminal device. The target terminal can establish a steering tunnel between the corresponding edge node according to the above configuration information. Specifically, the steering policy can include a steering method and address information of the corresponding edge node. The steering method can be a network tunneling protocol, so that the target terminal establishes a steering tunnel between the corresponding edge node through the steering method.

[0073] It should be noted that the network tunneling protocol in the flow directing mode can be a generic routing encapsulation (GRE), an internet protocol security (IPSec), a proxy auto-configuration (PAC), or other network tunneling protocols supported by the target terminal, and the mode is flexible and various. The generic routing encapsulation (GRE) is used to encapsulate data packets of certain network layer protocols (for example, IP and IPX) so that the encapsulated data packets can be transmitted in another network layer protocol; the internet protocol security (IPSec) is a protocol package that protects the internet protocol (IP) network transmission protocol family (a set of some interrelated protocols) by encrypting and authenticating IP protocol packets. For more specific descriptions of the flow directing mode and the flow directing process, refer to the following description of the working principle of the target terminal.

[0074] In addition, the address information of the edge node can include, but is not limited to, an IP address, a domain name, and the like of the edge node, and can also be a device number of the edge node or any related information capable of identifying the edge node, and the present application does not specially limit this. Thus, the target terminal can determine the edge node for which the flow tunnel needs to be established according to the address information, and establish the corresponding flow tunnel.

[0075] In addition, preferably, the flow directing strategy can further include a traffic filtering mode and a checking strategy. According to the traffic filtering mode, it can be determined that the access traffic corresponding to certain target access domain names of the target terminal needs to be flow directed, or the access traffic corresponding to certain target access domain names does not need to be flow directed, and the like. According to the checking strategy, it can be determined that checking needs to be performed on certain types of access traffic and corresponding checking rules, and the like, such as that checking needs to be performed on HTTP / HTTPS access traffic, and whether certain network properties contained in the HTTP / HTTPS access traffic conform to the checking rules, and the like. Thus, by pre-configuring the traffic filtering mode and the checking strategy, the access traffic can be screened before flow directing, so that the situations of mis-flow directing or missing-flow directing are avoided, the accuracy of flow directing is ensured, and the security of internet access is further ensured.

[0076] In some embodiments, the administrator configures a security access control policy for the target user on the cloud security management platform, so that the edge node can perform corresponding security access control processing on the access traffic from the corresponding target terminal according to the security access control policy. Specifically, the security access control policy can include at least one of an access control policy for IP, port, and protocol, an access control policy for DNS request, an access control policy for HTTP / HTTPS, and an access control policy for identity information.

[0077] In addition, the security access control processing can also include filtering processing on the access traffic from the target terminal according to the network attribute (such as IP, port, or protocol, etc.) of the target terminal, forwarding the allowed access traffic to the target website, and blocking the unallowed access traffic, thereby ensuring the security of Internet access.

[0078] It should be noted that the security control policy can contain multiple rules, wherein each rule corresponds to a matching condition and a handling action, and the corresponding handling action is executed when the matching condition is met. The matching condition corresponds to a logical comparison symbol, which is used to determine whether the matching condition is met, and the handling action includes allowing access, prohibiting access, and observing access, wherein observing access means allowing access and recording this access, so that the security administrator can observe the request behavior without blocking the request.

[0079] As shown in Table 1 below, Table 1 lists the definitions of the security control policies in the three-layer firewall, DNS, and HTTP access control modules.

[0080] Table 1

[0081]

[0082]

[0083] In addition, multiple rules can also correspond to different priorities, and be executed according to the priority. When one rule in the multiple rules is executed, other rules with lower priority than the rule will not be executed.

[0084] As an example, as shown in Table 2 below, Table 2 lists that each rule can contain a combination of multiple conditions, which can be combined by logical AND (&&), logical OR (||), and logical NOT (!).

[0085] Table 2

[0086]

[0087] In order to make the skilled in the art better understand the security access control policy in the embodiments of the present application, the specific way of setting the security access control policy is illustrated below. For more specific security access control policy and control process, please refer to the introduction of the working principle of the edge node below.

[0088] For example, for access control of dangerous domain names, the user can select the domain name type that needs to be blocked on the relevant operation interface to prevent access to any domain name under this type, such as C&C botnet, malware, phishing, virus Trojan or ransomware, etc., so as to avoid known and potential security risks on the Internet.

[0089] For example, for access control of domain name categories, the domain name categories can have two levels, the first level (i.e. a large type such as entertainment) contains multiple second-level categories (such as entertainment information, literature and fiction, lottery, etc.). In actual operation, in order to facilitate, when the user selects a large category on the relevant operation interface, all second-level categories under this large category will be selected, so that access to domain names under all second-level categories can be prohibited or passed.

[0090] For example, for access control of http / https, the user can set the access control policy on the relevant operation interface and create corresponding rules, wherein the number of rules can be set arbitrarily, each rule is provided with a matching condition, a disposition manner and a priority, and the user can adjust the priority through the arrow on the operation interface, such as up (increasing the priority), down (decreasing the priority), top (the highest priority) or bottom (the lowest priority).

[0091] For example, for filtering and checking of traffic, the user can select which traffic to filter and check on the relevant operation interface, such as checking HTTP / HTTPS traffic, and can also set matching conditions, logical symbols and matching targets for filtering and checking.

[0092] For example, for identity and access control, when the relevant condition of identity matching is configured in the control policy, identity authentication is automatically triggered. For example, when the user mailbox, group mailbox or group ID meets certain conditions, identity authentication is triggered. If the user's mailbox is equal to the set value, the corresponding target resource can be accessed. Alternatively, when the user accesses this resource for the first time, the policy engine executes this rule, judges whether the user identity information is required for this rule, if the user identity information is required, the identity authentication page is redirected, the user provides the identity, and the policy engine judges whether the rule setting condition is met and executes the corresponding disposition action (here, whether to allow access).

[0093] For example, for access control of dangerous domain names, the user can select the domain name type that needs to be blocked on the relevant operation interface to prevent access to any domain name under this type, such as C&C botnet, malware, phishing, virus Trojan or ransomware, etc., so as to avoid known and potential security risks on the Internet. Figure 3As shown, steps 104 to 105 are implemented on the target terminal. The target terminal obtains the traffic steering policy configured for the target user corresponding to the target terminal from the cloud security management platform, and then steers the access traffic of the target terminal to the corresponding edge node according to the traffic steering policy.

[0094] In an example embodiment of the present application, the traffic steering policy includes a traffic steering manner and address information of the edge node. The target terminal establishes a traffic steering tunnel between the target terminal and the edge node according to the traffic steering manner and the address information of the edge node, so as to steer the access traffic meeting the traffic steering policy to the edge node through the traffic steering tunnel. It should be noted that in this embodiment, the edge node can be an edge node in the same region as the target terminal, wherein the same region can be the same city (such as Beijing, Shanghai, etc.) or the same region (such as the Northeast region, the North China region, or the North America region, the Asia region, etc.). It should be noted that the number of edge nodes in the same region connected by the target terminal can be unlimited. For example, the target terminal can only establish a traffic steering tunnel with the edge node closest to the target terminal to ensure low latency of the access traffic to the edge node. Or, for example, the target terminal establishes a traffic steering tunnel (i.e., a primary traffic steering tunnel and a backup traffic steering tunnel) with two edge nodes (i.e., a primary edge node and a backup edge node) respectively, and steers the access traffic to the two edge nodes respectively, to ensure high availability and stability of the target terminal to the edge node network.

[0095] As described above, in some embodiments, the target terminal can be a network exit of a branch office, and the access traffic of the branch office network exit is introduced into the corresponding edge node. Figure 4 is a schematic diagram provided by an embodiment of the present application for introducing the access traffic of the branch office network exit into two edge nodes (a primary edge node and a backup edge node). As shown, Figure 4 When the branch office of the enterprise accesses an Internet application (such as IaaS, SaaS, a data center, an enterprise application), the branch office obtains a traffic steering policy from the cloud security management platform, the traffic steering policy including a traffic steering manner and address information of a primary edge node and a backup edge node assigned to the branch office (for example, assigned by the cloud security management platform according to the geographic location of the branch office, etc.), and the branch office is thereby configured at the network exit according to the corresponding traffic steering manner (such as GRE, IPSec, etc.) to establish a primary traffic steering tunnel and a backup traffic steering tunnel with the primary edge node and the backup edge node respectively, so as to steer the access traffic to the primary edge node and the backup edge node respectively for security access control processing when subsequent access traffic is generated. It should be noted that the traffic steering manner of the two traffic steering tunnels can be arbitrarily set, and can be the same or different, which is not specially limited by the present application.

[0096] Through the above method, the access traffic of the branch network outlet is directly diverted to the edge node, so that the traffic of the branch no longer needs to be backhauled to the enterprise headquarters for unified traffic inspection and filtering, in addition, the branch can also access the edge node in a flexible and diverse manner, significantly reducing the time delay of accessing the Internet, and greatly improving the user experience.

[0097] As described above, in some embodiments, the target terminal can be a user terminal device, when the target terminal is a user terminal device, an application for diversion can be pre-installed thereon, and the target user sends a request for obtaining the diversion policy to the cloud security management platform by logging in the application, and the specific process is as follows:

[0098] The user starts and logs in the diversion application on the user terminal device, and provides corresponding credentials (such as username and password, etc.) to complete identity authentication;

[0099] After identity authentication, the user sends a request for obtaining the diversion policy to the cloud security management platform through the user terminal device;

[0100] The user obtains the diversion policy configured for the user from the cloud security management platform through the user terminal device, the diversion policy includes the IP address allocated to the user terminal device and the address information of the edge node allocated to the user terminal device, so that the corresponding diversion tunnel can be established according to the IP address allocated to the user terminal device and the address information of the edge node.

[0101] This is especially suitable for enterprise employee home office and field work application scenarios, through identity authentication of enterprise employees, the employees are allowed to directly access the Internet in a time and place independent manner, and data does not need to be backhauled to the enterprise, which is flexible and convenient.

[0102] Figure 5 is a schematic diagram provided by an embodiment of the application for introducing the access traffic of the user terminal device to two edge nodes (primary edge node and standby edge node). As Figure 5As shown, when an employee accesses an Internet application (such as IaaS, SaaS, a data center, an enterprise application, etc.) through a user terminal device, the employee needs to first log in to the client software (i.e., the diversion application) pre-installed on the user terminal device, send a request for configuring a diversion policy to the cloud security management platform, then receive the diversion policy fed back by the cloud security management platform through the client software, the diversion policy including the IP address of the user terminal device allocated by the cloud security management platform and the address information of the primary edge node and the standby edge node allocated to the user terminal device according to the geographic location of the user terminal device, the user terminal device being configured according to the corresponding diversion mode (such as IPSec, PAC, etc.) to establish a primary diversion tunnel and a standby diversion tunnel with the primary edge node and the standby edge node respectively, and then divert the access traffic of the user terminal device to the primary edge node and the standby edge node respectively. It should be noted that the diversion modes of the two diversion tunnels can be set arbitrarily, and can be the same or different, with high flexibility.

[0103] Through the above method, when the user terminal device remotely accesses the enterprise application, the virtual private network (VPN) is no longer needed, and the individual user can safely access the Internet at any time, at any location and through any network, and the access traffic no longer needs to be sent back to the branch or back to the enterprise headquarters, but is directly transmitted from the user terminal device to the corresponding edge node and enters the Internet, solving the problems of delay and bandwidth, and improving the user experience.

[0104] In addition, in some embodiments, the target terminal can also obtain and install a CA root certificate from the cloud security management platform, which can be generated by default by the cloud security management platform or generated and uploaded by the target user. The CA root certificate needs to be added to the root certificate trust list of the system and the browser, and the root CA certificate is used for dynamic certificate issuance for the domain name of the HTTPS request of the target terminal. Through this processing mode, the security of Internet access is further enhanced.

[0105] As shown in FIG. 1, the cloud security management platform is connected to the Internet and the edge nodes. Figure 3 As shown, steps 106 to 108 are implemented on the edge node.

[0106] In this embodiment, the plurality of edge nodes distributedly deployed form a secure cloud. Each edge node can be connected to at least one target terminal, and each edge node pre-stores the diversion policy and the security access control policy configured for each target user obtained from the cloud security management platform. In addition, preferably, a full-stack security software program is run on each edge node, and various types of security software programs can be added according to needs, with greater flexibility and being able to meet various types of security access control needs.

[0107] When the edge node receives the access traffic of a target terminal, the network attribute of the target terminal is acquired. Specifically, the network attribute of a target terminal can include the IP address, port, protocol and diversion mode of the target terminal. By analyzing the network attribute of the target terminal, the edge node can determine that the received access traffic is the access traffic from which target terminal, and further find the security access control policy of the target user corresponding to the target terminal. Since the edge node saves the mapping relationship between the IP address of the target terminal and the target user corresponding to the target terminal, when the edge node receives the access traffic of a target terminal, the IP address of the target terminal is acquired, and then the target user corresponding to the target terminal is acquired in the mapping relationship. The security access control policy is bound to the target user corresponding to the target terminal, and the target user has been determined, so the security access control policy of the target user corresponding to the target terminal can be acquired. The target user can be identified by the network ID account of the target user.

[0108] Then, the edge node runs the security access control engine based on the security access control policy, and realizes the security access control processing of the access traffic.

[0109] In the embodiment, the security access control processing can include various security access control from three layers to seven layers, for example, the access control policy of IP, port and protocol, the access control policy of DNS request, the access control policy of HTTP / HTTPS and the access control policy of identity information.

[0110] To this end, the edge node of the embodiment runs three-layer to seven-layer security management software, including but not limited to the security management module as shown in the following figure: Figure 6

[0111] Three-layer firewall: filtering of data packets according to IP (IP address, IP address list, IP type, etc.), port, protocol, geographic location and other types at the network layer.

[0112] ​Domain name classification management module: obtain the domain name in the DNS resolution request and the HTTP / HTTPS request, determine the domain name category (such as entertainment, information, video, phishing, etc.) to which the domain name belongs according to the domain name, so as to support other modules to realize access control for the domain name category. In some embodiments, the cloud security management platform has a domain name classification library for managing domain names, wherein for each domain name, the domain name category to which the domain name belongs is recorded. Usually, the domain name category is divided by the operator of the cloud security management platform. The operator of the cloud security management platform manages and maintains the classification library on the cloud security management platform, for example, adds or deletes a domain name category, and adds or deletes a domain name under a domain name category, etc. The operator of the cloud security management platform sends the domain name and the domain name category to which it belongs in the classification library to the edge node. Of course, a domain name classification library can also be customized in the edge node, or the default domain name classification library on the cloud security management platform can be directly used, which is not limited here.

[0113] Secure DNS module: based on the domain name in the DNS request and the corresponding domain name category, and based on the access control rules, the security control of the resolution is realized. For example, the domain names of phishing and C2 types are blocked, and the domain names of specified types are passed.

[0114] Traffic inspection module: used for access control at the HTTP and HTTPS layers. In some embodiments, when receiving https access traffic sent by the target terminal, the traffic inspection module uses the CA root certificate corresponding to the target user corresponding to the target terminal to issue a dynamic certificate for the domain name to be accessed, and implements https handshake with the https access traffic, further enhancing the security of internet access. In addition, when accessing https, the request traffic can also be decrypted. The traffic inspection module supports fine access control for free combination of URL, domain name, request parameter, domain name category, response status code, file upload / download type, file suffix, etc.

[0115] Identity and access control module: the edge node can determine whether to enable identity authentication according to an access control policy, and when identity authentication is enabled, direct the access to an identity authentication page, the identity authentication interface including at least one identity authentication option, according to received selection information on the identity authentication interface for the at least one identity authentication option, determine an identity authentication policy corresponding to the selection information, wherein the identity authentication policy includes an identity information authentication policy and / or a permission information authentication policy. In some embodiments, the identity and access control module determines whether to enable identity authentication of a target user according to a secure access control policy, and when identity authentication of the target user is enabled, directs the access to an identity authentication page, which can be provided by an external identity provider (such as WeChat Enterprise, DingTalk), and after the target user completes identity authentication, feedbacks identity information (username, email, organization department, etc.) of the target user, and then the identity and access control module determines whether to allow access to corresponding resources based on the identity information of the target user and the secure access control policy. For example, determine whether the finance department can access the OA system, determine whether the R&D department can access the technical website, etc., and make personalized settings according to specific job requirements, with high flexibility.

[0116] Data leakage prevention module: for determining whether the access traffic has a data leakage risk according to the uniform resource locator (URL) in the DNS resolution request and the HTTP / HTTPS request and the file information of the uploaded file. In some embodiments, access control can be performed according to request domain name, URL (Uniform Resource Locator, URL), request method, response status code, and uploaded file information, etc. to check whether the request will cause information leakage. For example, a rule is set in the secure access control policy to prevent uploading of files with certain suffixes (such as pdf, doc, xls), or access control is performed on the upload point URL of a website, thereby avoiding employees from uploading sensitive files, effectively preventing data leakage, and enhancing the security of Internet access.

[0117] It should be noted that the edge node has full-stack secure access control capability through the above-mentioned security management module, but this is only one embodiment of the present application, and in actual application, the security management module on the edge node can not be limited in this way, and can be reduced or increased according to business needs.

[0118] It should be noted that, Figure 7 The arrow direction in the figure indicates the transmission direction of the access traffic, which is outwards, but in actual application, it is not limited to this. In fact, the edge node can not only perform secure access control on outwards access traffic, but also on inwards traffic data.

[0119] Further, in the above embodiment, the method can further include the following steps (not shown in the figure):

[0120] At step 109, the edge node records the security access control processing procedure and / or security access control processing result of the access traffic on the edge node through a log, and sends the log information to the cloud security management platform.

[0121] At step 110, the cloud security management platform receives the log information from the edge node, and aggregates, counts and analyzes the security access control processing procedure and / or security access control processing result in the log information in various dimensions (various security issues), displays a visual analysis view in each dimension on the platform, facilitates intuitive access to attack and threat conditions, and sends corresponding threat events to the centralized security analysis SIEM platform for further analysis and reporting, so as to prevent damage or limit damage caused by attacks.

[0122] In the embodiment, the edge node is provided with full-stack security control management capability, and only needs to implement security management and control of the access traffic of the target terminal according to the diversion strategy and the security access control strategy configured by the cloud security management platform for the target terminal, and the target terminal no longer needs to manage numerous security devices, thereby greatly reducing the cost. In addition, the distributed deployment of the edge node allows the target terminal to access one or more edge nodes in the same area based on the principle of proximity, significantly reduces the time delay of information reaching the edge node, and greatly improves the user experience.

[0123] Embodiment two

[0124] In order for those skilled in the art to have a deep understanding of the working principle of the edge node in the above embodiment, the composition structure and working process of the edge node will be described below in combination with a specific application example. Among them, Figure 7 is a schematic diagram of the composition structure of an edge node provided by the embodiment of the present application, Figure 8 is a flowchart of security access control on an edge node provided by the embodiment of the present application.

[0125] As shown in Figure 7 , the edge node can include a load balancer and multiple security servers, wherein the load balancer is used to forward the access traffic to one of the multiple security servers, and the security servers run a configuration management module, a traffic scheduling module, a three-layer firewall module, a secure DNS module, a traffic inspection module, etc. The configuration management module receives the configuration of the cloud security management platform and provides the configuration to other modules, and other modules perform corresponding security access control processing on the access traffic according to the security access control strategy.

[0126] The access traffic of the target terminal arrives at the network interface of the edge node, which can be a load balancer, and the same network interface can receive all the traffic of the target terminal. The access traffic enters a security server through the network interface, and the security server processes the received access traffic as follows (as shown in Figure 8

[0127] The traffic scheduling module stores the network attributes of all target terminals (including network exit IP, tunnel IP on exit diversion device, etc.) and the mapping relationship with the target terminals. The traffic scheduling module identifies which target terminal the traffic belongs to according to the received data packet. As shown in Table 3 below, when a data packet with an exit IP of 10.2.1.0 / 24 is received, it is found that it belongs to target terminal A, and when a data packet with an exit IP of 10.2.7.0 / 24 is received, it is found that it belongs to target terminal B.

[0128] Table 3

[0129] Draining mode Network address or public network exit address in the draining device Target terminal GRE 10.2.1.0 / 24 A IPSec 10.2.3.0 / 24 B PAC 58.56.78.45 / 32 C GRE 10.2.5.0 / 24 D GRE 10.2.8.0 / 24 E IPSec 10.2.7.0 / 24 B

[0130] The three-layer firewall module implements filtering and processing of data packets according to the security access control policy. This module supports setting multiple rules, and each firewall rule is executed in order according to priority. Each rule contains a rule condition and a disposition method (allow, prohibit, observe). Each rule allows free combination of multiple rule types. As shown in Table 4 below, typical rule types include:

[0131] Table 4

[0132]

[0133] In particular, for ease of setting, the three-layer firewall module also supports disposition by application protocol, including but not limited to the following commonly used application protocols:

[0134] Table 5

[0135] Protocol name Protocol port HTTP 80 HTTPS 443 ICMP ICMP protocol has no port FTP 20,21 SSH 22 Telnet 23 DNS 53, 853 (DNS over TLS) POP 109, 110, 995 (secure POP3) SMTP 25, 465 (secure SMTP) MySQL 3306

[0136] Generally, each protocol has a corresponding default protocol port, but some special scenarios may not use the default protocol port, such as running an https service on port 8443. In addition, users can also customize the application protocol port, such as enterprise administrators can configure a non-standard protocol port for a protocol, and notify the cloud security management platform of the protocol port information corresponding to the protocol. The cloud security management platform will issue the received protocol port information to the edge node. In this way, the three-layer firewall can implement access control for the non-standard protocol port of the protocol.

[0137] ​For the convenience of understanding, an example of a firewall rule is given as shown in Table 6 below, the rule destination IP is 1.1.1.0 / 24 or 8.8.8.8, and the application protocol is the data packet of UDP, ICMP and TCP, which will be blocked:

[0138] Table 6

[0139]

[0140] The secure DNS module, the data packet processed by the three-layer network firewall module, if the secure DNS function is enabled, enters the secure DNS processing logic.

[0141] The HTTP / HTTPS traffic inspection module, if the HTTP / HTTPS traffic inspection is enabled, enters the HTTP / HTTPS inspection module, which performs access control on the request domain name, URL, request method, response status code and other conditions;

[0142] By default, only the standard HTTP port (i.e. 80 / HTTP, 443 / HTTPS) is controlled, and for non-standard ports, access control needs to be enabled on the security management platform for specific non-standard ports. In order to process HTTPS encrypted traffic, the traffic inspection module needs to first issue a certificate according to the current request domain name.

[0143] It should be noted that, Figure 7 The arrow direction in the edge node indicates the transmission direction of the access traffic, but in actual application, it is not limited thereto. In fact, the edge node can not only perform security access control on the outgoing access traffic, but also on the incoming traffic data.

[0144] Figure 9 is a logic flowchart provided by the embodiment of the application for HTTP / HTTPS traffic inspection. As shown in Figure 9 The request domain name, uniform resource locator URL, request method and response status code are controlled, which can include:

[0145] Determine whether the port type is a standard port (i.e. 80 / 443 port);

[0146] If it is a standard port, directly enable access control on the request domain name, uniform resource locator URL, request method and response status code;

[0147] If it is a non-standard port, determine whether traffic inspection is enabled for that non-standard port. It should be noted that traffic inspection for that non-standard port needs to be enabled on the cloud security management platform first. If enabled, access control will be performed on the request domain name, Uniform Resource Locator URL, request method, and response status code.

[0148] In this embodiment, after the security access control process, the result of the control process is recorded in the log information and sent to the cloud security management platform. Specifically, this includes:

[0149] Each security module at the edge node outputs logs in the corresponding format after processing the appropriate type of access traffic. The log format is configurable by the cloud security management platform. For example, by default, only requests that hit the forbidden mode are logged. Other logs, due to their large volume, are not logged by default, but are aggregated and output at time intervals (e.g., once every 5 minutes). Logs can be recorded for requests in the allowed and observation modes.

[0150] Each module has its own log format, but in common, each log entry includes, but is not limited to, the fields shown in Table 7 below:

[0151] Table 7

[0152]

[0153] Specifically, the logs for the DNS security module also include the log fields shown in Table 8 below:

[0154] Table 8

[0155]

[0156]

[0157] Specifically, for HTTP / HTTPS logs, there are also log fields as shown in Table 9 below:

[0158] Table 9

[0159]

[0160] It should be noted that in some embodiments, for a three-layer firewall, only the aggregate log of access control rules that are hit can be recorded.

[0161] In this embodiment, each security module of the edge node provides rich log information. The cloud security management platform can aggregate, statistically analyze, and perform various dimensions (various security issues) on this log information, displaying visual analysis views of each dimension on the platform to intuitively obtain attack and threat information, and connecting the corresponding threat events to the SIEM platform.

[0162] In the present embodiment, the security cloud platform provides, but is not limited to, the following types of data analysis and visualization analysis shown in Table 10:

[0163] Table 10

[0164]

[0165] Embodiment Three

[0166] Figure 10 is a constituent block diagram of a cloud-based Internet access control system provided by an embodiment of the present application, as shown in the figure, the system comprises: Figure 10 a cloud security management platform 1061, configured to configure a flow diversion policy and a security access control policy for a target terminal, send the flow diversion policy to an edge node 1062 and the target terminal (the target terminal in the figure can be a branch 10631, an enterprise headquarters 10632, a home office device 10633, a mobile office device 10634 and a BYOD 10635), and send the security access control policy to the edge node 1062;

[0167] the edge node 1062, configured to perform security access control processing on access traffic from the target terminal according to the security access control policy.

[0168] In some embodiments, the above system can further comprise:

[0169] a target terminal, configured to establish a flow diversion tunnel between the target terminal and the edge node according to the flow diversion policy.

[0170] The target terminal comprises a user terminal device and a network exit of a branch, when the target terminal is the user terminal device, a flow diversion application is preset on the user terminal device, and a flow diversion tunnel is established between the user terminal device and the edge node 1062 through the flow diversion application according to the flow diversion policy; when the target terminal is the network exit of the branch, a flow diversion tunnel is established between the network exit and the edge node 1062 according to the flow diversion policy.

[0171] For technical details not disclosed in the cloud-based Internet access control system provided by the present embodiment, please refer to the description of the cloud-based Internet access control method in the foregoing embodiments, which will not be repeated here.

[0172] Embodiment Four

[0173] The following is an apparatus embodiment of the present application, which can be used to execute the method embodiments of the present application. For details not disclosed in the apparatus embodiment of the present application, please refer to the method embodiments of the present application.

[0174]

[0175] ​The embodiment provides a cloud-based Internet access control device, which is arranged on an edge node. The device has the function of executing the above method example, and the function can be realized by hardware or corresponding software executed by hardware. The device can include:

[0176] An acquisition unit is configured to acquire network attributes of the target terminal according to the access traffic received from the target terminal;

[0177] A determination unit is configured to determine a security access control policy of a target user corresponding to the target terminal according to the pre-stored diversion policy and the network attributes of the target terminal;

[0178] A control unit is configured to perform security access control processing on the access traffic from the target terminal according to the security access control policy.

[0179] The embodiment also provides a block diagram of a cloud-based Internet access control device, which is arranged on a cloud security management platform. The device has the function of executing the above method example, and the function can be realized by hardware or corresponding software executed by hardware. The device can include:

[0180] A configuration unit is configured to configure a diversion policy and a security access control policy for a target user;

[0181] A first sending unit is configured to send the diversion policy to the edge node and the target terminal corresponding to the target user, so that the target terminal diverts the access traffic to the edge node according to the diversion policy;

[0182] A second sending unit is configured to send the security access control policy to the edge node, so that the edge node performs security access control processing on the access traffic according to the security access control policy.

[0183] The embodiment also provides a block diagram of a cloud-based Internet access control device, which is arranged on a target terminal. The device has the function of executing the above method example, and the function can be realized by hardware or corresponding software executed by hardware. The device can include:

[0184] An acquisition unit is configured to acquire a diversion policy from a cloud security management platform, wherein the diversion policy is a diversion policy of a target user corresponding to the target terminal;

[0185] A diversion unit is configured to divert the access traffic to a corresponding edge node according to the diversion policy.

[0186] It should be noted that the apparatus provided in the above embodiments is only used as an example for the division of the above functional modules in realizing the functions thereof, and in actual applications, the above functions can be distributed to different functional modules according to the needs, that is, the internal structure of the device is divided into different functional modules to complete all or part of the above-described functions. In addition, the apparatus and method embodiments provided in the above embodiments belong to the same concept, and the specific implementation process is detailed in the method embodiments, which will not be described here.

[0187] Embodiment five

[0188] The embodiment provides a computer readable medium, which stores a computer program, and the program is executed by a processor to realize each step of a cloud-based Internet access control method as shown in the specification. Figure 1

[0189] It should be noted that the present application realizes all or part of the processes in the above embodiments, which can be completed by a computer program to instruct related hardware, and the computer program can be stored in a computer readable storage medium, and the computer program can realize the steps of the above method embodiments when executed by a processor. The computer program includes computer program code, which can be in the form of source code, object code, executable file or some intermediate form, etc. The computer readable medium can include any entity or device capable of carrying the computer program code, recording medium, U disk, mobile hard disk, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signal, telecommunication signal and software distribution medium, etc. Of course, there are other ways of readable storage medium, such as quantum memory, graphene memory, etc. It should be noted that the content of the computer readable medium can be appropriately increased or decreased according to the requirements of legislation and patent practice in the jurisdiction, for example, in some jurisdictions, according to the legislation and patent practice, the computer readable medium does not include electrical carrier signals and telecommunication signals.

[0190] Embodiment six

[0191] Figure 11 is a structural schematic diagram of an electronic device according to an embodiment of the present application. As shown in Figure 11 ​As shown in the hardware layer, the electronic device includes a processor, and optionally further includes an internal bus, a network interface, and a memory. The memory can include a memory such as a random-access memory (RAM), and can further include a non-volatile memory such as at least one disk memory. Of course, the electronic device can further include other hardware required by the business.

[0192] The processor, the network interface, and the memory can be connected to each other through the internal bus, which can be an industry standard architecture (ISA) bus, a peripheral component interconnect (PCI) bus, or an extended industry standard architecture (EISA) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 11 Only a line segment is used to represent the bus in the figure, but it does not mean that there is only one bus or only one type of bus.

[0193] The memory is used to store programs. Specifically, the program can include program code including computer operation instructions. The memory can include a memory and a non-volatile memory, and provide instructions and data to the processor. The processor reads the corresponding computer program from the non-volatile memory into the memory and then runs. The processor executes the program stored in the memory to perform the steps of the method as Figure 3 All steps in the cloud-based Internet access control method.

[0194] The communication bus mentioned in the above device can be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus, etc. The communication bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, only one thick line is used to represent the bus in the figure, but it does not mean that there is only one bus or only one type of bus. The communication interface is used for communication between the above electronic device and other devices.

[0195] The bus includes hardware, software, or both for coupling together various components including the above-described components. For example, the bus can include an Accelerated Graphics Port (AGP) or other graphics bus, an Enhanced Industry Standard Architecture (EISA) bus, a Front Side Bus (FSB), a HyperTransport (HT) interconnect, an Industry Standard Architecture (ISA) bus, an Infmiband interconnect, a Low Pin Count (LPC) bus, a memory bus, a Micro Channel Architecture (MCA) bus, a Peripheral Component Interconnect (PCI) bus, a PCI-Express (PCI-X) bus, a Serial Advanced Technology Attachment (SATA) bus, a Video Electronics Standards Association local (VLB) bus, or another suitable bus or a combination of two or more of these. Where appropriate, the bus can include one or more buses. Although the present embodiments describe and show a particular bus, the present embodiments contemplate any suitable bus or interconnect.

[0196] The memory can include a Random Access Memory (RAM) that can also include a Non-Volatile Memory (NVM). The memory can also be at least one storage device that is located remotely from the processor.

[0197] The memory can include a mass storage for data or instructions. As an example and not by way of limitation, the memory can include a Hard Disk Drive (HDD), a floppy disk drive, a flash memory, a Compact Disc (CD) Read Only Memory (ROM), a Digital Versatile Disc (DVD) ROM, a Blu-ray disc, a magnetic tape, or a Universal Serial Bus (USB) drive or a combination of two or more of these. The memory can include removable or non-removable (or fixed) media, where appropriate. In particular embodiments, the memory is non-volatile, solid-state memory. In particular embodiments, the memory includes Read Only Memory (ROM). Where appropriate, this ROM can be mask-programmed ROM, programmable ROM (PROM), erasable PROM (EPROM), electrically erasable PROM (EEPROM), electrically alterable ROM (EAROM), or flash memory or a combination of two or more of these. The memory can be a memory drive, a memory unit, a memory card, an onboard memory, or a combination of two or more of these, where appropriate. Where appropriate, the memory can be a non-transitory memory or other storage medium.

[0198] The processor described above can be a general processor, including a central processing unit (CPU), a network processor (NP), etc.; can also be a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or other programmable logic device, a discrete gate or transistor logic device, a discrete hardware component.

[0199] It should be explained that, for the convenience and brevity of description, it can be clearly understood by those skilled in the art that only the above-mentioned division of functional units and modules is exemplified, and in actual application, the above-mentioned functions can be completed by different functional units and modules according to needs, that is, the internal structure of the device is divided into different functional units or modules to complete all or part of the functions described above. Each functional unit and module in the embodiment can be integrated in one processing unit, or each unit can exist physically, or two or more units can be integrated in one unit. The integrated unit can be realized in the form of hardware or in the form of software functional unit. In addition, the specific name of each functional unit and module is only for easy distinction, and does not limit the protection scope of the present application. The specific working process of the unit and module in the system can refer to the corresponding process in the foregoing method embodiment, which will not be repeated here.

[0200] The device, equipment, system, module or unit illustrated in the above embodiments can be specifically realized by a computer chip or entity, or by a product with certain functions. A typical implementation device is a computer. Specifically, the computer can be, for example, a personal computer, a laptop computer, a vehicle-mounted human-computer interaction device, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an electronic mail device, a game console, a tablet computer, a wearable device, or a combination of any of these devices.

[0201] Although the present application provides method operation steps as described in the embodiments or flowcharts, more or fewer operation steps can be included based on conventional or non-inventive means. The order of steps listed in the embodiments is only one of the many step execution orders, and does not represent the only execution order. In actual device or terminal product execution, the method order shown in the embodiments or the drawings can be executed in sequence or in parallel (for example, in a parallel processor or multi-thread processing environment, or even in a distributed data processing environment).

[0202] The present application is described in reference to the flowchart and / or block diagrams of the methods, apparatus (systems) and computer program products according to embodiments of the present application. It will be understood that each block of the flowchart and / or block diagrams, and combinations of blocks in the flowchart and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general purpose computer, special purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions specified in the flowchart and / or block diagram block or blocks. Figure 1 Figure 1

[0203] These computer program instructions can also be stored in a computer- readable memory that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer-readable memory produce an article of manufacture including instructions which implement the function specified in the flowchart and / or block diagram block or blocks. Figure 1 Figure 1

[0204] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart and / or block diagram block or blocks. Figure 1 Figure 1

[0205] It should be noted that, in the description, relative terms such as first and second, and the like, can be used solely to distinguish one from another without necessarily implying any actual relationship or order between or among the entities or operations so distinguished. Also, the terms "comprises", "comprising", or any other variation thereof, are intended to cover a non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements does not include only those elements but can include other elements not expressly listed or inherent to such process, method, article, or apparatus. An element proceeded by "comprises... a" does not, without more constraints, exclude the presence of additional identical elements in the process, method, article, or apparatus that comprises the element.

[0206] ​​​​​​Various embodiments are described in related manner in the specification, and the same or similar parts among various embodiments can be referred to each other. Each embodiment focuses on the difference from other embodiments. In particular, for the device, electronic device and readable storage medium embodiments, since they are basically similar to the method embodiments, the description is relatively simple, and the relevant parts can be referred to the part of the method embodiment.

[0207] The above only describes the preferred embodiments of the present application, and is not used to limit the protection scope of the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application.

Claims

1. A cloud-based Internet access control method applied to an edge node, the edge node being connected with at least one target terminal, the edge node comprising a primary edge node and a backup edge node, the method comprising: obtaining network attributes of the target terminal according to access traffic received from the target terminal, the network attributes comprising a network egress IP address and / or a tunnel IP address on an egress steering device; determining a security access control policy of a target user corresponding to the target terminal according to a pre-stored steering policy and the network attributes of the target terminal; performing security access control processing on the access traffic from the target terminal according to the security access control policy, comprising: filtering the access traffic according to the network attributes of the target terminal; if the access traffic passes the filtering, performing further processing, comprising: obtaining a uniform resource locator and file information of an uploaded file contained in the access traffic; if it is determined that the access traffic has a data leakage risk according to the uniform resource locator and the file information, blocking the access traffic; otherwise, sending the access traffic to a corresponding service node; wherein: the target terminal establishes a primary steering tunnel and a backup steering tunnel with the primary edge node and the backup edge node respectively; the edge node comprises a load balancer and a plurality of security servers, the load balancer being configured to forward the access traffic to one of the plurality of security servers, and the security server comprising a traffic scheduling module; wherein the traffic scheduling module stores the network attributes of all the target terminals and a mapping relationship with the target terminals, and identifies the target terminal corresponding to the access traffic according to the network attributes of the received access traffic.

2. The method of claim 1, wherein, The security access control policy comprises at least one of an access control policy for IP, port and protocol, an access control policy for DNS request, an access control policy for HTTP / HTTPS, and an access control policy for identity information.

3. The method of claim 1, wherein, The filtering of the access traffic according to the network attributes of the target terminal, if the access traffic passes the filtering, performing further processing, can also be: obtaining a target access domain name contained in the access traffic; determining a domain name category corresponding to the target access domain name according to the target access domain name; if the domain name category is a target category, sending the access traffic to a corresponding service node.

4. The method of claim 1, wherein, The filtering of the access traffic according to the network attributes of the target terminal, if the access traffic passes the filtering, performing further processing, can also be: indicating the target terminal to display an identity authentication interface, the identity authentication interface comprising at least one identity authentication option; determining an identity authentication policy corresponding to selection information received from the identity authentication interface according to the selection information for the at least one identity authentication option; performing identity authentication processing on the target terminal according to the identity authentication policy; if the identity authentication processing is passed, sending the access traffic to a corresponding service node.

5. The method of claim 4, wherein, The identity authentication policy comprises an identity information authentication policy and / or an authority information authentication policy.

6. The method of claim 1, wherein, The access traffic is filtered according to the network attribute of the target terminal; if the access traffic passes the filtering, further processing is performed, which can also be: The access traffic is subjected to HTTP / HTTPS access control processing according to a pre-set HTTP / HTTPS access control policy. If the access traffic does not pass the HTTP / HTTPS access control processing, corresponding error information is returned to the target terminal.

7. The method of claim 6, wherein, Before the access traffic is subjected to HTTP / HTTPS access control processing according to a pre-set HTTP / HTTPS access control policy, the method further comprises: Obtaining a CA root certificate from a cloud security management platform; When receiving https access traffic sent by a target terminal, a CA root certificate corresponding to a target user of the target terminal is used to issue a certificate for a target access domain name, and https handshake is implemented with the https access traffic. 8.A cloud-based Internet access control method applied to a cloud security management platform, wherein, The method comprises: Configuring a target user with a diversion policy and a security access control policy; Sending the diversion policy to an edge node and a target terminal corresponding to the target user, so that the target terminal diverts access traffic to the edge node according to the diversion policy; Sending the security access control policy to the edge node, so that the edge node performs security access control processing on the access traffic according to the security access control policy; The edge node comprises a primary edge node and a backup edge node, and the following steps are applied to the edge node: According to the received access traffic from the target terminal, obtaining the network attribute of the target terminal, the network attribute comprising a network egress IP address and / or a tunnel IP address on an egress diversion device; According to a pre-stored diversion policy and the network attribute of the target terminal, determining a security access control policy of a target user corresponding to the target terminal; According to the security access control policy, performing security access control processing on the access traffic from the target terminal, comprising: Filtering the access traffic according to the network attribute of the target terminal; If the access traffic passes the filtering, further processing is performed, comprising: Obtaining a uniform resource locator and file information of an uploaded file contained in the access traffic; According to the uniform resource locator and the file information, if it is determined that the access traffic has a data leakage risk, the access traffic is blocked; Otherwise, the access traffic is sent to a corresponding service node; The target terminal establishes a primary diversion tunnel and a backup diversion tunnel with the primary edge node and the backup edge node, respectively; The edge node comprises a load balancer and a plurality of security servers, the load balancer being configured to forward access traffic to one of the plurality of security servers, and the security server comprising a traffic scheduling module. ​ The flow scheduling module saves network attributes of all target terminals and mapping relationships with the target terminals, and identifies a target terminal corresponding to access traffic according to network attributes of the received access traffic.

9. The method of claim 8, wherein, The target terminal includes a user terminal device or a network outlet of a branch.

10. The method of claim 9, wherein, When the target terminal is a user terminal device, the diversion strategy includes configuration information for establishing a diversion tunnel through a diversion application program arranged on the user terminal device.

11. The method of claim 9, wherein, When the target terminal is a network outlet of a branch, the diversion strategy includes configuration information for establishing a diversion tunnel at the network outlet.

12. The method of claim 8, wherein, The diversion strategy includes a diversion mode, and the diversion mode is a network tunnel protocol.

13. The method of claim 12, wherein, The network tunnel protocol includes GRE, IPSec, PAC, a custom network tunnel protocol, or other network tunnel protocols supported by the target terminal.

14. The method of claim 9, wherein, When the target terminal is a user terminal device, sending the diversion strategy to the target terminal corresponding to the target user includes: According to an access request of the target terminal, feeding back a diversion strategy of a target user corresponding to the target terminal to the target terminal.

15. The method of claim 8, wherein, The security access control strategy includes at least one of an access control strategy for IP, port, and protocol, an access control strategy for DNS request, an access control strategy for HTTP / HTTPS, and an access control strategy for identity information.

16. The method of claim 8, wherein, The method further includes: Obtaining log information from the edge node, and analyzing and / or visualizing processing results of security access control in the log information.

17. A cloud-based Internet access control method applied to a target terminal, wherein, The target terminal includes a user terminal device or a network outlet of a branch, and the method includes: Obtaining a diversion strategy from a cloud security management platform, the diversion strategy being a diversion strategy of a target user corresponding to the target terminal; Diverting access traffic to a corresponding edge node according to the diversion strategy; The edge node includes a primary edge node and a backup edge node, and the edge node applies the following steps: According to received access traffic from a target terminal, obtaining network attributes of the target terminal, the network attributes including a network outlet IP address and / or a tunnel IP address on an outlet diversion device; According to a pre-stored diversion strategy and the network attributes of the target terminal, determining a security access control strategy of a target user corresponding to the target terminal; According to the security access control strategy, performing security access control processing on access traffic from the target terminal, including: According to the network attributes of the target terminal, performing filtering processing on the access traffic; If the access traffic passes the filtering processing, performing further processing, including: Obtaining a uniform resource locator and file information of an uploaded file contained in the access traffic; According to the uniform resource locator and the file information, if it is determined that the access traffic has a data leakage risk, blocking the access traffic; Otherwise, sending the access traffic to a corresponding service node; The target terminal establishes a primary diversion tunnel and a backup diversion tunnel with the primary edge node and the backup edge node, respectively. ​ The edge node comprises a load balancer and a plurality of security servers, the load balancer is configured to forward access traffic to a security server of the plurality of security servers, and the security server comprises a traffic scheduling module; The traffic scheduling module stores network attributes of all target terminals and mapping relationships with the target terminals, and identifies a target terminal corresponding to the access traffic according to network attributes of the received access traffic.

18. The method of claim 17, wherein, The traffic steering strategy comprises a traffic steering mode, and the traffic steering mode is a network tunnel protocol.

19. The method of claim 17, wherein, When the target terminal is a user terminal device, the traffic steering strategy is obtained from the cloud security management platform, comprising: In response to a login request for a traffic steering application, a request for obtaining a traffic steering strategy is sent to the cloud security management platform; The cloud security management platform feeds back a traffic steering strategy corresponding to a target user of the current target terminal.

20. The method of claim 18, wherein, The traffic steering strategy further comprises address information of the edge node; The traffic steering strategy further comprises address information of the edge node; According to the traffic steering mode and the address information of the edge node, a traffic steering tunnel between the current target terminal and the edge node is established; Access traffic conforming to the traffic steering strategy is steered to the edge node through the traffic steering tunnel.

21. The method of claim 18, wherein, The network tunnel protocol comprises GRE, IPSec, PAC, a custom network tunnel protocol, or other network tunnel protocols supported by the target terminal.

22. The method of claim 17, wherein, The edge node is an edge node in the same region as the target terminal.

23. The method of claim 17, wherein: According to the traffic steering strategy, access traffic is steered to a primary edge node and a backup edge node, respectively. Further comprising:

24. The method of claim 17, wherein, A CA root certificate is obtained and installed from the cloud security management platform, the CA root certificate being generated by default by the cloud security management platform or generated and uploaded by the target user. The system comprises:

25. A cloud-based Internet access control system, characterized by, A cloud security management platform configured to configure a traffic steering strategy and a security access control strategy for a target user, and send the traffic steering strategy to an edge node and a target terminal corresponding to the target user, respectively; and send the security access control strategy to the edge node; An edge node applying the cloud-based Internet access control method of claim 1, configured to perform security access control processing on access traffic from the target terminal according to the security access control strategy. The system further comprises:

26. The system of claim 25, wherein, A target terminal configured to establish a traffic steering tunnel with an edge node according to a traffic steering strategy. A traffic steering application is configured on the target terminal, and the traffic steering application is configured to establish a traffic steering tunnel with an edge node.

27. The system of claim 26, wherein, Comprising:

28. A cloud-based Internet access control device, which is arranged at an edge node of a cloud-based Internet access control method according to claim 1, and is connected to at least one target terminal, wherein An obtaining unit configured to obtain network attributes of a target terminal according to received access traffic from the target terminal; A determining unit configured to determine a security access control strategy of a target user corresponding to the target terminal according to a pre-stored traffic steering strategy and the network attributes of the target terminal; A control unit configured to perform security access control processing on access traffic from the target terminal according to the security access control strategy. ​ 29. A cloud-based Internet access control device, which is arranged in a cloud security management platform for applying the cloud-based Internet access control method according to claim 8. The method comprises the following steps: A configuration unit is configured to configure a target user with a traffic steering policy and a security access control policy; A first sending unit is configured to send the traffic steering policy to an edge node and a target terminal corresponding to the target user, respectively, so that the target terminal steers access traffic to the edge node according to the traffic steering policy; A second sending unit is configured to send the security access control policy to the edge node, so that the edge node performs security access control processing on the access traffic according to the security access control policy.

30. A cloud-based Internet access control apparatus provided in a target terminal to which a cloud-based Internet access control method according to claim 17 is applied, characterized by The method comprises the following steps: An acquisition unit is configured to acquire a traffic steering policy from a cloud security management platform, the traffic steering policy being a traffic steering policy for a target user corresponding to a target terminal; A steering unit is configured to steer access traffic to a corresponding edge node according to the traffic steering policy.

31. A computer readable storage medium having stored thereon a computer program, characterized in that, The program is executed by a processor to implement the cloud-based Internet access control method of any one of claims 1-24.

32. An electronic device, comprising: It comprises: A processor; A memory for storing instructions executable by the processor; Wherein the processor is configured to execute the instructions to implement the cloud-based Internet access control method of any one of claims 1-24.

Citation Information

Patent Citations

  • Method and device for transmitting network attack defense policy and method and device for defending against network attack

    CN107710680A

  • Virtual network security protection system, and traffic attracting method and device

    CN107872443A