A cross-network exchange security management collaboration method
Patent Information
- Application Number
- CN202211662109.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-23
- Publication Date
- 2026-09-08
- Estimated Expiration
- 2042-12-23
AI Technical Summary
[0004]目前现有技术中针对高安全等级网络与低安全等级网络间安全保障信息协同的框架存在多个系统,结构复杂、协同性较差
本发明提出的一种跨网交换的安全管理协同方法,针对高等级网络与低等级网络间安全管理运维系统协同工作的需求,为了解决高低等级网络协同信息传输过程中数据真实性、可靠性的关键问题,提出了切实可行的高低等级网络安全运维管理系统协同框架,设计了基于XML格式的高低等级协同信息格式,规划了高低等级协同信息安全的可靠传输流程,能够确保高低等级网络安全管理运维系统协同工作过程中数据信息的安全可靠传输,该方法的提出,为高低等级网络安全管理运维系统协同工作提供了切实可行的方案,对建设高低等级网络融合系统具有重要的现实意义。
Smart Images

Figure CN115766288B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network service technology, and in particular to a collaborative method for security management of cross-network switching. Background Technology
[0002] With the continuous development of information technology, more and more data information needs to be transferred between networks with different security levels. However, due to the special nature of high-security networks, it is necessary to establish dedicated high-security network zones, isolation switching centers, and low-security network zones to achieve data processing and secure interaction.
[0003] High-security and low-security network areas each deploy relevant business systems and security protection measures. However, high-security network areas need to keep abreast of the security protection information of the low-security networks connected to them. Therefore, they need to coordinate security information with low-security network areas. However, how to ensure that high-security network areas receive security situation information and alarm information from low-security network areas in a timely manner, how to issue security baseline policies and security event queries to low-security network areas, and how to ensure the security and reliability of data transmission are key issues that they must address.
[0004] Currently, there are multiple existing frameworks for the coordination of security assurance information between high-security and low-security networks, which are complex in structure and have poor coordination. Summary of the Invention
[0005] Because the security and reliability of collaborative working mechanisms between high- and low-level networks cannot be guaranteed, especially during collaborative data transmission, the authenticity and reliability of data cannot be effectively guaranteed. Therefore, a secure and reliable collaborative working mechanism has not yet been established for the security management and maintenance systems of high- and low-level networks. This invention addresses the need for collaborative working between security management and maintenance systems of high- and low-level networks, focusing on solving the problems of data authenticity and reliability during collaborative information transmission between high- and low-level networks. It proposes a practical collaborative framework for high- and low-level network security operation and maintenance management systems and designs a secure and reliable transmission process to ensure the collaborative working of security management and maintenance systems between high- and low-level networks.
[0006] This invention is achieved through the following technical solution: A collaborative method for security management of cross-network switching includes the following steps: S1, the low-level network converts collaborative and interactive operation and maintenance data into standard XML files; S2. Add operation and maintenance information to the Information node of the XML file; S3. Low-level networks use low-level network cryptographic algorithms to complete the CivSignedInfo signature of XML files. S4. The low-level network uses a low-level network cryptographic algorithm to verify the authenticity of the CivSignedInfo and SecurityInfo contents of the XML file; S5. Low-level networks use a cross-network dedicated signature algorithm to sign the contents of SecurityInfo and write it into CroSignedInfo; S6. The lower-level network transmits the verified and signed XML file to the higher-level network through the high-low level network isolation exchange center. S7. High-level networks use a cross-network dedicated signature algorithm to verify the authenticity of the CroSignedInfo and SecurityInfo content in XML files; S8. The high-level network uses the high-level network cryptographic signature algorithm to perform signature calculation on the content of SecurityInfo and writes it into the MilSignedInfo signature. S9. The high-level network uses a high-level network cryptographic algorithm to verify the authenticity of the MilSignedInfo and SecurityInfo content, and then processes the received data after acceptance.
[0007] Furthermore, the XML file contains multiple Information nodes, each containing a single piece of independent operation and maintenance information.
[0008] Furthermore, the operation and maintenance information includes equipment asset information, equipment status information, alarm information, and security situation information transmitted from the low-level network to the high-level network, as well as baseline security policy information, security device query information, and alarm log query information transmitted from the high-level network to the low-level network.
[0009] Furthermore, the CivSignedInfo is signed based on the SecurityInfo node.
[0010] Furthermore, the XML file after S5 completion is sent remotely to the high-low level network isolation exchange center in the low-level network.
[0011] Furthermore, the XML file after completing S8 is sent to the high-level network security management and maintenance system via remote transmission in the high-level network.
[0012] Furthermore, the high- and low-level network isolation switching centers can record and trace the switching behavior through the InfoSum and Signature information recorded during data exchange.
[0013] Furthermore, the process executed when a higher-level network transmits data to a lower-level network is the reverse of the process executed when a lower-level network transmits data to a higher-level network.
[0014] The beneficial effects of this invention are: This invention proposes a cross-network exchange security management and collaboration method. Addressing the need for collaborative work between high-level and low-level network security management and maintenance systems, and to solve the key issues of data authenticity and reliability during collaborative information transmission between high and low-level networks, it proposes a practical collaborative framework for high- and low-level network security management and maintenance systems. It designs a high- and low-level collaborative information format based on XML and plans a reliable transmission process for high- and low-level collaborative information security. This ensures the secure and reliable transmission of data information during the collaborative work of high- and low-level network security management and maintenance systems. This method provides a practical solution for collaborative work between high- and low-level network security management and maintenance systems and has significant practical implications for building integrated high- and low-level network systems. Attached Figure Description
[0015] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0016] Figure 1 This invention provides a system framework for a cross-network switching security management and collaboration method. Figure 1 ; Figure 2 This invention provides a system framework for a cross-network switching security management and collaboration method. Figure 2 . Detailed Implementation
[0017] To make the objectives, technical solutions, and advantages of the present invention clearer, the present invention will be further described in detail below with reference to the embodiments and accompanying drawings. The illustrative embodiments and descriptions of the present invention are only used to explain the present invention and are not intended to limit the present invention.
[0018] Example 1 This embodiment proposes a specific implementation method for a cross-network switching security management collaboration method.
[0019] Since high-level and low-level networks cannot communicate directly, security management and maintenance systems deployed on both networks must exchange data through a dedicated isolation switching center if they need to work together. These high- and low-level isolation switching centers require special design, typically employing online or offline unidirectional transmission internally, and comprehensively utilizing various security protection measures such as boundary security, data security, and identity trust. Since this invention does not involve security protection aspects, they will not be described in detail here.
[0020] Each network's security management and maintenance system can monitor and manage its own network's security devices; and high-level network security management and maintenance systems can collaborate with low-level network security management and maintenance systems. Due to the existence of the isolation switching center, high-level and low-level networks cannot interact at the protocol level, only able to transmit data unidirectionally. This embodiment uses XML format to convert the information requiring collaborative interaction into standard XML files for unidirectional file transmission, thereby enabling collaborative work between the security management and maintenance systems of high-level and low-level networks. Furthermore, to ensure the authenticity and reliability of collaborative information, cryptographic signatures are used for information protection and verification. Since the cryptographic systems of high-level and low-level networks differ, a cryptographic system conversion method is employed to achieve the conversion and mutual recognition of signature information. The high- and low-level network security management collaborative architecture is as follows: Figure 1 As shown.
[0021] High- and low-level network collaboration information is encapsulated in a standardized XML format. The basic collaboration information format and items are as follows: <cooperationinfo> <securityinfo> / / Security assurance collaborative information <infosum> / / Security Assurance Collaborative Information Summary <infotime>< / InfoTime> / / Time when this information was generated <infosour>< / InfoSour> / / The source of information <infotarg>< / InfoTarg> / / The recipient of the information <infourge>2< / InfoUrge> / / Information urgency level: 1 indicates high, 2 indicates moderate, 3 indicates low <infosum> <infonum>< / InfoNum> / / Number of information entries in this message <information> < / information> / / Information entry, i.e., detailed collaboration information < / infonum> < / infosum> < / infourge> < / infotarg> < / infosour> < / infotime> < / infosum> < / securityinfo> <signature> / / Signature information <infohash>< / InfoHash> / / Fingerprint information of Information <civsignedinfo> < / civsignedinfo> / / Low-level network signature information <crosignedinfo> < / crosignedinfo> / / Cross-network dedicated signature information <milsignedinfo> < / milsignedinfo> / / High-level network signature information < / infohash> < / signature> < / cooperationinfo> In addition to the essential signature information, the nodes in the security management collaboration information can be added, reduced, or changed according to specific needs.
[0022] Example 2 This embodiment proposes a specific implementation method for operation and maintenance information of a cross-network switching security management collaboration method based on embodiment 1.
[0023] I. Security management and maintenance deployed in low-level networks need to transmit equipment assets, equipment status, alarm information, and security status information in this area to the high-level network security management and maintenance system. That is, the data information transmitted unidirectionally from the low-level network to the high-level network is equipment assets, equipment status, alarm information, and security status information. When reporting information, the relevant content of the Information node should be improved.
[0024] (1) Equipment asset information This information describes the asset information of security protection equipment. The relevant node information can be adjusted according to actual needs. Taking intrusion detection equipment as an example, the asset description is as follows: <information> <infotype>1< / InfoType> / / Information type: 1. Equipment assets, 2. Equipment status, 3. Alarm information, 4. Security status <classfun>2< / ClassFun> / / Security feature types: 1. Firewall, 2. Intrusion Detection, 3. Virus… <manufacture>xxxx< / Manufacture> / / Equipment supply location <functype>NIDS-4000< / FuncType> / / Product Model <serialnum>IDS-002< / SerialNum> / / Unique asset number <place>xxx LAN exit< / Place> / / Deployment location <address>11.22.3.56< / Address> / / Device address <makeuse>YES< / MakeUse> Is it in use? < / Information> .
[0025] (2) Equipment status This describes the current operating status of the security equipment. The relevant node information can be adjusted according to actual needs. Taking intrusion detection equipment as an example, the status information is described as follows: <information> <infotype>3< / InfoType> / / Information type: 1. Equipment assets, 2. Equipment status, 3. Alarm information, 4. Security status <serialnum>IDS-002< / SerialNum> / / Unique asset number <workstatus>YES< / WorkStatus> Is the operation normal? <cpuuse>56< / CpuUse> / / CPU usage percentage, 0-100 <memuse>40< / MemUse> / / Memory usage percentage, 0-100 <diskuse>20< / DiskUse> / / Disk usage percentage, 0-100 < / Information> .
[0026] (3) Alarm information Security alarm events generated by security protection equipment generally only require separate reporting to a higher-level network for high-risk alarms. Specific adjustments can be made based on needs. For example, an intrusion detection alarm might be described as follows: <information> <infotype>3< / InfoType> / / Information type: 1. Equipment assets, 2. Equipment status, 3. Alarm information, 4. Security status <serialnum>IDS-002< / SerialNum> / / Unique asset number <classfun>2< / ClassFun> / / Security feature types: 1. Firewall, 2. Intrusion Detection, 3. Virus… <alerturge>1< / AlertUrge> / / The urgency level of the alarm message is 1 for extremely high, 2 for high, and 3 for normal. <alertdispose>1< / AlertDispose> / / Has this alarm been handled? -1 Not handled, 0 Being handled, 1 Handled <alertnum>1< / AlertNum> / / The number of alarms included in this information is the same as the number in the EventInfo section below. <eventinfo> <eventnum>12306< / EventNum> / / Attack ID in the intrusion detection rule base <saddress>192.168.2.3< / SAddress> / / Attack source address <daddress>192.168.9.3< / DAddress> / / Target address <sport>7654< / SPort> / / Source port <dport>443< / DPort> / / Destination port <protocol>TCP< / Protocol> / / Protocol type <attacktype>Buffer overflow< / AttackType> / / Attack type <degree>1< / Degree> / / The severity of this attack: 1 High, 2 Medium, 3 Low <des>Exploiting the Windows SMB malformed request vulnerability< / Des> / / Detailed description of the attack < / EventInfo> < / Information> .
[0027] (4) Security situation The security management and operation system can receive various security events from this network and perform security posture analysis. The analysis results can be transmitted to higher-level networks for global analysis. The information related to the security posture analysis results can be adjusted according to actual needs. The security posture information is described as follows: <information> <infotype>4< / InfoType> / / Information type: 1. Equipment assets, 2. Equipment status, 3. Alarm information, 4. Security status <serialnum>Audit-001< / SerialNum> / / Unique asset number <starttime>2022-07-22 13:00< / EndTime> / / End time of security situation analysis <secstatus>2.4< / SecStatus> / / Security status level, ranging from 0 to 5, with 5 being the highest level of hazard. <higalertnum>16< / HigAlertNum> / / Number of security incidents with high threat level <midalertnum>75< / MidAlertNum> / / Number of security incidents with a medium threat level <perdispose>80< / PerDispose> / / Percentage of security incidents handled, 0-100 < / Information> me>2022-07-22 12:00< / StartTime> / / Start time of security posture analysis <endtime>.
[0028] Second, high-level network security management and operation systems need to send baseline security policies, security device query information, and alarm log query information to low-level network security management and operation systems for policy distribution and information retrieval. Therefore, the data information transmitted unidirectionally from the high-level network to the low-level network consists of baseline security policies, security device query information, and alarm log queries. When sending information, the main focus is on completing the relevant content of the Information node.
[0029] (1) Baseline security strategy High-level networks configure basic security baseline policies for security protection equipment in certain areas of low-level networks, based on requirements. This information can be adjusted according to actual needs. For example, regarding intrusion detection and firewalls, the information is described below: <information> <infotype>11< / InfoType> / / Information type: 11 is baseline security policy, 12 is device query, and 13 is alarm query. <policynum>2< / PolicyNum> / / The number of basic policies is the same as the number of PolicyInfo nodes. <policyinfo> <serialnum>IDS-002< / SerialNum> / / Unique asset number <saddress>any< / SAddress> / Detection source address range <daddress>192.168.2.1-192.168.2.254< / DAddress> / / Target range for detection <ruleid>124, 135, 356… … 10234, 12365< / RuleID> / / Enabled rule number <disposal>1< / Disposal> / / Alarm handling methods: 1 alarm, 2 alarms + blocking < / PolicyInfo> <policyinfo> <serialnum>FW-012< / SerialNum> / / Unique asset number <saddress>any< / SAddress> / Detection source address range <daddress>192.168.2.1-192.168.2.254< / DAddress> / / Target address range <protocol>TCP< / Protocol> / / Protocol type <interdiction>2< / Interdiction> / / Handling strategy: 1. Allow, 2. Block < / PolicyInfo> < / Information> .
[0030] (2) Safety equipment query information To query the status information of a specific security device, the information is described as follows: <information> <infotype>12< / InfoType> / / Information type: 11 is baseline security policy, 12 is device query, and 13 is alarm query. <serialnum>Audit-001< / SerialNum> / / Unique asset identifier, can be empty <classfun>2< / ClassFun> / / For security feature types, if the asset number is empty, query all devices of that type. < / Information> .
[0031] (3) Alarm log query For high-level networks, query alarm logs for further information. The query can be adjusted according to actual conditions. Alarm log query information is as follows: <information> <infotype>13< / InfoType> / / Information type: 11 is baseline security policy, 12 is device query, and 13 is alarm query. <querynum>3< / QueryNum> / / Number of query conditions <queryitem> / / Query conditions <queryrela>and< / QueryRela> / / Relationship with other conditions, and or or <degree>1< / Degree> / / The severity of the attack: 1 High, 2 Medium, 3 Low < / QueryItem> <queryitem> / / Query conditions <queryrela>and< / QueryRela> / / Relationship with other conditions, and or or <classfun>2< / ClassFun> / / Security feature types: 1. Firewall, 2. Intrusion Detection, 3. Virus… < / QueryItem> <queryitem> / / Query conditions <queryrela>and< / QueryRela> / / Relationship with other conditions, and or or <serialnum>IDS-002< / SerialNum> / / Unique asset number < / QueryItem> < / Information> .
[0032] Example 3 This embodiment proposes an information interaction process for a cross-network exchange security management collaboration method based on Embodiments 1 and 2.
[0033] Taking low-level network information reporting as an example, when information is generated, the low-level network cryptographic algorithm needs to be called to complete the CivSignedInfo signature. Before the information is transmitted to the high-low level network isolation exchange center, a signature verification service is used. First, the low-level network cryptographic algorithm is used to verify the authenticity and reliability of the CivSignedInfo signature and the SecurityInfo content. Then, a cross-network dedicated signature algorithm is used to calculate the signature of the SecurityInfo content and write it into the CroSignedInfo. After the high-low level network collaborative information reaches the high-level network through the high-low level network isolation exchange center, the signature verification service is used again. First, the cross-network dedicated signature algorithm is used to verify the authenticity and reliability of the CroSignedInfo signature and the SecurityInfo content. Then, the high-level network cryptographic signature algorithm is used to calculate the signature of the SecurityInfo content and write it into the MilSignedInfo. When the high-low level collaborative information arrives at the high-level network security management and maintenance system, the high-level network cryptographic algorithm is called to verify the MilSignedInfo signature and the SecurityInfo content. After acceptance, it is received and processed. The specific process is as follows: Figure 2 As shown.
[0034] The entire process ensures secure and reliable data transmission throughout the entire process of information exchange between high- and low-level networks, including information transmission, transmission and isolation switching on the low-level network, transmission on the high-level network, and information reception. When information is sent from the high-level network, the reverse process is executed.
[0035] The foregoing has shown and described the basic principles, main features, and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited to the above embodiments. The embodiments and descriptions in the specification are merely illustrative of the principles of the invention. Various changes and modifications can be made to the invention without departing from its spirit and scope, and all such changes and modifications fall within the scope of the present invention as claimed. The scope of protection of this invention is defined by the appended claims and their equivalents.< / serialnum> < / queryrela> < / queryitem> < / classfun> < / queryrela> < / queryitem> < / degree> < / queryrela> < / queryitem> < / querynum> < / infotype> < / information> < / classfun> < / serialnum> < / infotype> < / information> < / interdiction> < / protocol> < / daddress> < / saddress> < / serialnum> < / policyinfo> < / disposal> < / ruleid> < / daddress> < / saddress> < / serialnum> < / policyinfo> < / policynum> < / infotype> < / information> < / endtime> < / perdispose> < / midalertnum> < / higalertnum> < / secstatus> < / starttime> < / serialnum> < / infotype> < / information> < / des> < / degree> < / attacktype> < / protocol> < / dport> < / sport> < / daddress> < / saddress> < / eventnum> < / eventinfo> < / alertnum> < / alertdispose> < / alerturge> < / classfun> < / serialnum> < / infotype> < / information> < / diskuse> < / memuse> < / cpuuse> < / workstatus> < / serialnum> < / infotype> < / information> < / makeuse> < / address> < / place> < / serialnum> < / functype> < / manufacture> < / classfun> < / infotype> < / information>
Claims
1. A collaborative method for security management of cross-network switching, characterized in that, Includes the following steps: S1. The low-level network converts the collaborative operation and maintenance data into a standard XML file. The XML file is encapsulated in a hierarchical structure, including a CooperationInfo root node. The lower layers of the CooperationInfo root node contain SecurityInfo nodes for security assurance collaboration information and Signature nodes for signature information. The SecurityInfo node contains an InfoNum node for the number of information entries and at least one Information node for carrying detailed operation and maintenance information entries. The Signature node contains an InfoHash node for fingerprint information, a CivSignedInfo node for low-level network signature information, a CroSignedInfo node for cross-network dedicated signature information, and a MilSignedInfo node for high-level network signature information. S2. Add operation and maintenance information to the Information node of the XML file; S3. The low-level network uses a low-level network cryptographic algorithm to complete the CivSignedInfo signature of the XML file and write it into the CivSignedInfo node. S4. The low-level network uses a low-level network cryptographic algorithm to verify the authenticity of the CivSignedInfo and SecurityInfo contents of the XML file; S5. Low-level networks use a cross-network dedicated signature algorithm to sign the contents of SecurityInfo and write it into CroSignedInfo; S6. The lower-level network transmits the verified and signed XML file to the higher-level network through the high-low level network isolation exchange center. S7. High-level networks use a cross-network dedicated signature algorithm to verify the authenticity of the CroSignedInfo and SecurityInfo content in XML files; S8. The high-level network uses the high-level network cryptographic signature algorithm to perform signature calculation on the content of SecurityInfo and writes it into the MilSignedInfo signature. S9. The high-level network uses a high-level network cryptographic algorithm to verify the authenticity of the MilSignedInfo and SecurityInfo content, and then processes the received data after acceptance.
2. The cross-network switching security management and collaboration method according to claim 1, characterized in that, The XML file contains multiple Information nodes, and each Information node contains an independent piece of operation and maintenance information.
3. The cross-network switching security management and collaboration method according to claim 1, characterized in that, The operation and maintenance information includes equipment asset information, equipment status information, alarm information and security situation information transmitted from the low-level network to the high-level network, as well as baseline security policy information, security device query information and alarm log query information transmitted from the high-level network to the low-level network.
4. The cross-network switching security management and collaboration method according to claim 1, characterized in that, The CivSignedInfo is signed based on the SecurityInfo node.
5. The cross-network switching security management and collaboration method according to claim 1, characterized in that, After S5 is completed, the XML file is sent remotely from the low-level network to the high-low level network isolation exchange center.
6. The cross-network switching security management and collaboration method according to claim 1, characterized in that, After completing S8, the XML file is sent to the high-level network security management and maintenance system via remote transmission in the high-level network.
7. The cross-network switching security management and collaboration method according to claim 1, characterized in that, The high- and low-level network isolation switching centers can record and trace the switching behavior by using the InfoSum and Signature information recorded during data exchange.
8. A collaborative method for security management of cross-network switching, characterized in that, Includes the following steps: S10. The high-level network converts the collaborative operation and maintenance data into a standard XML file. The XML file is encapsulated in a hierarchical structure, including a CooperationInfo root node. The lower layers of the CooperationInfo root node contain SecurityInfo nodes for security assurance collaboration information and Signature nodes for signature information. The SecurityInfo node contains an InfoNum node for the number of information entries and at least one Information node for carrying detailed operation and maintenance information entries. The Signature node contains an InfoHash node for fingerprint information, a CivSignedInfo node for low-level network signature information, a CroSignedInfo node for cross-network dedicated signature information, and a MilSignedInfo node for high-level network signature information. S11. Add operation and maintenance information to the Information node of the XML file; S12. The high-level network uses the high-level network cryptographic algorithm to complete the MilSignedInfo signature of the XML file and write it into the MilSignedInfo node; S13. The high-level network uses a high-level network cryptographic algorithm to verify the authenticity of the MilSignedInfo and SecurityInfo contents of the XML file; S14. The high-level network uses a cross-network dedicated signature algorithm to perform signature calculation on the content of SecurityInfo and write it into CroSignedInfo; S15. The high-level network transmits the verified and signed XML file to the low-level network through the high-low level network isolation exchange center. S16. Low-level networks use a cross-network dedicated signature algorithm to verify the authenticity of the CroSignedInfo and SecurityInfo content of XML files; S17. The low-level network uses a low-level network cryptographic algorithm to sign the contents of SecurityInfo and writes it into the CivSignedInfo signature. S18. The low-level network uses a low-level network cryptographic algorithm to verify the authenticity of the contents of CivSignedInfo and SecurityInfo, and then processes the received data after acceptance.
Citation Information
Patent Citations
Cross-network exchange service system and method based on secure network
CN110855634A