A message security detection method, device and storage medium

By performing data structure analysis and legality judgment on IS-IS protocol messages, the problem of not being able to detect abnormal messages in a timely manner was solved, realizing the security detection of IS-IS protocol messages and improving network security and stability.

CN115834229BActive Publication Date: 2026-05-26BEIJING NETTAI TECH DEV CO LTD

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
BEIJING NETTAI TECH DEV CO LTD
Filing Date
2022-12-09
Publication Date
2026-05-26

AI Technical Summary

Technical Problem

Existing technologies cannot detect abnormal messages in IS-IS protocol messages in a timely manner, which leads to a lack of network security and may trigger attacks or network failures.

Method used

By acquiring the messages to be inspected generated by the IS-IS protocol, determining the data structure of the message content, analyzing the historical messages to be inspected according to the predetermined message inspection rules, and judging the legality of the message in combination with the first data structure, the security inspection of IS-IS messages is achieved.

Benefits of technology

Timely detection of abnormal messages enhances network security, prevents attacks, and ensures stable network operation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115834229B_ABST
    Figure CN115834229B_ABST
Patent Text Reader

Abstract

This invention discloses a message security detection method, device, and storage medium. The method includes: acquiring a message to be detected based on an intermediate system-to-intermediate system routing protocol; determining a first data structure for the message content based on the message to be detected; if a pre-determined message detection rule determines the existence of a historical message to be detected, analyzing the historical message and the first data structure to determine the message's legitimacy. This solves the problem of not being able to detect abnormal ISIS messages in a timely manner. By analyzing the message to be detected to determine the first data structure for the message content, and determining whether a historical message to be detected exists according to the pre-determined message detection rule, if so, analyzing the historical message and the first data structure to determine the legitimacy of the message to be detected, this invention achieves security detection of messages formed by intermediate system-to-intermediate system routing protocols, enabling timely detection of abnormal messages and improving data security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network security technology, and in particular to a message security detection method, device and storage medium. Background Technology

[0002] IS-IS (Intermediate System-to-Intermediate System) is an interior gateway protocol used within an autonomous system. IS-IS is a link-state protocol that uses the shortest path first algorithm for route calculation.

[0003] When data is transmitted via the ISIS protocol, attackers can intercept ISIS messages when they are relayed by routers. They can then modify the message content or send unauthorized messages through compromised routers to attack the target router, thereby compromising the autonomous system and impacting the security of the entire network. Furthermore, due to misconfigurations or other reasons, even legitimate messages sent by routers can cause network instability, loops, and other malfunctions. Current technologies lack security detection for ISIS protocol messages, making it impossible to detect abnormal messages in a timely manner and thus compromising network security. Summary of the Invention

[0004] This invention provides a message security detection method, device, and storage medium to solve the problem of failing to detect abnormal ISIS messages in a timely manner and to ensure network security.

[0005] According to one aspect of the present invention, a message security detection method is provided, comprising:

[0006] Obtain the message to be detected based on the intermediate system to intermediate system routing protocol;

[0007] A first data structure for determining the message content based on the message to be detected;

[0008] If a historical message to be detected is determined based on a predetermined message detection rule, the message to be detected is analyzed in conjunction with the first data structure to determine the legality of the message.

[0009] According to another aspect of the present invention, an electronic device is provided, the electronic device comprising:

[0010] At least one processor; and

[0011] A memory communicatively connected to the at least one processor; wherein,

[0012] The memory stores a computer program that can be executed by the at least one processor, which enables the at least one processor to perform the message security detection method according to any embodiment of the present invention.

[0013] According to another aspect of the present invention, a computer-readable storage medium is provided, the computer-readable storage medium storing computer instructions, the computer instructions being configured to cause a processor to execute and implement the message security detection method according to any embodiment of the present invention.

[0014] The technical solution of this invention, through acquiring the packet to be detected formed based on the intermediate system-to-intermediate system routing protocol; determining the data structure of the packet content according to the packet to be detected; and if it is determined that there is a historical packet to be detected based on a predetermined packet detection rule, analyzing the packet to be detected in conjunction with the historical packet to be detected and the first data structure to determine the legitimacy of the packet, solves the problem of not being able to detect abnormal ISIS packets in a timely manner. By analyzing the packet to be detected to determine the first data structure of the packet content, determining whether there is a historical packet to be detected according to the predetermined packet detection rule, and if so, analyzing the historical packet to be detected and the first data structure to determine the legitimacy of the packet to be detected, the security detection of packets formed by the intermediate system-to-intermediate system routing protocol is realized, so as to detect abnormal packets in a timely manner and improve data security.

[0015] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of the present invention, nor is it intended to limit the scope of the invention. Other features of the invention will become readily apparent from the following description. Attached Figure Description

[0016] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0017] Figure 1 This is a flowchart of a message security detection method provided in Embodiment 1 of the present invention;

[0018] Figure 2 This is a flowchart of a message security detection method provided in Embodiment 2 of the present invention;

[0019] Figure 3 This is a schematic diagram of the structure of a message security detection device according to Embodiment 3 of the present invention;

[0020] Figure 4 This is a schematic diagram of the structure of an electronic device that implements the message security detection method of this invention. Detailed Implementation

[0021] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.

[0022] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0023] Example 1

[0024] Figure 1 This is a flowchart illustrating a message security detection method provided in Embodiment 1 of the present invention. This embodiment is applicable to situations involving message detection. The method can be executed by a message security detection system, which can be implemented in hardware and / or software and can be configured in an electronic device. Figure 1 As shown, the method includes:

[0025] S101. Obtain the message to be detected based on the intermediate system to intermediate system routing protocol.

[0026] In this embodiment, the message to be detected can be specifically understood as a message with security detection requirements. The intermediate system-to-intermediate system (IS-IS) routing protocol is also known as the Intermediate System-to-Intermediate System (IS-IS) routing protocol. The message security detection method provided in this application embodiment performs security detection on ISIS routing protocol messages (hereinafter referred to as ISIS messages). The device or system executing the message security detection method can be deployed between important routing nodes, or it can be deployed according to the minimum connectivity graph in the routing network, or it can be deployed throughout the entire router network.

[0027] Specifically, this execution device can receive any type of message transmitted by a router or attacker, filter the messages to obtain the message to be detected based on the intermediate system-to-intermediate system routing protocol; or, it can filter the messages transmitted by the router through an intermediate device to obtain the message to be detected based on the intermediate system-to-intermediate system routing protocol and send it to this execution device. The message security detection method provided in this application adopts a network architecture that separates the control plane and data plane, such as Software Defined Network (SDN) or Data Plane Development Kit (Intel DPDK), so that while performing security detection on the message to be detected, it does not affect the normal transmission of other types of messages.

[0028] S102. The first data structure for determining the content of the message based on the message to be detected.

[0029] In this embodiment, the message content can be specifically understood as the actual data content contained in the message to be detected, such as field types and the data content corresponding to the fields; the first data structure can be understood as the way the computer stores and organizes the data in the message content contained in the message to be detected. The first data structure can be an array, stack, queue, linked list, tree, graph, heap, hash table, etc. By analyzing the message to be detected, the message content of the message to be detected is determined, and the message content is stored according to the pre-set first data structure to construct the first data structure of the message content, which facilitates data processing by the computer.

[0030] S103. If it is determined that there are historical messages to be detected based on the pre-determined message detection rules, the legality of the messages to be detected is determined by analyzing the historical messages to be detected in conjunction with the first data structure.

[0031] In this embodiment, the message detection rules can be specifically understood as rules for judging whether ISIS messages are secure. Message detection rules can be set according to security level requirements and the types of attacks being protected against, allowing for targeted security checks on messages. Message detection rules can be dynamically updated based on requirements, business scenarios, etc. The historical messages to be detected can be specifically understood as historical messages that assist in the security detection of the messages to be detected; the legitimacy of these messages can be legal, illegal, etc.

[0032] Specifically, message detection rules are predetermined. These rules define the data types to be detected and the corresponding specific rule content. The specific rule content can define the amount of data to be detected, such as data over a consecutive period or for a specific duration. Based on the message detection rules, the data types to be detected are determined. The existence of historical messages to be detected is also determined based on the specific rule content. If such messages exist, they are retrieved. Data is obtained from the first data structure of the message content and from the historical messages to be detected, and these are analyzed comprehensively. The legitimacy of the message is determined by combining this with the specific rules for message protection. For example, the specific rule content for message detection could be three consecutive A-type data values ​​greater than 10 and two consecutive B-type data values ​​greater than 12.

[0033] It's important to understand that during security checks on packets, you can analyze only the packet to be checked. If, based on pre-defined packet detection rules, it's determined that no historical packets to be checked exist, the packet is analyzed according to the first data structure to determine its legality. For example, if the data corresponding to type A (or field A) is less than 10, the packet is legal; otherwise, it's illegal. When analyzing packet legality, you can perform checks solely on the packet to be checked, or you can combine analysis with historical packets, which can be configured through packet detection rules.

[0034] This invention provides a message security detection method. It acquires a message to be detected based on an intermediate system-to-intermediate system routing protocol; determines a first data structure for the message content based on the message to be detected; if a pre-determined message detection rule indicates the existence of a historical message to be detected, it analyzes the message to be detected in conjunction with the historical message and the first data structure to determine the message's legitimacy. This solves the problem of failing to detect abnormal ISIS messages in a timely manner. By analyzing the message to be detected to determine the first data structure for the message content, and determining whether a historical message to be detected exists based on the pre-determined message detection rule, if so, it analyzes the historical message and the first data structure to determine the legitimacy of the message to be detected. This achieves secure detection of messages formed by intermediate system-to-intermediate system routing protocols, enabling timely detection of abnormal messages and improving data security.

[0035] Example 2

[0036] Figure 2 This is a flowchart of a message security detection method provided in Embodiment 2 of the present invention. This embodiment is a refinement based on the above embodiments, such as... Figure 2 As shown, the method includes:

[0037] S201. Obtain the message to be forwarded.

[0038] In this embodiment, the message to be forwarded can be specifically understood as a message with a forwarding requirement. The message to be forwarded can be a message forwarded by the router or a message sent by the attacker. The device of this application can receive a message to be forwarded forwarded by the router; or, the attacker can modify the message forwarded by the router to form a message to be forwarded and send it to the execution device; or, the attacker can directly form a message to be forwarded and send it to the execution device.

[0039] S202. Determine the message to be detected based on the message type of the message to be forwarded.

[0040] In this embodiment, the message type can be OSPF, ISIS, ICMP, etc. The message type is determined by parsing the message to be forwarded. Messages of type ISIS are identified as messages to be inspected, and subsequent message security checks are performed on these messages. Other message types are transmitted normally to minimize the impact on the network.

[0041] S203. Obtain the message to be detected based on the intermediate system to intermediate system routing protocol.

[0042] S204. Parse the message to be detected.

[0043] Parsing the message to be detected can be done by parsing all fields of the message sequentially to obtain the data corresponding to each field, which can be done by using a parsing tool to parse all fields sequentially; or by parsing the message in blocks to obtain the parsed data.

[0044] As an optional embodiment of this example, this optional embodiment further optimizes the parsing of the message to be detected as follows:

[0045] A1. Based on the predetermined protocol specifications, the message to be detected is divided into blocks to determine the data blocks to be detected.

[0046] In this embodiment, the data block to be detected can be specifically understood as the data block that needs to be parsed; the protocol specification can be specifically understood as the specification followed by the protocol used to form the message to be detected when forming the message. For example, the TLV structure includes: Tag + Length + Value.

[0047] The protocol specification is determined in advance based on the protocol (or message type) of the message to be inspected. The protocol specification determines the message structure and which fields constitute a data block. Then, the message to be inspected is divided into blocks, which are one or more data blocks to be inspected. For example, fields A, B, and C constitute one data block to be inspected.

[0048] A2. The data block to be detected is parsed according to the offset and data type corresponding to the data block to be detected.

[0049] For each data block to be inspected, determine the offset and data type of each field within the block. The data type includes the data type corresponding to each field, which can be the field length (e.g., 3 bytes, 4 bytes, etc.) and type (e.g., int, char, float, etc.). Determine the offset and data type corresponding to the data block to be inspected, and then parse the block according to these values ​​to obtain the data for the corresponding fields. By parsing the message to be inspected in blocks, the data content of the message can be quickly obtained.

[0050] S205. Determine the first data structure of the message content based on the parsed data.

[0051] The data structure of the message content is constructed based on the parsed data. The data and its corresponding types are stored according to the data structure to generate the data structure of the message content so that the computer can process the data.

[0052] S206. If it is determined that there are historical messages to be detected based on the predetermined message detection rules, obtain the second data structure of the message content of the historical messages to be detected.

[0053] In this embodiment, the second data structure can be specifically understood as the way a computer stores and organizes the data in the message content contained in the historical messages to be detected. The second data structure can be an array, stack, queue, linked list, tree, graph, heap, hash table, etc.

[0054] When generating message detection rules, the data types and specific rule content required for security detection can be determined. Based on the specific rule content, it can be determined whether there are any historical messages to be detected. For example, if the specific rule is that a message is considered abnormal if type A data exceeds 10 in 10 consecutive messages, then historical messages to be detected exist. The message detection rules determine and obtain a corresponding number of historical messages to be detected; for example, the 9 ISIS messages preceding the message to be detected can be obtained as historical messages to be detected. The message content of the historical messages to be detected is parsed to construct their corresponding second data structure; or, if the historical messages to be detected already have a second data structure, their corresponding second data structure can be directly obtained. It is known that the number of historical messages to be detected can be multiple, and correspondingly, the number of second data structures can also be multiple.

[0055] S207. Obtain the first data structure and the second data structure, and perform rule matching in combination with the message detection rules.

[0056] The analysis is performed based on the second data structure of the historical packets to be detected and the first data structure of the packets to be detected. After security detection, the first data structure of a packet to be detected can be stored as the data structure of the packet content. When performing security detection on the next packet to be detected, the data structure of the corresponding packet content of the current packet to be detected, as a historical packet to be detected, can be directly obtained as the second data structure. The analysis results are matched with the packet detection rules, or analyzed according to the packet detection rules. The packet detection rules can detect one or more types of data. For example, the specific rule content of the packet detection rule can be that after three consecutive A-type data values ​​are greater than 10, two consecutive B-type data values ​​are greater than 11; the specific rule content of the packet detection rule can be that after three consecutive A-type data values ​​are greater than 10, at least three of the five B-type data values ​​are greater than 11, and so on.

[0057] If no historical packets to be detected exist, the data structure of the packet content to be detected is analyzed directly and matched with the packet detection rules. For example, the specific rule content of the packet detection rules is that type A data is greater than 10 and type B data is greater than 12.

[0058] S208. Determine if the match is successful. If yes, execute S209; otherwise, execute S210.

[0059] If, after analyzing the data, it is determined that the data conforms to the specific rules of the message detection rules, the match is considered successful; otherwise, the match is considered unsuccessful.

[0060] S209. The message is determined to be an illegal message.

[0061] S210. Confirm that the message is a valid message.

[0062] As an optional embodiment of this example, this optional embodiment is further optimized to include the following steps:

[0063] B1. Determine the current routing status based on the message to be detected.

[0064] In this embodiment, the current routing state can be specifically understood as the state of the router when it is currently transmitting the packet to be detected, such as whether the route prefix is ​​correct and whether it is reachable. The current routing state corresponding to the maintained routing table is determined based on the packet to be detected.

[0065] B2. Determine the route status change information based on the current route status and the historical route status.

[0066] In this embodiment, historical routing state can be specifically understood as the state of the router when it transmitted packets in the past, such as the state when it last transmitted the packet to be detected. There can be one or more historical routing states to achieve the purpose of determining changes in routing state by comparing multiple routing states.

[0067] The system compares the current routing state with the historical routing state to determine whether the routing state has changed. Based on the changes, it generates routing state change information, which may include whether the prefix has changed and the frequency of changes.

[0068] B3. Based on message detection rules, perform rule matching on routing status change information.

[0069] Pre-define protection rules for route state changes in the packet detection rules. For example, an anomaly is identified if the prefix change frequency is greater than 4 times / min. Match the route state change information with the protection rules for route state changes in the packet detection rules.

[0070] B4. Determine if the match is successful. If yes, determine that the message is an illegal message; otherwise, determine that the message is a legal message.

[0071] If a match is successful, the message is determined to be invalid; if a match fails, the message is determined to be valid. For example, if the prefix change frequency in the route state change information is 6 times / min, then a match is successful and the message is invalid. If the route state change information includes multiple types of information, when determining the validity of the message, it can be determined that the message is invalid if only one type of information matches successfully, or it can be determined that the message is invalid if more than n types of information match successfully. n can be set according to requirements.

[0072] As an optional embodiment of this example, this optional embodiment is further optimized to include the following steps:

[0073] C1. Data structure for determining the routing status based on the current routing status.

[0074] The current route state is parsed, and a data structure for the route state is constructed based on the parsed data, such as prefix, path, sequence number, system ID, time, etc. The data contained in the current route state and the data type are stored according to the data structure, thus completing the construction of the route state data structure.

[0075] C2. Based on message detection rules, perform rule matching on the data structure of the routing state.

[0076] Protection rules for routing states are predefined in the packet inspection rules. These rules are then used to evaluate the data structure of the routing states, determining its validity—for example, whether the prefix matches an abnormal prefix defined in the protection rules. When matching the routing state data structure against rules, one or more data types can be specified for matching.

[0077] C3. Determine if the match is successful. If yes, determine that the message is an illegal message; otherwise, determine that the message is a legal message.

[0078] If the routing state data structure matches the packet detection rules, the packet is determined to be an illegal packet; otherwise, the packet is determined to be a legal packet. If multiple data types are set for matching, a successful match of one type of data can determine the packet as illegal, or multiple types of information can be set to determine the packet as illegal only after successful matching.

[0079] The method provided in this application embodiment can be deployed in a bypass manner in a router network to detect and alert against attacks against the ISIS protocol.

[0080] As an optional embodiment of this example, this optional embodiment is further optimized to include forwarding the message to be detected if the message is a valid message, and modifying or discarding the message to be detected if the message is an invalid message.

[0081] When a message is legitimate, it is forwarded directly. When a message is illegitimate, it can be modified or discarded. For illegitimate messages, it can be determined whether modification is necessary. This can be defined in the message detection rules, specifying whether and how modification should be performed. Alternatively, the message can be discarded without modification, saving time. By modifying or discarding illegitimate messages, protection against attacks can be achieved.

[0082] For example, the message security detection method provided in this application can be deployed and implemented systematically by a message security detection system. This system employs a network architecture that separates the control plane and data plane, and includes a data processing module, a controller module, and a management module. The data processing module connects to a router, receives messages to be forwarded from the router, analyzes the messages to be forwarded, determines the message type, identifies the message to be detected based on the message type, and sends the message to be detected to the controller module. Messages that are not of the ISIS type are directly forwarded quickly or otherwise processed. The controller module processes and analyzes the messages to be detected to determine their legality, and based on the legality of the messages, decides whether to forward, modify, or discard them, and then performs the corresponding forwarding, modification, or discarding operations on the messages to be detected. The controller module can also send the processing method of the message to be detected to the data processing module, which can then forward, modify or discard the message to be detected accordingly. The controller module can also interact with the management module, which is used to maintain the message detection rules. It can modify and update the message detection rules, and record and display the analysis results of the message to be detected.

[0083] This invention provides a packet security detection method that solves the problem of failing to detect abnormal ISIS packets in a timely manner. The method determines the packet to be detected based on its packet type, performs security detection on the packet, and processes other types of packets in the same way without affecting the processing of other packets. The method analyzes the packet to be detected to determine a first data structure of the packet content, determines whether there are any historical packets to be detected according to pre-determined packet detection rules, and determines the corresponding second data structure if such historical packets exist. The method comprehensively analyzes the first and second data structures to determine the legitimacy of the packet to be detected, thus achieving security detection of ISIS packets, timely detection of abnormal packets, and improved data security. Abnormal packets can be modified or discarded to block attacks, while ensuring the rapid forwarding of legitimate packets. The method can also perform security detection and defense on packets sent by the router itself, analyze and protect against known and unknown vulnerabilities in the ISIS protocol, is easy to deploy, and does not affect normal network operation.

[0084] Example 3

[0085] Figure 3 This is a schematic diagram of a message security detection device provided in Embodiment 3 of the present invention. Figure 3 As shown, the device includes: a message acquisition module 31, a message structure determination module 32, and a first legality determination module 33;

[0086] The detection packet acquisition module 31 is used to acquire the packet to be detected based on the intermediate system to intermediate system routing protocol;

[0087] The message structure determination module 32 is used to determine the first data structure of the message content based on the message to be detected.

[0088] The first legality determination module 33 is used to determine the legality of a message if it is determined that there is a historical message to be detected based on a pre-determined message detection rule.

[0089] This invention provides a message security detection device that solves the problem of failing to detect abnormal ISIS messages in a timely manner. It analyzes the message to be detected to determine a first data structure, determines whether there are any historical messages to be detected based on pre-determined message detection rules, and analyzes the second data structure of the historical messages to be detected in conjunction with the first data structure to determine the legitimacy of the message to be detected. This achieves secure detection of messages formed by intermediate system-to-intermediate system routing protocols, enabling timely detection of abnormal messages and improving data security.

[0090] Optionally, the device may also include:

[0091] The forwarding message determination module is used to obtain the message to be forwarded;

[0092] The detection message determination module is used to determine the message to be detected based on the message type of the message to be forwarded.

[0093] Optionally, the message structure determination module 32 includes:

[0094] A message parsing unit is used to parse the message to be detected;

[0095] The message structure determination unit is used to determine the first data structure of the message content based on the parsed data.

[0096] Optionally, the message parsing unit is specifically used for: dividing the message to be detected into blocks based on a predetermined protocol specification to determine the data block to be detected; and parsing the data block to be detected according to the offset and data type corresponding to the data block to be detected.

[0097] Optionally, the first legality determination module 33 includes:

[0098] A data structure acquisition unit is used to acquire the second data structure of the message content of the historical message to be detected;

[0099] The rule matching unit is used to perform rule matching based on the first data structure and the second data structure in combination with the message detection rules;

[0100] The status determination unit is used to determine whether the match is successful. If it is, the message is determined to be an illegal message; otherwise, the message is determined to be a legal message.

[0101] Optionally, the device may also include:

[0102] The route status determination module is used to determine the current route status based on the packet to be detected;

[0103] The state change determination module is used to determine route state change information based on the current route state and the historical route state.

[0104] The state change matching module is used to perform rule matching on the routing state change information based on the packet detection rules;

[0105] The second legality determination module is used to determine whether the match is successful. If it is, the message is determined to be an illegal message; otherwise, the message is determined to be a legal message.

[0106] Optionally, the device may also include:

[0107] A routing structure determination module is used to determine the data structure of the routing state based on the current routing state.

[0108] The routing structure matching module is used to perform rule matching on the data structure of the routing state based on packet detection rules;

[0109] The third legality determination module is used to determine whether the match is successful. If it is, the message is determined to be an illegal message; otherwise, the message is determined to be a legal message.

[0110] Optionally, the device may also include:

[0111] The message forwarding module is used to forward the message to be detected if the message is illegal.

[0112] The message processing module is used to modify or discard messages to be detected if the message is a valid message.

[0113] The message security detection device provided in the embodiments of the present invention can execute the message security detection method provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of executing the method.

[0114] Example 4

[0115] Figure 4A schematic diagram of an electronic device 40 that can be used to implement embodiments of the present invention is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices (e.g., helmets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the invention described and / or claimed herein.

[0116] like Figure 4 As shown, the electronic device 40 includes at least one processor 41 and a memory, such as a read-only memory (ROM) 42 or a random access memory (RAM) 43, communicatively connected to the at least one processor 41. The memory stores computer programs executable by the at least one processor. The processor 41 can perform various appropriate actions and processes based on the computer program stored in the ROM 42 or loaded into the RAM 43 from storage unit 48. The RAM 43 may also store various programs and data required for the operation of the electronic device 40. The processor 41, ROM 42, and RAM 43 are interconnected via a bus 44. An input / output (I / O) interface 45 is also connected to the bus 44.

[0117] Multiple components in electronic device 40 are connected to I / O interface 45, including: input unit 46, such as keyboard, mouse, etc.; output unit 47, such as various types of monitors, speakers, etc.; storage unit 48, such as disk, optical disk, etc.; and communication unit 49, such as network card, modem, wireless transceiver, etc. Communication unit 49 allows electronic device 40 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.

[0118] Processor 41 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of processor 41 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. Processor 41 performs the various methods and processes described above, such as message security inspection methods.

[0119] In some embodiments, the message security detection method may be implemented as a computer program tangibly contained in a computer-readable storage medium, such as storage unit 48. In some embodiments, part or all of the computer program may be loaded and / or installed on electronic device 40 via ROM 42 and / or communication unit 49. When the computer program is loaded into RAM 43 and executed by processor 41, one or more steps of the message security detection method described above may be performed. Alternatively, in other embodiments, processor 41 may be configured to perform the message security detection method by any other suitable means (e.g., by means of firmware).

[0120] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), payload-programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.

[0121] Computer programs used to implement the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when executed by the processor, the computer programs cause the functions / operations specified in the flowcharts and / or block diagrams to be performed. The computer programs may be executed entirely on a machine, partially on a machine, or as a standalone software package, partially on a machine and partially on a remote machine, or entirely on a remote machine or server.

[0122] In the context of this invention, a computer-readable storage medium can be a tangible medium that may contain or store a computer program for use by or in conjunction with an instruction execution system, apparatus, or device. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination thereof. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.

[0123] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).

[0124] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or computing systems that include middleware components (e.g., application servers), or computing systems that include frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include local area networks (LANs), wide area networks (WANs), blockchain networks, and the Internet.

[0125] A computing system can include clients and servers. Clients and servers are generally located far apart and typically interact through communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or cloud host, which is a hosting product within the cloud computing service system to address the shortcomings of traditional physical hosts and VPS services, such as high management difficulty and weak business scalability.

[0126] It should be understood that the various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps described in this invention can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution of this invention can be achieved, and this is not limited herein.

[0127] The specific embodiments described above do not constitute a limitation on the scope of protection of this invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this invention should be included within the scope of protection of this invention.

Claims

1. A message security detection method, characterized in that, It is used for security inspection of intermediate system-to-intermediate system routing protocol messages, including: Obtain the message to be detected based on the intermediate system to intermediate system routing protocol; The message to be detected is divided into blocks based on a predetermined protocol specification to determine the data blocks to be detected; wherein, the protocol specification is the specification followed by the protocol used to form the message to be detected when forming the message; The data block to be detected is parsed according to the offset and data type corresponding to the data block to be detected; wherein, the data type includes the data type corresponding to each field; The first data structure of the message content is determined based on the parsed data; If a historical message to be detected is determined based on a predetermined message detection rule, the message to be detected is analyzed in conjunction with the first data structure to determine the legality of the message. The current routing state is determined based on the message to be detected; wherein, the current routing state is the state of the router when the message to be detected is being transmitted. The routing status change information is determined based on the current routing status and the historical routing status; wherein, the routing status change information includes whether the prefix has changed and the frequency of change; Based on the packet detection rules, rule matching is performed on the routing state change information; Determine whether the match is successful. If yes, determine that the message is an illegal message; otherwise, determine that the message is a legal message. The data structure for determining the routing status based on the current routing status; Based on the packet detection rules, rule matching is performed on the data structure of the routing state; Determine if the match is successful. If yes, determine that the message is an illegal message; otherwise, determine that the message is a legal message.

2. The method according to claim 1, characterized in that, Before obtaining the packet to be detected based on the intermediate system-to-intermediate system routing protocol, the method further includes: Obtain the message to be forwarded; The message to be detected is determined based on the message type of the message to be forwarded.

3. The method according to claim 1, characterized in that, The step of analyzing the message to be detected based on the historical messages to be detected and the first data structure to determine the legality of the message includes: A second data structure for obtaining the message content of the historical messages to be detected; Rule matching is performed based on the first data structure and the second data structure in conjunction with the message detection rules; Determine if the match is successful. If yes, determine that the message is an illegal message; otherwise, determine that the message is a legal message.

4. The method according to any one of claims 1-3, characterized in that, Also includes: If the message is a valid message, then the message to be tested will be forwarded; If the message is illegal, the message to be detected will be modified or discarded.

5. An electronic device, characterized in that, The electronic device includes: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that can be executed by the at least one processor, the computer program being executed by the at least one processor to enable the at least one processor to perform the message security detection method according to any one of claims 1-4.

6. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions that cause a processor to execute the message security detection method according to any one of claims 1-4.