Method, apparatus, device and computer readable storage medium for network protection

By deploying a second access network with partially overlapping coverage on the first access network, and using similar SSIDs and different encryption levels to confuse intrusion targets, the problems of frequent network intrusions and poor compatibility with outdated equipment in existing technologies are solved, thereby improving security and convenience.

CN115913582BActive Publication Date: 2026-04-28SCHNEIDER ELECTRIC IND SAS
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
SCHNEIDER ELECTRIC IND SAS
Filing Date
2021-07-20
Publication Date
2026-04-28

AI Technical Summary

Technical Problem

Existing network protection solutions, when using advanced encryption and authentication methods, make wireless networks difficult to use and incompatible with outdated network equipment. Furthermore, conventional solutions are passive and cannot effectively reduce the possibility of network intrusion.

Method used

By deploying a second access network that is isolated from the first access network to be protected and whose coverage partially overlaps, the intruder's target is confused. By setting a similar SSID and an encryption level lower or higher than that of the first access network, the intruder is lured into intruding into the second access network, thereby reducing the risk of intrusion into the first access network.

Benefits of technology

It improves the security of the primary access network, reduces the possibility of intrusion, and can be applied to networks using outdated network equipment, maintaining network ease of use.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115913582B_ABST
    Figure CN115913582B_ABST
Patent Text Reader

Abstract

Embodiments of the present disclosure relate to a method, apparatus, device and computer readable storage medium for network protection. A method for network protection comprises: obtaining first configuration information associated with a first access network, the first configuration information indicating at least a coverage range of the first access network; determining, based on the first configuration information, second configuration information for deploying a second access network, the second access network being isolated from the first access network and at least partially overlapping with the first access network in the coverage range. Compared with conventional network protection methods, the method for network protection according to embodiments of the present disclosure can implement a network compatible with obsolete network devices while reducing the possibility of the first access network being invaded, and without reducing the use convenience of the network.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Embodiments of this disclosure relate to the field of network security, and more specifically to methods, apparatus, devices, and computer-readable storage media for network protection. Background Technology

[0002] With the continuous development of internet technology and the increasing prevalence of networks, intrusions targeting wireless networks are becoming more frequent. Existing network protection solutions typically use advanced encryption and authentication methods (e.g., WAP3, MAC whitelists, RADIUS / EAP, etc.). However, such encryption and authentication methods often make wireless networks less user-friendly and unsuitable for networks using outdated network equipment. Furthermore, conventional network protection solutions are usually passive; by the time a network intrusion is detected, devices within the network may already be compromised.

[0003] Therefore, there is a need for a network protection method that can reduce the likelihood of network intrusion and is compatible with networks using outdated network equipment. Summary of the Invention

[0004] According to an example embodiment of this disclosure, a solution for network protection is provided. This solution improves the security of the first access network by deploying a second access network that is isolated from the first access network to be protected and whose coverage at least partially overlaps with the first access network, thereby reducing the likelihood of the first access network being compromised.

[0005] In a first aspect of this disclosure, a method for network protection is provided. The method includes: acquiring first configuration information associated with a first access network, the first configuration information indicating at least the coverage area of ​​the first access network; and, based on the first configuration information, determining second configuration information for deploying a second access network, the second access network being isolated from the first access network and having a coverage area at least partially overlapping with the first access network.

[0006] In some embodiments, determining the second configuration information includes: determining the deployment location of the access device used to provide the second access network.

[0007] In some embodiments, the first configuration information further indicates the Service Set Identifier (SSID) of the first access network, and wherein determining the second configuration information includes: determining the SSID of the second access network based on the SSID of the first access network, such that the SSID of the second access network is similar to the SSID of the first access network.

[0008] In some embodiments, the first configuration information further indicates the encryption level of the first access network.

[0009] In some embodiments, determining the second configuration information includes: determining the encryption level of the second access network based on the encryption level of the first access network, such that the encryption level of the second access network is lower than the encryption level of the first access network.

[0010] In some embodiments, the method further includes: sending the second configuration information to the access device to deploy the second access network.

[0011] In some embodiments, the method further includes: determining third configuration information for configuring at least one third access network, the at least one third access network being isolated from the first access network, and the total coverage of the second access network and the at least one third access network covering the coverage of the first access network.

[0012] In some embodiments, the method further includes: providing a warning message in response to a network intrusion targeting the first access network or the second access network.

[0013] In a second aspect of this disclosure, an apparatus for network protection is provided. The apparatus includes: a first configuration information acquisition module configured to acquire first configuration information associated with a first access network, the first configuration information indicating at least the coverage area of ​​the first access network; and a second configuration information determination module configured to determine, based on the first configuration information, second configuration information for deploying a second access network, the second access network being isolated from the first access network and at least partially overlapping the coverage area of ​​the first access network.

[0014] In some embodiments, the second configuration information determining module includes a deployment location determining module, configured to determine the deployment location of the access device used to provide the second access network.

[0015] In some embodiments, the first configuration information further indicates the Service Set Identifier (SSID) of the first access network, and the second configuration information determining module includes an SSID determining module configured to determine the SSID of the second access network based on the SSID of the first access network, such that the SSID of the second access network is similar to the SSID of the first access network.

[0016] In some embodiments, the first configuration information further indicates the encryption level of the first access network.

[0017] In some embodiments, the second configuration information determining module includes an encryption level determining module, configured to determine the encryption level of the second access network based on the encryption level of the first access network, such that the encryption level of the second access network is lower than the encryption level of the first access network.

[0018] In some embodiments, the apparatus further includes a configuration information sending module configured to send the second configuration information to the access device so that the second access network is deployed.

[0019] In some embodiments, the apparatus further includes a third configuration information determination module configured to determine third configuration information for configuring at least one third access network, the at least one third access network being isolated from the first access network, and the total coverage of the second access network and the at least one third access network covering the coverage of the first access network.

[0020] In some embodiments, the apparatus further includes a warning information providing module configured to provide a warning information in response to a network intrusion targeting the first access network or the second access network.

[0021] In a third aspect of this disclosure, an apparatus for network protection is provided. The apparatus includes: at least one processing unit; and at least one memory coupled to the at least one processing unit and storing instructions for execution by the at least one processing unit, the instructions, when executed by the at least one processing unit, causing the apparatus to perform the method according to any one of claims 1-7.

[0022] In a fourth aspect of this disclosure, a computer-readable storage medium is provided having a computer program stored thereon, which, when executed by a device, causes the device to perform the method according to any one of claims 1-7.

[0023] As described above, the network protection scheme according to embodiments of this disclosure uses a second access network that is isolated from the first access network and at least partially overlaps with it in coverage to confuse the intrusion target of a network intruder, thereby reducing the likelihood of the first access network being compromised and providing network protection for the first access network. Furthermore, the network protection scheme according to embodiments of this disclosure can also induce network intruders to compromise the second access network by appropriately setting the SSID and / or encryption level of the second access network, further reducing the probability of the first access network being compromised.

[0024] It should be understood that the description in the Summary of the Invention section is not intended to limit the key or essential features of the embodiments of this disclosure, nor is it intended to restrict the scope of this disclosure. Other features of this disclosure will become readily apparent from the following description. Attached Figure Description

[0025] The above and other features, advantages, and aspects of the embodiments of this disclosure will become more apparent from the accompanying drawings and the following detailed description. In the drawings, the same or similar reference numerals denote the same or similar elements, wherein:

[0026] Figure 1 A block diagram of an example environment according to an embodiment of the present disclosure is shown;

[0027] Figure 2 A flowchart of a method for network protection according to an embodiment of the present disclosure is shown;

[0028] Figure 3 A block diagram of an example apparatus for network protection according to embodiments of the present disclosure is shown; and

[0029] Figure 4 A schematic block diagram of an example device that can be used to implement embodiments of the present disclosure is shown. Detailed Implementation

[0030] Embodiments of this disclosure will now be described in more detail with reference to the accompanying drawings. While some embodiments of this disclosure are shown in the drawings, it should be understood that this disclosure can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided to provide a more thorough and complete understanding of this disclosure. It should be understood that the accompanying drawings and embodiments of this disclosure are for illustrative purposes only and are not intended to limit the scope of protection of this disclosure.

[0031] In the description of embodiments of this disclosure, the term "comprising" and similar terms should be understood as open-ended inclusion, i.e., "including but not limited to". The term "based on" should be understood as "at least partially based on". The term "one embodiment" or "the embodiment" should be understood as "at least one embodiment". The terms "first", "second", etc., may refer to different or the same objects. Other explicit and implicit definitions may also be included below.

[0032] As mentioned above, with the increasing prevalence of the internet, intrusions targeting wireless networks are also on the rise. Commonly known solutions typically employ advanced encryption and authentication methods, which reduce the ease of using wireless networks. Furthermore, these advanced encryption and authentication methods are often incompatible with networks using outdated network equipment.

[0033] Embodiments of the present disclosure provide a solution for network protection. In this solution, first configuration information associated with a first access network to be protected is obtained, and the first configuration information at least indicates the coverage area of the first access network. Based on the first configuration information, second configuration information for deploying a second access network can be determined. The second access network is isolated from the first access network and at least partially overlaps with the first access network in terms of coverage area. In this way, the intrusion target of network intruders can be confused by means of the second access network with at least partially overlapping coverage area. This can reduce the possibility of the first access network being attacked and invaded, thereby providing network protection for the first access network. In addition, compared with traditional solutions, embodiments according to the present disclosure can also be applied to networks using obsolete network devices and do not affect the normal use of the network by users or devices.

[0034] Figure 1 A block diagram of an example environment 100 according to an embodiment of the present disclosure is shown. Figure 2 A flowchart of a method 200 for network protection according to an embodiment of the present disclosure is shown. Figure 2 The method 200 can be executed, for example, by Figure 1 the control device 150 shown in

[0035] At block 202, the control device 150 obtains first configuration information associated with the first access network 110.

[0036] In the context of the present disclosure, the first access network 110 is a network to be protected with real traffic thereon. In some embodiments, the first access network 110 can be, for example, an in-plant industrial network deployed at a factory production site and workshop. Such an in-plant industrial network is connected to devices such as field sensors, actuators, and controllers to enable information interaction between programmable logic controllers (PLCs), numerical control machine controllers (CNCs), intelligent machines, etc. and various data servers. It should be understood that the in-plant industrial network is only exemplary, and the first access network 110 of the present disclosure can also be any other suitable network, such as an internal network deployed in a shopping mall, etc. Therefore, the scope of the present disclosure is not limited in this regard. In some embodiments, the first access network 110 can be, for example, a wireless network, and the access device 120 can be, for example, a wireless router.

[0037] It can be understood that the first access network 110 has the possibility of being invaded by a network. Once the first access network 110 is invaded, the real traffic thereon may be intercepted or tampered with, thereby affecting the normal operation of the devices connected to the network.

[0038] To reduce this risk, the first configuration information obtained at block 202 at least indicates the coverage area of the first access network 110.

[0039] In some embodiments, the control device 150 obtains first configuration information associated with the first access network 110 via an access device 120 for providing the first access network 110. Exemplarily, the control device 150 may be communicatively coupled to the access device 120 and send a request to the access device 120 for the first configuration information of the first access network 110. In response to receiving the request for the first configuration information of the first access network 110, the access device 120 may send configuration parameters of the access device 120 to the control device 150, including but not limited to configuration parameters such as the deployment location, transmit power, and antenna gain of the access device 120. Based on the deployment location, transmit power, and antenna gain of the access device 120, the control device 150 may determine the coverage area of ​​the first access network 110.

[0040] It should be understood that, in addition to the example configuration parameters listed above, the “first configuration information” in this disclosure may include any other suitable information that can indicate the coverage of the first access network 110.

[0041] At box 204, control device 150 determines second configuration information for deploying second access networks 130-1, 130-2, and 130-3 (referred to individually or collectively as second access network 130) based on first configuration information. The second access network 130 is isolated from the first access network 110 and at least partially overlaps with the first access network 110 in terms of coverage.

[0042] In some embodiments, after determining the coverage area of ​​the first access network 110 based on the first configuration information, the control device 150 can determine the deployment locations of the access devices 140-1, 140-2, and 140-3 (individually or collectively referred to as access devices 140) used to provide the second access network 130, such that their deployment locations are within the coverage area of ​​the first access network 110, for example... Figure 1 The deployment locations of access devices 140-2 and 140-3 are shown. Since access devices 140-2 and 140-3 are located within the coverage area of ​​the first access network 110, the second access network 130 provided by access devices 140-2 and 140-3 will at least partially overlap with the first access network 110 in terms of coverage. Furthermore, the second access network 130 is configured to be isolated from the first access network 110; that is, the first access network 110 cannot be accessed via the second access network 130, thereby ensuring that the normal operation of the first access network 110 will not be affected in the event of an intrusion into the second access network 130.

[0043] In some embodiments, the control device 150 may also obtain configuration parameters of the access device 140, such as transmit power and antenna gain, via communication with the access device 140 used to provide the second access network 130. After determining the coverage area of ​​the first access network 110 based on the first configuration information, the control device 150 may use the configuration parameters of the access device 140 used to provide the second access network 130 to determine the deployment location of the access device 140, such that the deployment location of the access device 140 is outside the coverage area of ​​the first access network 110 and the coverage area of ​​the second access network 130 provided by the access device 140 at least partially overlaps with the coverage area of ​​the first access network 110, for example... Figure 1 The location of access device 140-1 is shown in the diagram. Furthermore, the second access network 130 is configured to be isolated from the first access network 110, meaning that the first access network 110 cannot be accessed via the second access network 130, thereby ensuring that the normal operation of the first access network 110 is not affected in the event of an intrusion into the second access network 130.

[0044] It should be understood that, in addition to the example configuration parameters listed above, the “second configuration information” in this disclosure may include any other suitable information that can indicate the coverage of the second access network 130.

[0045] It should be understood that method 200 may also include additional boxes not shown, and / or the boxes shown may be omitted.

[0046] As can be seen from the above description, the network protection method 200 according to embodiments of the present disclosure can be applied to networks using outdated network equipment. Furthermore, by deploying a second access network 130 whose coverage at least partially overlaps with the first access network 110, the intrusion target of a network intruder can be confused, thereby reducing the likelihood of a network intruder intruding into the first access network 110 and thus improving the security of the first access network 110. Compared to conventional network protection methods, the method 200 according to embodiments of the present disclosure can be applied to networks using outdated network equipment without reducing the ease of use of the network.

[0047] In some embodiments, after determining the second configuration information for deploying the second access network 130, the control device 150 may send the second configuration information to the access device 140 for providing the second access network 130, so that the second access network 130 is deployed. For example, the second access network 130 may be deployed by a user or a deployment device based on the determined second configuration information.

[0048] In some embodiments, control device 150 may monitor first access network 110 and second access network 130 by means of an intrusion prevention system (IDS). In response to the intrusion prevention system detecting a network intrusion against first access network 110 or second access network 130, control device 150 may provide a warning message to a user to notify the user that the network has been intruded upon. One example of a warning message is a visual element output by means of a display, such as the text visual element “Network intrusion detected!”. Another example of a warning message is an alarm sound output by means of a speaker, such as a beeping sound. It should be understood that, based on the teachings of this disclosure, those skilled in the art will be able to conceive of other suitable methods for detecting network intrusions and providing warning messages in other suitable ways.

[0049] By providing warning information after a network intrusion is detected, users can be reminded or urged to take timely countermeasures, thereby preventing network intruders from successfully intruding into the first access network 110, or mitigating the losses caused by the network intrusion if the first access network 110 has already been intruded into.

[0050] In some embodiments, the first configuration information associated with the first access network 110 obtained by the control device 150 further includes the service set identifier (SSID) of the first access network 110, such as the string "FactoryNMO". Based on the SSID of the first access network 110, the control device 150 can determine the SSID of the second access network 130 such that the SSID of the second access network 130 is similar to the SSID of the first access network 110.

[0051] In some embodiments, the control device 150 can generate a string for use as the SSID of the second access network 130 by editing the string corresponding to the SSID of the first access network 110 (e.g., by replacing one character with another, inserting a character, or deleting a character). For example, “FactoryNM0” or “FactoryMNO”.

[0052] The similarity between two SSIDs can be measured, for example, by the edit distance between the strings corresponding to the two SSIDs. As is known to those skilled in the art, edit distance considers the minimum number of operations required to transform one string into another. An example of edit distance is the Levenshtein distance, which is the minimum number of edit operations required to transform one string into another. Allowed edit operations include replacing one character with another, inserting a character, or deleting a character. For example, with “FactoryNMO” and “FactoryNM0”, only replacing the character “O” with the character “0” is needed to obtain “FactoryNM0” from “FactoryNMO”; therefore, the Levenshtein distance between these two strings is 1. Generally, the smaller the Levenshtein distance between two strings, the higher their similarity.

[0053] In some embodiments, the similarity between the SSID of the second access network 130 and the SSID of the first access network 110 means that the Levenstein distance between the strings corresponding to the two SSIDs is less than a distance threshold. This distance threshold may have a fixed value (e.g., 3) or may depend on the length of the string corresponding to the SSID of the first access network 110 (e.g., one-fifth of the string length).

[0054] In some embodiments, the SSID of the first access network 110 and the SSID of the second access network 130 may have similar or identical semantic information. For example, the SSID of the first access network 110 may be "Factory", and the SSID of the second access network 130 may be "Factory". The control device 150 may, for example, utilize a trained machine learning model to identify the semantic similarity between the two SSIDs. In this case, similarity between the SSID of the first access network 110 and the SSID of the second access network 130 means that the semantic similarity between the two SSIDs is higher than a predetermined similarity threshold.

[0055] It should be understood that, based on the technical teachings of this disclosure, those skilled in the art will be able to conceive of other ways to define the similarity between the SSID of the second access network 130 and the SSID of the first access network 110. Therefore, the scope of this disclosure is not limited in this respect.

[0056] By setting the SSID of the second access network 130 to be similar to that of the first access network 110, the intrusion target of network intruders can be further confused, and the probability of network intruders mistakenly intruding into the second access network 130 can be increased. Therefore, in this way, the probability of the first access network 110 being intruded can be further reduced.

[0057] In some embodiments, the first configuration information associated with the first access network 110, acquired by the control device 150, further indicates the encryption level of the first access network 110. For example, the control device 150 may acquire the password of the first access network 110. The control device 150 can identify the encryption level of the access network by the complexity of the password (e.g., password length, number of character types contained in the password, etc.). It is understood that the longer the password or the greater the number of character types contained in the password, the more complex the password and the higher the encryption level of the access network.

[0058] Based on the encryption level of the first access network 110, the control device 150 can determine the encryption level of the second access network 130, such that the encryption level of the second access network 130 is different from the encryption level of the first access network 110.

[0059] In some embodiments, the control device 150 may determine the encryption level of the second access network 130 such that the encryption level of the second access network 130 is lower than the encryption level of the first access network 110. For example, the control device 150 may set a password for the second access network 130 that has a lower complexity than the password for the first access network 110, such as setting a short, simple, repeating string of numbers "111222" as the password.

[0060] When a network intruder simultaneously attempts to brute-force the passwords of the first access network 110 and the second access network 130 offline, the second access network 130 will be cracked before the first access network 110 due to its lower encryption level. When the intruder attempts to access the second access network 130, the intrusion prevention system can detect the intrusion and provide a warning to the user, thus preventing the first access network 110 from being compromised.

[0061] Therefore, by configuring the encryption level of the second access network 130 to be lower than that of the first access network 110, network intruders can be induced to intrude into the second access network 130, which has a lower encryption level, thereby further reducing the probability of the first access network 110 being intruded into and improving the security of the first access network 110.

[0062] In some embodiments, the control device 150 may determine the encryption level of the second access network 130 such that the encryption level of the second access network 130 is higher than the encryption level of the first access network 110. For example, the control device 150 may set a password for the second access network 130 that has a higher complexity than the password for the first access network 110, such as setting a longer string with a combination of multiple characters as the password.

[0063] The inventors of this disclosure have noted that, according to social engineering principles, by configuring the encryption level of the second access network 130 to be higher than that of the first access network 110, it is possible to induce a network intruder with anti-spoofing capabilities to mistake the second access network 130, which has a higher encryption level, for a genuine access network. Therefore, in this way, it is possible to induce a network intruder with anti-spoofing capabilities to intrude into the second access network 130, which has a higher encryption level, thereby further enhancing the security of the first access network 110.

[0064] It should be noted that, based on the technical teachings of this disclosure, those skilled in the art will be able to conceive of other suitable ways to set the encryption level of a network, such as by using different encryption technologies such as WPA3 and WPA2. Therefore, the scope of this disclosure is not limited in this respect.

[0065] Although the encryption level of the second access network 130 has been described above as being lower or higher than that of the first access network 110, multiple second access networks 130 can be deployed simultaneously. One second access network 130 may have an encryption level lower than that of the first access network 110, another second access network 130 may have an encryption level higher than that of the first access network 110, and optionally, a third second access network 130 may have the same encryption level as the first access network 110. This approach further enhances the ability to confuse network intruders, thereby reducing the likelihood of them accessing the first access network 110.

[0066] In some embodiments, the control device 150 may also determine third configuration information for configuring at least one third access network based on the first configuration information of the first access network 110, in a manner similar to that described with reference to the second configuration information description, such that the total coverage of the second access network 130 and these third access networks covers the coverage of the first access network 110. These third access networks are also isolated from the first access network 110, i.e., the first access network 110 cannot be accessed through the third access networks. These third access networks may be configured in a manner similar to that described above with reference to the second access network 130.

[0067] In this way, a second access network 130 or a third access network can be installed throughout the entire coverage area of ​​the first access network 110 to confuse network intruders, thereby further reducing the probability of the first access network 110 being compromised and improving the security of the first access network 110.

[0068] In some embodiments, a service flow similar to that of the first access network 110 can be provided in the second access network 130. For example, real field sensors, actuators, controllers, and other devices can be deployed in the second access network 130, but these devices do not participate in actual services. In this way, the similarity between the second access network 130 and the first access network 110 can be increased, thereby enticing network intruders to intrude into the second access network 130, further reducing the probability of the first access network 110 being compromised.

[0069] It should be noted that, based on the technical teachings of this disclosure, those skilled in the art can conceive of other suitable ways to improve the similarity between the second access network 130 and the first access network 110. Therefore, the scope of this disclosure is not limited in this respect.

[0070] As can be seen from the above description, the network protection solution according to the embodiments of this disclosure can solve many problems in conventional solutions. The embodiments of this disclosure improve the security of the first access network by utilizing a second access network that is isolated from the first access network and at least partially overlaps with it in coverage, thereby reducing the likelihood of the first access network being intruded upon. Compared to conventional network protection solutions, the solution according to this disclosure can be applied to networks using outdated network equipment without reducing the ease of use of the network.

[0071] Figure 3 A block diagram of an example apparatus 300 for network protection according to an embodiment of the present disclosure is shown. This apparatus 300 can, for example, be used to implement... Figure 1 The control device 150 shown. (e.g.) Figure 3 As shown, the device 300 includes a first configuration information acquisition module 302, configured to acquire first configuration information associated with a first access network, the first configuration information indicating at least the coverage area of ​​the first access network. Furthermore, the device 300 also includes a second configuration information determination module 302, configured to determine second configuration information for deploying a second access network based on the first configuration information, the second access network being isolated from the first access network and at least partially overlapping the coverage area of ​​the first access network.

[0072] In some embodiments, the second configuration information determination module 302 includes a deployment location determination module configured to determine the deployment location of an access device used to provide a second access network.

[0073] In some embodiments, the first configuration information further indicates a service set identifier (SSID) of the first access network, and wherein the second configuration information determining module 302 includes an SSID determining module configured to determine the SSID of the second access network based on the SSID of the first access network, such that the SSID of the second access network is similar to the SSID of the first access network.

[0074] In some embodiments, the first configuration information further indicates the encryption level of the first access network.

[0075] In some embodiments, the second configuration information determination module 302 includes an encryption level determination module, configured to determine the encryption level of the second access network based on the encryption level of the first access network, such that the encryption level of the second access network is lower than the encryption level of the first access network.

[0076] In some embodiments, the apparatus 300 further includes a configuration information sending module configured to send second configuration information to the access device so that the second access network is deployed.

[0077] In some embodiments, the apparatus 300 further includes a third configuration information determination module configured to determine third configuration information for configuring at least one third access network, wherein the at least one third access network is isolated from the first access network, and the total coverage of the second access network and the at least one third access network covers the coverage of the first access network.

[0078] In some embodiments, the device 300 further includes a warning information providing module configured to provide a warning information in response to a network intrusion targeting a first access network or a second access network.

[0079] The modules and / or units included in device 300 can be implemented in various ways, including software, hardware, firmware, or any combination thereof. In some embodiments, one or more units may be implemented using software and / or firmware, such as machine-executable instructions stored on a storage medium. In addition to or as an alternative to machine-executable instructions, some or all of the units in device 300 may be implemented at least partially by one or more hardware logic components. By way of example and not limitation, exemplary types of hardware logic components that may be used include field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-chips (SoCs), complex programmable logic devices (CPLDs), and so on.

[0080] Figure 3The modules and / or units shown can be implemented, in part or in whole, as hardware modules, software modules, firmware modules, or any combination thereof. In particular, in some embodiments, the processes, methods, or procedures described above can be implemented by hardware in a storage system, a host corresponding to the storage system, or other computing devices independent of the storage system.

[0081] Figure 4 A schematic block diagram of an example device 400 that can be used to implement embodiments of the present disclosure is shown. Device 400 can be used to implement, for example... Figure 1 The control device 150 shown. (e.g.) Figure 4 As shown, device 400 includes a central processing unit (CPU) 401, which can perform various appropriate actions and processes according to computer program instructions stored in read-only memory (ROM) 402 or loaded from storage unit 408 into random access memory (RAM) 403. The RAM 403 may also store various programs and data required for the operation of device 400. The CPU 401, ROM 402, and RAM 403 are interconnected via bus 404. Input / output (I / O) interface 405 is also connected to bus 404.

[0082] Multiple components in device 400 are connected to I / O interface 405, including: input unit 406, such as keyboard, mouse, etc.; output unit 407, such as various types of monitors, speakers, etc.; storage unit 408, such as disk, optical disk, etc.; and communication unit 409, such as network card, modem, wireless transceiver, etc. Communication unit 409 allows device 400 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.

[0083] Processing unit 401 executes the various methods and processes described above, such as method 200. For example, in some embodiments, method 200 may be implemented as a computer software program tangibly contained in a machine-readable medium, such as storage unit 408. In some embodiments, part or all of the computer program may be loaded and / or installed on device 400 via ROM 402 and / or communication unit 409. When the computer program is loaded into RAM 403 and executed by CPU 401, one or more steps of method 200 described above may be performed. Alternatively, in other embodiments, CPU 401 may be configured to execute method 200 by any other suitable means (e.g., by means of firmware).

[0084] The functions described above in this document can be performed at least in part by one or more hardware logic components. For example, exemplary types of hardware logic components that can be used, without limitation, include: field programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), payload programmable logic devices (CPLDs), and so on.

[0085] The program code used to implement the methods of this disclosure may be written in any combination of one or more programming languages. This program code may be provided to a processor or controller of a general-purpose computer, special-purpose computer, or other programmable data processing apparatus, such that when executed by the processor or controller, the program code causes the functions / operations specified in the flowcharts and / or block diagrams to be implemented. The program code may be executed entirely on a machine, partially on a machine, as a standalone software package partially on a machine and partially on a remote machine, or entirely on a remote machine or server.

[0086] In the context of this disclosure, a machine-readable medium can be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. Machine-readable media can be, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.

[0087] Furthermore, although the operations are described in a specific order, this should be understood as requiring that such operations be performed in the specific order shown or in sequential order, or requiring that all illustrated operations be performed to achieve the desired result. In certain environments, multitasking and parallel processing may be advantageous. Similarly, although several specific implementation details are included in the above discussion, these should not be construed as limiting the scope of this disclosure. Certain features described in the context of individual embodiments may also be implemented in combination in a single implementation. Conversely, various features described in the context of a single implementation may also be implemented individually or in any suitable sub-combination in multiple implementations.

[0088] Although the subject matter has been described using language specific to structural features and / or methodological logic, it should be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or actions described above. Rather, the specific features and actions described above are merely illustrative examples of implementing the claims.

Claims

1. A method for network protection, comprising: Obtain first configuration information associated with a first access network, wherein the first configuration information at least indicates the coverage area of ​​the first access network; Based on the first configuration information, second configuration information for deploying a second access network is determined, wherein the second access network is isolated from the first access network and at least partially overlaps with the first access network in terms of coverage.

2. The method according to claim 1, wherein determining the second configuration information includes: Determine the deployment location of the access device used to provide the second access network.

3. The method of claim 1, wherein the first configuration information further indicates the Service Set Identifier (SSID) of the first access network, and wherein determining the second configuration information includes: Based on the SSID of the first access network, the SSID of the second access network is determined such that the SSID of the second access network is similar to the SSID of the first access network.

4. The method according to claim 1, wherein the first configuration information further indicates the encryption level of the first access network.

5. The method according to claim 4, wherein determining the second configuration information includes: Based on the encryption level of the first access network, the encryption level of the second access network is determined such that the encryption level of the second access network is lower than that of the first access network.

6. The method according to claim 1, further comprising: The second configuration information is sent to the access device to enable the deployment of the second access network.

7. The method according to claim 1, further comprising: Third configuration information is determined for configuring at least one third access network, which is isolated from the first access network, and the total coverage of the second access network and the at least one third access network covers the coverage of the first access network.

8. The method according to claim 1, further comprising: A warning message is provided in response to the existence of a network intrusion against the first access network or the second access network.

9. A device for network protection, comprising: The first configuration information acquisition module is configured to acquire first configuration information associated with the first access network, wherein the first configuration information at least indicates the coverage area of ​​the first access network; The second configuration information determination module is configured to determine, based on the first configuration information, second configuration information for deploying a second access network, wherein the second access network is isolated from the first access network and at least partially overlaps with the first access network in terms of coverage.

10. The apparatus according to claim 9, wherein the second configuration information determining module comprises: The deployment location determination module is configured to determine the deployment location of the access device used to provide the second access network.

11. The apparatus of claim 9, wherein the first configuration information further indicates a Service Set Identifier (SSID) of the first access network, and wherein the second configuration information determining module comprises: The SSID determination module is configured to determine the SSID of the second access network based on the SSID of the first access network, such that the SSID of the second access network is similar to the SSID of the first access network.

12. The apparatus of claim 9, wherein the first configuration information further indicates the encryption level of the first access network.

13. The apparatus of claim 12, wherein the second configuration information determining module comprises: The encryption level determination module is configured to determine the encryption level of the second access network based on the encryption level of the first access network, such that the encryption level of the second access network is lower than the encryption level of the first access network.

14. The apparatus according to claim 9, further comprising: The configuration information sending module is configured to send the second configuration information to the access device so that the second access network can be deployed.

15. The apparatus according to claim 9, further comprising: The third configuration information determination module is configured to determine third configuration information for configuring at least one third access network, the at least one third access network being isolated from the first access network, and the total coverage of the second access network and the at least one third access network covering the coverage of the first access network.

16. The apparatus of claim 9, further comprising: The warning information providing module is configured to provide a warning information in response to a network intrusion targeting the first access network or the second access network.

17. A device for network protection, comprising: At least one processing unit; as well as At least one memory coupled to the at least one processing unit and storing instructions for execution by the at least one processing unit, the instructions, when executed by the at least one processing unit, causing the device to perform the method according to any one of claims 1-8.

18. A computer-readable storage medium having a computer program stored thereon, the computer program causing the device to perform the method according to any one of claims 1-8 when executed by a device.

Citation Information

Patent Citations

  • Network security early warning system based on self-adaptive mimicry technology

    CN112398876A