Network access management method, apparatus and electronic device
By monitoring and recognizing network protocol stack data at the driver layer, combined with security verification and control operations, the problem of insufficient user transparency and security in existing technologies is solved, achieving transparent and efficient network access management.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- GUANGZHOU TENCENT TECH CO LTD
- Filing Date
- 2021-09-18
- Publication Date
- 2026-04-24
AI Technical Summary
Existing network access management technologies are inadequate in terms of user transparency and security, making it easy for users to bypass restrictions, and are also inefficient and costly.
Transparent network access management is achieved through the driver layer, and data monitoring and behavior recognition of the network protocol stack are performed using permission management policies. Combined with security verification and control operations, security and efficiency are improved.
It achieves transparent network access management, improves security and efficiency, prevents users from bypassing restrictions, and is suitable for various terminal devices and servers.
Smart Images

Figure CN115842642B_ABST
Abstract
Description
Technical Field
[0001] This application relates to network technology, and more particularly to a network access management method, apparatus, electronic device, computer-readable storage medium, and computer program product. Background Technology
[0002] The Internet is a vast network connecting various networks. Electronic devices can access the Internet to perform network activities, such as accessing online information and playing online games. However, network access is characterized by high uncertainty and high risk, which can easily interfere with the daily work of users of electronic devices.
[0003] In solutions provided by related technologies, a common approach is to utilize the interface provided by a Layered Service Provider (LSP) to inject a Dynamic Link Library (DLL) for network access management into the process that performs network access actions, thereby achieving network access management. However, this approach is opaque to users, making it easy for them to bypass network access management restrictions, resulting in low security for network access management. Summary of the Invention
[0004] This application provides a network access management method, apparatus, electronic device, computer-readable storage medium, and computer program product, which can achieve transparent network access management through the driver layer and improve the security of network access management.
[0005] The technical solution of this application embodiment is implemented as follows:
[0006] This application provides a network access management method, including:
[0007] Retrieve the permission management policy configured for the target object;
[0008] According to the permission management policy, a monitoring instruction is sent to the driver layer, so that the driver layer can perform data monitoring and processing on the network protocol stack according to the monitoring instruction, and perform behavior recognition processing on the monitored network access data to obtain network access behavior.
[0009] The network access behavior is subjected to security verification processing according to the permission management policy to obtain a verification result indicating whether the network access behavior is blocked;
[0010] Based on the test results, control operations are performed on the network access behavior.
[0011] This application provides a network access management device, including:
[0012] The policy acquisition module is used to acquire the permission management policy configured for the target object;
[0013] The behavior monitoring module is used to send monitoring instructions to the driver layer according to the permission management policy, so that the driver layer can perform data monitoring and processing on the network protocol stack according to the monitoring instructions, and perform behavior recognition processing on the monitored network access data to obtain network access behavior.
[0014] The security verification module is used to perform security verification processing on the network access behavior according to the permission management policy, and obtain a verification result indicating whether the network access behavior is blocked.
[0015] An execution module is used to perform control operations on the network access behavior based on the test results.
[0016] This application provides an electronic device, including:
[0017] Memory, used to store executable instructions;
[0018] The processor, when executing executable instructions stored in the memory, implements the network access management method provided in the embodiments of this application.
[0019] This application provides a computer-readable storage medium storing executable instructions, which, when executed by a processor, implement the network access management method provided in this application.
[0020] This application provides a computer program product, including executable instructions, which, when executed by a processor, implement the network access management method provided in this application.
[0021] The embodiments of this application have the following beneficial effects:
[0022] After obtaining the access control policy configured for the target object, the driver layer is triggered according to this policy. The driver layer then monitors the network protocol stack and performs behavioral recognition processing on the monitored network access data to obtain network access behavior. Next, the network access behavior undergoes security verification according to the access control policy, and control operations are executed based on the verification results. In this way, transparent network access management can be achieved through the driver layer, improving network access management security and effectively preventing users from bypassing network access management restrictions. Attached Figure Description
[0023] Figure 1 This is a schematic diagram of the architecture of the network access management system provided in the embodiments of this application;
[0024] Figure 2This is a schematic diagram of the architecture of the terminal device provided in the embodiments of this application;
[0025] Figure 3A This is a flowchart illustrating a network access management method provided in an embodiment of this application;
[0026] Figure 3B This is another flowchart illustrating the network access management method provided in the embodiments of this application;
[0027] Figure 3C This is another flowchart illustrating the network access management method provided in the embodiments of this application;
[0028] Figure 4 This is another flowchart illustrating the network access management method provided in the embodiments of this application;
[0029] Figure 5 This is a schematic diagram of a network access management interface provided in an embodiment of this application;
[0030] Figure 6 This is another schematic diagram of the network access management interface provided in the embodiments of this application;
[0031] Figure 7 This is a schematic diagram of a dashboard interface provided in an embodiment of this application;
[0032] Figure 8 This is another schematic diagram of the dashboard interface provided in the embodiments of this application;
[0033] Figure 9 This is a schematic diagram of the browser interface provided in an embodiment of this application;
[0034] Figure 10 This is another flowchart illustrating the network access management method provided in the embodiments of this application;
[0035] Figure 11A This is a schematic diagram of an account tree provided in an embodiment of this application;
[0036] Figure 11B This is another schematic diagram of the account tree provided in the embodiments of this application;
[0037] Figure 11C This is another schematic diagram of the account tree provided in the embodiments of this application;
[0038] Figure 12 This is a schematic diagram illustrating network access management based on a management time period, provided in an embodiment of this application.
[0039] Figure 13 This is a schematic diagram illustrating the components of the whitelist strategy provided in the embodiments of this application;
[0040] Figure 14 This is a schematic diagram of the permission application process provided in the embodiments of this application. Detailed Implementation
[0041] To make the objectives, technical solutions, and advantages of this application clearer, the application will be further described in detail below with reference to the accompanying drawings. The described embodiments should not be regarded as limitations on this application. All other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0042] In the following description, references to "some embodiments" describe a subset of all possible embodiments; however, it is understood that "some embodiments" may be the same subset or different subsets of all possible embodiments and may be combined with each other without conflict. In the following description, the term "a plurality of" means at least two.
[0043] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs. The terminology used herein is for the purpose of describing embodiments of this application only and is not intended to limit this application.
[0044] In the implementation of this application, the collection and processing of relevant data should strictly comply with the requirements of relevant laws and regulations, obtain the informed consent or separate consent of the personal information subject, and carry out subsequent data use and processing within the scope of laws and regulations and the authorization of the personal information subject.
[0045] Before providing a further detailed description of the embodiments of this application, the nouns and terms involved in the embodiments of this application will be explained, and the nouns and terms involved in the embodiments of this application shall be interpreted as follows.
[0046] 1) Network Services: Services provided through a network, such as online information services and online game services. The provider of a network service can be a specific electronic device, such as a server or server cluster. In this embodiment, the access control service is a special type of network service used to provide access control functionality. The access control service can manage electronic devices as management units or teams as management units, where each team includes at least one electronic device. The type of access control service is not limited; for example, it can be a Software as a Service (SaaS) service.
[0047] 2) Team: Also known as an organization, it refers to a collection of electronic devices to be managed. A team includes at least one electronic device. For example, a team can refer to a family, a school, or a company. In the embodiments of this application, in order to facilitate the differentiation of different teams, different team identification information can be set for different teams, such as a personal identification number (PIN).
[0048] 3) Driver layer: Also known as the kernel layer, it mainly provides low-level drivers for various hardware components of electronic devices. Drivers operate at the same level as the operating system, and users cannot perceive the specific operations of the drivers; that is, drivers are equivalent to the capabilities provided by the operating system.
[0049] 4) Application layer: Used to run various applications as processes.
[0050] 5) Network protocol stack: Also known as a protocol stack, it is the software implementation of a suite of computer network protocols. It is the sum of the protocols at each layer in the network and reflects the data transmission process in the network. For example, a network protocol stack can be a Transmission Control Protocol / Internet Protocol (TCP / IP) protocol stack.
[0051] 6) Network access behavior: Used to access network services, and can be represented in the form of data in the network protocol stack.
[0052] 7) Access Control Policy: This is configured by the access control service. For example, when managing teams, the service can configure policies based on the characteristics of each team. A team can have one or more access control policies. Different teams can have the same or different access control policies, and the same applies when managing electronic devices.
[0053] 8) Cloud Technology: A hosting technology that unifies hardware, software, network, and other resources within a wide area network (WAN) or local area network (LAN) to achieve data computation, storage, processing, and sharing. Embodiments of this application can be implemented in conjunction with cloud technology; for example, the electronic devices involved can be cloud devices used to provide cloud services, such as cloud servers.
[0054] 9) Artificial Intelligence (AI): Theories, methods, technologies, and application systems that utilize digital computers or machines controlled by digital computers to simulate, extend, and expand human intelligence, perceive the environment, acquire knowledge, and use that knowledge to obtain optimal results. Embodiments of this application can be implemented in conjunction with artificial intelligence. For example, AI technology can be used to generate permission management policies for target objects, achieving automatic configuration of permission management policies; another example is that AI technology can be used to process supplementary permission requests for approval, achieving intelligent approval.
[0055] 10) Intelligent Traffic System (ITS): Also known as Intelligent Transportation System, it effectively integrates advanced science and technology (information technology, computer technology, data communication technology, sensor technology, electronic control technology, automatic control theory, operations research, artificial intelligence, etc.) into transportation, service control, and vehicle manufacturing. It strengthens the connection between vehicles, roads, and users, thereby forming a comprehensive transportation system that ensures safety, improves efficiency, improves the environment, and saves energy. The embodiments of this application can be applied to intelligent transportation systems to realize smart transportation. For example, it can manage network access for in-vehicle terminals to improve their security.
[0056] For network access management, the relevant technologies offer the following three solutions.
[0057] 1) The application-layer LSP Hook solution utilizes the interface provided by LSP to inject a network access management module (such as a DLL for network access management) into the process that performs network access behavior. This allows the network access management module to run within the injected process, thus achieving network access management. However, this solution, being application-layer network access management, has at least the following problems: ① The network access management module needs to be injected into each process performing network access management, which is not transparent to the user, making it easy for users to bypass the network access management mechanism and perform unauthorized network access; ② Batch network access management cannot be achieved, resulting in low efficiency; ③ Since the network has multiple input / output (I / O) models at the application layer, the DLL responsible for network access management needs to be adapted to these multiple I / O models, resulting in a large workload from a development perspective and potentially causing adverse effects on the process itself, thus affecting the user's normal office work.
[0058] 2) Browser Helper Object (BHO) Plugin Injection Scheme. This scheme uses browser plugin extension technology, injecting a network access management module into a specific browser process to monitor and intercept browser-based network access behavior. However, this scheme can only manage network access within the browser process and cannot manage network access from non-browser processes. Furthermore, some browsers typically have anti-injection logic for BHO schemes, making it difficult to guarantee a high success rate for injection; in other words, the success rate of network access management is low.
[0059] 3) Gateway AP Solution. This solution uses hardware deployment to process network access information at the ingress and egress points of the physical network, thereby managing network access for electronic devices within the physical network topology. However, this solution has very high equipment procurement costs and is relatively complicated to deploy, making it particularly unsuitable for small and medium-sized teams (such as SMEs).
[0060] This application provides a network access management method, apparatus, electronic device, computer-readable storage medium, and computer program product. These technologies enable transparent network access management through a driver layer, improving network access management security. They also allow for batch network access management for teams, enhancing network access management efficiency. The following describes exemplary applications of the electronic device provided in this application. This electronic device can be implemented as various types of terminal devices or as a server.
[0061] See Figure 1 , Figure 1 This is a schematic diagram of the architecture of the network access management system 100 provided in the embodiments of this application. The terminal device 400 connects to the server 200 through the network 300, or the server 500 connects to the server 200 through the network 300. The server 200 connects to the database 600. The network 300 can be a wide area network or a local area network, or a combination of the two.
[0062] In some embodiments, taking the electronic device as a terminal device as an example, the network access management method provided in this application embodiment can be implemented by the terminal device. For example, the terminal device 400 sends a permission request to the permission management service to obtain the permission management policy configured by the permission management service for the target object (referring to the terminal device 400 or the team to which the terminal device 400 belongs); according to the permission management policy, it sends a monitoring instruction to the driver layer of the terminal device 400, so that the driver layer performs data monitoring processing on the network protocol stack according to the monitoring instruction, and performs behavior recognition processing on the monitored network access data to obtain the network access behavior; according to the permission management policy, it performs security verification processing on the network access behavior to obtain a verification result indicating whether to block the network access behavior; and executes control operations on the network access behavior according to the verification result. The permission management service can be provided by the server 200. In this case, when the server 200 receives the permission request sent by the terminal device 400, it retrieves the permission management policy corresponding to the target object from the database 600 and sends the permission management policy to the terminal device 400.
[0063] In some embodiments, taking the electronic device as a server as an example, the network access management method provided in this application embodiment can be implemented by a server. For example, server 500 sends a permission request to a permission management service to obtain the permission management policy configured by the permission management service for the target object (referring to server 500 itself or the team to which server 500 belongs); according to the permission management policy, it sends a monitoring instruction to the driver layer of server 500, so that the driver layer performs data monitoring processing on the network protocol stack according to the monitoring instruction, and performs behavior recognition processing on the monitored network access data to obtain network access behavior; according to the permission management policy, it performs security verification processing on the network access behavior to obtain a verification result indicating whether to block the network access behavior; and executes control operations on the network access behavior according to the verification result. The permission management service can be provided by server 200, which is different from server 500.
[0064] In some embodiments, various results involved in network access management (such as access control policies) can be stored in a blockchain. Because of the immutable nature of the blockchain, the accuracy of the data in the blockchain can be guaranteed. Electronic devices can send query requests to the blockchain to retrieve the data stored in the blockchain.
[0065] In some embodiments, the terminal device 400 or server 500 can implement the network access management method provided in this application by running a computer program. For example, the computer program can be a native program or software module in an operating system; it can be a native application (APP), that is, a program that needs to be installed in the operating system to run, such as a network access management APP for maintaining device security; it can also be a mini-program, that is, a program that only needs to be downloaded to a browser environment to run; or it can be a mini-program that can be embedded in any APP. In short, the above-mentioned computer program can be any form of application, module or plugin.
[0066] In some embodiments, the server (such as server 200 or server 500) can be an independent physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, content delivery networks (CDNs), and big data and artificial intelligence platforms. The terminal device 400 can be a smartphone, tablet, laptop, desktop computer, smart TV, smartwatch, in-vehicle terminal, etc., but is not limited to these. The terminal device 400 and server 200, as well as server 500 and server 200, can be directly or indirectly connected via wired or wireless communication; this embodiment does not impose any limitations.
[0067] In some embodiments, the database 600 and the server 200 can be set up independently. In some embodiments, the database 600 and the server 200 can also be integrated together, that is, the database 600 can be regarded as existing inside the server 200 and integrated with the server 200, and the server 200 can provide the data management functions of the database 600.
[0068] Taking the electronic device provided in this application as an example, which is a terminal device, it can be understood that in the case where the electronic device is a server, Figure 2 Some parts of the structure shown (such as the user interface, presentation module, and input processing module) can be omitted. See also Figure 2 , Figure 2 This is a schematic diagram of the structure of the terminal device 400 provided in the embodiments of this application. Figure 2The terminal device 400 shown includes at least one processor 410, a memory 450, at least one network interface 420, and a user interface 430. The various components in the terminal device 400 are coupled together via a bus system 440. It is understood that the bus system 440 is used to implement communication between these components. In addition to a data bus, the bus system 440 also includes a power bus, a control bus, and a status signal bus. However, for clarity, ... Figure 2 The general labeled all buses as Bus System 440.
[0069] The processor 410 can be an integrated circuit chip with signal processing capabilities, such as a general-purpose processor, a digital signal processor (DSP), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor or any conventional processor, etc.
[0070] User interface 430 includes one or more output devices 431 that enable the presentation of media content, including one or more speakers and / or one or more visual displays. User interface 430 also includes one or more input devices 432, including user interface components that facilitate user input, such as a keyboard, mouse, microphone, touch screen display, camera, other input buttons and controls.
[0071] The memory 450 may be removable, non-removable, or a combination thereof. Exemplary hardware devices include solid-state storage, hard disk drives, optical disk drives, etc. The memory 450 may optionally include one or more storage devices physically located away from the processor 410.
[0072] The memory 450 may include volatile memory or non-volatile memory, or both. The non-volatile memory may be read-only memory (ROM), and the volatile memory may be random access memory (RAM). The memory 450 described in this application embodiment is intended to include any suitable type of memory.
[0073] In some embodiments, memory 450 is capable of storing data to support various operations, examples of which include programs, modules, and data structures or subsets or supersets thereof, as illustrated below.
[0074] Operating system 451 includes system programs for handling various basic system services and performing hardware-related tasks, such as the framework layer, core library layer, driver layer, etc., for implementing various basic business functions and handling hardware-based tasks;
[0075] The network communication module 452 is used to reach other electronic devices via one or more (wired or wireless) network interfaces 420, exemplary network interfaces 420 including: Bluetooth, WiFi, and Universal Serial Bus (USB), etc.
[0076] Presentation module 453 is configured to enable the presentation of information (e.g., a user interface for operating peripheral devices and displaying content and information) via one or more output devices 431 (e.g., a display screen, a speaker, etc.) associated with user interface 430;
[0077] The input processing module 454 is used to detect and translate one or more user inputs or interactions from one or more input devices 432.
[0078] In some embodiments, the network access management device provided in this application can be implemented in software. Figure 2 A network access management device 455 stored in memory 450 is shown. This device can be software in the form of programs and plug-ins, and includes the following software modules: a policy acquisition module 4551, a behavior monitoring module 4552, a security verification module 4553, and an execution module 4554. These modules are logically linked and can therefore be arbitrarily combined or further divided according to the functions they implement. The functions of each module will be described below.
[0079] The network access management method provided in this application will be described in conjunction with exemplary applications and implementations of the electronic devices provided in the embodiments of this application.
[0080] See Figure 3A , Figure 3A This is a flowchart illustrating the network access management method provided in this application embodiment. This method can be executed by an electronic device and will combine... Figure 3A The steps shown are explained.
[0081] In step 101, the permission management policy configured for the target object is obtained.
[0082] Here, electronic devices can obtain permission management policies configured for target objects. The target object can be the electronic device itself or the team to which the electronic device belongs. Each target object can have one or more permission management policies, and each permission management policy can correspond to a network service.
[0083] It's worth noting that corresponding access control policies can be configured based on the characteristics of the target audience. These policies can include whitelists and / or blacklists. For example, with a whitelist, for a target audience within a family, the corresponding access control policy can restrict access to education-related network services only; for a target audience within an enterprise, the corresponding access control policy can restrict access to enterprise-related network services only.
[0084] In some embodiments, before step 101, the method further includes: obtaining management device parameters configured for the permission management policy; wherein the management device parameters include at least one of the management time period, management device, and management account; the above-mentioned method of obtaining the permission management policy configured for the target object can be implemented in the following way: periodically perform device parameter monitoring to obtain real-time device parameters, and match the real-time device parameters with the management device parameters; when the real-time device parameters and the management device parameters are successfully matched, the permission management policy configured for the target object is obtained.
[0085] Here, the electronic device can first obtain the management device parameters configured for the permission management policy corresponding to the target object. These management device parameters include at least one of the following: management time period, management device, and management account. After obtaining the management device parameters, the electronic device can periodically monitor its own device parameters to obtain real-time device parameters, and then match these real-time device parameters with the management device parameters.
[0086] The real-time device parameters include at least one of the following: real-time time, real-time device (i.e., the electronic device itself), and real-time account. The elements in the real-time device parameters correspond to the elements in the management device parameters. For example, if the management device parameters only include the management time period, then the real-time device parameters will also only include the real-time time; if the management device parameters only include the management time period and the management device, then the real-time device parameters will also only include the real-time time and the real-time device, and so on. It is worth noting that the management device and the real-time device can be represented by the device identification information of the electronic device, such as a globally unique identifier (GUID). The real-time account can refer to a logged-in account in the operating system or a logged-in account in a computer program (such as a computer program used for access control services); there is no limitation on this. The account can be represented by account identification information.
[0087] When the monitored real-time device parameters successfully match the managed device parameters, the electronic device obtains the permission management policy corresponding to the target object; when the monitored real-time device parameters fail to match the managed device parameters, the electronic device may not obtain the permission management policy corresponding to the target object, that is, it may not perform network access management. For example, if the managed device parameters only include the managed time period, specifically 9:00 AM to 5:00 PM, and the real-time device parameters only include the real-time time, specifically 1:00 PM, then since the real-time time matches the managed time period (1:00 PM falls within the range of 9:00 AM to 5:00 PM), the real-time device parameters are determined to be a successful match between the managed device parameters and the managed device parameters. Similarly, if the managed device parameters only include the managed devices, specifically Device 1, Device 2, and Device 3, and the real-time device parameters only include the real-time device, specifically Device 1, then since the real-time device matches the managed device (the real-time device falls within the range of the managed device), the real-time device parameters are determined to be a successful match between the managed device parameters and the managed device parameters. Likewise, if the managed device parameters only include the managed account, specifically Account 1, Account 2, and Account 3, and the real-time device parameters only include the real-time account, specifically Account 1, then since the real-time account matches the managed account (the real-time account falls within the range of the managed account), the real-time device parameters are determined to be a successful match between the managed device parameters and the managed device parameters. Of course, when the managed device parameters include multiple elements (such as the managed time period and the managed device), the real-time device parameters are considered to be successfully matched with the managed device parameters only if each element in the managed device parameters matches the corresponding element in the real-time device parameters.
[0088] By adopting the above methods, the necessity and accuracy of network access management can be improved, that is, permission management policies are only obtained when network access management is required.
[0089] In some embodiments, the permission management policy includes a temporary permission management policy and a fixed permission management policy; after step 101, the policy further includes: when the cleanup period arrives, the temporary permission management policy is cleaned up and the cleanup of the fixed permission management policy is prohibited.
[0090] Here, the access control policy corresponding to the target object can include temporary access control policies and fixed access control policies. Temporary access control policies are used temporarily, while fixed access control policies are used throughout the entire network access management process. Therefore, considering the timeliness and accuracy of network access management, temporary access control policies can be cleaned up when the cleanup cycle arrives, while cleaning up fixed access control policies is prohibited, i.e., the fixed access control policies remain unchanged. This cleanup process can be implemented through the driver layer. This allows for differentiated network access management while also saving storage space on electronic devices.
[0091] For example, a temporary access control policy can be an access control policy configured by an administrator through the access control service for network services that the target object can access. A fixed access control policy can include the access control policy corresponding to the access control service itself and / or the access control policy corresponding to network services that the access control service needs to access during operation.
[0092] In some embodiments, the above-described acquisition of the permission management policy configured for the target object can be achieved by performing any of the following processes: sending a permission request including device identification information to the permission management service to obtain the permission management policy configured by the permission management service for the target object; wherein the permission management service is used to manage at least one electronic device, and the target object is the electronic device corresponding to the device identification information among the at least one electronic device; sending a permission request including team identification information to the permission management service to obtain the permission management policy configured by the permission management service for the target object; wherein the permission management service is used to manage at least one team, and the target object is the team corresponding to the team identification information among the at least one team, and each team among the at least one team includes at least one electronic device.
[0093] Here, electronic devices can request permission management policies from the permission management service. The permission management service can manage electronic devices as management units or teams as management units. These two situations will be explained separately below.
[0094] In the first scenario, the access control service manages electronic devices as management units, and manages at least one electronic device. In this case, the electronic device can send a permission request, including its own device identification information, to the access control service. The service then filters out the electronic device corresponding to the received device identification information from among the at least one managed electronic device. For ease of identification, this filtered electronic device is named the target object. The access control service then sends the access control policy configured for the target object to the electronic device (the one that sent the permission request).
[0095] Here, the electronic device can display a network access management interface and obtain device identification information through this interface. For example, if the network access management interface includes an input field, the electronic device can use the information entered by the user in the input field as device identification information and initiate a permission request to the permission management service based on this device identification information. Alternatively, the device identification information can be pre-stored locally on the electronic device, eliminating the need for user input. Furthermore, when the electronic device obtains a permission management policy, it can display a prompt to begin network access management on the network access management interface so that the user is aware of the policy.
[0096] The second scenario involves a permission management service managing at least one team, where each team includes at least one electronic device, and each team corresponds to a team identifier. In this case, the electronic device can obtain the team identifier of its own team (hereinafter referred to as the target team for easy distinction) and send this team identifier to the permission management service. Based on the received team identifier, the permission management service filters out the target object (which is the target team in this case) from the at least one managed team and sends the permission management policy corresponding to the target team to the electronic device.
[0097] Here, the electronic device can display a network access management interface and obtain team identification information through this interface. For example, if the network access management interface includes an input box, the electronic device can use the information entered by the user in the input box as team identification information and initiate a permission request to the permission management service based on this team identification information. If the permission management service identifies the target team among at least one managed team based on the team identification information, the permission management service can send a joining notification to the electronic device. Upon receiving the joining notification, the electronic device displays a message indicating successful joining of the team (equivalent to a notification indicating the start of network access management) in the network access management interface to indicate that it has joined the target team.
[0098] It is worth noting that various results from the network access management process can be presented in the network access management interface, such as the monitored network access data and network access behavior, as well as the test results for network access behavior.
[0099] The above methods enhance the flexibility of network access management. In addition, they enable effective access to permission management services through the network access management interface, while also allowing users to clearly understand the relevant information about network access management.
[0100] In step 102, a monitoring instruction is sent to the driver layer according to the permission management policy, so that the driver layer can perform data monitoring and processing on the network protocol stack according to the monitoring instruction, and perform behavior recognition processing on the monitored network access data to obtain network access behavior.
[0101] This application embodiment implements transparent network access management based on the driver layer. When an electronic device receives an access control policy, it can send a monitoring command to the driver layer according to the policy, thereby triggering the driver layer. Upon receiving the monitoring command, the driver layer performs data monitoring processing on the network protocol stack of the electronic device to obtain network access data, and then performs behavior recognition processing on this data to obtain network access behavior. This network access behavior is used to access network services. For example, when the network access data includes data packets that need to be sent during a TCP handshake, the corresponding network access behavior is identified as TCP connection establishment behavior (i.e., TCP handshake behavior); when the network access data includes Hypertext Transfer Protocol (HTTP) data, the corresponding network access behavior is identified as HTTP data sending behavior. The network protocol stack supports data transmission in the network, and the type of network protocol stack depends on the electronic device; for example, it could be a TCP / IP protocol stack.
[0102] In some embodiments, before step 102, the method further includes: obtaining management device parameters configured for the permission management policy; wherein the management device parameters include at least one of the management time period, management device, and management account; the above-mentioned sending of monitoring instructions to the driver layer according to the permission management policy can be achieved in the following way: periodically performing device parameter monitoring processing to obtain real-time device parameters, and matching the real-time device parameters with the management device parameters; when the real-time device parameters and the management device parameters are successfully matched, sending monitoring instructions to the driver layer according to the permission management policy.
[0103] Here, in addition to obtaining the access control policy, the electronic device can also obtain the management device parameters configured for that policy. These parameters include at least one of the following: management time period, management device, and management account. The electronic device can periodically monitor its own device parameters to obtain real-time parameters and match them with the management device parameters. When the real-time parameters match successfully, a monitoring command is sent to the driver layer according to the access control policy; when the match fails, no monitoring command is sent, i.e., network access management is stopped. This approach enhances the necessity and effectiveness of network access management from another perspective, reducing unnecessary waste of computing resources.
[0104] In some embodiments, the above-mentioned acquisition of the permission management policy configured for the target object can be achieved by sending a permission request to the permission management service to obtain the permission management policy configured for the target object by the permission management service; after step 102, the method further includes: performing information statistical processing on network access behavior to obtain behavior information; and sending the behavior information to the permission management service so that the permission management service can perform behavior warning processing based on the behavior information.
[0105] For monitored network access behavior, electronic devices can perform statistical processing to obtain behavioral information and send this information to the access control service. The access control service can then issue warnings based on this information. For example, the access control service can perform profiling analysis on the behavioral information to obtain user profiles. Based on these profiles, it can determine whether to send warnings to the administrators of the target users. For instance, if a user profile indicates low work efficiency (e.g., network access frequency exceeding a frequency threshold and / or mouse stillness duration exceeding a duration threshold) and / or a risk of job loss (e.g., network access behavior used to access online services provided by recruitment websites), a warning is sent to the administrator managing the target users to alert them to the potential risks associated with that user profile.
[0106] At the underlying implementation level, the driver layer of the electronic device can perform statistical processing on network access behavior to obtain behavioral information. This behavioral information includes, but is not limited to, the network service accessed by the network access behavior, the execution result of the network access behavior (i.e., whether it was blocked), the network access duration after successful execution, the interface dwell time related to the network access behavior, and mouse operation information related to the network access behavior. The driver layer can send the behavioral information to the application layer, which in turn sends it to the permission management service, enabling the permission management service to perform behavioral warning processing based on the behavioral information. The application layer can perform data structuring operations on the behavioral information before sending it to the permission management service, allowing the permission management service to better understand the behavioral information from a machine perspective, thereby improving the accuracy of behavioral warning processing.
[0107] The above methods enable the expansion of capabilities based on network access management, achieving accurate and effective behavioral early warning.
[0108] In some embodiments, the above-mentioned acquisition of the permission management policy configured for the target object can be achieved by sending a permission request to the permission management service to obtain the permission management policy configured for the target object by the permission management service; after step 102, the method further includes: when the network access behavior is used for the access permission management service, assigning an execution permission to the network access behavior; wherein, the execution permission is used to indicate that the network access behavior is allowed to be executed.
[0109] Since access control services are also a type of network service, in order to ensure that access to access control services can proceed normally, execution permissions can be assigned to network access behaviors used for access control services. That is, network access behaviors used for access control services are not included in the scope of network access management and are not subject to access control policies. In this way, data transmission between the access control service and the network can proceed smoothly.
[0110] In step 103, network access behavior is subjected to security verification processing according to the access control policy to obtain the verification result indicating whether the network access behavior is blocked.
[0111] Here, network access behavior is subjected to security checks based on the access control policy corresponding to the target object, and the check results are obtained. The check results can include two types: check success and check failure. Check success means that the network access behavior is not blocked, and check failure means that the network access behavior is blocked. Blocking the network access behavior means prohibiting the execution of the network access behavior.
[0112] It is worth noting that access control policies can include whitelisted address information and / or blacklisted address information. The whitelisted address information refers to the address information of network services that can be accessed, while the blacklisted address information refers to the address information of network services that are prohibited from access. Accordingly, security checks can be performed based on the whitelisted and / or blacklisted address information in the access control policy.
[0113] In some embodiments, the access control policy includes whitelisted address information, which includes whitelisted Internet Protocol (IP) addresses and whitelisted domain name addresses. The above-mentioned security verification of network access behavior based on the access control policy can be achieved in the following way: when the network access behavior is a connection establishment behavior based on an IP address, the connection establishment behavior is verified based on the whitelisted IP address; when the network access behavior is a data transmission behavior based on a domain name address, the data transmission behavior is verified based on the whitelisted domain name address.
[0114] Here, effective network access management can be achieved through a whitelist approach. This means the access control policy includes whitelisted address information, which in turn includes whitelisted Internet Protocol (IP) addresses and whitelisted domain names. It's worth noting that the domain names used in this embodiment can also be replaced with Uniform Resource Locator (URL) addresses.
[0115] In this scenario, when network access involves establishing a connection based on an Internet Protocol (IP) address, security checks are performed on the connection establishment process according to a whitelist of IP addresses, such as a TCP handshake. Similarly, when network access involves sending data based on a domain name address, security checks are performed on the data sending process according to a whitelist of domain names, such as data sending via Hypertext Transfer Protocol (HTTP) in a proxy environment. This approach allows for targeted security checks based on the characteristics of network access behavior, improving the effectiveness of security checks.
[0116] In step 104, control operations for network access behavior are performed based on the test results.
[0117] After obtaining the test results, control operations for network access behavior are executed based on the test results. For example, the driver layer of the electronic device can execute control operations for network access behavior based on the test results. Since the driver runs in the same space as the operating system, the network access management process is imperceptible to the user, similar to the network access management implemented by the operating system itself. In this way, the transparency and security of network access management can be improved, effectively preventing users from bypassing the restrictions of network access management.
[0118] In some embodiments, the above-mentioned acquisition of the permission management policy configured for the target object can be achieved by: sending a permission request to the permission management service to obtain the permission management policy configured for the target object by the permission management service; between any steps, the method further includes: sending a supplementary permission request for the corresponding target network service to the permission management service, so that the permission management service approves the supplementary permission request; wherein, the target network service refers to a network service different from the permission management service; and acquiring the supplementary permission management policy sent by the permission management service; wherein, the supplementary permission management policy is sent by the permission management service when the supplementary permission request is approved, and the supplementary permission management policy is used to provide execution permission for the target network access behavior, and the target network access behavior is used to access the target network service.
[0119] Since the permission management policy corresponding to the target object is pre-configured, it may not meet the real-time access needs of the electronic device user. Therefore, in this embodiment, it is also possible to supplement (extend) the permission management policy corresponding to the target object. For example, the electronic device can send a supplementary permission request for the corresponding target network service to the permission management service, so that the permission management service can approve and process the supplementary permission request. Here, the target network service is a network service that is different from the permission management service.
[0120] Here, the approval process is not limited; it can be manual or automated based on artificial intelligence. When the supplementary permission request is approved, the access control service sends a supplementary permission management policy to the electronic device. Under this policy-based network access management, the electronic device can successfully execute the target network access behavior to access the target network service. The network access management process based on the supplementary permission management policy is similar to that based on the permission management policy corresponding to the target object. Similarly, corresponding management device parameters can be configured for the supplementary permission management policy. This approach enhances the flexibility of network access management and meets users' real-time access needs.
[0121] like Figure 3A As shown, this application embodiment captures network access behavior through the driver layer, thereby realizing network access management based on network access behavior, which can improve the transparency of network access management, achieve user non-awareness, and thus improve the security of network access management.
[0122] In some embodiments, see Figure 3B , Figure 3B This is a flowchart illustrating a network access management method provided in an embodiment of this application, which can be executed by an electronic device. Figure 3B middle, Figure 3A Step 103 shown can be implemented through steps 201 to 202, which will be explained in conjunction with each step.
[0123] In step 201, the network access behavior is subjected to security verification based on the whitelist address information to obtain the whitelist verification result.
[0124] Here, the access control policy can include whitelisted address information and graylisted address information. The graylisted address information corresponds to usage limits and is used to provide network access management based on usage limits. Compared with the graylisted address information, the whitelisted address information has a higher priority. Therefore, network access behavior can be first processed for security verification based on the whitelisted address information to obtain the whitelist verification result.
[0125] It is worth noting that the usage limit can be the duration of use or the number of uses, but it is not limited to these forms.
[0126] In some embodiments, the whitelist address information includes whitelist domain names, and the graylist address information includes graylist domain names. After step 102, the method further includes: parsing the Domain Name System (DNS) data in the network access data to obtain the access Internet Protocol (IP) address and the corresponding access domain name address; matching the access domain name address with the whitelist domain name address; when the access domain name address matches the whitelist domain name address successfully, the access IP address is used as the whitelist IP address and added to the whitelist address information; when the access domain name address fails to match the whitelist domain name address, the access domain name address is matched with the graylist domain name address, and when the access domain name address matches the graylist domain name address successfully, the access IP address is used as the graylist IP address and added to the graylist address information.
[0127] Here, when the whitelist address information includes whitelisted domain names, the corresponding whitelisted Internet Protocol (IP) address can be obtained through Domain Name System (DNS) resolution. For example, DNS traffic data in network access data is parsed to obtain the access IP address and its corresponding domain name, and then the access domain name is matched against the whitelisted domain names. When the access domain name and the whitelisted domain name match successfully (e.g., they are the same), the access IP address is used as the whitelisted IP address corresponding to the whitelisted domain name and added to the whitelist address information.
[0128] When the access control policy includes graylist address information, and the graylist address information includes graylist domain names, further parsing can be performed to obtain graylist Internet Protocol addresses. For example, when the access domain name fails to match a whitelist domain name, the access domain name is matched with a graylist domain name. When the access domain name matches a graylist domain name (e.g., they are the same), the access Internet Protocol address is used as the graylist Internet Protocol address and added to the graylist address information. This method allows for the supplementation of corresponding Internet Protocol addresses even when only domain names are available, thereby improving the completeness of the access control policy.
[0129] In step 202, when the whitelist verification result is a failure, the network access behavior is subjected to security verification processing based on the graylist address information to obtain the graylist verification result; wherein, the graylist verification result is used to indicate whether to block the network access behavior.
[0130] When the whitelist verification result is successful, control operations on network access behavior can be performed based on the whitelist verification result. The control operation here is to not block network access behavior.
[0131] When the whitelist verification fails, the network access behavior is subjected to security verification based on the graylist address information with lower priority, and the graylist verification result is obtained. In this case, the graylist verification result is used to indicate whether to block the network access behavior.
[0132] exist Figure 3B middle, Figure 3A Step 104 shown can be implemented through either step 203 or step 204, and will be explained in conjunction with each step.
[0133] In step 203, when the gray list verification result is successful and the usage limit corresponding to the gray list address information is greater than zero, execution permission is assigned to the network access behavior and the usage limit is deducted; wherein, the execution permission is used to indicate that the network access behavior is allowed to be executed.
[0134] When the gray list verification result is successful and the usage limit corresponding to the gray list address information is greater than zero, execution permission is assigned to the network access behavior, for example, by the driver layer. This execution permission is used to indicate that the network access behavior is allowed to be executed, that is, the network access behavior is not blocked. In this way, the smooth execution of the network access behavior can be guaranteed.
[0135] Additionally, usage limits are deducted, for example, by the driver layer. For instance, when the usage limit is the usage duration, the network access duration after successful execution of the current network access action can be subtracted from the original usage duration to obtain the new usage duration (i.e., the deducted usage duration); when the usage limit is the number of uses, the number of uses can be subtracted by 1 to obtain the new number of uses (i.e., the deducted usage count).
[0136] In step 204, when the gray list verification result is a failure or the usage limit corresponding to the gray list address information is zero, the network access behavior is blocked.
[0137] Here, when the gray list verification result is a failure, or the usage limit corresponding to the gray list address information is equal to zero, it proves that the network access behavior carries a certain security risk. Therefore, the network access behavior is blocked, such as by the driver layer.
[0138] like Figure 3B As shown, this application embodiment uses graylist address information to implement quota-based network access management, which can improve the flexibility of network access management.
[0139] In some embodiments, see Figure 3C , Figure 3C This is a flowchart illustrating a network access management method provided in an embodiment of this application, which can be executed by an electronic device. Figure 3C middle, Figure 3AStep 103 shown can be implemented through steps 301 to 303, and will be explained in conjunction with each step.
[0140] In step 301, the access address information to be accessed by the network access behavior is matched with the whitelist address information.
[0141] Here, an example of a security verification process is provided when the access management policy includes whitelisted address information. First, the access address information requested by the network access behavior is matched against the whitelisted address information. The access address information includes at least one of an Internet Protocol address and a domain name address; similarly, the whitelisted address information includes at least one of a whitelisted Internet Protocol address and a whitelisted domain name address. The access address information can be located within the network access data.
[0142] In step 302, when the access address information matches the whitelist address information successfully, the verification result is determined to be successful.
[0143] For example, when the access address information is a subset of the whitelist address information, it is determined that the access address information matches the whitelist address information successfully, and the verification result is determined to be successful.
[0144] In step 303, when the access address information fails to match the whitelist address information, the verification result is determined to be a verification failure.
[0145] For example, if the access address information is not a subset of the whitelist address information, it is determined that the access address information fails to match the whitelist address information, and the verification result is determined to be a verification failure.
[0146] It is worth noting that the verification results in steps 302 and 303 refer to the whitelist verification results. If the access control policy also includes graylist address information, the graylist verification results can be obtained in a similar manner to steps 301 to 303.
[0147] In some embodiments, the above-mentioned matching process between the access address information to be accessed by the network access behavior and the whitelist address information can be implemented in the following way: the access address information is matched with the whitelist address information through the driver layer; the above-mentioned control operation for the network access behavior can be implemented in the following way: when the verification result is successful, the driver layer assigns execution permission to the network access behavior; wherein, the execution permission is used to indicate that the network access behavior is allowed to be executed; when the verification result is unsuccessful, the driver layer intercepts the network access behavior.
[0148] Here, the operation of matching the access address information with the whitelist address information can be implemented by the driver layer. In this case, when the verification result is successful, the driver layer assigns execution permissions to the network access behavior, that is, the network access behavior is not blocked; when the verification result is unsuccessful, the driver layer blocks the network access behavior. The above method integrates the matching logic within the driver layer, which can avoid the I / O blocking problem that is prone to occur in the application layer.
[0149] In some embodiments, the above-mentioned matching process between the access address information to be accessed by the network access behavior and the whitelist address information can be implemented in the following manner: the access address information is matched with the whitelist address information through the application layer; after step 303, the method further includes: when the verification result is successful, the verification result is sent to the driver layer through the application layer, so that the driver layer assigns execution permission to the network access behavior according to the verification result; wherein, the execution permission is used to indicate that the network access behavior is allowed to be executed; when the verification result is unsuccessful, the verification result is sent to the driver layer through the application layer, so that the driver layer intercepts the network access behavior according to the verification result.
[0150] Here, after obtaining the access address information required by the network access behavior, the driver layer can also send the access address information to the application layer, whereby the application layer matches the access address information with the whitelist address information. The application layer can then send the verification result back to the driver layer, enabling the driver layer to perform control operations on the network access behavior based on the received verification result. For example, if the verification result is successful, the driver layer can assign execution permissions to the network access behavior; if the verification result is unsuccessful, the driver layer can intercept the network access behavior. This approach integrates the matching logic within the application layer, reducing the logical complexity of the driver layer. Furthermore, a completion port model or other I / O models can be deployed at the application layer to minimize I / O blocking issues and prevent stuttering.
[0151] like Figure 3C As shown in the embodiments of this application, an example method for security verification processing is provided, which can improve the security of network access based on a whitelist model.
[0152] See Figure 4 , Figure 4 This is a flowchart illustrating the network access management method provided in this application embodiment. This method can be implemented by a terminal device (such as...). Figure 1 The terminal device 400 shown) and the server (such as Figure 1 The server 200 shown is implemented collaboratively, and will combine Figure 4 The steps shown are explained.
[0153] In step 401, the terminal device sends a permission request to the server.
[0154] Here, the server can be used to provide permission management services. Terminal devices can send permission requests to the server to access the permission management services.
[0155] In step 402, the server selects the target object from at least one managed object based on the received permission request.
[0156] Here, the server filters for the target object from at least one managed object based on the received permission request. The object can be an electronic device or a team.
[0157] Taking the scenario where the object is a team as an example, the permission management service manages at least one team, and each team corresponds to a team identifier. The server can match the team identifier in the received permission request with the team identifier of each team, and select the team that matches successfully (e.g., the team identifier is the same as the team identifier received by the server) as the target object (target team), thus achieving the filtering of target objects.
[0158] In step 403, the server sends the permission management policy corresponding to the target object to the terminal device.
[0159] Here, each object managed by the server corresponds to a permission management policy. After selecting a target object, the server sends the corresponding permission management policy to the terminal device. The permission management policy can be stored in a database, the server's distributed file system, or a blockchain, etc., without limitation.
[0160] In some embodiments, before step 403, the method further includes: the server obtaining address information configured for the target object, performing address detection processing on the address information to obtain detection address information, and combining the address information and the detection address information into a permission management policy corresponding to the target object.
[0161] For example, an administrator managing target objects can configure address information for each target object on the server. This address information corresponds to a network service and can be either a whitelist or a blacklist. Since a network service typically includes multiple address information (e.g., a website's main site has many sub-links), the server can perform address probing based on the received address information, obtaining multiple probe address information. The received address information and these probe address information can then be combined to form the corresponding permission management policy for the target object. This improves the comprehensiveness and completeness of the permission management policy. The method of address probing is not limited; for example, it can be implemented using browser hooks from a BHO (Browser Helper Object).
[0162] In step 404, the terminal device sends a monitoring instruction to the driver layer according to the permission management policy, so that the driver layer can perform data monitoring and processing on the network protocol stack according to the monitoring instruction, and perform behavior recognition processing on the monitored network access data to obtain network access behavior.
[0163] Since data transmission in the network requires the support of the network protocol stack, when a terminal device receives an access control policy, it can trigger the driver layer to monitor the network protocol stack and perform behavior recognition processing on the monitored network access data to obtain network access behavior.
[0164] In step 405, the terminal device performs security verification on network access behavior according to the permission management policy, and obtains a verification result indicating whether the network access behavior is blocked.
[0165] The terminal device performs security checks on network access behavior according to the permission management policy corresponding to the target object, and obtains a check result indicating whether the network access behavior is blocked. This check result also reflects the security risks of the network access behavior.
[0166] In step 406, the terminal device performs control operations on network access behavior based on the test results.
[0167] After receiving the verification results, the terminal device can execute control operations on network access behavior based on the results. For the terminal device itself, the transparency of network access management can be improved through the driver layer, thereby enhancing security. In the case of a team, the server can implement batch network access management by issuing policies (e.g., batch network access management for all terminal devices within the team).
[0168] The following will illustrate exemplary applications of the embodiments of this application in real-world scenarios. For ease of understanding, examples will be provided using a team as the subject. These embodiments can be used by various teams (such as families, schools, or companies) requiring restricted network access (i.e., network access management). By setting whitelist address information, controlling management time periods, requesting permissions, providing motivational warnings (behavioral warnings), and setting limits, they can improve the engagement of children, students, or company employees with tasks (such as learning or work tasks), prevent interference from irrelevant information, and ultimately improve efficiency. Furthermore, these embodiments enable transparent network access management. The controlled end (such as the terminal device mentioned above) can be controlled by the permission management service of the controlling end (such as the server mentioned above) without the user's awareness. In practice, as long as the controlled end has a network access management app installed, the administrator of the app can issue permission management policies in the background. The configuration is simple and efficient, requiring no special hardware intervention.
[0169] Compared with the solutions provided by related technologies, the embodiments of this application have been optimized in at least the following two aspects.
[0170] 1) Network awareness. This application adopts a driver-layer scheme, which can monitor and modify data at each layer of the TCP / IP protocol stack. It is a transparent network access management scheme for the user on the controlled end, that is, the user is unaware of the network access management and feels that it is implemented by the operating system itself.
[0171] 2) Regarding network access management. The embodiments of this application achieve scalability of capabilities, including at least the following aspects.
[0172] a) Identify login accounts (corresponding to the real-time accounts mentioned above) for differentiated time-period control. This application embodiment can manage network access based on login accounts, and furthermore, differentiated time-period control can be implemented for different accounts. For example, after a child in a family logs in with their own account (which could be an operating system account), according to the permission management policy, they can be controlled to only access education-related network services during study periods, while other network services such as video, entertainment, and games are blocked during those study periods. On weekends, the management time periods can be adjusted to better meet the student's entertainment needs. If a parent logs in with their own account, no permission management policy needs to be set. In this way, network access scenarios can be controlled by differentiating users and / or time periods, achieving flexibility and scalability.
[0173] (b) Provides intelligent authorization management capabilities for network services that the user does not have permission to access. For general network access management apps, once a policy is set, the controlled device can only work or study under that policy. If it wants to access a network service it doesn't have permission to access, it can only request a policy change, which cannot meet the needs of emergency scenarios. For example, in a company environment, a policy is set that only allows access to internal company network services. If a terminal device within the company has a temporary need for external network access, a general network access management app cannot meet this need. To address this, this application provides the capability for temporary authorized access. The controlled device can submit a supplementary permission request to access a network service through an authorization entry point (such as the authorization entry point in the network access management interface), for example, requesting access to the interface with the domain name xx.com within a certain time period. When the control terminal receives the supplementary permission request, it approves it and, upon approval, issues the corresponding supplementary permission management policy for that network service (which can be reflected in the form of whitelist address information). In this way, the controlled device can access the requested network service.
[0174] c) When the control terminal issues permission management policies, it provides subchain detection capabilities to improve the comprehensiveness of permission management policies.
[0175] Taking whitelisted domain addresses as an example, a website's main site typically contains many sub-links. Therefore, when setting up a whitelist for a website, all sub-link domain addresses must be configured to ensure that the controlled end can access the website normally under the access control policy. To address this, this application provides an automatic sub-link aggregation function. For the control end, sub-link information can be automatically retrieved from the main site's domain address, and the whitelist policy (i.e., whitelisted address information) can be obtained through aggregation. This method is very fast and efficient, has a low barrier to entry, and is very user-friendly, even for novice users.
[0176] d) Implement time / number control for network access through quota access.
[0177] Typically, access control policies are either blacklists or whitelists, which only indicate to users whether they can or cannot access a particular network service, resulting in limited flexibility. To address this, this application incorporates a graylist policy (corresponding to the graylist address information mentioned above). This policy allows for quota-based access. For example, for a video website with the domain name v.xx.com, configuring a graylist policy allows for quota-based access based on the number of visits or the duration of access. Quota-based access can be used in home network access management scenarios, providing parents with a protective function for their children's internet use, ensuring that their online time is controlled.
[0178] e) By statistically analyzing network access behavior, behavioral warnings can be issued for the controlled users (i.e., users on the controlled end).
[0179] This application embodiment can collect statistics on the network access duration, interface dwell time, and blocked access interfaces of the controlled user. The backend can use this statistical information to create a user profile of the controlled user, and then determine whether the controlled user has low work efficiency, is at risk of leaving the company (such as trying to access recruitment websites), or is "slacking off" (such as judging based on the duration of interface dwell and / or the duration of mouse stillness). If behavioral risks exist, an early warning can be sent to the administrator of the management team (such as the enterprise administrator), thereby improving personnel management efficiency.
[0180] Next, the network access management scheme provided in the embodiments of this application will be explained from a visualization perspective.
[0181] For terminal devices, the first step is to join a team. This makes the terminal device a controlled device, meaning it's managed by the team's corresponding access control policies. Administrators of the network access management app can see the terminal devices within the team in the dashboard interface (i.e., the backend interface) and can issue access control policies to these devices. After the access control policy is successfully issued, the controlled device can manage subsequent network access behavior according to the received policy. This will be explained in the following aspects.
[0182] 1) Terminal devices need to join the team via a PIN code (corresponding to the team identification information above). Each team's PIN code is unique. As an example, the following is provided: Figure 5 The diagram illustrates the network access management interface. After installing and launching the network access management app on their terminal device, users can enter a PIN code in the app's interface to join a team. For example, the terminal device can send the received PIN code to the control terminal, allowing the control terminal to filter for the target team from at least one managed team. This target team is the team the terminal device has joined. It's worth noting that in addition to network access management functions, the network access management app can also integrate virus scanning, junk file cleaning, and PC acceleration functions; these are not limited to these features.
[0183] 2) After joining the team, a message indicating successful team joining will be displayed on the network access management interface. As an example, the following is provided: Figure 6 The diagram shown illustrates the network access management interface. Figure 6 The message "Successfully joined the team" is displayed in section 61.
[0184] 3) For the control side, the required permission management policies can be configured through the dashboard interface. As an example, the following is provided: Figure 7 The diagram shown is a schematic of the Kanban interface. Figure 7 The internet access policy shown is the access control policy, which can specifically support the configuration of whitelist or blacklist policies. For ease of understanding, the following explanation will use the whitelist policy as an example. Figure 7 The policy list is shown, including policies 1 through 4, where each policy corresponds to a network service. For example, policy 1 corresponds to a network chat service, policy 2 to a network search service, policy 3 to a network video service, and policy 4 to another network video service. Administrators on the control panel can select at least one policy from the policy list to issue commands.
[0185] 4) From the control end, the whitelist policy management time period can be configured through the dashboard interface to manage network access by time period. For example... Figure 8 As shown, the management time period can be configured as 8:00 to 11:59 and 14:00 to 18:00.
[0186] 5) Automatic sub-link detection (corresponding to the address detection processing above) provides administrators with a very convenient policy setting experience. For example, if the main website address of a web search service is www.xx.com, sub-link detection can obtain the domain addresses of sub-sites such as t.xx.com and abcxx.com. Aggregating www.xx.com, t.xx.com, and abcxx.com yields the whitelist policy corresponding to that web search service.
[0187] 6) After the whitelist policy is issued, if the access address requested by the controlled terminal's network access behavior is not within the whitelist policy (i.e., the match fails), the controlled terminal will block the network access behavior. Taking the controlled terminal's network access behavior (such as accessing a website) through a browser as an example, the following is provided: Figure 9 The browser interface shown is the result of blocking the network access behavior.
[0188] The following will describe the network access management scheme provided by the embodiments of this application from the underlying implementation level. Compared with the solutions provided by related technologies, the embodiments of this application have made improvements in at least the following aspects: 1) A team-based group control scheme, where electronic devices within the team are controlled by permission management policies, transforming the scenario that originally required device control through physical network topology into a scenario controlled entirely through software logic structure, reducing the investment cost of group control scenarios; 2) Transparent network access management through a driver-based approach, which avoids user bypassing and, because the logic is embedded in the TCP / IP protocol stack, the system has high stability. In addition, the interception method directly discards data packets, and the interception behavior is similar to the system disabling the network; 3) A flexible decision chain is designed to support scalable network access management scenarios. This decision chain supports the application of scenarios such as time period management, permission management policy expansion, gray list quota control, and behavior warning, thereby supporting network access management for families, schools, organizations, or enterprises, improving the personalized experience of network access management. In addition, the decision chain is an extensible plug-in logic system, and customized logic modules can be inserted according to scenario requirements in the future.
[0189] For ease of understanding, the following are provided: Figure 10 The flowchart shown below illustrates the network access management method, which will be combined with... Figure 10 The explanation is presented step by step.
[0190] 1) After the terminal device launches the network access management app, it retrieves the basic configuration (corresponding to the management device parameters mentioned above) for that team, assuming the terminal device is already joined. This basic configuration indicates whether the terminal device requires network access management. If network access management is required, the app will further retrieve the whitelist policy from the backend. Additionally, if a management period is configured, network access management will be stopped if the whitelist policy is not retrieved within that period.
[0191] It's worth noting that the network access management app can send the terminal device's GUID and the login account's username (corresponding to the account identification information mentioned above) to the backend. The backend can then use the terminal device's GUID and username to construct an account tree rooted at the terminal device, such as... Figure 11A , Figure 11B and Figure 11C As shown. In this way, the administrator can configure management time periods for different accounts on terminal devices and distribute them to the controlled terminals. After receiving the management time period, the controlled terminal determines whether to perform network access management based on whether the real-time time is within the management time period (referring to the management time period corresponding to the real-time terminal device and login account). Figure 12 As shown, where, Figure 12 The timer polling thread shown is used to periodically obtain real-time information. Of course, in this embodiment, network access management can also be performed without being based on a management time period; for example, persistent network access management can be implemented.
[0192] 2) After retrieving the whitelist policy, it is parsed at the application layer of the terminal device. Simultaneously, the application layer invokes the driver module in the driver layer. The driver module is the software module in the driver layer used to implement network access management. The parsing performed by the application layer is to parse the whitelist policy into data that the driver module can understand. Taking a whitelist policy that includes whitelist domain addresses as an example, after parsing, the application layer sends the whitelist domain addresses to the driver module. It is worth noting that, due to the control of the decision chain capability, if quota control is required, a gray list policy is also issued during the policy issuance process. This gray list policy will affect the network access management logic throughout the entire policy decision-making process.
[0193] 3) After the driver module starts, it will monitor the TCP / IP protocol stack, meaning that every data packet passing through the TCP / IP protocol stack will flow through the driver module.
[0194] 4) For monitored User Datagram Protocol (UDP) traffic, the driver module listens for DNS protocol traffic (corresponding to Domain Name System data mentioned above) on port 53 within the UDP traffic. If DNS protocol traffic is detected, it performs DNS resolution to obtain the access IP address and access domain name. The driver module then matches the access domain name with whitelisted domain names. If a match is found (i.e., the access domain name is in the whitelist policy), the access IP address is added to the whitelisted IP address list for later use.
[0195] 5) This application embodiment uses a driver to implement network access management. Therefore, the interception effect is effective for all processes at the application layer. This raises the issue of ensuring that the network access management APP's own network access and policy transmission processes are not intercepted. To address this, this application embodiment provides the following two methods to ensure that the network access management APP's own network access proceeds normally.
[0196] a) Regarding strategy delivery, such as Figure 13As shown, the whitelist policy received by the application layer can include whitelist domain address + default domain address + default IP address. The whitelist domain address refers to the domain address that can be accessed configured by the administrator in the dashboard interface. The default domain address is the domain address that the network access management APP backend needs to access. The default IP address is the IP address that the internal process of the network access management APP needs to access.
[0197] When the application layer distributes policies, it performs a union operation on the whitelisted domain names and the default domain names (treating the default domain names as whitelisted domain names in this process). Thus, the information sent to the driver module includes the default IP address and the resulting whitelisted domain name address list. Then, after performing DNS resolution, the driver module performs a union operation on the default IP address and the resolved whitelisted IP addresses (again treating the default IP address as whitelisted IP address), obtaining a whitelisted IP address list. This facilitates subsequent interception based on the whitelisted domain name address list and the whitelisted IP address list.
[0198] b) In terms of driver layer awareness, for example, the driver module can sense the process to which the TCP connection belongs. When the process is the process of the network access management APP itself, the process is not included in the management logic; when the process is not the process of the network access management APP itself, the process is included in the management logic.
[0199] 6) There are two situations when intercepting: one is intercepting TCP handshakes; the other is intercepting HTTP data traffic in a proxy environment. These will be explained separately.
[0200] a) During the TCP handshake at the application layer, the driver module can obtain the access IP address of the remote network service to be connected to and determine whether to block the connection based on the whitelist of IP addresses. If the access IP address is in the whitelist, no blocking is performed, ensuring the smooth progress of the TCP handshake; if the access IP address is not in the whitelist, the TCP handshake is blocked.
[0201] (b) For HTTP data, the driver module parses the HTTP header to obtain the access domain name address that needs to be connected. Then, the driver module matches the access domain name address with a whitelist of domain names. If the access domain name address is in the whitelist, the HTTP data is not intercepted; if the access domain name address is not in the whitelist, the HTTP data is intercepted, for example, the HTTP data can be discarded directly.
[0202] 7) In the interception decisions during both the TCP handshake and HTTP data transmission stages, if the whitelist policy is not matched (i.e., the match with the whitelisted IP address list or whitelisted domain address list fails), the process will proceed to the graylist conditional quota decision stage. If the graylist policy is matched, the remaining usage limit under that graylist policy will determine whether to take further interception action, thereby implementing conditional quota-based network access management.
[0203] It's worth noting that, in cases where a graylist policy exists, after the DNS resolution in step 4), if the accessed domain name fails to match the whitelisted domain name, it can be matched against the graylisted domain name. When the accessed domain name matches successfully, the accessed IP address is added to the graylist IP address list. Thus, during the TCP handshake, if the accessed IP address fails to match the whitelisted IP address list, it is matched against the graylisted IP address list. When the accessed IP address matches successfully, the usage limit corresponding to that graylisted IP address list (i.e., the usage limit corresponding to the graylist policy) is queried. If the usage limit is greater than zero, the TCP handshake is not blocked; if the usage limit is zero, the TCP handshake is blocked. The interception process for HTTP data is similar.
[0204] 8) Additionally, after repeated DNS resolutions, the driver layer continuously stores a whitelist of IP addresses. Since DNS resolution has a time limit, the driver module periodically cleans up the whitelist of IP addresses. However, the driver module does not clean up the default IP addresses issued by the application layer during the system's lifecycle.
[0205] 9) If the administrator disables network access management in the background, the application layer will retrieve the basic configuration (indicating that network access management is disabled) and then shut down the driver module. This allows users on the terminal devices to access the network normally. Conversely, if the administrator modifies the whitelist policy, the application layer will receive a notification from the background, retrieve the modified whitelist policy, clear all whitelist policies in the driver layer, and distribute the modified whitelist policy to the driver layer. This allows a new round of network access management to continue.
[0206] 10) The driver module can push the behavioral information of each network access behavior to the application layer, which will then parse it and send the structured data to the backend. The backend can perform behavioral warning processing on the behavioral information, such as user profiling, and determine whether the corresponding user has behavioral risks based on the obtained user profile. If behavioral risks are found, a warning will be sent to the administrator.
[0207] It is worth noting that this application embodiment can also provide an entry point for emergency access requests, such as... Figure 14 As shown, when the controlled client sends a supplementary permission request for a specific website to the administrator's machine (i.e., the backend), the administrator can approve the request. When the administrator approves the request, the permission management service uses the website address information requested in the supplementary permission request as a supplementary whitelist policy (corresponding to the supplementary permission management policy mentioned above) and sends it to the controlled client. Thus, the controlled client can successfully access the website.
[0208] It's worth noting that the driver module can also push monitored traffic information up to the application layer, where the application layer determines whether to block the corresponding traffic based on a whitelist policy. The application layer can then notify the driver module of its blocking decision, allowing the driver module to either block or not block the traffic. This simplifies the logic complexity of the driver layer. Furthermore, a completion port model or other I / O model can be deployed at the application layer to reduce the likelihood of I / O operations and prevent system lag.
[0209] The embodiments of this application have at least the following technical effects: They implement a group control solution for teams, forming a logical network topology from terminal devices within the team in a purely software-based manner, enabling effective network access management for terminal devices in different regions; they provide a scalable decision control chain, allowing for personalized customization for different network access management scenarios; they are low-cost and widely applicable, for example, adaptable to home-based learning network access management scenarios, school group teaching and entertainment quota control scenarios, and company-level strong network access restriction scenarios. The embodiments of this application can adapt to device environments of various sizes, from a few devices to company-level devices of several thousand or more.
[0210] The following continues to describe the exemplary structure of the network access management device 455 provided in the embodiments of this application as a software module. In some embodiments, such as Figure 2 As shown, the software modules stored in the network access management device 455 in the memory 450 may include: a policy acquisition module 4551, used to acquire the permission management policy configured for the target object; a behavior monitoring module 4552, used to send monitoring instructions to the driver layer according to the permission management policy, so that the driver layer performs data monitoring processing on the network protocol stack according to the monitoring instructions, and performs behavior recognition processing on the monitored network access data to obtain network access behavior; a security verification module 4553, used to perform security verification processing on the network access behavior according to the permission management policy, and obtain a verification result indicating whether to block the network access behavior; and an execution module 4554, used to execute control operations on the network access behavior according to the verification result.
[0211] In some embodiments, the access control policy includes whitelist address information and graylist address information; the security verification module 4553 is further configured to: perform security verification processing on network access behavior according to the whitelist address information to obtain a whitelist verification result; when the whitelist verification result is a verification failure, perform security verification processing on network access behavior according to the graylist address information to obtain a graylist verification result; wherein, the graylist verification result is used to indicate whether to block network access behavior; the execution module 4554 is further configured to: when the graylist verification result is a successful verification and the usage limit corresponding to the graylist address information is greater than zero, assign execution permission to the network access behavior and deduct the usage limit; wherein, the execution permission is used to indicate that the network access behavior is allowed to be executed; when the graylist verification result is a verification failure or the usage limit corresponding to the graylist address information is equal to zero, block the network access behavior.
[0212] In some embodiments, the whitelist address information includes whitelist domain names, and the graylist address information includes graylist domain names. The network access management device 455 further includes a parsing module, configured to: parse the Domain Name System (DNS) data in the network access data to obtain the access Internet Protocol (IP) address and the corresponding access domain name address; match the access domain name address with the whitelist domain name address; when the access domain name address matches the whitelist domain name address successfully, use the access IP address as the whitelist IP address and add it to the whitelist address information; when the access domain name address fails to match the whitelist domain name address, match the access domain name address with the graylist domain name address, and when the access domain name address matches the graylist domain name address successfully, use the access IP address as the graylist IP address and add it to the graylist address information.
[0213] In some embodiments, the access control policy includes whitelist address information; the security verification module 4553 is further configured to: match the access address information to be accessed by the network access behavior with the whitelist address information; when the access address information matches the whitelist address information successfully, determine the verification result as successful; when the access address information fails to match the whitelist address information, determine the verification result as failed.
[0214] In some embodiments, the security verification module 4553 is further configured to: perform matching processing between the access address information and the whitelist address information through the driver layer; the execution module 4554 is further configured to: when the verification result is successful, allocate execution permission to the network access behavior through the driver layer; wherein, the execution permission is used to indicate that the network access behavior is allowed to be executed; when the verification result is unsuccessful, intercept the network access behavior through the driver layer.
[0215] In some embodiments, the security verification module 4553 is further configured to perform matching processing between the access address information and the whitelist address information through the application layer; the execution module 4554 is further configured to send the verification result to the driver layer through the application layer, so that the driver layer can perform control operations on network access behavior according to the verification result.
[0216] In some embodiments, the network access management device 455 further includes a parameter acquisition module, used to acquire management device parameters configured for the permission management policy; wherein, the management device parameters include at least one of the management time period, management device, and management account; the behavior monitoring module 4552 is further used to: periodically perform device parameter monitoring processing to obtain real-time device parameters, and match the real-time device parameters with the management device parameters; when the real-time device parameters and the management device parameters are successfully matched, send a monitoring instruction to the driver layer according to the permission management policy.
[0217] In some embodiments, the network access management device 455 further includes a parameter acquisition module, configured to acquire management device parameters configured for the permission management policy; wherein the management device parameters include at least one of the management time period, management device, and management account; the policy acquisition module 4551 is further configured to: periodically perform device parameter monitoring to obtain real-time device parameters, and match the real-time device parameters with the management device parameters; when the real-time device parameters and the management device parameters are successfully matched, acquire the permission management policy configured for the target object.
[0218] In some embodiments, the policy acquisition module 4551 is further configured to: send a permission request to a permission management service to obtain a permission management policy configured by the permission management service for the target object; the network access management device 455 further includes a supplementary module configured to: send a supplementary permission request for the corresponding target network service to the permission management service so that the permission management service can approve the supplementary permission request; wherein, the target network service refers to a network service different from the permission management service; obtain a supplementary permission management policy sent by the permission management service; wherein, the supplementary permission management policy is sent by the permission management service when the supplementary permission request is approved, and the supplementary permission management policy is used to provide execution permission for the target network access behavior, and the target network access behavior is used to access the target network service.
[0219] In some embodiments, the access control policy includes whitelist address information, which includes whitelist Internet Protocol addresses and whitelist domain name addresses; the security verification module 4553 is further configured to: when the network access behavior is a connection establishment behavior based on an Internet Protocol address, perform security verification processing on the connection establishment behavior according to the whitelist Internet Protocol address; when the network access behavior is a data sending behavior based on a domain name address, perform security verification processing on the data sending behavior according to the whitelist domain name address.
[0220] In some embodiments, the access control policy includes a temporary access control policy and a fixed access control policy; the network access management device 455 further includes a cleanup module, which is used to: clean up the temporary access control policy when the cleanup period arrives, and prohibit the cleanup of the fixed access control policy.
[0221] In some embodiments, the policy acquisition module 4551 is further configured to: send a permission request to the permission management service to obtain the permission management policy configured by the permission management service for the target object; the network access management device 455 further includes an early warning module, configured to: perform information statistical processing on network access behavior to obtain behavior information; and send the behavior information to the permission management service so that the permission management service can perform behavior early warning processing based on the behavior information.
[0222] In some embodiments, the policy acquisition module 4551 is further configured to: send a permission request to the permission management service to obtain the permission management policy configured by the permission management service for the target object; the network access management device 455 further includes an execution permission module, configured to assign an execution permission to the network access behavior when the network access behavior is used for the access permission management service; wherein the execution permission is used to indicate that the network access behavior is allowed to be executed.
[0223] In some embodiments, the policy acquisition module 4551 is further configured to perform any of the following processes: sending a permission request including device identification information to a permission management service to obtain a permission management policy configured by the permission management service for a target object; wherein the permission management service is used to manage at least one electronic device, and the target object is the electronic device corresponding to the device identification information among the at least one electronic device; sending a permission request including team identification information to a permission management service to obtain a permission management policy configured by the permission management service for a target object; wherein the permission management service is used to manage at least one team, and the target object is the team corresponding to the team identification information among the at least one team, and each team among the at least one team includes at least one electronic device.
[0224] This application provides a computer program product or computer program that includes computer instructions (i.e., executable instructions) stored in a computer-readable storage medium. A processor of an electronic device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the electronic device to perform the network access management method described in this application.
[0225] This application provides a computer-readable storage medium storing executable instructions. When the executable instructions are executed by a processor, the processor will execute the network access management method provided in this application.
[0226] In some embodiments, the computer-readable storage medium may be a memory such as FRAM, ROM, PROM, EPROM, EEPROM, flash memory, magnetic surface memory, optical disk, or CD-ROM; or it may be a variety of devices including one or any combination of the above-mentioned memories.
[0227] In some embodiments, executable instructions may take the form of a program, software, software module, script, or code, written in any form of programming language (including compiled or interpreted languages, or declarative or procedural languages), and may be deployed in any form, including as a standalone program or as a module, component, subroutine, or other unit suitable for use in a computing environment.
[0228] As an example, executable instructions may, but do not necessarily, correspond to files in a file system. They may be stored as part of a file that holds other programs or data, for example, in one or more scripts in a Hyper Text Markup Language (HTML) document, in a single file dedicated to the program in question, or in multiple collaborating files (e.g., a file that stores one or more modules, subroutines, or code sections).
[0229] As an example, executable instructions can be deployed to execute on a single electronic device, or on multiple electronic devices located at one location, or on multiple electronic devices distributed across multiple locations and interconnected via a communication network.
[0230] The above are merely embodiments of this application and are not intended to limit the scope of protection of this application. Any modifications, equivalent substitutions, and improvements made within the spirit and scope of this application are included within the scope of protection of this application.
Claims
1. A network access management method, characterized in that, The method includes: Obtain the permission management policy configured for the target object; obtain the management device parameters configured for the permission management policy; wherein, the management device parameters include at least one of the following: management time period, management device, and management account; The equipment parameters are periodically monitored to obtain real-time equipment parameters, and then the real-time equipment parameters are matched with the managed equipment parameters. When the real-time device parameters match the management device parameters, a monitoring instruction is sent to the driver layer according to the permission management policy, so that the driver layer performs data monitoring processing on the network protocol stack according to the monitoring instruction, and performs behavior recognition processing on the monitored network access data to obtain network access behavior. The permission management policy includes whitelist address information, which includes whitelist domain name address, default domain name address and default Internet Protocol address. The default Internet Protocol address and the whitelisted domain name address list are sent to the driver layer. The whitelisted domain name address list is obtained by combining the whitelisted domain name address and the default domain name address. The driver layer performs Domain Name System (DNS) resolution to obtain a whitelist of Internet Protocol (IP) addresses. The whitelisted IP addresses and the default IP addresses are then combined to obtain a whitelist of IP addresses. This DNS resolution is continuous, allowing the driver layer to store the resolved whitelisted IP addresses and periodically clean them up, while the default IP addresses are not cleaned up. The network access behavior is subjected to security verification processing according to the permission management policy. The security verification processing is used to obtain the Internet Protocol address of the remote network service to be connected through the driver layer. When the Internet Protocol address is in the whitelist of Internet Protocol addresses, the verification result is determined to be successful. When the Internet Protocol address is not in the whitelist of Internet Protocol addresses, the verification result is determined to be unsuccessful. Based on the verification result, control operations are performed on the network access behavior. When the verification result is successful, execution permission is assigned to the network access behavior through the driver layer; wherein, the execution permission is used to indicate that the network access behavior is allowed to be executed; when the verification result is unsuccessful, the network access behavior is intercepted through the driver layer.
2. The method according to claim 1, characterized in that, The access control policy includes whitelist address information and graylist address information; the security verification process for network access behavior based on the access control policy includes: The network access behavior is subjected to security verification based on the whitelist address information to obtain the whitelist verification result; When the whitelist verification result is a failure, the network access behavior is subjected to security verification processing based on the graylist address information to obtain the graylist verification result; wherein, the graylist verification result is used to indicate whether the network access behavior is blocked; When the verification result is successful, the driver layer assigns execution permissions to the network access behavior, including: When the gray list verification result is successful and the usage limit corresponding to the gray list address information is greater than zero, the driver layer allocates execution permissions to the network access behavior and deducts the usage limit. When the verification result is a failure, the network access behavior is intercepted through the driver layer, including: When the gray list verification result is a failure, or the usage limit corresponding to the gray list address information is equal to zero, the network access behavior is intercepted through the driver layer.
3. The method according to claim 2, characterized in that, The graylist address information includes graylist domain names; before performing security verification processing on the network access behavior based on the whitelist address information, the method further includes: The Domain Name System (DNS) data in the network access data is parsed to obtain the Internet Protocol (IP) address and the corresponding domain name address. The access domain name address is matched with the whitelist domain name address; When the access domain name address successfully matches the whitelist domain name address, the access Internet Protocol address is used as the whitelist Internet Protocol address and added to the whitelist address information; When the access domain address fails to match the whitelisted domain address, the access domain address is then matched with the graylisted domain address. When the access domain name address successfully matches the gray list domain name address, the access Internet Protocol address is used as the gray list Internet Protocol address and added to the gray list address information.
4. The method according to claim 1, characterized in that, The method further includes: The access address information is matched with the whitelist address information at the application layer; The step of performing control operations on the network access behavior based on the test results includes: The application layer sends the verification result to the driver layer, so that the driver layer can perform control operations on the network access behavior based on the verification result.
5. The method according to any one of claims 1 to 4, characterized in that, The process of obtaining the permission management policy configured for the target object includes: Send the permission request to the permission management service to obtain the permission management policy configured by the permission management service for the target object; The method further includes: A supplementary permission request for the corresponding target network service is sent to the permission management service, so that the permission management service can approve and process the supplementary permission request; wherein, the target network service refers to a network service that is different from the permission management service; Obtain the supplementary permission management policy sent by the permission management service; wherein, the supplementary permission management policy is sent by the permission management service when the supplementary permission request is approved, and the supplementary permission management policy is used to provide execution permission for the target network access behavior, and the target network access behavior is used to access the target network service.
6. The method according to any one of claims 1 to 4, characterized in that, The access control strategy includes temporary access control strategy and fixed access control strategy; After obtaining the permission management policy configured for the target object, the method further includes: When the cleanup period arrives, the temporary permission management policy is cleaned up, and the cleanup of the fixed permission management policy is prohibited.
7. The method according to any one of claims 1 to 4, characterized in that, The process of obtaining the permission management policy configured for the target object includes: Send the permission request to the permission management service to obtain the permission management policy configured by the permission management service for the target object; The method further includes: The network access behavior is statistically processed to obtain behavioral information; The behavior information is sent to the permission management service so that the permission management service can perform behavior warning processing based on the behavior information.
8. The method according to any one of claims 1 to 4, characterized in that, The process of obtaining the permission management policy configured for the target object includes: Send the permission request to the permission management service to obtain the permission management policy configured by the permission management service for the target object; The method further includes: When the network access behavior is used to access the permission management service, an execution permission is assigned to the network access behavior; wherein, the execution permission is used to indicate that the network access behavior is allowed to be executed.
9. The method according to any one of claims 1 to 4, characterized in that, The process of obtaining the permission management policy configured for the target object includes: Perform any of the following processes: A permission request, including device identification information, is sent to a permission management service to obtain a permission management policy configured by the permission management service for the target object; wherein, the permission management service is used to manage at least one electronic device, and the target object is the electronic device among the at least one electronic device that corresponds to the device identification information; A permission request, including team identification information, is sent to a permission management service to obtain the permission management policy configured by the permission management service for the target object; wherein, the permission management service is used to manage at least one team, the target object is the team corresponding to the team identification information in the at least one team, and each team in the at least one team includes at least one electronic device.
10. A network access management device, characterized in that, The device includes: The policy acquisition module is used to acquire the permission management policy configured for the target object; The parameter acquisition module is used to acquire management device parameters configured for the permission management policy; wherein, the management device parameters include at least one of the following: management time period, management device, and management account; The behavior monitoring module is used to periodically monitor device parameters to obtain real-time device parameters and match these real-time device parameters with the managed device parameters. When the real-time device parameters and the managed device parameters match successfully, a monitoring instruction is sent to the driver layer according to the permission management policy. This causes the driver layer to monitor the network protocol stack according to the monitoring instruction and perform behavior recognition processing on the monitored network access data to obtain network access behavior. The permission management policy includes whitelist address information, which includes whitelist domain names, default domain names, and default Internet Protocol (IP) addresses. The module then sends a monitoring instruction to the driver layer. The system sends the default Internet Protocol (IP) address and the whitelisted domain name address list. The whitelisted domain name address list is obtained by performing a union operation on the whitelisted domain name addresses and the default domain name addresses. The driver layer performs Domain Name System (DNS) resolution to obtain the whitelisted IP addresses. The whitelisted IP addresses and the default IP addresses are then combined to obtain the whitelisted IP address list. The DNS resolution is performed continuously so that the driver layer stores the resolved whitelisted IP addresses and periodically cleans them up, while the default IP addresses are not cleaned up. The security verification module is used to perform security verification processing on the network access behavior according to the permission management policy. The permission management policy includes whitelist address information. The security verification processing is used to obtain the Internet Protocol address of the remote network service to be connected through the driver layer. When the access Internet Protocol address is in the whitelist Internet Protocol address list, the verification result is determined to be successful. When the access Internet Protocol address is not in the whitelist Internet Protocol address list, the verification result is determined to be unsuccessful. An execution module is used to perform control operations on the network access behavior based on the verification result. When the verification result is successful, the execution permission is assigned to the network access behavior through the driver layer. The execution permission is used to indicate that the network access behavior is allowed to be executed. When the verification result is unsuccessful, the network access behavior is intercepted through the driver layer.
11. The apparatus as claimed in claim 10, characterized in that, The access control policy includes whitelist address information and graylist address information; The security verification module is further configured to perform security verification processing on the network access behavior based on the whitelist address information to obtain a whitelist verification result; when the whitelist verification result is a verification failure, the module performs security verification processing on the network access behavior based on the graylist address information to obtain a graylist verification result; wherein, the graylist verification result is used to indicate whether the network access behavior is blocked. The execution module is further configured to, when the gray list verification result is successful and the usage limit corresponding to the gray list address information is greater than zero, allocate execution permissions to the network access behavior through the driver layer and deduct the usage limit; when the gray list verification result is unsuccessful or the usage limit corresponding to the gray list address information is equal to zero, intercept the network access behavior through the driver layer.
12. The apparatus as claimed in claim 11, characterized in that, The graylist address information includes graylist domain names; It also includes a parsing module, used to parse the Domain Name System (DNS) data in the network access data to obtain the access Internet Protocol (IP) address and the corresponding access domain name address; to match the access domain name address with the whitelist domain name address; when the access domain name address successfully matches the whitelist domain name address, the access IP address is added to the whitelist address information as a whitelist IP address; when the access domain name address fails to match the whitelist domain name address, the access domain name address is matched with the graylist domain name address, and when the access domain name address successfully matches the graylist domain name address, the access IP address is added to the graylist address information as a graylist IP address.
13. The apparatus as claimed in claim 10, characterized in that, The security verification module is also used to match the access address information with the whitelist address information through the application layer; The execution module is further configured to send the verification result to the driver layer through the application layer, so that the driver layer performs control operations on the network access behavior based on the verification result.
14. The apparatus according to any one of claims 10 to 13, characterized in that, The policy acquisition module is also used to send a permission request to the permission management service to obtain the permission management policy configured by the permission management service for the target object; It also includes a supplementary module, used to send a supplementary permission request for the corresponding target network service to the permission management service, so that the permission management service can approve the supplementary permission request; wherein, the target network service refers to a network service different from the permission management service; and to obtain a supplementary permission management policy sent by the permission management service; wherein, the supplementary permission management policy is sent by the permission management service when the supplementary permission request is approved, and the supplementary permission management policy is used to provide execution permission for the target network access behavior, and the target network access behavior is used to access the target network service.
15. The apparatus according to any one of claims 10 to 13, characterized in that, The access management strategy includes a temporary access management strategy and a fixed access management strategy; the device also includes a cleanup module, used for: When the cleanup period arrives, the temporary permission management policy is cleaned up, and the cleanup of the fixed permission management policy is prohibited.
16. The apparatus according to any one of claims 10 to 13, characterized in that, The strategy acquisition module is also used for: Send the permission request to the permission management service to obtain the permission management policy configured by the permission management service for the target object; The device further includes an early warning module, which is used to perform information statistical processing on the network access behavior to obtain behavior information; and send the behavior information to the permission management service so that the permission management service can perform behavior early warning processing based on the behavior information.
17. The apparatus according to any one of claims 10 to 13, characterized in that, The strategy acquisition module is also used for: Send the permission request to the permission management service to obtain the permission management policy configured by the permission management service for the target object; The device further includes an execution permission module, configured to assign execution permission to the network access behavior when the network access behavior is used to access the permission management service; wherein the execution permission is used to indicate that the network access behavior is allowed to be executed.
18. An electronic device, characterized in that, The electronic device includes: Memory, used to store executable instructions; A processor, when executing executable instructions stored in the memory, implements the network access management method according to any one of claims 1 to 9.
19. A computer-readable storage medium storing executable instructions, characterized in that, When the executable instructions are executed by the processor, they implement the network access management method according to any one of claims 1 to 9.
20. A computer program product comprising executable instructions, characterized in that, When the executable instructions are executed by the processor, they implement the network access management method according to any one of claims 1 to 9.
Citation Information
Patent Citations
Management method of network
CN102307114A
Data access control method for network driver layer in operating system
CN102571434A
Protection method and device for network access behavior
CN102932375A