Business data access method, device and equipment and computer storage medium
By receiving configuration information of the security management server, generating IP routing rules and intercepting traffic, the problem of low network access reliability in zero-trust networks is solved, secure access to controlled sites and traffic management of uncontrolled sites is realized, and the reliability and flexibility of network access is improved.
Patent Information
- Application Number
- CN202110907929.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-08-09
- Publication Date
- 2025-08-22
- Estimated Expiration
- 2041-08-09
AI Technical Summary
Under the zero-trust network architecture, when enterprises migrate from traditional network architecture, network access reliability is reduced, especially long-chain access traffic is easily interrupted, and there is a lack of flexible multi-scenario control methods.
By receiving the service access configuration information of the security management server, determining the IP address information of the controlled service site, generating IP routing rules, and only intercepting traffic for the controlled site, using the access proxy component and zero-trust gateway to achieve strict access control, avoiding traffic interruption of uncontrolled sites.
Improve the reliability of network access, ensure the security of data access of controlled service sites, reduce the probability of traffic interruption of uncontrolled sites, and realize flexible traffic management.
Smart Images

Figure CN115913583B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of computer technology, in particular to the field of network security technology, and provides a business data access method, device and equipment, and a computer storage medium. Background Art
[0002] Traditional network security architectures are based on perimeters, assuming the intranet is secure by default. However, illicit means can easily breach the perimeter, leading to infiltration and data leaks. With the interconnection and open sharing of data resources, physical boundaries have been eliminated, prompting the emergence of a more rigorous and innovative security technology: zero trust. Zero trust adheres to the principle of "never trust, always verify." Its strategy is to distrust everything, breaking with the traditional network perimeter mentality. It distrusts all networks, both inside and outside the perimeter, requiring verification before authorized access is achieved.
[0003] However, because zero-trust network architecture is a completely new security architecture, enterprises need to make significant adjustments to existing business sites, organizational structures, and security management when migrating from traditional network architecture to zero-trust architecture. Furthermore, in the current enterprise Internet Technology (IT) environment, business scenarios are complex and ever-changing, and each enterprise has vastly different business sites and data exchange scenarios, requiring zero-trust security architecture to have strong multi-scenario adaptability. For example, under a zero-trust network architecture, all traffic is required to pass through the security proxy components on the terminal device. Therefore, some traffic is affected by the lifecycle of the proxy component service or process, especially traffic that maintains a long chain of access to public network services or sites. As the zero-trust network access function in the terminal device stops, this long chain may become interrupted or unavailable, reducing the reliability of network access. Summary of the Invention
[0004] The embodiments of the present application provide a business data access method, apparatus, device, and computer storage medium for improving the reliability of network access while ensuring the security of business data access.
[0005] In one aspect, a service data access method is provided, which is applied to a terminal device, and the method includes:
[0006] Receiving service access configuration information sent by the security management server, the service access configuration information including interception mode indication information and identification information of the controlled service site;
[0007] When it is determined based on the interception mode indication information that only the service access request of the controlled service site is to be intercepted, the controlled IP address information of the controlled service site is determined based on the identification information of the controlled service site;
[0008] Based on the obtained controlled IP address information, a corresponding IP routing rule is generated, wherein the IP routing rule is used to indicate that when a destination address carried in a service access request is recorded in the controlled IP address information, the service access request is forwarded to a designated access proxy component;
[0009] For business access requests that comply with the IP routing rules, the business access request is intercepted by the access proxy component, and when it is determined that the business access request complies with the zero-trust access policy, the business access request is sent to the target business site through the zero-trust gateway.
[0010] In one aspect, a business data access method is provided, which is applied to a security management server, and the method includes:
[0011] receiving service access configuration information sent by the management terminal device, the service access configuration information including interception mode indication information, identification information of the controlled service site, and access logic information, the interception mode indication information being used to indicate: intercepting service access requests for the controlled service site or all service sites, and the access logic information being used to indicate each controlled object;
[0012] According to the access logic information, the interception mode indication information and the identification information of the controlled business site are sent to the terminal devices corresponding to each controlled object, so that the corresponding terminal devices generate controlled IP address information according to the interception mode indication information and the identification information of the controlled business site, and perform business access control according to the controlled IP address information.
[0013] In one aspect, a service data access device is provided, which is applied to a terminal device, and the device includes:
[0014] a receiving unit, configured to receive service access configuration information sent by a security management server, wherein the service access configuration information includes interception mode indication information and identification information of a controlled service site;
[0015] a determining unit configured to determine, based on the identification information of the controlled service site, the controlled IP address information of the controlled service site when it is determined that only the service access request of the controlled service site is to be intercepted based on the interception mode indication information;
[0016] a rule generating unit, configured to generate a corresponding IP routing rule based on the obtained controlled IP address information, wherein the IP routing rule is configured to indicate that when a destination address carried in a service access request is recorded in the controlled IP address information, the service access request is forwarded to a designated access proxy component;
[0017] An access control unit is used to intercept the business access request that complies with the IP routing rule through the access proxy component, and when it is determined that the business access request complies with the zero-trust access policy, send the business access request to the target business site through the zero-trust gateway.
[0018] In one aspect, a service data access device is provided, which is applied to a security management server, and the device includes:
[0019] a receiving unit, configured to receive service access configuration information sent by a management terminal device, the service access configuration information including interception mode indication information, identification information of a controlled service site, and access logic information, the interception mode indication information being used to indicate: intercepting service access requests for a controlled service site or all service sites, and the access logic information being used to indicate each controlled object;
[0020] An execution unit is used to send the interception mode indication information and the identification information of the controlled business site to the terminal devices corresponding to each controlled object according to the access logic information, so that the corresponding terminal device generates controlled IP address information according to the interception mode indication information and the identification information of the controlled business site, and performs business access control according to the controlled IP address information.
[0021] In one aspect, a computer device is provided, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps of any one of the above methods when executing the computer program.
[0022] In one aspect, a computer storage medium is provided, on which computer program instructions are stored, and when the computer program instructions are executed by a processor, the steps of any of the above methods are implemented.
[0023] In one aspect, a computer program product or computer program is provided, the computer program product or computer program comprising computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform the steps of any of the above methods.
[0024] In an embodiment of the present application, when receiving business access configuration information issued by a security management server and determining, based on the interception mode indication information carried therein, that only business access requests for controlled business sites are to be intercepted, the controlled IP address information of the controlled business site is determined based on the identification information of the controlled business site, and corresponding IP routing rules are generated based on the obtained controlled IP address information, wherein the IP routing rules are used to indicate that when the destination address carried by the business access request is recorded in the controlled IP address information, the business access request is forwarded to the designated access proxy component. In this way, traffic interception can be performed only for controlled business sites that require strict access control, thereby realizing an interception mode for specific traffic in a zero-trust network, that is, strict zero-trust access is still performed for controlled business sites, while traffic interception will not be performed for uncontrolled business sites, thereby avoiding the traffic of uncontrolled business sites from being affected by the life cycle of the proxy component service or process, reducing the probability of the long chain of the uncontrolled business site being interrupted or unavailable, thereby improving the reliability of network access on the basis of ensuring the security of business data access of the controlled business sites. BRIEF DESCRIPTION OF THE DRAWINGS
[0025] In order to more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the following briefly introduces the drawings required for use in the embodiments or related technical descriptions. Obviously, the drawings described below are only embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without paying any creative work.
[0026] Figure 1 A schematic diagram of the architecture of the zero-trust access security service provided in an embodiment of the present application;
[0027] Figure 2 A schematic diagram of the architecture of the security management system provided in an embodiment of the present application;
[0028] Figure 3 A flowchart of a method for accessing business data provided in an embodiment of the present application;
[0029] Figure 4 A schematic diagram of a page for an administrator to configure a controlled business site provided in an embodiment of the present application;
[0030] Figure 5 A schematic diagram of the process of pushing configuration information to the security management component provided in an embodiment of the present application;
[0031] Figure 6 A flowchart for processing a service access request in the full-flow interception mode provided in an embodiment of the present application;
[0032] Figure 7A schematic diagram of the process of service access based on self-built DNS provided in an embodiment of the present application;
[0033] Figure 8 A schematic diagram of the process of pushing direct access rules and direct access lists by the security management component provided in an embodiment of the present application;
[0034] Figure 9 A conversion diagram of the mapping relationship provided in the embodiment of the present application;
[0035] Figure 10 A flowchart of domain name processing based on direct access rules provided in an embodiment of the present application;
[0036] Figure 11 A schematic diagram of the structure of a business data access device provided in an embodiment of the present application;
[0037] Figure 12 A schematic diagram of the structure of another service data access device provided in an embodiment of the present application;
[0038] Figure 13 A schematic diagram of the structure of a computer device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0039] In order to make the purpose, technical solutions and advantages of the present application clearer, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of this application. In the absence of conflict, the embodiments in the present application and the features in the embodiments can be combined with each other in any way. In addition, although a logical order is shown in the flow chart, in some cases, the steps shown or described can be performed in an order different from that here.
[0040] The method involved in the embodiment of the present application can be based on cloud technology. After intercepting the business access request of the controlled business site mentioned in the embodiment of the present application, the business access is initiated through the zero-trust gateway through the control of the zero-trust access policy, and is suitable for the cloud security field in cloud technology.
[0041] Cloud technology refers to a hosting technology that unifies hardware, software, network and other resources within a wide area network or local area network to achieve data computing, storage, processing and sharing.
[0042] Cloud technology is a general term for network technology, information technology, integration technology, management platform technology, and application technology based on the cloud computing business model. It can form a resource pool for on-demand, flexible and convenient use. Cloud computing technology will become a key support. Backend services of technical network systems, such as video websites, image websites, and more portals, require extensive computing and storage resources. With the rapid development and application of the internet industry, every item will likely have its own unique identification mark, which will need to be transmitted to backend systems for logical processing. Different levels of data will be processed separately. All types of industry data require strong system support, which can only be achieved through cloud computing.
[0043] Cloud security refers to the security software, hardware, users, organizations, and cloud platforms used in cloud computing business models. Integrating emerging technologies and concepts such as parallel processing, grid computing, and the identification of unknown virus behaviors, cloud security uses a network of clients to monitor software anomalies on the network, obtaining the latest information on Trojans and malicious programs on the internet. This information is then sent to servers for automatic analysis and processing, and solutions for these viruses and Trojans are distributed to every client.
[0044] Specifically, the main research directions of cloud security include:
[0045] 1. Cloud computing security, which focuses on how to ensure the security of the cloud itself and various cloud applications, including cloud computer system security, secure storage and isolation of user data, user access authentication, information transmission security, network attack protection, and compliance auditing;
[0046] 2. Cloudification of security infrastructure: This focuses on how to use cloud computing to build and integrate security infrastructure resources and optimize security protection mechanisms. This includes using cloud computing to build a large-scale security event and information collection and processing platform to enable the collection and correlation analysis of massive amounts of information, thereby improving the ability to control security incidents and risks across the entire network.
[0047] 3. Cloud security services mainly study various security services provided to users based on cloud computing platforms, such as antivirus services.
[0048] To facilitate understanding of the technical solutions provided in the embodiments of the present application, some key terms used in the embodiments of the present application are explained here:
[0049] A Zero Trust access policy consists of trusted applications and accessible zones that users can use. Within the scope of a Zero Trust access policy, users can access any zone through any trusted application. Zero Trust access policies are granular at the logged-in user level, allowing different Zero Trust access policies to be defined for different logged-in users.
[0050] Trusted applications: Terminal devices authorized by the management end can access application carriers of internal business systems. They can include any application that can be installed on the terminal device, including operating system applications and applications that users can install themselves, such as Outlook, WeChat, or Office, etc. For example, trusted applications can be social clients, office clients, search clients (for example, browser clients), multimedia clients (for example, video clients), entertainment clients (for example, game clients), education clients, live broadcast clients, news clients, or shopping clients (for example, e-commerce clients).
[0051] Reachable Zone: Users can access a list of controlled business sites set by the enterprise through a zero-trust network. Based on the zero-trust access policy configured for a user, the controlled business sites on the list that the user can access are considered the user's reachable zone. Controlled business sites can be, for example, internal enterprise resource sites.
[0052] Zero Trust Gateway: Deployed at the entrance of enterprise applications and data resources, it is responsible for verifying and forwarding each business access request to enterprise resources.
[0053] Access proxy component: The access proxy is a terminal agent deployed on controlled terminal devices to initiate secure access. It is responsible for initiating requests for trusted identity authentication of the access subject. Once the identity is verified to be trustworthy, it can establish an encrypted access connection with the zero-trust gateway. It is also the policy execution point for access control.
[0054] Controlled object: generally refers to a user. In the network, a user ID (such as a user account) is used as a controlled object. One user ID uniquely corresponds to one user. When selecting a controlled object, you can quickly select it according to the enterprise organization or department.
[0055] Zero Trust Access Security Service: A service provided to parties requiring access security, including Figure 1 As shown, the security management system provided in the embodiment of the present application is a zero-trust network security service provider. The security management system includes a security management client (including a security management component and an access proxy component), a security management server and an intelligent gateway. The access proxy component and the zero-trust gateway set on the terminal device provide a unified entrance for the access subject to request access to the object's resources through the network. The security management component and the security management server provide authentication operations for the unified entrance. Only business access requests that pass the authentication can be forwarded by the access proxy component to the zero-trust gateway, and the access to the actual business system is proxied by the zero-trust gateway.
[0056] Direct access mode: In a zero-trust network architecture, a business application initiates a network access request to a site. After intercepting the network access request, it directly initiates network access to the target business site, that is, initiates direct connection access, and sends the network response of the target business site to the business application. This access mode is called direct access.
[0057] Proxy access mode: In a zero-trust network architecture, a business application initiates a network access request to a site. After the access proxy component intercepts the network access request, the access proxy component initiates traffic forwarding to the zero-trust gateway, and the zero-trust gateway proxies access to the target business site. After the access, the zero-trust gateway sends the network response of the target business site to the access proxy component, and the access proxy component forwards the network response of the target business site to the business application. This access mode is called proxy access.
[0058] The solution provided by the embodiment of the present application can be applied to zero-trust network access scenarios, such as Figure 2 As shown in FIG. 1 , a schematic diagram of the architecture of a zero-trust network provided by an embodiment of the present application is provided. In this scenario, multiple terminal devices 10 may be included, such as Figure 2 The terminal devices 10~1 to 10~n shown may also include a security management server 20, a zero trust gateway 30, a business site server 40 and a cloud detection and killing server 50.
[0059] The terminal device 10 may be a smart terminal with business data access capabilities, such as a smartphone, tablet computer, laptop computer, desktop computer, wearable device, smart home device, or head-mounted device. Each terminal device 10 may be a terminal device controlled by a user group, such as a terminal device used by employees within an enterprise or a terminal device used by members of a group organization.
[0060] like Figure 2 As shown, each terminal device 10 can be installed with a business application 102 and a security management client 101. The security management client 101 includes a security management component (also referred to as a security management client) and an access proxy component (also referred to as an access proxy client). The business application 102 can include both trusted applications and untrusted applications.
[0061] The security management server 20 is the background server of the security management component. It can be an independent physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN, as well as big data and artificial intelligence platforms, but is not limited to these.
[0062] The zero-trust gateway 30 can be any gateway device that can implement service access request verification and request forwarding.
[0063] The business site server 40 is the server access object corresponding to the target business site requested by the business access request, for example, it can be an internal site of an enterprise. The business data and other contents of the business site server 40 are protected access objects and can only be accessed after authorization verification is passed.
[0064] The cloud antivirus server 50 is used to implement the cloud antivirus function, which is used to detect whether the application process of the business application is safe, such as whether there are vulnerabilities or viruses, and thus provide a result of whether the application process is a malicious process. For example, it can be a threat intelligence cloud check service or a TAV antivirus engine.
[0065] In specific applications, users can pre-install the security management client 101 on the terminal device. The security management component included is a security agent installed on the terminal device, which is used to connect to the security management server 20 and is responsible for security verification functions. For example, it can be responsible for verifying the user's trusted identity on the terminal device, verifying whether the terminal device and the business application are trustworthy, and requesting unknown processes to the server for process inspection. The access agent component can hijack device traffic through a virtual network card (such as a TUN / TAP virtual network card) to obtain business access requests, and connect to the zero-trust gateway 30 to implement functions such as forwarding business access requests. After the security management component passes authentication, the access agent component is responsible for forwarding the business access request to the intelligent gateway. If the authentication fails, it will directly connect or terminate the connection.
[0066] When a user logs in to his or her account on the security management client 101, the security management component can obtain the zero-trust access policy configured by the administrator for the user from the security management server 20. Therefore, when the user initiates network access using the business application 102 on the terminal device 10, the access proxy component can intercept the business access request triggered by the network access and request the security management component to authenticate the business access request, that is, apply to the security management component for the verification certificate corresponding to the business access request. The authentication request parameters include the source Internet Protocol (IP) address or domain name, source port, destination IP address or domain name, destination port, and process identification (PID) corresponding to the business application.
[0067] On the one hand, when the security management component determines whether the business application and access site initiating the access comply with the zero-trust access policy, if they do not comply with the zero-trust access policy, the security management component responds with a direct connection result to the access proxy component. After receiving the direct connection result, the access proxy component directly forwards the business access request to the target business site that needs to be connected. If the security management component determines that it complies with the zero-trust access policy, the security management component needs to collect feature information of the business application and determine whether the business application is a risky process. If so, a ticket rejection response is sent to the access proxy component. If it is not a risky process, the security management component obtains a verification credential from the locally cached credential list and responds to the access proxy component.
[0068] The access proxy component first initiates a request with verification credentials to the zero trust gateway 30. After receiving the request from the access proxy component, the zero trust gateway 30 verifies the above verification credentials with the security management server 20. If the verification is successful, the zero trust gateway 30 successfully establishes a connection with the access proxy component. After that, the access proxy component sends the original business access request to the zero trust gateway 30, which forwards it to the corresponding business site server to proxy the actual application network access; if the verification credential verification fails, the connection between the access proxy component and the zero trust gateway 30 is interrupted.
[0069] On the other hand, the security management component will also collect more detailed feature information of the business application and asynchronously initiate a deep security check to the security management server 20. The security management server 20 can perform a security check on the business application, or it can also initiate a check request to the cloud detection server 50 to perform a deep security check on the business application. When the security management server 20 or the cloud detection server 50 determines that the application process of the business application is a malicious process, the security management server 20 notifies the security management component to implement a blocking operation on the existing access link.
[0070] Zero-trust access policies are implemented at the end-user level. The security management server 20 distributes policies to appropriate users based on the organizational structure. Different types of policies can be distributed to designated enterprise groups, departments, organizations, or individuals (with the smallest granularity being the user level). Zero-trust access policies include the business system identifiers (domain names, IP addresses, or IP segments) and ports accessible to end users, as well as the restricted applications that can access these business systems. Business systems can support fuzzy matching and IP segment settings.
[0071] With the interconnection, interoperability, sharing and openness of data resources, the application of zero-trust technology is becoming more and more extensive. However, in actual application, as mentioned above, under the zero-trust network architecture, all traffic is required to pass through the proxy components on the terminal devices, so some traffic is affected by the proxy component service or process life cycle, especially the traffic that maintains long-chain access to public network services or sites. As the zero-trust network access function in the terminal device stops, the long chain may be interrupted or unavailable, reducing the reliability of network access.
[0072] In addition, when the enterprise's internal terminal devices are in different network scenarios (for example, in a specific network or within a specific IP segment), there may be a need for direct access to business systems that have been connected to the zero-trust security architecture. For example, there may be a need for direct access when in the enterprise intranet environment, while in ordinary scenarios, it is required to be transmitted through a secure channel between the access proxy component and the zero-trust gateway and strictly controlled by the zero-trust access policy. However, the current diverse scenarios for access to different business systems lack unified and flexible control methods.
[0073] In view of this, the present invention provides a method for accessing business data, which can be applied to Figure 2 In the illustrated security management system, the security management server 20 can, based on the service access configuration information of the management device, pre-deliver interception mode indication information and identification information of the controlled service site to the terminal devices 10 of each designated controlled object. The interception mode indication information is used to indicate whether to intercept service access requests for the controlled service site or all service sites, that is, to adopt the full traffic interception mode or the controlled service site traffic interception mode. Furthermore, through configuration on the management side, switching between the two modes can be supported, allowing enterprises to set and select the appropriate traffic interception mode based on their needs.
[0074] When the terminal device 10 determines to adopt the controlled business site traffic interception mode, it can generate IP routing rules based on the IP address information of the controlled business site, that is, when the destination address carried by the service access request is recorded in the controlled IP address information, the service access request is forwarded to the designated virtual network card based on the IP routing rules preset for the corresponding controlled IP address information, and the service access request is intercepted through the virtual network card, so as to perform the subsequent proxy access process.
[0075] During specific implementation, for a business access request initiated by a business application, when the destination address carried by the business access request is recorded in the controlled IP address information, the business access request is forwarded to the designated virtual network card based on the preset IP routing rules corresponding to the controlled IP address information. The business access request is intercepted by the virtual network card, and then business access control is performed on the intercepted business network access request. In this way, traffic can be intercepted only for controlled business sites that require strict access control, thereby realizing a specific traffic interception mode in a zero-trust network, that is, strict zero-trust access is still performed for controlled business sites, while traffic will not be intercepted for uncontrolled business sites, thus avoiding the traffic of uncontrolled business sites from being affected by the proxy component service or process life cycle, reducing the probability of the long chain of uncontrolled business sites being interrupted or unavailable, thereby improving the reliability of network access on the basis of ensuring the security of business data access at controlled business sites.
[0076] When the terminal device 10 determines to adopt the full-traffic interception mode, the routing priority of the virtual network card can be set to the highest priority, so that all business access requests will be automatically forwarded to the specified virtual network card, and then the business access requests will be intercepted through the virtual network card, so as to carry out the subsequent proxy access process.
[0077] In an embodiment of the present application, a dynamic direct access solution is also proposed, that is, the security management server 20 pre-issues direct access rules and direct access lists to the terminal devices 10 of each controlled object. The direct access rules indicate: under the specified network segment, a direct access method is adopted for each controlled business site in the direct access list, and then the network environment where the monitoring terminal device in the terminal device 10 is located, when in a specific network segment (such as an enterprise intranet), some controlled business sites can adopt a direct access method, and when in other network segments (such as non-enterprise intranets), the above-mentioned some controlled business sites need to switch to a proxy access method, so that the business access method can be flexibly switched in different network environments.
[0078] Of course, the method provided in the embodiment of the present application is not limited to Figure 2 The application scenarios shown can also be used in other possible zero-trust architecture scenarios, and the embodiments of this application are not limited thereto. Figure 2 The functions that can be implemented by each device in the application scenario shown will be described in subsequent method embodiments and will not be described in detail here.
[0079] In the embodiment of this application, when an enterprise accesses a zero-trust network architecture from a traditional network architecture, it is necessary to introduce a pre-control logic for accessing a business system. Therefore, the process of accessing a zero-trust architecture business system is first introduced below. Figure 3 The figure shows the process flow of accessing the zero-trust architecture business system.
[0080] Step 301: The management terminal device obtains the service access configuration information configured by the administrator.
[0081] In an embodiment of the present application, the enterprise administrator can input corresponding configuration information through the management page of the security management system, so that the management end device obtains the business access configuration information based on the input of the enterprise administrator.
[0082] Specifically, the service access configuration information may include one or a combination of the following:
[0083] (1) Identification information of controlled business sites
[0084] The identification information of the controlled business site is used to indicate which sites belong to the controlled business site. Usually for an enterprise, in order to avoid leakage of enterprise resources, the controlled business site is usually the internal resource site of the enterprise. Internal resources can include data, interfaces, functions, etc., and the controlled business site can be the site that provides these data, interfaces and functions.
[0085] Specifically, the identification information can generally be in the form of a domain name and an IP form, and the IP form can include a specific IP address or IP segment. Therefore, as long as the target business site of the service access request initiated in the terminal device hits the set domain name or IP, it is considered that the user is trying to access corporate resources.
[0086] See also Figure 4 As shown in the figure, it is a schematic diagram of the page for administrators to configure controlled business sites. Administrators can add controlled business sites of the categories of domain names, IP addresses or IP segments, i.e., intranet resources, and set the relevant configuration information of the content resources. Figure 4 As shown, when the administrator chooses to add an intranet resource identified by a domain name, Figure 4 In the “*.sohu.com”, set the resource name of the resource, i.e. “News Site”, as well as the access port and resource grouping of the resource.
[0087] (2) Interception mode indication information
[0088] The interception mode indication information is used to indicate the traffic interception mode to be adopted. The traffic interception modes include the following two:
[0089] ① Full-traffic interception mode intercepts business access requests from all business sites. This means that any business access request initiated from a terminal device must be proxied through the access proxy component, meaning that the request must be forwarded through a zero-trust gateway.
[0090] Of course, the "all business sites" here does not refer to absolutely all business sites, but may refer to most business sites. In actual applications, business access requests from a small number of sites may not be intercepted.
[0091] ② Controlled Business Site Traffic Interception Mode intercepts only service access requests from controlled business sites. This means that only service access requests initiated from terminal devices targeting controlled business sites, such as requests to access internal enterprise resource sites, are proxied through the access proxy component. Service access requests from other business sites do not require proxied through the access proxy component.
[0092] Generally speaking, controlled business sites are usually enterprise resource sites, so the controlled business site traffic interception mode can also be
[0093] In specific applications, the same traffic interception mode can be configured for all users in the enterprise, or different traffic interception modes can be configured for different users.
[0094] (3) Access logic information
[0095] Access logic information is used to indicate each controlled object. Administrators can specify the issuance of relevant zero-trust access control policies or business access configuration information for some or all groups in the enterprise organizational structure, so that personnel or devices associated with the selected organizational structure can access the zero-trust security architecture, thereby completing the gradual grayscale and access logic within the enterprise.
[0096] Step 302: The management terminal device sends the service access configuration information to the security management server.
[0097] Step 303: The security management server sends the service access configuration information to each controlled object, and the terminal device of each controlled object receives the service access configuration information.
[0098] In an embodiment of the present application, the security management server can determine which controlled objects the service access configuration information needs to be sent to based on the access logic information, and then send the service access configuration information to these controlled objects.
[0099] In a possible implementation, the security management server may push the service access configuration information to each controlled object in a push manner, and then, after the user logs in to the security management component through his or her own account, he or she may receive the service access configuration information;
[0100] In another possible implementation, the terminal device may obtain the service access configuration information by pulling the service access configuration information from the security management server.
[0101] In an embodiment of the present application, a security management component and an access proxy component are installed in the terminal device. The security management component is responsible for security detection on the terminal, and the access proxy component is responsible for intercepting business access requests and performing forwarding, etc. A connection channel is established between the security management server and the security management component, and then the business access configuration information is received through the security management component, and the push process of the business access configuration information to the access proxy component is triggered.
[0102] Step 304: Determine the traffic interception mode to be adopted based on the interception mode indication information.
[0103] Step 305: When it is determined to adopt the controlled service site traffic interception mode, the controlled IP address information of the controlled service site is determined according to the identification information of the controlled service site.
[0104] Specifically, the identification information of the controlled business site may include an IP address and an IP segment. Based on the IP address and IP segment issued by the security management server, the IP address of the corresponding controlled business site may be directly acquired.
[0105] In addition, the identification information of the controlled business site may also include domain name information. The identification information in the form of a domain name needs to be converted into an IP address. Then, after the security management component receives the business access configuration information sent by the security management server and pushes the business access configuration information to the access proxy component, and the access proxy component determines to adopt the controlled business site traffic interception mode based on the interception mode indication information in the business access configuration information, it can call the system's default Domain Name System (DNS) to resolve the received domain name information of the controlled business site, obtain the real IP address of each domain name information that has been successfully resolved, and then return the real IP address of the successfully resolved domain name information to the security management component.
[0106] Step 306: Based on the obtained controlled IP address information, a corresponding IP routing rule is generated. The IP routing rule is used to indicate that when the destination address carried in the service access request is recorded in the controlled IP address information, the service access request is forwarded to the designated access proxy component.
[0107] In an embodiment of the present application, since the number of obtained IP addresses may be large and there may be continuous IP addresses, in order to reduce the number of IP routes, the obtained IP addresses can be aggregated to obtain multiple IP segments, each IP segment including multiple continuous IP addresses.
[0108] Specifically, the IP routing rules can be written into the routing table of the terminal device through the security management component, that is, the next hop address of the IP or IP segment of the controlled business site is changed to the address of the virtual network card of the access proxy component. In this way, the business access requests of these controlled business sites will automatically enter the virtual network card.
[0109] In specific applications, after the IP routing rules are written into the routing table, when the terminal device receives a business access request sent by the business application for accessing the target business site, if, based on the above-mentioned IP routing rules, it is determined that the destination address carried by the business access request is recorded in the controlled IP address information, the business access request will be forwarded to the virtual network card of the access proxy component, thereby intercepting the business access request through the virtual network card.
[0110] Step 307: For a service access request that complies with the IP routing rules, the access proxy component intercepts the service access request and, when it determines that it complies with the zero-trust access policy, sends the service access request to the target service site through the zero-trust gateway.
[0111] Specifically, business access requests that comply with IP routing rules will be automatically intercepted by the access proxy component, and then the access proxy component will request authentication from the security management component to determine whether it complies with the current user's zero-trust access policy. If the authentication is successful, the business access request will be sent to the target business site through the zero-trust gateway for access proxy; if the authentication is not successful, the business access request will be sent directly to the target business site to achieve direct access.
[0112] Step 308: When it is determined to adopt the full traffic interception mode, the routing level of the virtual network card is set to the highest priority.
[0113] Step 309: All business access requests are intercepted by the access proxy component. For each business access request, when it is determined that it complies with the zero-trust access policy, the business access request is sent to the target business site through the zero-trust gateway.
[0114] In an embodiment of the present application, when it is determined to adopt the full-traffic interception mode, that is, to intercept the business access requests of all business sites, the routing level of the virtual network card can be set to the highest priority, so that the business access requests of each business site will automatically enter the virtual network card.
[0115] Specifically, based on the determined full-traffic interception mode, the security management component can add the IP address of the virtual network card of the access proxy component (such as the TUN / TAP network card mentioned in the previous section) as the default route in the host routing table of the terminal device, and the number of interface hops is dynamically set to the minimum value. In this way, the routing priority of the virtual network card of the access proxy component is set to the highest, so that network access initiated by a certain application APP will automatically enter the TUN / TAP network card, realizing full-traffic hijacking.
[0116] In this way, all business access requests on the terminal device will be automatically intercepted by the access proxy component, and then the access proxy component will request authentication from the security management component to determine whether it complies with the current user's zero-trust access policy. If the authentication is successful, the business access request will be sent to the target business site through the zero-trust gateway, and the access will be proxied through the zero-trust gateway; if the authentication is not successful, the business access request will be sent directly to the target business site to achieve direct access.
[0117] Of course, when using the full-traffic interception mode, business access requests for certain business sites may not be intercepted. For these business sites, this can be achieved by setting corresponding routing table entries, that is, changing the next-hop address corresponding to the IP address of these business sites to the physical network card. In this way, the business access requests of these business sites will be forwarded through the physical network card.
[0118] In the embodiment of the present application, a security management component and an access proxy component are installed in the terminal device. The security management component is responsible for security detection on the terminal device, and the access proxy component is responsible for intercepting and forwarding service access requests. A connection channel is established between the security management server and the security management component, and then the service access configuration information is received through the security management component, which triggers the push process of pushing the service access configuration information to the access proxy component. Figure 5 The figure shows a flow chart of the security management component pushing configuration information.
[0119] Step S10: The security management component pulls the service access configuration information from the security management server, or the security management server pushes the service access configuration information to the security management component.
[0120] Step S11: The security management component triggers the push process of the service access configuration information.
[0121] Step S12: The security management component performs format checking and filtering operations on the business access configuration information to remove illegal and invalid data, and at the same time performs aggregation operations on the IP and IP segments of the controlled business sites to reduce the number of routes written to the terminal device, forming business system rules and traffic hijacking patterns.
[0122] Among them, illegal data includes, for example, illegal IP addresses included in the IP addresses sent by the security management server, and these illegal IP addresses will be removed from the IP addresses.
[0123] Step S13: The access proxy component performs authentication on the push interface call request of the security management component. If the authentication fails, the push of the security management component fails. If the authentication succeeds, the access proxy component responds to the push interface of the security management component, that is, allows the push interface call of the security management component.
[0124] The authentication of the interface call of the security management component by the access proxy component can be achieved through a communication protocol pre-agreed between processes, such as a public key and private key authentication method.
[0125] Step S14: The security management component pushes the latest business system rules and traffic hijacking patterns to the access proxy component based on the access logic issued by the security management server.
[0126] Step S15: The security management component checks whether the push is successful according to the response result of the access proxy component, and builds a push status cache according to the push result.
[0127] The push status cache consists of multiple cache items, each of which consists of a corresponding hash value and push status, forming a key-value (KV) structure. The key is the hash value corresponding to the configuration, and the value includes the configured push timestamp and push status. The push status includes unknown status, pending push status, push success, and push failure. If the security management component identifies that a push configuration was unsuccessful, the push automatically enters a retry state until the maximum number of retries is reached (for example, after three attempts). If the push still fails, the push is stopped, the last push result is recorded in the push status cache, and the operational data is reported to the security management server.
[0128] Through the above steps, the Security Management Server pushes the enterprise administrator's business access configuration information to the Access Agent component in a timely and efficient manner through the Security Management component. Any configuration changes made by the enterprise administrator on the management side are synchronized to the Security Management Server, which then distributes this information to the Security Management component on each controlled device.
[0129] The embodiments of the present application provide two traffic interception modes, namely the full traffic interception mode mentioned above, and the other is the controlled business site traffic interception mode. The full traffic interception mode imports all traffic of the terminal device into the access proxy component, and initiates traffic forwarding or direct access through the access proxy component. The controlled business site traffic interception mode only parses the network traffic of the IP or IP segment of the business system that accesses enterprise resources including data, interfaces and functions, and does not interfere with other traffic, especially the traffic of users accessing public websites. Below, the business access process of the two modes is introduced respectively.
[0130] 1. Full Traffic Interception Mode
[0131] See also Figure 6 FIG. 1 shows a flowchart of processing a service access request in a full-traffic interception mode.
[0132] The access proxy component consists of two parts: a virtual network card and a user-mode proxy process. The access proxy component hijacks service access requests initiated by the terminal device through the virtual network card, and controls the start and stop of the virtual network card and the reading and writing of kernel data through the user-mode proxy process. The access proxy component processes data packets (i.e., IP packets) from the network layer through the virtual network card. Unlike the physical network card, one end of the virtual network card of the access proxy component is connected to the kernel protocol stack, and the other end is connected to the user-mode proxy process. The network data sent by the kernel protocol stack in the terminal device to the virtual network card of the access proxy component is sent to the user-mode proxy process. After certain data conversion, it is sent to the zero-trust gateway or the corresponding target business site through the terminal's physical network card.
[0133] Step S20: The security management component adds the routing priority of the virtual network card of the access proxy component to the host routing table of the terminal device as the highest based on the service access configuration information set by the administrator.
[0134] Specifically, the security management component adds the IP address of the virtual network card of the access proxy component as the default route in the host routing table of the terminal device based on the business access configuration information set by the administrator, and dynamically sets the number of interface hops to the minimum value. In this way, the routing priority of the virtual network card of the access proxy component is set to the highest, so that business access requests will automatically enter the virtual network card to achieve full traffic interception mode.
[0135] Step S21: The service access request data packet initiated by the service application is transmitted from the application layer to the transport layer, and then sent down to the network layer. The corresponding layer header data is added at each layer, and then the service access request data packet is sent to the kernel protocol stack of the terminal device via the socket interface.
[0136] Step S22: The kernel protocol stack searches for a route in the host routing table according to the destination address of the service access request data packet, finds out that the next hop address is the virtual network card of the access proxy component, and sends the service access request data packet to the virtual network card of the access proxy component.
[0137] Step S23: After receiving the service access request data packet (IP data packet), the virtual network card notifies the user-mode agent process to obtain the data sent from the kernel space to the virtual network card, thereby executing data exchange between the kernel protocol stack layer and the user layer.
[0138] Step S24: After the user-mode proxy process obtains the service access request data packet, it analyzes the data packet and initiates traffic authentication to the security management component to determine whether the service access request complies with the zero-trust access policy configured for the user.
[0139] Step S24: After the security management component successfully performs traffic authentication on the network data packet, a new data packet with a source address of the Ethernet card address and a destination address of the intelligent gateway connection address is constructed through the socket based on the original service access request data packet; if the traffic authentication fails, a new data packet with a source address of the Ethernet card address and a destination address of the target service site is constructed through the socket based on the original IP data packet.
[0140] Step S25: The new data packet is sent to the intelligent gateway via the Ethernet card, or is directly connected to the target service site via an external network device connected to the Ethernet card.
[0141] Through the above process, the access proxy component is responsible for sending the actual network access traffic to the intelligent gateway through the physical network card after being authenticated by the security management component, and the intelligent gateway will proxy the actual business access; if the traffic authentication of the security management component fails, the proxy client component will hijack the original network access traffic directly through the physical network card to the corresponding destination business site for network access and response process, thereby realizing direct access.
[0142] 2. Traffic interception mode for controlled business sites
[0143] In controlled business site traffic interception mode, administrators configure domain name matching rules, IP addresses, or IP segments for controlled business sites on the management side. These rules are then aggregated and formatted by the security management component to form standardized traffic interception rules. Domain name matching rules are pushed to the access proxy component, while IP or IP segment matching rules are written to the terminal device's host routing table via the security management component.
[0144] (1) IP or IP segment matching rules
[0145] Specifically, if some business sites are accessed in the form of IP, the administrator can configure the IP or IP segments covered by the business sites. The security management server or security management component can automatically aggregate them into a reasonable number of IP segments based on the administrator's input, and generate corresponding IP routing rules, which will be written into the host routing table of the terminal device as precise access routes.
[0146] IP or IP segment matching rules are the same as the aforementioned IP routing rules. However, in addition to the IP addresses or IP segments directly configured by the administrator, IP routing rules also include IP addresses derived from administrator-configured domain name information. Since IP-based traffic interception has been described in detail previously, it will not be repeated here.
[0147] It should be noted that for controlled business sites configured in IP form, the host routing setting process of the security management component in the terminal device can be dynamic, that is, these IP routing rules are automatically added when zero-trust network access control is started, and these IP routing rules are automatically deleted when zero-trust network access control is stopped. Moreover, in full-traffic hijacking mode and enterprise resource traffic hijacking mode, if there are other business needs for direct access to certain business sites, the enterprise management end can also set up a routing direct connection list for some business sites in IP form, that is, by sending the configuration to the security management component, the security management component sets the next hop of the IP address of these business sites to the physical network card, thereby achieving direct access to some business sites, freeing them from the influence of traffic interception by the access proxy component, and enhancing the adaptability of the zero-trust network access function to traditional business systems.
[0148] (2) Domain name matching rules
[0149] If the administrator configures controlled business sites in the form of domain names, then the domain name information of these controlled business sites needs to be resolved to obtain the corresponding real IP addresses, and then the corresponding IP routing rules are set based on the real IP addresses.
[0150] Specifically, after the security management server sends the domain name information to the security management component, the security management component can push the domain name information to the access proxy component. The access proxy component can call the system DNS to resolve the domain name information. For successful resolution and obtaining of real IP addresses, the access proxy component can return these real IP addresses to the security proxy component, so that the security proxy component can generate corresponding IP routing rules based on these real IP addresses, so that business access requests with destination addresses of these real IP addresses will also be intercepted by the virtual network card.
[0151] In an embodiment of the present application, when a business application initiates access to a site in the form of a domain name, it must wait for the DNS to resolve the correct IP address before it can initiate subsequent access behavior with the IP address as the destination address. However, considering that most of the controlled business sites are internal resource sites of the enterprise, DNS resolution failure may occur in the public network, that is, the corresponding IP address cannot be resolved, or domain name pollution may occur in the DNS resolution, which ultimately leads to the business application being unable to initiate subsequent business access requests and the business access behavior cannot continue.
[0152] Therefore, in order to solve this problem, the embodiment of the present application also provides a service access method based on self-built DNS, see Figure 7 The figure below is a flowchart of service access based on self-built DNS.
[0153] Step S30: The security management component pushes the domain name information of the controlled business site configured by the administrator to the access proxy component so that the access proxy component can determine whether the domain name in the access session is a controlled business site, ie, an enterprise resource.
[0154] Step S31: The access proxy component intercepts the domain name resolution request of the business application.
[0155] Specifically, when the access subject accesses the corporate domain name through a business application APP (a browser or a C / S architecture application), the access proxy component can capture the corresponding DNS request by detecting port 53, which is the port opened by DNS.
[0156] Step S32: The access proxy component determines whether the target domain name carried in the domain name resolution request complies with the controlled site domain name rules, that is, determines whether the target domain name carried in the domain name resolution request is recorded in the domain name information of the controlled business site.
[0157] Step S33: If it complies with the controlled site domain name rules, the target domain name of the access proxy component is assigned a virtual IP address.
[0158] For example, some of an enterprise's business resources are accessed in the form of domain names, such as "www.oa.com" and "www.corp.com". Then the business application requests a DNS request for "www.oa.com". The access proxy component intercepts a DNS request by detecting port 53 and automatically allocates a virtual IP for "www.oa.com", such as "192.168.221.3".
[0159] Step S34: access the proxy component and store the first mapping relationship between the virtual IP address and the target domain name, and return the virtual IP address to the service application.
[0160] Specifically, in order to avoid DNS resolution failure or domain name pollution, the access proxy component also executes the resolution logic of its own DNS. That is, when the access proxy component determines that the target domain name belongs to the domain name of a controlled business site, it assigns a unique virtual IP address to the domain name, caches the first mapping relationship between the virtual IP address and the target domain name, and returns the virtual IP address to the business application. In this way, the business application can use the virtual IP address to initiate business access to ensure that the subsequent business access process can proceed smoothly.
[0161] When receiving a business access request initiated by a business application based on a virtual IP address, the access proxy component can obtain the target domain name to be accessed by the business access request based on the first mapping relationship, and then initiate traffic authentication to the security management component based on the target domain name. When the security management component passes the authentication, that is, when it is determined that the target domain name complies with the preset zero-trust access policy, the access proxy component sends the business access request to the controlled business site corresponding to the target domain name through the zero-trust gateway. Otherwise, if the security management component fails to pass the authentication, the access proxy component sends the business access request to the controlled business site corresponding to the target domain name through the physical network card.
[0162] Step S35: If it does not comply with the controlled site domain name rules, call the system DNS to resolve the domain name resolution request and obtain the corresponding real IP address.
[0163] Step S36: The access proxy component stores the second mapping relationship between the target real IP address and the target domain name, and returns the real IP address to the service application.
[0164] Then, when a business access request is received from a business application based on a real IP address, the access proxy component obtains the target domain name corresponding to the business access request according to the second mapping relationship, and then initiates traffic authentication to the security management component based on the target domain name. When the security management component passes the authentication, that is, when it is determined that the target domain name complies with the preset zero-trust access policy, the access proxy component sends the business access request to the controlled business site corresponding to the target domain name through the zero-trust gateway. Otherwise, if the security management component fails to pass the authentication, the access proxy component sends the business access request to the controlled business site corresponding to the target domain name through the physical network card.
[0165] For example, the above process is described below by taking access to a specific domain name as an example.
[0166] The administrator configures the domain name "*.corp.com" for enterprise resources on the management side. The Security Management Server sends this domain name to the Security Management component, which then pushes it to the Access Proxy component. The following describes the DNS resolution process when a user accesses "www.corp.com" and "www.baidu.com" through a business application.
[0167] When the access subject accesses "www.corp.com" through a business application, the traffic performing DNS resolution is intercepted by the virtual network card, and the access proxy component takes over the DNS resolution process. The access proxy component first queries its own enterprise resource domain name rules to check whether the target domain name of the request complies with the enterprise resource domain name rules. If the check finds that the target domain name complies with the enterprise resource domain name rules, it is considered to be the enterprise intranet domain name and the self-built DNS resolution logic is executed: that is, the virtual IP address is generated and allocated. If the target domain name does not comply with the enterprise resource domain name rules, it is considered not the enterprise intranet domain name and the proxy client component directly sends the domain name to the system DNS for DNS resolution to resolve the real IP address.
[0168] Because "www.corp.com" meets the "*.corp.com" rule for enterprise resource domain names, it is identified as the enterprise intranet domain name by the access proxy component and a virtual IP address is assigned through the self-built DNS of the proxy client component, rather than being resolved into a native IP address by the system DNS.
[0169] When a user visits "www.baidu.com", the traffic performing DNS resolution is hijacked by the virtual network card, and the access proxy component takes over the DNS resolution process. The access proxy component first queries its own enterprise resource domain name rules. Because "www.baidu.com" does not meet the enterprise resource domain name rule of "*.corp.com", the proxy client component recognizes that the domain name is not the enterprise intranet domain name. The proxy client component sends the domain name directly to the system DNS for DNS resolution to resolve the real IP address.
[0170] After the real IP address is resolved to a virtual IP address through a self-built DNS or a real IP address through the system DNS, the virtual IP address or real IP address is sent to the business application through the virtual network card, completing the DNS resolution process for the business application. Simultaneously, the access proxy component stores the first mapping between the virtual IP address and the domain name, and the second mapping between the real IP address and the domain name, in its memory cache. This cache remains valid as long as the access proxy process exists.
[0171] After the business application successfully performs DNS resolution, it immediately sends a business access request to the IP address resolved by the DNS (which may be a virtual IP address or a real IP address resolved by the system DNS). This request is also hijacked by the virtual network interface card (VNIC) and captured by the access proxy component. The access proxy component then reverse-checks the domain name based on the IP address to see if it is in the first virtual IP address-domain name mapping list or the second real IP address-domain name mapping list. Because the enterprise resource domain name rule includes "*.corp.com", access to "www.corp.com" is reverse-checked from the virtual IP address-domain name mapping list based on the IP address, ultimately obtaining the domain name "www.corp.com" corresponding to the request, completing the virtual IP address-domain name lookup. Because "www.baidu.com" does not meet the enterprise resource domain name rule, access to "www.baidu.com" is reverse-checked from the real IP address-domain name mapping list based on the real IP address, and the corresponding domain name is finally determined based on the domain name. Whether proxy access is required is determined based on the domain name. If proxy access is required, the request is sent to the target business site through the zero-trust gateway. If proxy access is not required, the target business site is accessed directly.
[0172] The above domain name resolution logic can solve the problem in zero-trust access scenarios where the application cannot initiate subsequent business access requests due to the failure of DNS resolution of some enterprises' intranet domain names on the public network or domain name pollution.
[0173] In an embodiment of the present application, the controlled business site configuration in the above-mentioned domain name form and IP form is used to complete the dynamic configuration of the controlled business site interception mode. For the enterprise domain name rules configured by the administrator, the access traffic of the controlled business site is identified by the self-built DNS of the access proxy component. For the business system IP or IP segment configured by the enterprise administrator, the IP routing rules automatically aggregated and generated by the security management component are written into the host routing table of the controlled terminal device as precise access routes, thereby realizing traffic interception for the controlled business site without affecting data access of uncontrolled business sites (such as public network traffic).
[0174] In an embodiment of the present application, for the functions of enterprise access to business systems in grayscale or extended zero-trust security architecture, it is necessary to be compatible with some business applications to directly access enterprise resource sites in a specific network environment. For example, when in the company's intranet environment, the enterprise resource site can be directly accessed, and outside the specific network segment, the enterprise resource site can still be securely accessed through the access proxy component and the zero-trust gateway.
[0175] Therefore, the embodiment of the present application also proposes a dynamic direct access method, which combines the changes in the network environment where the terminal device is located, and realizes the switching of enterprise resource access methods without user perception through the linkage of the access proxy component and the security management component, thereby enhancing the applicable scenario scope of the zero-trust security architecture without adjusting third-party functions. Figure 8 The figure shows a flow chart of the security management component pushing direct access rules and direct access lists.
[0176] Step S40: The administrator configures a zero-trust access policy on the management device, including direct access rules and a direct access list.
[0177] Direct access rules instruct users within designated network segments to directly access controlled business sites listed in a specified direct access list. The direct access list contains the IP addresses and domain names of the controlled business sites accessed based on the direct access rules. Direct access rules specify the rules that allow specific business applications to directly access enterprise resources within certain network segments, while securely accessing enterprise resources outside of these segments through proxy components and zero-trust gateways.
[0178] like Figure 4 As shown, the administrator can select whether a specific business site supports "Intranet Direct Connection". If selected, the business site will be added to the direct connection access list.
[0179] Step S41: The security management component pulls the direct access rules and the direct access list from the security management server, or the security management server pushes the direct access rules and the direct access list to the security management component.
[0180] Step S42: The security management component triggers the push process of the service access configuration information.
[0181] Step S43: The security management component performs format checking and filtering operations on the business access configuration information to remove illegal and invalid data, and at the same time forms direct access rules and direct access lists according to the format agreed upon by the access proxy component and the security management component.
[0182] Step S44: The access proxy component performs authentication on the push interface call request of the security management component. If the authentication fails, the push of the security management component fails. If the authentication succeeds, the access proxy component responds to the push interface of the security management component, that is, allows the push interface call of the security management component.
[0183] Step S45: The security management component pushes the latest direct access rules and direct access list to the access proxy component based on the access logic issued by the security management server.
[0184] Step S46: The security management component checks whether the push is successful based on the response result of the access proxy component, and builds a push status cache based on the push result.
[0185] The push status cache consists of multiple cache items, each of which consists of a corresponding hash value and push status, forming a key-value (KV) structure. The key is the hash value corresponding to the configuration, and the value includes the configured push timestamp and push status. The push status includes unknown status, pending push status, push success, and push failure. If the security management component identifies that a push configuration was unsuccessful, the push automatically enters a retry state until the maximum number of retries is reached (for example, after three attempts). If the push still fails, the push is stopped, the last push result is recorded in the push status cache, and the operational data is reported to the security management server.
[0186] Through the above steps, the Security Management Server pushes the administrator's configured direct access rules and direct access lists to the Access Agent component in a timely and efficient manner through the Security Management component. Any configuration changes made by the administrator on the management side are synchronized to the Security Management Server, which then distributes this information to the Security Management component on each controlled device.
[0187] In the embodiment of the present application, after the access proxy component obtains the direct access rules and the direct access list, it can detect the network environment of the terminal in real time and process the service access request based on the direct access rules and the direct access list.
[0188] Specifically, the identification information of the controlled service site in the direct access list may include identification information in the form of IP and identification information in the form of domain name, which are respectively introduced below.
[0189] (1) IP format
[0190] When the access proxy component intercepts a business access request to a controlled business site and the network segment where the terminal device is located matches the direct access rule, that is, when it is determined that the network record where the terminal device is located is in the specified network segments and the target business site accessed by the business access request is recorded in the direct access list, a target IP data packet with a source address as the physical network card address and a destination address as the target business site is constructed through a socket in the virtual network card based on the original IP data packet, and then the target IP data packet is sent to the target business site through the physical network card, thereby achieving direct access to the target site through the access proxy component.
[0191] If the network segment where the local terminal is located does not match the direct access rule, that is, it is determined that the network where the terminal device is located is not recorded in the specified network segments, a traffic authentication request is initiated to the security management component. After the traffic authentication of the security management component is passed, a target IP data packet with a source address as the physical network card address and a destination address as the zero-trust gateway connection address is constructed through the socket based on the original IP data packet to achieve proxy access through the zero-trust gateway; if the traffic authentication fails, a target IP data packet with a source address as the Ethernet card address and a destination address as the target business site is constructed through the socket based on the original IP data packet to achieve direct access.
[0192] (2) Domain name format
[0193] Since the access proxy component caches the mapping relationship between domain names and IP addresses, namely the first mapping relationship and the second mapping relationship mentioned above, after the access proxy component receives the direct access list in the form of domain names, it first needs to process the mapping cache between its own domain names and IP addresses accordingly, that is, Figure 9 The conversion of the mapping relationship shown.
[0194] In specific applications, if the network environment where the terminal device is located meets the direct access rules, the access proxy component deletes the first mapping relationship between the domain name and the virtual IP address of the controlled business site in the stored direct access list, and when a domain name resolution request initiated for the controlled business site in the direct access list is intercepted, the access proxy component calls the system DNS for resolution, obtains the corresponding real IP address, returns the real IP address to the business application, and stores the second mapping relationship between the target real IP address and the target domain name.
[0195] Specifically, the access proxy component checks whether there is a mapping relationship between the virtual IP address and the domain name in the mapping table. If so, the corresponding cache entry is removed from the table. If not, no processing is required. Furthermore, when the actual access is made, the system DNS resolves the real IP address and adds it to the domain name-to-real IP address mapping cache.
[0196] If the network segment where the terminal device is located does not comply with the direct access rules, the access proxy component deletes the second mapping relationship between the domain name and the real IP address of the controlled business site in the stored direct access list, and when a domain name resolution request initiated for the controlled business site in the direct access list is intercepted, the access proxy component assigns a virtual IP address to the target domain name, returns the virtual IP address to the business application, and stores the first mapping relationship between the virtual IP address and the target domain name.
[0197] Specifically, the access proxy component checks whether there is a mapping record for the domain name and IP address in the mapping table corresponding to real IP addresses and domain names. If so, the corresponding cache entry is removed from the table. If not, no processing is required. Furthermore, when an actual access is made, the access proxy component resolves the virtual IP address and adds it to the domain name and virtual IP mapping cache.
[0198] See also Figure 10 The figure shows a flowchart of domain name processing based on direct access rules.
[0199] Step S50: The security management component pushes the direct access rules configured by the administrator to the access proxy component.
[0200] Step S51: When a business application accesses a controlled business site domain name, the access proxy component can intercept the DNS request of the business application.
[0201] Step S52: The access proxy component determines whether the network segment of the terminal device and the DNS request comply with direct access rules.
[0202] Step S53: If the direct access rule is not met, the access proxy component allocates a virtual IP address to the target domain name, stores a first mapping relationship between the virtual IP address and the target domain name, and returns the virtual IP address to the service application.
[0203] Step S54: If the direct access rule is met, the access proxy component calls the system DNS to resolve the domain name resolution request, obtains the corresponding real IP address, stores the second mapping relationship between the target real IP address and the target domain name, and returns the real IP address to the business application.
[0204] That is, when the network segment where the terminal device is located meets the direct access rules, when the access subject accesses a domain name in the direct access list, the access proxy component directly resolves the generated real IP address to the system DNS to initiate direct access. When the network segment where the terminal device is located switches to a segment that does not meet the direct access rules, when the access subject accesses a domain name in the direct access list, the access proxy component uses the virtual IP address to reverse-check the virtual IP address and domain name mapping cache to find the real domain name. The access proxy component then initiates traffic authentication with the security management component based on the domain name. Once authentication is successful, the traffic will be sent to the Zero Trust gateway, which will perform the actual proxy access. Thus, dynamic detection and association are performed based on the terminal device's environment and the direct access rules. Through the conversion of the virtual IP address and domain name mapping cache to the real IP address and domain name mapping cache as shown in the figure above, direct access to domain names in specific scenarios and proxy access to domain names in non-specific scenarios are achieved.
[0205] In summary, the embodiment of the present application proposes a solution for business system access in a zero-trust architecture. On the basis of identity authentication and access control for network access initiated by the access subject, the security management component introduces the pre-control logic for business system access. The user's terminal device is controlled by the security management server and the security management component to support two modes: full traffic hijacking and authentication and controlled business site traffic hijacking and authentication. Flexible switching between the two modes is supported. Enterprises can choose the appropriate mode according to their own characteristics. In the controlled business site traffic hijacking mode, it can solve the problem of maintaining long-chain access traffic with public network services or sites. With the cessation of the zero-trust network access function in the terminal device, the access is temporarily interrupted or the service is unavailable. For the function of grayscale or extended zero-trust security architecture business system access for enterprises, it is necessary to be compatible with some applications in a specific network segment to directly access enterprise resources, while still securely accessing enterprise resources through proxy client components and resource-side gateways outside the specific network segment. The embodiment of the present application also proposes a dynamic direct access solution to solve the problem of insufficient coverage of dynamic direct access scenarios in zero-trust security architecture scenarios.
[0206] See Figure 11 Based on the same inventive concept, the embodiment of the present application further provides a service data access device 110, which is applied to a terminal device and includes:
[0207] The receiving unit 1101 is configured to receive service access configuration information sent by the security management server, wherein the service access configuration information includes interception mode indication information and identification information of a controlled service site;
[0208] The determining unit 1102 is configured to determine the controlled IP address information of the controlled service site according to the identification information of the controlled service site when it is determined based on the interception mode indication information that only the service access request of the controlled service site is to be intercepted;
[0209] A rule generating unit 1103 is configured to generate a corresponding IP routing rule based on the obtained controlled IP address information, wherein the IP routing rule is configured to indicate that when a destination address carried in a service access request is recorded in the controlled IP address information, the service access request is forwarded to a designated access proxy component;
[0210] The access control unit 1104 is used to intercept the business access request that complies with the IP routing rules through the access proxy component, and when it is determined that the business access request complies with the zero trust access policy, send the business access request to the target business site through the zero trust gateway.
[0211] Optionally, the access control unit 1104 is specifically configured to:
[0212] Receive a business access request sent by a business application, where the business access request is used to access a target business site;
[0213] Based on the IP routing rules, when it is determined that the destination address carried in the service access request is recorded in the controlled IP address information, the service access request is forwarded to the access proxy component, and the service access request is intercepted by the access proxy component.
[0214] Optionally, the determining unit 1102 is further configured to set the routing level of the virtual network card corresponding to the access proxy component to the highest priority when it is determined based on the interception mode indication information that the service access requests of all service sites are to be intercepted;
[0215] The access control unit 1104 is further configured to forward the service access request to the virtual network card when receiving the service access request sent by the service application, so that the access proxy component intercepts the service access request through the virtual network card.
[0216] Optionally, the rule generating unit 1103 is specifically configured to:
[0217] Aggregating the obtained IP addresses to obtain multiple IP segments, each IP segment including multiple consecutive IP addresses;
[0218] Based on multiple IP segments, an IP routing rule is generated, and the IP routing rule is used to indicate that when the destination address carried by the service access request is located in multiple IP segments, the service access request is forwarded to the virtual network card corresponding to the access proxy component.
[0219] Optionally, the terminal device further includes a security management component, and the identification information of the controlled business site includes domain name information;
[0220] The receiving unit 1101 is specifically configured to receive the service access configuration information sent by the security management server through the security management component, and push the service access configuration information to the access proxy component;
[0221] Determination unit 1102 is specifically used to determine that only business access requests for controlled business sites are to be intercepted through the access proxy component based on the interception mode indication information, call the system DNS to resolve the received domain name information of the controlled business site, and obtain the real IP address that has been successfully resolved; and send the real IP address that has been successfully resolved to the security management component.
[0222] Optionally, the access control unit 1104 is further configured to:
[0223] Intercept domain name resolution requests sent by business applications through the access proxy component;
[0224] When it is determined that the target domain name carried in the domain name resolution request is recorded in the domain name information of the controlled business site, a virtual IP address is allocated to the target domain name through the access proxy component;
[0225] Returning the virtual IP address to the business application through the access proxy component and storing a first mapping relationship between the virtual IP address and the target domain name;
[0226] Upon receiving a service access request initiated by a service application based on the virtual IP address, the access proxy component obtains a target domain name corresponding to the service access request according to the first mapping relationship;
[0227] When it is determined that the target domain name complies with the preset zero-trust access policy, the access proxy component sends the business access request to the controlled business site corresponding to the target domain name through the zero-trust gateway.
[0228] Optionally, the access control unit 1104 is further configured to:
[0229] When the proxy component is accessed and it is determined that the target domain name carried in the domain name resolution request is not recorded in the domain name information of the controlled business site, the system DNS is called to resolve the domain name resolution request and obtain the corresponding real IP address;
[0230] By accessing the proxy component, the real IP address is returned to the business application, and a second mapping relationship between the target real IP address and the target domain name is stored;
[0231] Upon receiving a service access request initiated by a service application based on a real IP address, the access proxy component obtains a target domain name corresponding to the service access request according to the second mapping relationship;
[0232] When it is determined that the target domain name does not comply with the preset zero-trust access policy, the access proxy component sends the business access request to the controlled business site corresponding to the target domain name through the physical network card of the terminal device.
[0233] Optionally, the access control unit 1104 is further configured to:
[0234] The security management component receives direct access rules sent by the security management server. The direct access rules are that when in the specified network segments, the controlled business sites in the specified direct access list are accessed through direct connection.
[0235] Push direct access rules to the access proxy component through the security management component;
[0236] By accessing the proxy component, it monitors whether the network where the terminal device is located is located in each specified network segment;
[0237] If the domain name of the controlled service site is located in each of the specified network segments, the first mapping relationship between the domain name and the virtual IP address of the controlled service site in the stored direct access list is deleted through the access proxy component;
[0238] When intercepting a domain name resolution request initiated for a controlled business site in the direct access list, the access proxy component calls the system DNS for resolution to obtain the corresponding real IP address;
[0239] The real IP address is returned to the business application through the access proxy component, and a second mapping relationship between the target real IP address and the target domain name is stored.
[0240] Optionally, the access control unit 1104 is further configured to:
[0241] If it is not located in the specified network segments, the second mapping relationship between the domain name and the real IP address of the controlled business site in the stored direct access list is deleted through the access proxy component;
[0242] When intercepting a domain name resolution request initiated for a controlled business site in the direct access list, the access proxy component allocates a virtual IP address for the target domain name;
[0243] The virtual IP address is returned to the service application through the access proxy component, and a first mapping relationship between the virtual IP address and the target domain name is stored.
[0244] Optionally, the access control unit 1104 is further configured to:
[0245] Obtain the preset direct access rule, which is to access the controlled business sites in the direct access list through direct connection when in the specified network segments;
[0246] When it is determined that the network record where the terminal device is located is in the specified network segments, and the target service site to be accessed by the service access request is recorded in the direct access list, a target IP data packet is generated. The source address of the target IP data packet is the address of the physical network card of the terminal device, and the destination address is the IP address of the target service site.
[0247] The target IP data packet is sent to the target business site through the physical network card.
[0248] The device can be used to perform Figures 3 to 10 The method executed by the terminal device side in the embodiment shown in FIG. 1 is a method executed by the terminal device side in the embodiment shown in FIG. 1 . Therefore, for the functions that can be realized by each functional module of the device, reference can be made to FIG. Figures 3 to 10 The description of the illustrated embodiment is omitted for brevity.
[0249] See Figure 12Based on the same inventive concept, the embodiment of the present application further provides a service data access device 120, which is applied to a security management server and includes:
[0250] The receiving unit 1201 is configured to receive service access configuration information sent by the management terminal device. The service access configuration information includes interception mode indication information, identification information of a controlled service site, and access logic information. The interception mode indication information is used to indicate whether to intercept service access requests for a controlled service site or all service sites. The access logic information is used to indicate each controlled object.
[0251] The execution unit 1202 is used to send the interception mode indication information and the identification information of the controlled business site to the terminal device corresponding to each controlled object according to the access logic information, so that the corresponding terminal device generates the controlled IP address information according to the interception mode indication information and the identification information of the controlled business site, and performs business access control according to the controlled IP address information.
[0252] The device can be used to perform Figures 3 to 10 The method executed by the security management server side in the embodiment shown is as follows. Therefore, for the functions that can be realized by each functional module of the device, reference can be made to Figures 3 to 10 The description of the illustrated embodiment is omitted for brevity.
[0253] See Figure 13 Based on the same technical concept, an embodiment of the present application further provides a computer device 130 , which may include a memory 1301 and a processor 1302 .
[0254] The memory 1301 is used to store computer programs executed by the processor 1302. The memory 1301 may mainly include a program storage area and a data storage area, wherein the program storage area may store an operating system, an application program required for at least one function, etc.; the data storage area may store data created according to the use of the computer device, etc. The processor 1302 may be a central processing unit (CPU), or a digital processing unit, etc. The specific connection medium between the above-mentioned memory 1301 and the processor 1302 is not limited in the embodiment of the present application. The embodiment of the present application is Figure 13 In the embodiment, the memory 1301 and the processor 1302 are connected via a bus 1303. The bus 1303 is connected to the processor 1302 via a bus 1303. Figure 13 The bus 1303 can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 13 Only one thick line is used in the diagram, but this does not mean that there is only one bus or one type of bus.
[0255] Memory 1301 may be a volatile memory, such as random-access memory (RAM); a non-volatile memory, such as read-only memory, flash memory, a hard disk drive (HDD), or a solid-state drive (SSD); or any other medium capable of carrying or storing desired program code in the form of instructions or data structures and accessible by a computer, but is not limited thereto. Memory 1301 may be a combination of the aforementioned memories.
[0256] The processor 1302 is configured to execute the following when calling the computer program stored in the memory 1301: Figures 3 to 10 The method executed by the device in the embodiment shown.
[0257] In some possible implementations, various aspects of the method provided in the present application may also be implemented in the form of a program product, which includes program code. When the program product is run on a computer device, the program code is used to enable the computer device to perform the steps of the method according to various exemplary embodiments of the present application described above in this specification. For example, the computer device may perform the following steps: Figures 3 to 10 The method executed by the device in the embodiment shown.
[0258] The program product may employ any combination of one or more readable media. The readable medium may be a readable signal medium or a readable storage medium. The readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device, or component, or any combination thereof. More specific examples (a non-exhaustive list) of readable storage media include: an electrical connection having one or more wires, a portable disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof.
[0259] Although the preferred embodiments of the present application have been described, those skilled in the art may make additional changes and modifications to these embodiments once they have learned the basic creative concept. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of the present application.
[0260] Obviously, those skilled in the art may make various changes and modifications to this application without departing from the spirit and scope of this application. Thus, if these modifications and variations of this application fall within the scope of the claims of this application and their equivalents, this application is intended to include these modifications and variations.
Claims
1. A business data access method, characterized in that: Applied to a terminal device, the method includes: Receiving service access configuration information sent by the security management server, the service access configuration information including interception mode indication information and identification information of the controlled service site; When it is determined based on the interception mode indication information that only the service access request of the controlled service site is to be intercepted, the controlled IP address information of the controlled service site is determined based on the identification information of the controlled service site; Based on the obtained controlled IP address information, a corresponding IP routing rule is generated, wherein the IP routing rule is used to indicate that when a destination address carried in a service access request is recorded in the controlled IP address information, the service access request is forwarded to a designated access proxy component; For a service access request that complies with the IP routing rule, the access proxy component intercepts the service access request, and when it is determined that the service access request complies with the zero-trust access policy, the service access request is sent to the target service site through the zero-trust gateway; When it is determined based on the interception mode indication information that the service access requests for all service sites are to be intercepted, the routing level of the virtual network card corresponding to the access proxy component is set to the highest priority; When receiving a service access request sent by a service application, all service access requests are automatically forwarded to the virtual network card, so that the access proxy component intercepts the service access request through the virtual network card.
2. The method according to claim 1, wherein For a service access request that complies with the IP routing rule, intercepting the service access request by the access proxy component includes: receiving a service access request sent by a service application, where the service access request is used to access the target service site; Based on the IP routing rule, when it is determined that the destination address carried in the service access request is recorded in the controlled IP address information, the service access request is forwarded to the access proxy component, and the service access request is intercepted by the access proxy component.
3. The method according to claim 1, wherein Based on the obtained controlled IP address information, corresponding IP routing rules are generated, including: Aggregating the obtained IP addresses to obtain multiple IP segments, each IP segment including multiple consecutive IP addresses; Based on the multiple IP segments, the IP routing rules are generated, and the IP routing rules are used to indicate that when the destination address carried by the service access request is located in the multiple IP segments, the service access request is forwarded to the virtual network card corresponding to the access proxy component.
4. The method according to claim 2, wherein The terminal device further includes a security management component, and the identification information of the controlled service site includes domain name information; The receiving of the service access configuration information sent by the security management server includes: Receiving, through the security management component, the service access configuration information sent by the security management server, and pushing the service access configuration information to the access proxy component; When it is determined based on the interception mode indication information that only the service access request of the controlled service site is to be intercepted, the IP address of the controlled service site is determined based on the identification information of the controlled service site, including: When the access proxy component determines, based on the interception mode indication information, that only the service access request of the controlled service site is to be intercepted, the system DNS is called to resolve the received domain name information of the controlled service site to obtain the real IP address that is successfully resolved; The successfully resolved real IP address is sent to the security management component.
5. The method according to claim 4, wherein After receiving, by the security management component, the service access configuration information sent by the security management server and pushing the service access configuration information to the access proxy component, the method further includes: intercepting the domain name resolution request sent by the business application through the access proxy component; When it is determined that the target domain name carried in the domain name resolution request is recorded in the domain name information of the controlled business site, a virtual IP address is allocated to the target domain name through the access proxy component; Returning the virtual IP address to the business application through the access proxy component, and storing a first mapping relationship between the virtual IP address and the target domain name; Upon receiving a service access request initiated by the service application based on the virtual IP address, the access proxy component obtains a target domain name corresponding to the service access request according to the first mapping relationship; When it is determined that the target domain name complies with the preset zero-trust access policy, the access proxy component sends the business access request to the controlled business site corresponding to the target domain name through the zero-trust gateway.
6. The method according to claim 5, wherein After intercepting the domain name resolution request sent by the business application through the access proxy component, the method further includes: When it is determined by the access proxy component that the target domain name carried in the domain name resolution request is not recorded in the domain name information of the controlled business site, the system DNS is called to resolve the domain name resolution request to obtain the corresponding real IP address; Returning the real IP address to the business application through the access proxy component, and storing a second mapping relationship between the real IP address and the target domain name; Upon receiving a service access request initiated by the service application based on the real IP address, the access proxy component obtains a target domain name corresponding to the service access request according to the second mapping relationship; When it is determined that the target domain name does not comply with the preset zero-trust access policy, the access proxy component sends the service access request to the controlled service site corresponding to the target domain name through the physical network card of the terminal device.
7. The method according to claim 6, wherein The method further comprises: Receiving, through the security management component, a direct access rule sent by the security management server, wherein the direct access rule is to access a controlled business site in a specified direct access list in a direct connection manner when in each specified network segment; Pushing the direct access rule to the access proxy component through the security management component; Monitoring, by means of the access proxy component, whether the network where the terminal device is located is located in each of the specified network segments; If the domain name of the controlled service site is located in each of the specified network segments, the first mapping relationship between the domain name and the virtual IP address of the controlled service site in the stored direct access list is deleted through the access proxy component; When intercepting a domain name resolution request initiated for a controlled service site in the direct access list, the access proxy component calls the system DNS for resolution to obtain the corresponding real IP address; The real IP address is returned to the service application through the access proxy component, and a second mapping relationship between the real IP address and the target domain name is stored.
8. The method according to claim 7, wherein After monitoring, by the access proxy component, whether the network where the terminal device is located is located in each of the specified network segments, the method further includes: If it is not located in the specified network segments, deleting the second mapping relationship between the domain name and the real IP address of the controlled service site in the stored direct access list through the access proxy component; When intercepting the domain name resolution request initiated for a controlled service site in the direct access list, the access proxy component allocates a virtual IP address for the target domain name; The virtual IP address is returned to the service application through the access proxy component, and a first mapping relationship between the virtual IP address and the target domain name is stored.
9. The method according to any one of claims 1 to 8, wherein: After intercepting the service access request through the access proxy component, the method further includes: Obtaining a preset direct access rule, wherein the direct access rule is to access a controlled business site in a direct access list in a direct connection manner when in each specified network segment; When it is determined that the network where the terminal device is located is recorded in each of the specified network segments, and the target service site accessed by the service access request is recorded in the direct access list, a target IP data packet is generated, where the source address of the target IP data packet is the address of the physical network card of the terminal device, and the destination address is the IP address of the target service site; The target IP data packet is sent to the target service site through the physical network card.
10. A method for accessing business data, characterized in that: Applied to a security management server, the method includes: receiving service access configuration information sent by a management terminal device, the service access configuration information including interception mode indication information, identification information of a controlled service site, and access logic information, the interception mode indication information being used to indicate: intercepting service access requests for a controlled service site or all service sites, and the access logic information being used to indicate each controlled object to which the service access configuration information needs to be sent; When it is determined based on the interception mode indication information that only business access requests for controlled business sites are to be intercepted, the interception mode indication information and the identification information of the controlled business sites are sent to the terminal devices corresponding to the respective controlled objects according to the access logic information, so that the corresponding terminal devices generate controlled IP address information according to the interception mode indication information and the identification information of the controlled business sites, and perform business access control according to the controlled IP address information; when the interception mode indication information indicates that business access requests for all business sites are to be intercepted, the terminal device sets the routing level of the virtual network card corresponding to the access proxy component to the highest priority, so that all business access requests are automatically forwarded to the virtual network card, so that the access proxy component intercepts the business access requests through the virtual network card.
11. A business data access device, characterized in that: Applied in a terminal device, the device includes: a receiving unit, configured to receive service access configuration information sent by a security management server, wherein the service access configuration information includes interception mode indication information and identification information of a controlled service site; a determining unit configured to determine, based on the identification information of the controlled service site, the controlled IP address information of the controlled service site when it is determined that only the service access request of the controlled service site is to be intercepted based on the interception mode indication information; a rule generating unit, configured to generate a corresponding IP routing rule based on the obtained controlled IP address information, wherein the IP routing rule is configured to indicate that when a destination address carried in a service access request is recorded in the controlled IP address information, the service access request is forwarded to a designated access proxy component; An access control unit is configured to intercept, through the access proxy component, a business access request that complies with the IP routing rules, the business access request, and when it is determined that the business access request complies with the zero-trust access policy, send the business access request to the target business site through the zero-trust gateway; when it is determined based on the interception mode indication information that the business access requests for all business sites are to be intercepted, the routing level of the virtual network card corresponding to the access proxy component is set to the highest priority; when a business access request sent by a business application is received, all business access requests are automatically forwarded to the virtual network card, so that the access proxy component intercepts the business access request through the virtual network card.
12. A business data access device, characterized in that: Applied to a security management server, the device includes: a receiving unit, configured to receive service access configuration information sent by a management terminal device, the service access configuration information including interception mode indication information, identification information of a controlled service site, and access logic information, the interception mode indication information being used to indicate: intercepting service access requests for a controlled service site or all service sites, and the access logic information being used to indicate each controlled object to which the service access configuration information needs to be sent; An execution unit is used to, when it is determined based on the interception mode indication information that only business access requests for controlled business sites are to be intercepted, send the interception mode indication information and the identification information of the controlled business sites to the terminal devices corresponding to the respective controlled objects according to the access logic information, so that the corresponding terminal devices generate controlled IP address information according to the interception mode indication information and the identification information of the controlled business sites, and perform business access control according to the controlled IP address information; when the interception mode indication information indicates that business access requests for all business sites are to be intercepted, the terminal device sets the routing level of the virtual network card corresponding to the access proxy component to the highest priority, so that all business access requests are automatically forwarded to the virtual network card, so that the access proxy component intercepts the business access requests through the virtual network card.
13. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 9 or 10 are implemented.
14. A computer storage medium having computer program instructions stored thereon, characterized in that: When the computer program instructions are executed by a processor, the steps of the method according to any one of claims 1 to 9 or 10 are implemented.
Citation Information
Patent Citations
Service data access method and device, equipment, and storage medium
CN111935169A