Intranet security detection method and device, electronic equipment and nonvolatile storage medium
By obtaining network protocol addresses and configuring virtual terminal devices, the problems of low scanner resource reuse rate and low detection efficiency in existing technologies are solved, and efficient intranet security detection is achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- CHINA TELECOM CORP LTD
- Filing Date
- 2022-10-08
- Publication Date
- 2026-04-14
AI Technical Summary
Existing technologies require bringing an offline scanner to the customer's site to connect to the customer's intranet, resulting in low scanner resource reuse rate and low efficiency in intranet security detection.
By obtaining the first network protocol address, configuring a virtual terminal device, and using the virtual terminal device to interact with the target intranet, the system can acquire and send test data generated by the scanner, receive and analyze feedback data from the target intranet, and achieve remote security status assessment.
It achieves high resource reuse rate of scanners, high efficiency of intranet security detection, no need for on-site operation by customers, and excellent service experience.
Smart Images

Figure CN115589591B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network security technology, and more specifically, to an intranet security detection method, apparatus, electronic device, and non-volatile storage medium. Background Technology
[0002] 5G wireless networks are characterized by flexibility, openness, and high heterogeneity, and are widely used in scenarios such as connected vehicles, smart grids, smart cities, smart healthcare, and customized private networks for various industries. However, while 5G networks bring convenience, they also face various security and performance challenges.
[0003] Currently, when providing security assessment services for the intranets built by 5G government and enterprise customers, related technologies require bringing offline scanners to the customer's site to connect with the customer's intranet. At the same time, the customer's cooperation is required to complete the docking of the offline scanner with the customer's network. This results in a poor customer experience, long service time, low scanner resource reuse rate, and low intranet security detection efficiency.
[0004] There is currently no effective solution to the above problems.
[0005] Application content
[0006] This application provides an intranet security detection method, apparatus, electronic device, and non-volatile storage medium to at least solve the technical problems of low scanner resource reuse rate and low intranet security detection efficiency caused by the need to bring an offline scanner to the customer's site to connect to the customer's intranet in related technologies.
[0007] According to one aspect of the embodiments of this application, an intranet security detection method is provided, comprising: obtaining a first network protocol address, wherein the first network protocol address is a network protocol address that can connect to a target intranet; configuring a virtual terminal device based on the first network protocol address, wherein the virtual terminal device is used to interact with the target intranet; obtaining target test data by configuring gateway information, and sending it to the target intranet through the virtual terminal device, wherein the target test data is data generated by a scanner for detecting the security status of the target intranet; receiving target feedback data and sending it to a scanner for analysis to obtain security status information of the target intranet, wherein the target feedback data is data fed back by the target intranet after receiving the target test data.
[0008] Optionally, obtaining the first network protocol address includes: retrieving the SIM card information corresponding to the virtual terminal device, wherein the SIM card information includes the data network name corresponding to the target intranet; accessing a general communication network based on the SIM card information and the data network name to obtain the first network protocol address, wherein the general communication network includes: a 5G network.
[0009] Optionally, the virtual terminal device includes: a target virtual terminal and an operating system corresponding to the target virtual terminal. Configuring the virtual terminal device according to the first network protocol address includes: virtualizing the network card of the operating system to obtain a target virtual network card; configuring the first network protocol address in the target virtual network card through a target interface, wherein the target interface is used to connect the target virtual terminal and the operating system, and the operating system after virtualization and configuration of the network card is used to simulate the actual terminal device and perform data interaction with the target intranet.
[0010] Optionally, obtaining target test data by configuring gateway information and sending it to the target intranet via a virtual terminal device includes: obtaining the second network protocol address of a first server, wherein the first server is a server running the virtual terminal device; setting the second network protocol address as the gateway information of the second server, wherein the second server is a server running a scanner, and the scanner in the second server after configuring the gateway information is used to interact with the first server; controlling the scanner to generate raw test data and preprocessing the raw test data to obtain target test data; and sending the target test data to the target intranet.
[0011] Optionally, preprocessing the original test data to obtain the target test data includes: determining the target data format, wherein the target data format is the data format supported by the target intranet; and converting the original test data into target test data in the target data format.
[0012] Optionally, the original test data includes: the original network protocol address, wherein the original network protocol address is the network protocol address of the second server, and sending the target test data to the target intranet includes: obtaining the original network protocol address; converting the original network protocol address into a target network protocol address in a target address format, wherein the target address format is a network protocol address format supported by a general communication network, including a 5G network; and sending the target test data to the target intranet according to the target network protocol address.
[0013] Optionally, the method further includes: when multiple target intranets exist, obtaining a first network protocol address corresponding to each target intranet; configuring a virtual terminal device based on the multiple first network protocol addresses, wherein the virtual terminal device is used to simulate actual terminal devices interacting with multiple target intranets; obtaining target test data corresponding to each target intranet and sending it to the corresponding target intranet through the virtual terminal device; receiving target feedback data corresponding to each target intranet and sending it to a scanner for analysis to obtain security status information of each target intranet.
[0014] According to another aspect of the embodiments of this application, an intranet security detection device is also provided, comprising: a protocol address acquisition module, configured to acquire a first network protocol address, wherein the first network protocol address is a network protocol address that can connect to a target intranet; a virtual terminal configuration module, configured to configure a virtual terminal device according to the first network protocol address, wherein the virtual terminal device is used to interact with the target intranet; a test data sending module, configured to acquire target test data by configuring gateway information and send it to the target intranet through the virtual terminal device, wherein the target test data is data generated by a scanner for detecting the security status of the target intranet; and a security status analysis module, configured to receive target feedback data and send it to a scanner for analysis to obtain security status information of the target intranet, wherein the target feedback data is data fed back by the target intranet after receiving the target test data.
[0015] According to another aspect of the embodiments of this application, an electronic device is also provided, the electronic device including a processor, the processor being used to run a program, wherein the program executes an intranet security detection method when running.
[0016] According to another aspect of the embodiments of this application, a non-volatile storage medium is also provided, the non-volatile storage medium including a stored computer program, wherein the device where the non-volatile storage medium is located executes an intranet security detection method by running the computer program.
[0017] In this embodiment, the method involves obtaining a first network protocol address, where the first network protocol address is a network protocol address that can connect to the target intranet; configuring a virtual terminal device based on the first network protocol address, where the virtual terminal device is used to interact with the target intranet; obtaining target test data by configuring gateway information and sending it to the target intranet through the virtual terminal device, where the target test data is data generated by the scanner to detect the security status of the target intranet; receiving target feedback data and sending it to the scanner for analysis to obtain the security status information of the target intranet, where the target feedback data is the data fed back by the target intranet after receiving the target test data. By migrating the IP obtained by the cloud-based 5G simulated terminal to the server where the 5G simulated terminal is located, and configuring the server IP where the 5G simulated terminal is located as the server gateway, the scanner can access the customer's intranet through the 5G simulated terminal, achieving the goal of remotely accessing the customer's intranet for security service assessment. This solves the technical problems of low scanner resource reuse rate and low intranet security detection efficiency caused by the need to bring the offline scanner to the customer's site to connect to the customer's intranet in related technologies. Attached Figure Description
[0018] The accompanying drawings, which are included to provide a further understanding of this application and form part of this application, illustrate exemplary embodiments and are used to explain this application, but do not constitute an undue limitation of this application. In the drawings:
[0019] Figure 1 This is a schematic diagram of a method flow for intranet security detection according to an embodiment of this application;
[0020] Figure 2 This is a schematic diagram of a network structure for implementing an intranet security detection method according to an embodiment of this application;
[0021] Figure 3 This is a schematic diagram of a method flow for a scanner to access a customer's intranet via a 5G analog terminal, according to an embodiment of this application.
[0022] Figure 4 This is a schematic diagram of the structure of an intranet security detection device according to an embodiment of this application;
[0023] Figure 5 This is a hardware structure block diagram of a computer terminal (or electronic device) for implementing a method for intranet security detection, according to an embodiment of this application. Detailed Implementation
[0024] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present application, and not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative effort should fall within the scope of protection of the present application.
[0025] To facilitate a better understanding of the embodiments of this application by those skilled in the art, some technical terms or nouns involved in the embodiments of this application are explained as follows:
[0026] 5G (Fifth Generation Mobile Communication Technology) is a new generation of broadband mobile communication technology characterized by high speed, low latency, and massive connectivity. 5G communication infrastructure serves as the network infrastructure for realizing the interconnection of humans, machines, and things. Currently, the focus of 5G applications is shifting from the consumer internet (2C) to the industrial internet (2B), empowering various industries. The difference lies in the fact that 2B applications can leverage 5G SA's unique technologies such as network slicing, service-oriented architecture, control-forward separation, and edge computing to achieve cloud-network convergence, providing users with customizable and differentiated "deterministic services." These services have very broad demand in fields such as industry, energy, video, and transportation.
[0027] Internet Protocol (IP): is a network layer protocol in the TCP / IP architecture.
[0028] Internet Protocol Address (IP Address): An IP address is a unified address format provided by the IP protocol. It assigns a logical address to every network and every host on the Internet to mask the differences in physical addresses.
[0029] Data Network Name (DNN): In 5G, the definition of DNN is equivalent to that of the previously defined APN. The two identifiers have the same meaning and contain the same information. DNN can be used to select SMF and UPF for PDU sessions, select the N6 interface for PDU sessions, and determine the policies to be applied to this PDU session. DNN can be used by operators in conjunction with S-NSSAI to allow subscribers to access any data network supported within the network slice associated with the S-NSSAI.
[0030] Gateway: Also known as an internetwork connector or protocol converter. A gateway enables network interconnection at the network layer and above. It is a complex network interconnection device used only for interconnecting two networks with different high-level protocols.
[0031] Network Address Translation (NAT): When some hosts within a private network have already been assigned local IP addresses (i.e., private addresses used only within this private network), but want to communicate with hosts on the Internet (without requiring encryption), the NAT method can be used.
[0032] Local Area Network (LAN): A type of network that typically covers an area of several kilometers. Its ease of installation, cost-effectiveness, and expandability make it widely used in various offices. LANs enable functions such as file management, application software sharing, and printer sharing. Maintaining LAN network security effectively protects data security and ensures the normal and stable operation of the LAN.
[0033] A scanner is a program that automatically detects security weaknesses on a local or remote host. It can quickly and accurately find vulnerabilities in the target and provide the user with the scan results. The scanner works by sending data packets to the target computer and then using the information returned to determine the target's operating system type, open ports, services provided, and other sensitive information.
[0034] 3GPP (3rd Generation Partnership Project): The goal of 3GPP is to achieve a smooth transition from 2G to 3G networks, ensure backward compatibility of future technologies, and support easy network construction and roaming and compatibility between systems. The 3GPP protocol is a mobile communication network protocol specification developed by the 3GPP organization, which includes 5G mobile communication networks.
[0035] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0036] Example 1
[0037] According to an embodiment of this application, a method embodiment for intranet security detection is provided. It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Furthermore, although a logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order than that shown here.
[0038] Figure 1This is a schematic diagram of a method flow for intranet security detection according to an embodiment of this application. Figure 2 This is a schematic diagram of a network structure for implementing an intranet security detection method according to an embodiment of this application, such as... Figure 1 and Figure 2 As shown, through Figure 2 The network structure shown is implemented Figure 1 The intranet security detection method in the document includes the following steps:
[0039] Step S102: Obtain the first network protocol address, wherein the first network protocol address is a network protocol address that can connect to the target intranet;
[0040] In some embodiments of this application, obtaining the first network protocol address includes the following steps: obtaining the SIM card information corresponding to the virtual terminal device, wherein the SIM card information includes the data network name corresponding to the target intranet; accessing a general communication network based on the SIM card information and the data network name to obtain the first network protocol address, wherein the general communication network includes: a 5G network.
[0041] In this embodiment, the target intranet is the client's intranet for which a security scanning service is planned, the first network protocol address is an IP address that can connect to the client's intranet, and the data network name is the client's network-specific Data NetworkName (DNN).
[0042] In this embodiment, the cloud-based 5G simulation terminal uses a customer-customized Data Network Name (DNN) to register the network and obtain an IP address to connect to the customer's intranet.
[0043] Specifically, the 5G simulated terminal (i.e., the virtual terminal device mentioned above) reads the test SIM card information through a standard card reader program, just like an actual 5G terminal. With the customer's consent, the test SIM card obtains the 5G customer-exclusive Data Network Name (DNN). The simulated terminal uses the customer-exclusive DNN to access the 5G network, thereby enabling the 5G simulated terminal to obtain an IP address for connecting to the customer's intranet.
[0044] Step S104: Configure the virtual terminal device according to the first network protocol address, wherein the virtual terminal device is used to interact with the target intranet;
[0045] In this embodiment, the virtual terminal device includes a target virtual terminal and an operating system corresponding to the target virtual terminal. In order to achieve the effect of sharing the IP of the simulated terminal with the server operating system, the configuration of the virtual terminal device according to the first network protocol address includes the following steps: virtualizing the network card of the operating system to obtain a target virtual network card; configuring the first network protocol address in the target virtual network card through the target interface, wherein the target interface is used to connect the target virtual terminal and the operating system, and the operating system after the network card is virtualized and configured is used to simulate the actual terminal device and the target intranet for data interaction.
[0046] In this embodiment, the target virtual terminal is a cloud-based 5G simulation terminal, and the operating system is the operating system on the server where the cloud-based 5G simulation terminal is located.
[0047] Specifically, a 5G 2B channel management module is deployed on the server where the 5G simulation terminal is located, and the IP obtained by the cloud-based 5G simulation terminal is ported to the operating system of the server where the 5G simulation terminal is located for use.
[0048] The aforementioned 5G 2B channel management module can send the IP obtained by the cloud-based simulated terminal to the operating system's network card for virtualization processing through the cloud-based simulated terminal and the operating system interface, thereby enabling the simulated terminal to activate and share the network channel, and ultimately sharing the simulated terminal's IP with the server operating system.
[0049] Step S106: By configuring gateway information, obtain target test data and send it to the target intranet through a virtual terminal device. The target test data is data generated by the scanner to detect the security status of the target intranet.
[0050] To achieve communication between the virtual terminal device and the scanner, the following steps are taken to obtain target test data by configuring gateway information and sending it to the target intranet via the virtual terminal device: obtaining the second network protocol address of the first server, where the first server is the server running the virtual terminal device; setting the second network protocol address as the gateway information of the second server, where the second server is the server running the scanner, and the scanner in the second server after configuring the gateway information is used to interact with the first server; controlling the scanner to generate raw test data and preprocessing the raw test data to obtain target test data; and sending the target test data to the target intranet.
[0051] In this embodiment, the first server is the server where the cloud-based simulated terminal is located, the second network protocol address is the internal network IP of the server where the 5G simulated terminal is located, and the second server is the server where the scanner is located.
[0052] In some embodiments of this application, preprocessing the original test data to obtain target test data includes: determining the target data format, wherein the target data format is a data format supported by the target intranet; and converting the original test data into target test data in the target data format.
[0053] In some embodiments of this application, the original test data includes: an original network protocol address. Sending the target test data to the target intranet includes: obtaining the original network protocol address; converting the original network protocol address into a target network protocol address in a target address format, wherein the target address format is a network protocol address format supported by a general communication network, including: a 5G network; and sending the target test data to the target intranet according to the target network protocol address.
[0054] In this embodiment, the scanner server and the 5G simulated terminal server are connected through an internal network. The 5G simulated terminal server sends and receives messages from the scanner through the Local Area Network Gateway (LAN Gateway) module. The data proxy forwarding module performs rule matching on the information received by the LAN Gateway and forwards it. The traffic destined for the customer's intranet (i.e., the test data mentioned above) is forwarded to the Network Address Translation (NAT) module. The NAT module performs IP address translation on the traffic destined for the customer's intranet, sharing the IP of the 5G simulated terminal. Thus, the traffic scanned by the scanner for the customer's intranet is delivered to the customer's intranet through the IP of the 5G simulated terminal.
[0055] As an optional implementation, the scanner interacts with the server where the 5G analog terminal is located using a LAN gateway module. This module is also deployed on the 5G analog terminal server. Meanwhile, the scanner server and the 5G analog terminal server are connected through an internal network. The server where the scanner is located is configured with the internal network IP of the server where the 5G analog terminal is located as the server gateway. The 5G analog terminal server sends and receives messages from the scanner through the LAN gateway module. The LAN gateway supports receiving raw format IP data with the target address being the customer's internal network from the internal network and supports forwarding the raw format IP data back to the scanner.
[0056] As an optional implementation, a dedicated line data proxy forwarding module is deployed on the 5G simulated terminal server. This module sends data to the scanner server, matches it according to relevant rules, and hands over the data packets that meet the rules to the NAT module for processing. For data received from the core network, it calls the LAN gateway to send it to the corresponding scanner server host according to preset rules.
[0057] As an optional implementation, a NAT module function is deployed on the 5G simulated terminal server. This function enables IP address translation of traffic scanning the customer's intranet, allowing the 5G simulated terminal to access the 5G customer's intranet via shared IP addresses.
[0058] Step S108: Receive target feedback data and send it to the scanner for analysis to obtain the security status information of the target intranet. The target feedback data is the data fed back by the target intranet after receiving the target test data.
[0059] To provide services to multiple customers simultaneously, the method further includes: in the presence of multiple target intranets, obtaining a first network protocol address corresponding to each target intranet; configuring a virtual terminal device based on the multiple first network protocol addresses, wherein the virtual terminal device is used to simulate actual terminal devices interacting with multiple target intranets; obtaining target test data corresponding to each target intranet and sending it to the corresponding target intranet through the virtual terminal device; receiving target feedback data corresponding to each target intranet and sending it to a scanner for analysis to obtain the security status information of each target intranet.
[0060] For example, such as Figure 2 As shown in the figure, DNNA, DNNB, and DNNC are the exclusive DNN names for customers A, B, and C, respectively. They follow the 5G service process in the standard 3GPP protocol and access different customer networks through different DNNs.
[0061] The intranet security detection method provided in the embodiments of this application can realize centralized deployment of scanners, provide services to multiple customers at the same time, with high reusability and low cost; it can remotely access the customer's intranet for security service assessment without going to the customer's site, which is highly efficient; and the customer does not need to configure anything, only needs to authorize the scanning, resulting in excellent service perception.
[0062] The intranet security detection method in steps S102 to S104 of the embodiments of this application will be further described below.
[0063] Figure 3 This is a schematic diagram illustrating a method flow for a scanner to access a customer's intranet via a 5G simulated terminal, according to an embodiment of this application. Figure 3 As shown, the method includes the following steps:
[0064] Step S302: Obtain the DNN based on the SIM card information;
[0065] Specifically, the 5G simulated terminal reads the test SIM card information through a standard card reader program, just like a regular 5G terminal. With the customer's consent, the test SIM card obtains the customer's exclusive Data Network Name (DNN).
[0066] Step S304: Obtain the IP address for connecting to the intranet;
[0067] Specifically, the cloud-based simulation terminal uses a customer-specific DNN to access the 5G network, thereby enabling the 5G simulation terminal to obtain an IP address for connecting to the customer's intranet.
[0068] Step S306: Share the IP address of the simulated terminal with the server operating system.
[0069] Specifically, the IP address of the cloud-based 5G simulation terminal is ported to the server where the 5G simulation terminal resides. A 5G 2B channel management module is deployed on the server where the 5G simulation terminal resides. This module's functions mainly include: developing a self-developed interface between the cloud-based simulation terminal and the operating system; virtualizing the IP address obtained by the cloud-based simulation terminal to the operating system's network card; enabling network activation and sharing of the simulation terminal's channel; and ultimately sharing the simulation terminal's IP address with the server's operating system.
[0070] Through the above steps, the IP address of the cloud-based 5G simulation terminal is migrated to the server where the 5G simulation terminal is located. The scanner server is configured with the IP address of the server where the 5G simulation terminal is located as the server gateway, and the scanner is connected to the customer's intranet through the 5G simulation terminal. This achieves the goal of remotely accessing the customer's intranet for security service assessment, thereby solving the technical problems of low scanner resource reuse rate and low intranet security detection efficiency caused by the need to bring the offline scanner to the customer's site to connect to the customer's intranet in related technologies.
[0071] Example 2
[0072] According to an embodiment of this application, an example of an intranet security detection method is provided. Specifically, the scanner accesses the intranet of a 5G enterprise customer via a cloud-based 5G simulated terminal. In this embodiment, the IP address obtained by the mobile terminal is used to simulate the customer's intranet IP address, including the following steps:
[0073] Step 1: With the customer's authorization, test the exclusive DNN of customer A (card 180****3654): nwdltest.5gzx.gd.
[0074] Step 2: The cloud-based simulated terminal reads the test card data, successfully initiates a connection request to the 5G network, and obtains the terminal IP address that can access the customer's intranet: 10.18.18.2.
[0075] Step 3: Configure the scanner host (name H1) with the LAN gateway IP of the server (name set to H2) where the 5G analog terminal is located: 172.41.171.20.
[0076] Step 4: Use the mobile terminal to register the network and obtain an IP address to simulate the customer's internal network IP address: 10.18.18.5.
[0077] Step 5: The scanner sends the scan data to server H2 (server name) through the private network. The scan data is then forwarded to the 5G network via a data proxy (shared analog terminal IP: 10.18.18.2). The 5G network then forwards the data to the customer's intranet 10.18.18.5.
[0078] Step 6: The customer's intranet device (in this example, a mobile terminal) responds to the scanning action. The response data is transmitted back to the server H2 via the 5G network. The data proxy forwards the response data to the scanner via the LAN gateway, thus enabling the scanner to remotely reach the customer A's intranet.
[0079] In this embodiment, a cloud-based 5G simulated terminal accesses the 5G network to obtain the terminal IP address that can reach the customer's intranet, and provides the IP address to the server where the simulated terminal is located. The scanner establishes a connection with the 5G simulated terminal server through the intranet, and can share the simulated terminal IP address through the various functional modules deployed on the server, enabling the scanner to remotely access the customer's intranet.
[0080] Example 3
[0081] According to an embodiment of this application, an embodiment of an intranet security detection device is also provided. Figure 4 This is a schematic diagram of the structure of an intranet security detection device according to an embodiment of this application. Figure 4 As shown, the device includes:
[0082] Protocol address acquisition module 40 is used to acquire a first network protocol address, wherein the first network protocol address is a network protocol address that can connect to the target intranet;
[0083] The virtual terminal configuration module 42 is used to configure a virtual terminal device according to the first network protocol address, wherein the virtual terminal device is used to interact with the target intranet.
[0084] The test data sending module 44 is used to obtain target test data by configuring gateway information and send it to the target intranet through a virtual terminal device. The target test data is data generated by the scanner to detect the security status of the target intranet.
[0085] The security status analysis module 46 is used to receive target feedback data and send it to the scanner for analysis to obtain the security status information of the target intranet. The target feedback data is the data fed back by the target intranet after receiving the target test data.
[0086] This embodiment provides a device capable of accessing the internal network of government and enterprise customers via a 5G network. It enables centralized scanners to communicate with the customer's internal network, achieving high-speed, dedicated channel, and secure and reliable remote scanning. This solves the problem of scanners remotely accessing any 5G customer's internal network and is used to remotely provide security risk identification services for the customer's internal network.
[0087] It should be noted that each module in the above-mentioned intranet security detection device can be a program module (for example, a set of program instructions that implement a certain function) or a hardware module. For the latter, it can be manifested in the following forms, but is not limited to them: each of the above modules is manifested as a processor, or the functions of each of the above modules are implemented by a processor.
[0088] It should be noted that the intranet security detection device provided in this embodiment can be used to perform... Figure 1 The intranet security detection method shown above is also applicable to the embodiments of this application, and will not be repeated here.
[0089] Example 4
[0090] According to an embodiment of this application, an embodiment of a computer terminal for implementing a method for intranet security detection is also provided. Figure 5 This is a hardware structure block diagram of a computer terminal (or electronic device) for implementing a method for intranet security detection, according to an embodiment of this application. Figure 5 As shown, the computer terminal 50 (or electronic device 50) may include one or more processors (shown as 502a, 502b, ..., 502n in the figure) (the processor may include, but is not limited to, a microprocessor MCU or a programmable logic device FPGA, etc.), a memory 504 for storing data, and a transmission module 506 for communication functions. In addition, it may also include: a display, an input / output interface (I / O interface), a universal serial bus (USB) port (which may be included as one of the ports of the I / O interface), a network interface, a power supply, and / or a camera. Those skilled in the art will understand that... Figure 5 The structure shown is for illustrative purposes only and does not limit the structure of the aforementioned electronic device. For example, computer terminal 50 may also include... Figure 5 The more or fewer components shown, or having the same Figure 5 The different configurations shown.
[0091] It should be noted that the aforementioned one or more processors and / or other data processing circuits are generally referred to herein as "data processing circuits". These data processing circuits may be wholly or partially embodied in software, hardware, firmware, or any other combination thereof. Furthermore, the data processing circuits may be a single, independent processing module, or wholly or partially integrated into any other element within the computer terminal 50 (or electronic device). As involved in the embodiments of this application, the data processing circuit serves as a processor control mechanism (e.g., selection of a variable resistor termination path connected to an interface).
[0092] The memory 504 can be used to store software programs and modules of application software, such as the program instructions / data storage device corresponding to the intranet security detection method in this embodiment. The processor executes various functional applications and data processing by running the software programs and modules stored in the memory 504, thereby realizing the aforementioned intranet security detection method. The memory 504 may include high-speed random access memory, and may also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 504 may further include memory remotely located relative to the processor, and these remote memories can be connected to the computer terminal 50 via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.
[0093] The transmission module 506 is used to receive or send data via a network. Specific examples of the network described above may include a wireless network provided by the communication provider of the computer terminal 50. In one example, the transmission device 506 includes a Network Interface Controller (NIC), which can connect to other network devices via a base station to communicate with the Internet. In another example, the transmission device 506 may be a Radio Frequency (RF) module, used for wireless communication with the Internet.
[0094] The display can be, for example, a touchscreen liquid crystal display (LCD) that allows a user to interact with the user interface of the computer terminal 50 (or electronic device).
[0095] It should be noted here that, in some optional embodiments, the above... Figure 5 The computer device (or electronic device) shown may include hardware elements (including circuitry), software elements (including computer code stored on a computer-readable medium), or a combination of both hardware and software elements. It should be noted that... Figure 5This is only one instance of a particular specific instance, and is intended to illustrate the types of components that may exist in the aforementioned computer equipment (or electronic equipment).
[0096] It should be noted that, Figure 5 The electronic device shown is used to perform intranet security detection. Figure 1 The method for intranet security testing shown above also applies to the electronic devices used for intranet security testing, and will not be repeated here.
[0097] Example 5
[0098] According to another aspect of the embodiments of this application, a non-volatile storage medium is also provided. The non-volatile storage medium includes a stored computer program, wherein the device where the non-volatile storage medium is located executes the following intranet security detection method by running the computer program: obtaining a first network protocol address, wherein the first network protocol address is a network protocol address that can connect to the target intranet; configuring a virtual terminal device according to the first network protocol address, wherein the virtual terminal device is used to interact with the target intranet; obtaining target test data by configuring gateway information, and sending it to the target intranet through the virtual terminal device, wherein the target test data is data generated by a scanner for detecting the security status of the target intranet; receiving target feedback data and sending it to the scanner for analysis to obtain the security status information of the target intranet, wherein the target feedback data is data fed back by the target intranet after receiving the target test data.
[0099] The sequence numbers of the embodiments in this application are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.
[0100] In the above embodiments of this application, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments.
[0101] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. The device embodiments described above are merely illustrative; for example, the division of units can be a logical functional division, and in actual implementation, there may be other division methods. For instance, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the displayed or discussed mutual coupling, direct coupling, or communication connection may be through some interfaces; the indirect coupling or communication connection between units or modules may be electrical or other forms.
[0102] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0103] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0104] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as a USB flash drive, read-only memory (ROM), random access memory (RAM), portable hard drive, magnetic disk, or optical disk.
[0105] The above description is only a preferred embodiment of this application. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principle of this application, and these improvements and modifications should also be considered within the scope of protection of this application.
Claims
1. A method for detecting intranet security, characterized in that, include: Obtain the first network protocol address, wherein the first network protocol address is a network protocol address that can connect to the target intranet; Based on the first network protocol address, a virtual terminal device is configured in the cloud, wherein the virtual terminal device is used to interact with the target intranet, and the virtual terminal device includes: a target virtual terminal and an operating system corresponding to the target virtual terminal; By configuring gateway information, target test data is obtained and sent to the target intranet through the virtual terminal device. The target test data is data generated by the scanner to detect the security status of the target intranet. The system receives target feedback data and sends it to the scanner for analysis to obtain the security status information of the target's intranet. The target feedback data is the data returned by the target's intranet after receiving the target test data. Configuring the virtual terminal device based on the first network protocol address includes: The network card of the operating system is virtualized to obtain the target virtual network card; The first network protocol address is configured in the target virtual network card through the target interface, wherein the target interface is used to connect the target virtual terminal and the operating system, and the operating system after network card virtualization processing and configuration is used to simulate the actual terminal device and the target intranet for data interaction; The configured gateway information includes: Obtain the second network protocol address of the first server, wherein the first server is the server running the virtual terminal device; The second network protocol address is set as the gateway information of the second server, wherein the second server is the server running the scanner, and the scanner in the second server after configuring the gateway information is used to interact with the first server.
2. The intranet security detection method according to claim 1, characterized in that, Obtaining the first network protocol address includes: Obtain the SIM card information corresponding to the virtual terminal device, wherein the SIM card information includes the data network name corresponding to the target intranet; Based on the SIM card information and the data network name, access a general communication network to obtain the first network protocol address, wherein the general communication network includes a 5G network.
3. The intranet security detection method according to claim 1, characterized in that, Acquiring target test data and sending it to the target intranet via the virtual terminal device includes: The scanner is controlled to generate raw test data, and the raw test data is preprocessed to obtain the target test data; Send the target test data to the target intranet.
4. The intranet security detection method according to claim 3, characterized in that, The target test data is obtained by preprocessing the original test data, including: Determine the target data format, wherein the target data format is a data format supported by the target intranet; The original test data is converted into the target test data in the target data format.
5. The intranet security detection method according to claim 3, characterized in that, The raw test data includes: the raw network protocol address, wherein the raw network protocol address is the network protocol address of the second server, and sending the target test data to the target intranet includes: Obtain the original network protocol address; The original network protocol address is converted into a target network protocol address in a target address format, wherein the target address format is a network protocol address format supported by a general communication network, including a 5G network. Based on the target network protocol address, the target test data is sent to the target intranet.
6. The intranet security detection method according to claim 1, characterized in that, The method also includes: In the case of multiple target intranets, obtain the first network protocol address corresponding to each target intranet; The virtual terminal device is configured based on the plurality of first network protocol addresses, wherein the virtual terminal device is used to simulate actual terminal devices to perform data interaction with the plurality of target intranets; The target test data corresponding to each target intranet is obtained and sent to the corresponding target intranet through the virtual terminal device; The system receives target feedback data corresponding to each target intranet and sends it to the scanner for analysis to obtain the security status information of each target intranet.
7. An intranet security detection device, characterized in that, include: The protocol address acquisition module is used to acquire a first network protocol address, wherein the first network protocol address is a network protocol address that can connect to the target intranet; A virtual terminal configuration module is used to configure a virtual terminal device in the cloud based on the first network protocol address. The virtual terminal device is used to interact with the target intranet. The virtual terminal device includes a target virtual terminal and an operating system corresponding to the target virtual terminal. The virtual terminal configuration module is further configured to virtualize the network card of the operating system to obtain a target virtual network card; and to configure the first network protocol address in the target virtual network card through the target interface, wherein the target interface is used to connect the target virtual terminal and the operating system, and the operating system after the network card is virtualized and configured is used to simulate the actual terminal device and the target intranet for data interaction; The test data sending module is used to obtain target test data by configuring gateway information and send it to the target intranet through the virtual terminal device. The target test data is data generated by the scanner to detect the security status of the target intranet. The security status analysis module is used to receive target feedback data and send it to the scanner for analysis to obtain the security status information of the target intranet, wherein the target feedback data is the data fed back by the target intranet after receiving the target test data; The test data sending module is further configured to obtain the second network protocol address of the first server, wherein the first server is the server running the virtual terminal device; and to set the second network protocol address as the gateway information of the second server, wherein the second server is the server running the scanner, and the scanner in the second server after configuring the gateway information is used to interact with the first server.
8. An electronic device, the electronic device comprising a processor, characterized in that, The processor is used to run a program, wherein the program executes the intranet security detection method according to any one of claims 1 to 6 when it runs.
9. A non-volatile storage medium, characterized in that, The non-volatile storage medium includes a stored computer program, wherein the device containing the non-volatile storage medium executes the intranet security detection method according to any one of claims 1 to 6 by running the computer program.
Citation Information
Patent Citations
Intranet remote scanning system and method thereof for scanning intranet
CN106534172A
Network online security detection method, system and device equipment and readable storage medium
CN111770110A