A security protection control method, device and equipment

By enabling security protection functions on the service port of network equipment and establishing an authorization list, only authorized terminal equipment is allowed to access, the problem of illegal access of unauthorized terminal equipment is solved, and data security is achieved.

CN116015885BActive Publication Date: 2025-07-22HANGZHOU HIKVISION DIGITAL TECHNOLOGY CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202211690286.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-27
Publication Date
2025-07-22
Estimated Expiration
2042-12-27

AI Technical Summary

Technical Problem

In a local area network environment, unauthorized terminal devices may illegally access the network, resulting in security risks of data leakage.

Method used

Through the management device, determine the service port of the target network device, and enable the security protection function, obtain the address information of the terminal device, establish an authorization list, and only allow the address information of the authorized terminal device to pass, prohibit the access of the unauthorized device.

Benefits of technology

Effectively avoid unauthorized terminal equipment from illegally accessing the network, ensure data security, and prevent data leakage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116015885B_ABST
    Figure CN116015885B_ABST
Patent Text Reader

Abstract

The present application provides a security protection control method, apparatus, and device. The method includes: determining a service port corresponding to a target network device, where the service port is a port on the target network device that is connected to a terminal device, and enabling a security protection function for the service port; obtaining address information of at least one terminal device connected under the service port; for each terminal device, if the protection policy corresponding to the terminal device is an authorized protection policy, adding the correspondence between the service port and the address information of the terminal device to an authorization list; sending the authorization list to the target network device, so that after the target network device determines that the security protection function has been enabled for the service port, performing security protection on the service port based on the authorization list. Through the technical solution of the present application, it is possible to ensure that authorized terminal devices can access the network normally, prevent unauthorized terminal devices from accessing the network illegally, and ensure data security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security, and particularly to a security protection control method, device, and equipment. Background Art

[0002] Cyber Security refers to the protection of the hardware, software, and data in a network system from being damaged, altered, or leaked due to accidental or malicious reasons, ensuring that the system operates continuously, reliably, and normally, and that network services are not interrupted. With the increasing demand for data security from users, network security has attracted more and more attention from users, and it is necessary to ensure the security of data and avoid data leakage.

[0003] In a local area network environment, there is a situation where unauthorized terminal devices access the network illegally. Unauthorized terminal devices may steal network data through dangerous tools, resulting in data leakage and potential security risks. Summary of the Invention

[0004] In view of this, this application provides a security protection control method, device, and equipment, which can prevent unauthorized terminal devices from accessing the network illegally, thereby ensuring the security of data and avoiding data leakage.

[0005] This application provides a security protection control method applied to a management device. The method includes:

[0006] Determine the service port corresponding to the target network device. The service port is the port on the target network device that is connected to the terminal device, and enable the security protection function for the service port;

[0007] Obtain the address information of at least one terminal device connected under the service port;

[0008] For each terminal device, if the protection policy corresponding to the terminal device is an authorized protection policy, add the corresponding relationship between the service port and the address information of the terminal device to the authorization list;

[0009] Send the authorization list to the target network device, so that after the target network device determines that the service port has enabled the security protection function, it performs security protection on the service port based on the authorization list.

[0010] This application provides a security protection control device applied to a management device. The device includes:

[0011] A determination module, configured to determine the service port corresponding to the target network device. The service port is the port on the target network device that is connected to the terminal device, and enable the security protection function for the service port;

[0012] An obtaining module, configured to obtain address information of at least one terminal device connected under the service port;

[0013] A processing module, for each terminal device, if the protection policy corresponding to the terminal device is an authorization protection policy, adding the correspondence between the service port and the address information of the terminal device to an authorization list; sending the authorization list to a target network device, so that after the target network device determines that the service port has enabled the security protection function, performing security protection on the service port based on the authorization list.

[0014] This application provides a management device, including: a processor and a machine-readable storage medium, where the machine-readable storage medium stores machine-executable instructions that can be executed by the processor; wherein, the processor is configured to execute the machine-executable instructions to implement the above security protection control method.

[0015] This application provides a machine-readable storage medium, where the machine-readable storage medium stores machine-executable instructions that can be executed by a processor; wherein, the processor is configured to execute the machine-executable instructions to implement the above security protection control method.

[0016] This application provides a computer program, where the computer program is stored in a machine-readable storage medium, and when the processor executes the computer program, it causes the processor to implement the above security protection control method.

[0017] As can be seen from the above technical solutions, in the embodiments of this application, the management device can determine the service port corresponding to the target network device, enable the security protection function for the service port, obtain the address information of the terminal device connected under the service port (that is, automatically discover the terminal device through the protocol), add the address information of the authorized terminal device (the protection policy is the authorization protection policy) to the authorization list, and prohibit adding the address information of the unauthorized terminal device (the protection policy is the cancellation of authorization protection policy) to the authorization list. In this way, when performing security protection on the service port through the authorization list, it can ensure that the authorized terminal device can access the network normally, avoid the unauthorized terminal device from accessing the network illegally, thereby ensuring the security of data and avoiding data leakage. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] In order to more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the following will briefly introduce the drawings required to be used in the description of the embodiments of this application or the prior art. Obviously, the drawings in the following description are only some embodiments recorded in this application. For those of ordinary skill in the art, other drawings can also be obtained according to these drawings in the embodiments of this application.

[0019] Figure 1It is a schematic flowchart of a security protection control method in an embodiment of the present application;

[0020] Figure 2 It is a schematic structural diagram of a security protection control system in an embodiment of the present application;

[0021] Figure 3 It is a schematic flowchart of a security protection control method in an embodiment of the present application;

[0022] Figure 4A and Figure 4B It is a schematic diagram of the position of a terminal device in an embodiment of the present application;

[0023] Figure 5 It is a schematic structural diagram of a security protection control device in an embodiment of the present application;

[0024] Figure 6 It is a hardware structure diagram of a management device in an embodiment of the present application. Specific embodiments

[0025] The terms used in the embodiments of the present application are only for the purpose of describing specific embodiments and do not limit the present application. The singular forms "a", "the" and "said" used in the present application and the claims are also intended to include the plural forms unless the context clearly indicates otherwise. It should also be understood that the term "and / or" used herein refers to any or all possible combinations of one or more of the associated listed items.

[0026] It should be understood that although the terms first, second, third, etc. may be used in the embodiments of the present application to describe various information, such information should not be limited to these terms. These terms are only used to distinguish the same type of information from each other. For example, without departing from the scope of the present application, the first information may also be referred to as the second information, and similarly, the second information may also be referred to as the first information. Depending on the context, in addition, the word "if" used may be interpreted as "when" or "while" or "in response to determining".

[0027] In the embodiments of the present application, a security protection control method is proposed. This method can be applied to a management device. Refer to Figure 1 As shown, it is a schematic flowchart of the security protection control method. The method may include:

[0028] Step 101, determine the service port corresponding to the target network device. This service port may be the port on the target network device that is connected to the terminal device, and enable the security protection function for this service port.

[0029] Exemplarily, the MAC address table can be obtained from each network device. The MAC address table can include the correspondence between ports and MAC addresses, and the MAC address table is the forwarding entry of the network device. Based on the MAC address tables corresponding to each network device, the service port corresponding to the target network device can be determined; wherein, the target network device can be any one of all network devices.

[0030] Exemplarily, the backbone port corresponding to the target network device can also be determined. The backbone port can be the port on the target network device that is connected to other network devices (i.e., any network device other than the target network device), and the security protection function is prohibited from being enabled for this backbone port.

[0031] In a possible implementation manner, the MAC address table can be obtained from each network device. The MAC address table can include the correspondence between ports and MAC addresses, and the MAC address table is the forwarding entry of the network device. Based on the MAC address tables corresponding to each network device, the service port and the backbone port corresponding to the target network device are determined; wherein, the target network device is any one of all network devices.

[0032] Step 102: Obtain the address information of at least one terminal device connected under this service port.

[0033] Exemplarily, the address information of multiple terminal devices can be collected based on the target protocol, and the MAC address table can be obtained from the target network device; wherein, the address information of the terminal device includes the IP address and the MAC address; the target protocol includes at least one of the following: SADP multicast protocol, ONVIF multicast protocol, mDNS multicast protocol; the MAC address table includes the correspondence between this service port and the MAC address. On this basis, if the address information of the terminal device includes the MAC address corresponding to this service port, the address information of the terminal device can be determined as the address information of the terminal device connected under this service port.

[0034] Step 103: For each terminal device, if the protection policy corresponding to this terminal device is an authorization protection policy, add the correspondence between this service port and the address information of this terminal device to the authorization list. Or, if the protection policy corresponding to this terminal device is a deauthorization protection policy, prohibit adding the correspondence between this service port and the address information of this terminal device to the authorization list.

[0035] In a possible implementation, for each terminal device, if the terminal device is on the control list, it is prohibited to set the protection policy corresponding to the terminal device to an authorized protection policy or cancel the authorized protection policy. The control list is used to record information about unauthorized terminal devices. If the terminal device is not on the control list, it is allowed to set the protection policy corresponding to the terminal device to an authorized protection policy or cancel the authorized protection policy. For example, if an authorized protection policy indication message for the terminal device is received, the protection policy corresponding to the terminal device is set to the authorized protection policy based on the authorized protection policy indication message; if a message for canceling the authorized protection policy for the terminal device is received, the protection policy corresponding to the terminal device is set to the canceled authorized protection policy based on the message for canceling the authorized protection policy.

[0036] Step 104: Send the authorization list to the target network device, so that after the target network device determines that the service port has enabled the security protection function, it performs security protection on the service port based on the authorization list.

[0037] Exemplarily, after the target network device determines that the service port has enabled the security protection function, performing security protection on the service port based on the authorization list may include, but is not limited to: after receiving a to-be-forwarded packet matching the service port, if it is determined that the service port has enabled the security protection function, determining whether there is a correspondence between the service port and the address information of the to-be-forwarded packet in the authorization list; if so, forwarding the to-be-forwarded packet, and if not, discarding the to-be-forwarded packet. Among them, if the to-be-forwarded packet is a packet received from the service port, the address information corresponding to the to-be-forwarded packet is the source address information of the to-be-forwarded packet; if the to-be-forwarded packet is a packet that needs to be forwarded from the service port, the address information corresponding to the to-be-forwarded packet is the destination address information of the to-be-forwarded packet.

[0038] As can be seen from the above technical solutions, in the embodiments of the present application, the management device can determine the service port corresponding to the target network device, enable the security protection function for the service port, obtain the address information of the terminal device connected under the service port (i.e., automatically discover the terminal device through the protocol), add the address information of the authorized terminal device (protection policy is the authorized protection policy) to the authorization list, and prohibit adding the address information of the unauthorized terminal device (protection policy is the canceled authorized protection policy) to the authorization list. In this way, when performing security protection on the service port through the authorization list, it can ensure that the authorized terminal device can access the network normally, avoid unauthorized terminal devices from accessing the network illegally, thereby ensuring the security of data and avoiding data leakage.

[0039] The above technical solutions of the embodiments of the present application are described below in combination with specific application scenarios.

[0040] See Figure 2 As shown, it is a schematic structural diagram of a security protection control system. The security protection control system may include a management device 201, multiple network devices (taking network devices 211, 212, and 213 as examples, and the number of network devices is much larger than 3), multiple unknown switches (the unknown switches are transit devices between network devices and terminal devices), and multiple terminal devices (taking terminal devices 221, 222, 223, and 224 as examples, and the number of terminal devices is much larger than 4).

[0041] Among them, the management device 201 may also be referred to as a network management platform (including web). The management device 201 is used to manage each network device, and the security protection control function is realized through the management device 201.

[0042] Among them, each network device may be a device managed by the management device 201, and may also be referred to as a network transmission device, which may be a managed switch or a router, etc. The network devices in this article may be managed network devices, that is, network devices with IP addresses). Taking the network device 211 as an example for illustration, the network device 211 may include port A, port B, and port C. The network device 211 is connected to the terminal devices 221, 222, and 223 through port A, the network device 211 is connected to the terminal device 224 through port B, and the network device 211 is connected to the network device 222 through port C.

[0043] Among them, each unknown switch may be a device not managed by the management device 201, and is only used for transit between network devices and terminal devices. There is no limitation on this unknown switch in this embodiment. The unknown switches in this article are network devices without management functions, called non-managed network devices.

[0044] Among them, each terminal device may be a device that needs to access the network, such as a camera, a personal computer, a smart phone, a laptop computer, a printer, an access control device, etc. There is no limitation on the type of this terminal device.

[0045] In the above application scenario, an embodiment of the present application proposes a security protection control method. See Figure 3 As shown, it is a schematic flow diagram of the security protection control method. The method may include:

[0046] Step 301, the management device 201 obtains a MAC address table from each network device. The MAC address table may include the correspondence between ports and MAC addresses, and the MAC address table is a forwarding entry of the network device. That is to say, the network device forwards packets based on the MAC address table.

[0047] For example, the management device 201 sends a MAC address table request message to the network device 211, and the network device 211 returns a MAC address table response message to the management device 201. The MAC address table response message includes the MAC address table of the network device 211. As shown in Table 1, it is an example of the MAC address table of the network device 211. Similarly, the management device 201 can obtain the MAC address tables of the network devices 212 and 213. As shown in Table 2, it is an example of the MAC address table of the network device 212.

[0048] Table 1

[0049] Port MAC Address Port A MAC Address 221 Port A MAC Address 222 Port A MAC Address 223 Port B MAC Address 224 ... ...

[0050] Table 2

[0051]

[0052]

[0053] The MAC address 221 is the MAC address of the terminal device 221, the MAC address 222 is the MAC address of the terminal device 222, the MAC address 223 is the MAC address of the terminal device 223, the MAC address 224 is the MAC address of the terminal device 224, and the MAC address 211 is the MAC address of the network device 211.

[0054] In a possible implementation, when the network device 211 returns a MAC address table response message to the management device 201, in addition to including the MAC address table of the network device 211, the MAC address table response message may also include the device information of the terminal device. For example, the IP address, device model, device manufacturer, device serial number, etc. of the terminal device are not limited to this device information.

[0055] For example, the network device 211 can collect the device information of the subordinate terminal devices (such as the terminal devices 221, 222, 223, and 224). In this way, the network device 211 can also send the device information of these terminal devices to the management device 201 through the MAC address table response message.

[0056] In a possible implementation, the content format of the MAC address table response message may include, but is not limited to: list{port, list{ip, mac, device model, device manufacturer, device serial number}}, where port represents the port in the MAC address table, mac represents the MAC address in the MAC address table, and ip, device model, device manufacturer, and device serial number represent the device information of the terminal device corresponding to the MAC address.

[0057] In a possible implementation, the MAC address table request message and the MAC address table response message can be messages based on SNMP (Simple Network Management Protocol), or can be messages based on a private protocol. There is no restriction on the message type.

[0058] Step 302: The management device 201 obtains device information from each terminal device based on the target protocol. The device information may include, but is not limited to: the address information of the terminal device (such as IP address and MAC address), device model, device manufacturer, device serial number, software version, etc. There is no restriction on the device information.

[0059] Exemplarily, the target protocol may include, but is not limited to, at least one of the following: SADP multicast protocol, ONVIF multicast protocol, mDNS multicast protocol. The SADP multicast protocol can search for all online terminal devices within a local area network. The ONVIF (Open Network Video Interface Forum) multicast protocol is used to enable interoperability between terminal devices of different manufacturers. The mDNS (Multicast Domain Name System) multicast protocol is used to enable mutual discovery and communication between terminal devices within a local area network.

[0060] For example, the management device 201 can send a device information request message based on the SADP multicast protocol, a device information request message based on the ONVIF multicast protocol, and a device information request message based on the mDNS multicast protocol. Based on this, for a terminal device that supports the SADP multicast protocol, after receiving the device information request message, it can send a device information response message based on the SADP multicast protocol to the management device 201. The device information response message may include the device information of this terminal device. For a terminal device that supports the ONVIF multicast protocol, after receiving the device information request message, it can send a device information response message based on the ONVIF multicast protocol to the management device 201. The device information response message may include the device information of this terminal device. For a terminal device that supports the mDNS multicast protocol, after receiving the device information request message, it can send a device information response message based on the mDNS multicast protocol to the management device 201. The device information response message may include the device information of this terminal device.

[0061] Among them, for the device information of the terminal device included in the device information response message, it at least includes the IP address and MAC address of the terminal device. On this basis, optionally, it can also include the device model of the terminal device; optionally, it can also include the device manufacturer of the terminal device; optionally, it can also include the device serial number of the terminal device; optionally, it can also include the software version of the terminal device.

[0062] In summary, based on the SADP multicast protocol, ONVIF multicast protocol, and mDNS multicast protocol, the management device 201 can perform automatic discovery of terminal devices, that is, automatically discover the device information of terminal devices.

[0063] Step 303, the management device 201 determines the service port and backbone port corresponding to the target network device based on the MAC address table corresponding to each network device; where the target network device can be any network device among all network devices. Among them, the service port can be the port on the target network device connected to the terminal device, and the backbone port can be the port on the target network device connected to other network devices.

[0064] For example, if the MAC address table of the first network device includes the correspondence between the first port and the MAC address of the first terminal device, and the MAC address table of the second network device includes the correspondence between the second port and the MAC address of the first terminal device, and the MAC address table of the first network device includes the correspondence between the first port and the MAC address of the second network device, then it can be determined that the first port is the backbone port of the first network device, and it can be determined that the second port is the service port of the second network device.

[0065] For another example, if the MAC address table of the first network device includes the correspondence between the first port and the MAC address of the first terminal device, and the MAC address table of the second network device includes the correspondence between the second port and the MAC address of the first terminal device, and the MAC address table of the second network device includes the correspondence between the second port and the MAC address of the first network device, then it can be determined that the second port is the backbone port of the second network device, and it can be determined that the first port is the service port of the first network device.

[0066] See Figure 4A As shown, based on the MAC address table of network device S1 and the MAC address table of network device S2, if the MAC address tables of network device S1 and network device S2 include the MAC address of terminal device A, and the MAC address table of network device S1 includes the MAC address of network device S2, it is determined that terminal device A is under network device S2. See Figure 4BAs shown, based on the MAC address table of network device S1 and the MAC address table of network device S2, if the MAC address table of network device S1 and the MAC address table of network device S2 include the MAC address of terminal device A, and the MAC address table of network device S2 includes the MAC address of network device S1, it is determined that terminal device A is under network device S1.

[0067] In summary, based on the MAC address tables corresponding to each network device, the management device 201 can determine under which network device the terminal device is located, and determine the service ports and backbone ports corresponding to each network device.

[0068] Referring to the MAC address tables shown in Table 1 and Table 2, since the MAC address 221 is under port A of network device 211, and the MAC address 221 is under port D of network device 212, and the MAC address 211 of network device 211 also exists under port D of network device 212, it can be determined that port D is the backbone port of network device 212, and port A is the service port of network device 211.

[0069] In summary, the management device 201 can determine the service ports and backbone ports corresponding to each network device. Denote any network device among all network devices as the target network device. Then the management device 201 can determine the service ports and backbone ports corresponding to the target network device. Taking the target network device as network device 211 as an example, the backbone port corresponding to network device 211 is port C, and the service ports corresponding to network device 211 are port A and port B. Among them, the backbone port is used to indicate that the other end connected to port C is a network device, and the service port is used to indicate that the other end connected to port A (or port B) is a terminal device.

[0070] Step 304: For each service port, the management device 201 enables the security protection function for this service port. For each backbone port, the management device 201 prohibits enabling the security protection function for this backbone port.

[0071] Exemplarily, for each service port on the target network device, the management device 201 can enable the security protection function for the service port, so as to perform security protection on the service port, prevent unauthorized terminal devices from accessing network data through the service port, prevent unauthorized terminal devices from accessing the network illegally through the service port, ensure the security of data, and avoid data leakage. For each backbone port on the target network device, the management device 201 can not enable the security protection function for the backbone port, that is, prohibit enabling the security protection function for the backbone port, so as to avoid affecting the data exchanged between network devices and avoid affecting the forwarding of normal data. For example, since the backbone port is the port between network devices, the backbone port may transmit packets of each terminal device. If the security protection function is enabled for the backbone port, then the normal data exchanged between network devices cannot be transmitted normally. Therefore, in this embodiment, it is necessary to distinguish between the backbone port and the service port, and only enable the security protection function for the service port, but not for the backbone port, so as to ensure the correct forwarding of normal data.

[0072] Step 305: For each service port, the management device 201 obtains the address information of the terminal device connected under the service port, such as the IP address and MAC address of the terminal device connected under the service port.

[0073] Exemplarily, by obtaining the IP address and MAC address of the terminal device, in this way, the IP address and MAC address of the terminal device can be added to the authorization list. After sending the authorization list to the target network device, when the target network device performs security protection based on the authorization list, it can control the packets based on the IP address and MAC address of the terminal device. For example, for a packet with the destination IP address being this IP address, forward the packet; for a packet with the source IP address being this IP address, forward the packet. In summary, by obtaining the IP address of the terminal device connected under the service port, the packets corresponding to this IP address (packets with the source IP address or destination IP address being this IP address) can be controlled.

[0074] Exemplarily, referring to step 301, the management device 201 can obtain a MAC address table, and the MAC address table can include the correspondence between ports and MAC addresses. Therefore, the management device 201 can obtain the MAC address corresponding to the service port. Referring to step 302, the management device 201 can obtain the device information of each terminal device, and the device information can include the MAC address of the terminal device. Therefore, based on the device information of each terminal device, if the device information includes the MAC address corresponding to the service port, then the terminal device is regarded as the terminal device connected under the service port, that is, the address information of the terminal device is used as the address information of the terminal device connected under the service port, and the device information of the terminal device is used as the device information of the terminal device connected under the service port. Or, if the device information of the terminal device does not include the MAC address corresponding to the service port, then the terminal device is not regarded as the terminal device connected under the service port.

[0075] In summary, for each service port, the management device 201 can obtain the IP address, MAC address, device model, device manufacturer, device serial number, etc. of the terminal device connected under the service port.

[0076] For example, for port A (i.e., the service port) of the network device 211, as shown in Table 1, the MAC address table of the network device 211 is shown, and port A corresponds to MAC address 221, MAC address 222, and MAC address 223. Since the device information of the terminal device 221 includes MAC address 221, the device information of the terminal device 222 includes MAC address 222, and the device information of the terminal device 223 includes MAC address 223, the management device 201 can obtain the device information of the terminal device 221, the device information of the terminal device 222, and the device information of the terminal device 223 connected under port A.

[0077] Step 306: For each terminal device connected under the service port, if the protection policy corresponding to the terminal device is an authorized protection policy, then the management device 201 adds the correspondence between the service port and the address information (such as IP address and MAC address) of the terminal device to the authorization list. Or, if the protection policy corresponding to the terminal device is a de-authorization protection policy, then the management device 201 prohibits adding the correspondence between the service port and the address information of the terminal device to the authorization list.

[0078] Exemplarily, the protection policy corresponding to the terminal device can be an authorization protection policy or a de-authorization protection policy. Among them, the authorization protection policy indicates that the terminal device is an authorized terminal device, and the address information of the authorized terminal device needs to be added to the authorization list, so as to allow the authorized terminal device to access the network, that is, to allow the forwarding of the packet corresponding to the authorized terminal device. The de-authorization protection policy indicates that the terminal device is an unauthorized terminal device, and the address information of the unauthorized terminal device is prohibited from being added to the authorization list, so as to prohibit the unauthorized terminal device from accessing the network, that is, to prohibit the forwarding of the packet corresponding to the authorized terminal device.

[0079] In summary, it can be seen that based on the protection policy corresponding to the terminal device, the terminal device can already be controlled, that is, an authorization protection policy is configured for the authorized terminal device to allow the authorized terminal device to access the network, and a de-authorization protection policy is configured for the unauthorized terminal device to prohibit the unauthorized terminal device from accessing the network.

[0080] Furthermore, in order to more effectively control the terminal device and avoid wrongly configuring the authorization protection policy for the unauthorized terminal device, resulting in the unauthorized terminal device accessing the network. Therefore, in this embodiment, a control list can also be maintained, which is used to record the information of the unauthorized terminal device. For example, if it is known that a certain terminal device is an unauthorized terminal device (such as the user indicates that a certain terminal device is an unauthorized terminal device), the information of the terminal device can be recorded in the control list. In this way, for the terminal device in the control list (that is, the unauthorized terminal device), it is prohibited to configure a protection policy for the terminal device, that is, it is prohibited to configure an authorization protection policy for the terminal device, and it is also prohibited to configure a de-authorization protection policy for the terminal device, so as to avoid wrongly configuring the authorization protection policy for the unauthorized terminal device.

[0081] In a possible implementation manner, for each terminal device connected under the service port, if the terminal device is in the control list, the management device 201 prohibits setting the protection policy corresponding to the terminal device as an authorization protection policy or a de-authorization protection policy, that is, does not set the protection policy corresponding to the terminal device. Or, if the terminal device is not in the control list, the management device 201 allows setting the protection policy corresponding to the terminal device as an authorization protection policy or a de-authorization protection policy, that is, allows setting the protection policy corresponding to the terminal device. For example, if the management device 201 receives an authorization protection policy indication message for the terminal device, it can set the protection policy corresponding to the terminal device as an authorization protection policy based on the authorization protection policy indication message; or, if the management device 201 receives a de-authorization protection policy indication message for the terminal device, it can set the protection policy corresponding to the terminal device as a de-authorization protection policy based on the de-authorization protection policy indication message.

[0082] For example, after obtaining the device information of all the terminal devices connected under a service port, the management device 201 can also display the device information of all the terminal devices connected under the service port through a web page, such as displaying service ports, IP addresses, MAC addresses, device models, device manufacturers, device serial numbers, and other device information of the terminal devices. Among them, the management device 201 can display the device information of all the terminal devices connected under all service ports, or the user can click on a certain service port / some service ports, and the management device 201 filters and displays the device information of all the terminal devices connected under the service port.

[0083] Exemplarily, the management device 201 can maintain a control list, which is used to record information of unauthorized terminal devices. For example, if it is learned that a certain terminal device is an unauthorized terminal device (such as the user indicates that a certain terminal device is an unauthorized terminal device), the management device 201 can record the information of the terminal device in the control list. Also, for example, if it is learned that a certain terminal device in the control list is a legal terminal device (such as the user indicates that the terminal device in the control list is a legal terminal device, that is, cancels the unauthorized identity of the terminal device), the management device 201 can delete the information of the terminal device from the control list, that is, cancel the control list identity.

[0084] For example, after the management device 201 displays the device information of the terminal devices connected under a service port, if the user learns that the terminal device is an unauthorized terminal device and the terminal device is not in the control list, the user can send a message to add the terminal device to the control list to the management device 201. After receiving the message to add the terminal device to the control list, the management device 201 can record the information of the terminal device in the control list.

[0085] Also, for example, after the management device 201 displays the device information of the terminal devices connected under a service port, if the user learns that the terminal device is a legal terminal device and the terminal device is in the control list, the user can send a message to cancel the terminal device from the control list to the management device 201. After receiving the message to cancel the terminal device from the control list, the management device 201 can delete the information of the terminal device from the control list.

[0086] Exemplarily, for each terminal device connected under a service port, if the terminal device is in the control list, the management device 201 does not set the protection policy corresponding to the terminal device, that is, does not set the protection policy corresponding to the terminal device as an authorized protection policy or cancel the authorized protection policy, and does not add the corresponding relationship between the service port and the address information of the terminal device to the authorization list.

[0087] Exemplarily, for each terminal device connected under a service port, if the terminal device is not on the control list, the management device 201 allows the setting of the protection policy corresponding to the terminal device, that is, allows the protection policy corresponding to the terminal device to be set to an authorized protection policy or an unauthorized protection policy. For example, if it is known that access authorization is given to a certain terminal device (such as a user instructs to give access authorization to a certain terminal device), the management device 201 sets the protection policy corresponding to the terminal device to an authorized protection policy, that is, allows the terminal device to access the network. Another example, if it is known that access authorization is not given to a certain terminal device (such as a user instructs not to give access authorization to a certain terminal device), the management device 201 sets the protection policy corresponding to the terminal device to an unauthorized protection policy, that is, does not allow the terminal device to access the network.

[0088] For example, after the management device 201 displays the device information of the terminal device connected under the service port, if the user knows that access authorization needs to be given to the terminal device, the user can send an authorized protection policy indication message for the terminal device to the management device 201. After receiving the authorized protection policy indication message, the management device 201 can set the protection policy corresponding to the terminal device to an authorized protection policy.

[0089] Another example, after the management device 201 displays the device information of the terminal device connected under the service port, if the user knows that access authorization is not given to the terminal device, the user can send an unauthorized protection policy indication message for the terminal device to the management device 201. After receiving the unauthorized protection policy indication message, the management device 201 can set the protection policy corresponding to the terminal device to an unauthorized protection policy.

[0090] In a possible implementation manner, for each terminal device connected under a service port, if the protection policy corresponding to the terminal device is an authorized protection policy, the corresponding relationship between the service port and the address information of the terminal device is added to the authorization list to indicate that a packet carrying the address information is allowed to be forwarded through the service port. If the protection policy corresponding to the terminal device is an unauthorized protection policy, the corresponding relationship between the service port and the address information of the terminal device is not added to the authorization list to indicate that a packet carrying the address information is not allowed to be forwarded through the service port.

[0091] In a possible implementation, when the management device 201 displays the device information of the terminal devices connected under the service port, it can display device information such as the service port, the IP address, MAC address, device model, device manufacturer, and device serial number of the terminal device. It can also display the first online time (used to indicate the first online time of the terminal device), network status (such as whether the terminal device is online or offline), operation type (add to the control list, cancel the control list, authorize the protection policy, cancel the authorization of the protection policy), etc. It can also display the port status of the service port (such as whether the service port is connected or disconnected), and the port protection status (such as whether the service port is protected or unprotected). As shown in Table 3, it is an example of the display content.

[0092] Table 3

[0093]

[0094] In a possible implementation, after the protection function is enabled for the service port, for a newly added terminal device connected to the service port, if the protection policy corresponding to the terminal device is an authorized protection policy, the authorization list corresponding to the service port can also be adjusted, that is, the corresponding relationship between the service port and the address information (such as IP address and MAC address) of the terminal device is added to the authorization list.

[0095] Step 307: The management device 201 sends the authorization list corresponding to the service port to the target network device (i.e., the network device where the service port is located), so that after the target network device determines that the service port has enabled the security protection function, it performs security protection on the service port based on the authorization list.

[0096] For example, for port A (i.e., the service port) of the network device 211, the authorization list can be seen in Table 4, and the management device 201 can send this authorization list to the network device 211.

[0097] Table 4

[0098] Port IP Address MAC Address Port A IP Address 221 MAC Address 221 Port A IP Address 222 MAC Address 222 Port A IP Address 223 MAC Address 223

[0099] In a possible implementation, after receiving the authorization list, the target network device can store the authorization list and perform security protection on the service port based on the authorization list. For example, after the target network device receives a packet to be forwarded that matches the service port, if it determines that the security protection function has been enabled for the service port, it checks whether there is a corresponding relationship between the service port and the address information of the packet to be forwarded in the authorization list; if so, it forwards the packet to be forwarded, and if not, it discards the packet to be forwarded. Among them, if the packet to be forwarded is a packet received from the service port, the address information corresponding to the packet to be forwarded is the source address information of the packet to be forwarded (such as source IP address and / or source MAC address); if the packet to be forwarded is a packet that needs to be forwarded from the service port, the address information corresponding to the packet to be forwarded is the destination address information of the packet to be forwarded (such as destination IP address and / or destination MAC address).

[0100] For example, after network device 211 receives packet 1 to be forwarded through port A, if it determines that the security protection function has been enabled for port A (the management device 201 can send the information that the security protection function has been enabled for port A to network device 211, or it knows that the security protection function has been enabled for port A when the authorization list includes port A), it checks whether there is a corresponding relationship between port A and the source address information of packet 1 in the authorization list; if so, it forwards packet 1 to be forwarded, and if not, it discards packet 1 to be forwarded.

[0101] For another example, after network device 211 receives packet 2 to be forwarded that needs to be forwarded through port A, if it determines that the security protection function has been enabled for port A, it checks whether there is a corresponding relationship between port A and the destination address information of packet 2 in the authorization list; if so, it forwards packet 2 to be forwarded (i.e., forwards packet 2 to be forwarded through port A), and if not, it discards packet 2 to be forwarded.

[0102] In a possible implementation, after the target network device receives a packet to be forwarded that matches the backbone port (received through the backbone port or needs to be forwarded through the backbone port), if it determines that the security protection function has not been enabled for the backbone port, it directly forwards the packet to be forwarded, that is, there is no need to query the authorization list.

[0103] As can be seen from the above technical solutions, in the embodiments of the present application, the management device can determine the service port corresponding to the target network device, enable the security protection function for the service port, obtain the address information of the terminal device connected under the service port (i.e., automatically discover the terminal device through the protocol), add the address information of the authorized terminal device (the protection policy is the authorized protection policy) to the authorization list, and prohibit adding the address information of the unauthorized terminal device (the protection policy is the de-authorized protection policy) to the authorization list. In this way, when the service port is protected by the authorization list, it can ensure that the authorized terminal device can access the network normally and prevent the unauthorized terminal device from accessing the network illegally, thereby ensuring the security of data and avoiding data leakage. The terminal device information list under the network device can be intelligently displayed according to the network topology structure, and the port status (connected, disconnected) and port protection status (protected, unprotected, and the backbone port cannot be protected) of the service port can be visually displayed. After the port protection configuration is enabled, the device information of the terminal device connected under the port can also be intuitively displayed in a list for the user to perform authorization configuration on the terminal device.

[0104] Based on the same inventive concept as the above method, an embodiment of the present application provides a security protection control device, which is applied to a management device. Refer to Figure 5 As shown in the following figure, which is a schematic structural diagram of the device. The device includes:

[0105] A determination module 51, configured to determine a service port corresponding to the target network device, where the service port is a port on the target network device connected to the terminal device, and enable the security protection function for the service port; an acquisition module 52, configured to acquire the address information of at least one terminal device connected under the service port; a processing module 53, configured to, for each terminal device, if the protection policy corresponding to the terminal device is an authorized protection policy, add the correspondence between the service port and the address information of the terminal device to the authorization list; and send the authorization list to the target network device, so that after the target network device determines that the service port has enabled the security protection function, perform security protection on the service port based on the authorization list.

[0106] In a possible implementation manner, the determination module 51 is further configured to determine a backbone port corresponding to the target network device, where the backbone port is a port on the target network device connected to other network devices, and prohibit enabling the security protection function for the backbone port.

[0107] Exemplarily, when determining the service port corresponding to the target network device and the backbone port corresponding to the target network device, the determining module 51 is specifically configured to: obtain the MAC address table from each network device, where the MAC address table includes the correspondence between the port and the MAC address, and the MAC address table is the forwarding entry of the network device; determine the service port corresponding to the target network device and the backbone port based on the MAC address tables corresponding to each network device; where the target network device is any one of all network devices.

[0108] Exemplarily, when the obtaining module 52 obtains the address information of at least one terminal device connected under the service port, it is specifically configured to: collect the address information of multiple terminal devices based on the target protocol, and obtain the MAC address table from the target network device; where the address information of the terminal device includes the IP address and the MAC address; the target protocol includes at least one of the following: SADP multicast protocol, ONVIF multicast protocol, mDNS multicast protocol; the MAC address table includes the correspondence between the service port and the MAC address; if the address information of the terminal device includes the MAC address corresponding to the service port, then determine the address information of the terminal device as the address information of the terminal device connected under the service port.

[0109] In a possible implementation manner, the processing module 53 is further configured to, for each terminal device, if the protection policy corresponding to the terminal device is the unauthorized protection policy, then prohibit adding the correspondence between the service port and the address information of the terminal device to the authorization list.

[0110] Exemplarily, the processing module 53 is further configured to, if the terminal device is in the control list, then prohibit setting the protection policy corresponding to the terminal device to the authorized protection policy or the unauthorized protection policy, where the control list is used to record the information of unauthorized terminal devices; if the terminal device is not in the control list, then allow setting the protection policy corresponding to the terminal device to the authorized protection policy or the unauthorized protection policy; where, if an authorized protection policy indication message for the terminal device is received, then set the protection policy corresponding to the terminal device to the authorized protection policy; if an unauthorized protection policy indication message for the terminal device is received, then set the protection policy corresponding to the terminal device to the unauthorized protection policy.

[0111] Based on the same application concept as the above method, in an embodiment of the present application, a management device is proposed. Refer to Figure 6 As shown, the management device includes: a processor 61 and a machine-readable storage medium 62, where the machine-readable storage medium 62 stores machine-executable instructions that can be executed by the processor 61; the processor 61 is configured to execute the machine-executable instructions to implement the security protection control method disclosed in the above examples of the present application.

[0112] Based on the same application concept as the above method, an embodiment of the present application further provides a machine-readable storage medium, on which a number of computer instructions are stored. When the computer instructions are executed by a processor, the security protection control method disclosed in the above examples of the present application can be implemented.

[0113] Among them, the above machine-readable storage medium can be any electronic, magnetic, optical or other physical storage device that can contain or store information, such as executable instructions, data, and so on. For example, the machine-readable storage medium can be: RAM (Random Access Memory), volatile memory, non-volatile memory, flash memory, storage drives (such as hard disk drives), solid state drives, any type of storage disk (such as optical discs, DVDs, etc.), or similar storage media, or a combination thereof.

[0114] The systems, devices, modules or units illustrated in the above embodiments can be specifically implemented by a computer entity or by a product with certain functions. A typical implementation device is a computer, and the specific form of the computer can be a personal computer, a laptop computer, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an email transceiver device, a game console, a tablet computer, a wearable device, or a combination of any several of these devices.

[0115] For the convenience of description, when describing the above devices, they are described separately as various units according to functions. Of course, when implementing the present application, the functions of each unit can be implemented in the same or multiple software and / or hardware.

[0116] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the embodiments of the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0117] This application is described with reference to the flowcharts and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the present application. It should be understood that each flow and / or block in the flowchart and / or block diagram, and the combination of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing device to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing device produce means for implementing the functions specified in one or more flows and / or blocks in the flowchart. Figure 1 one or more flows and / or blocks Figure 1 or means for implementing the functions specified in one or more blocks.

[0118] Moreover, these computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory produce a manufactured article including instruction means that implement the functions specified in one or more flows and / or blocks in the flowchart. Figure 1 one or more flows and / or blocks Figure 1 or means for implementing the functions specified in one or more blocks.

[0119] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one or more flows and / or blocks in the flowchart. Figure 1 one or more flows and / or blocks Figure 1 or means for implementing the functions specified in one or more blocks.

[0120] The above are only embodiments of the present application and are not intended to limit the present application. For those skilled in the art, various changes and modifications can be made to the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included within the scope of the claims of the present application.

Claims

1. A security protection control method, characterized in that Applied to a management device, the method includes: Determine a service port corresponding to a target network device, where the service port is a port on the target network device that is connected to a terminal device, and enable a security protection function for the service port; Obtain address information of at least one terminal device connected under the service port; For each terminal device, if the protection policy corresponding to the terminal device is an authorization protection policy, add the correspondence between the service port and the address information of the terminal device to an authorization list; Send the authorization list to the target network device, so that after the target network device determines that the service port has enabled the security protection function, perform security protection on the service port based on the authorization list; Determine a backbone port corresponding to the target network device, where the backbone port is a port on the target network device that is connected to other network devices, and prohibit enabling the security protection function for the backbone port.

2. The method according to claim 1, wherein The determining the service port corresponding to the target network device and the backbone port corresponding to the target network device includes: Obtain a MAC address table from each network device, where the MAC address table includes the correspondence between ports and MAC addresses, and the MAC address table is a forwarding entry of the network device; Determine the service port and the backbone port corresponding to the target network device based on the MAC address tables corresponding to each network device; where the target network device is any one of all network devices.

3. The method according to claim 1, wherein The obtaining address information of at least one terminal device connected under the service port includes: Collect address information of multiple terminal devices based on a target protocol, and obtain a MAC address table from the target network device; where the address information of the terminal device includes an IP address and a MAC address; the target protocol includes at least one of the following: SADP multicast protocol, ONVIF multicast protocol, mDNS multicast protocol; the MAC address table includes the correspondence between the service port and the MAC address; If the address information of the terminal device includes the MAC address corresponding to the service port, determine the address information of the terminal device as the address information of the terminal device connected under the service port.

4. The method according to claim 1, characterized in that After the obtaining address information of at least one terminal device connected under the service port, the method further includes: If the protection policy corresponding to the terminal device is a deauthorization protection policy, prohibit adding the correspondence between the service port and the address information of the terminal device to the authorization list.

5. The method according to claim 4, wherein The method further includes: If the terminal device is on the control list, it is prohibited to set the protection policy corresponding to the terminal device to an authorized protection policy or cancel the authorized protection policy. The control list is used to record information about unauthorized terminal devices. If the terminal device is not on the control list, it is allowed to set the protection policy corresponding to the terminal device to an authorized protection policy or cancel the authorized protection policy. Among them, if an authorized protection policy indication message for the terminal device is received, the protection policy corresponding to the terminal device is set to the authorized protection policy; or, if a message for canceling the authorized protection policy indication for the terminal device is received, the protection policy corresponding to the terminal device is set to cancel the authorized protection policy.

6. The method according to claim 1, wherein After determining that the security protection function has been enabled for the service port, the target network device performs security protection on the service port based on the authorization list, including: after receiving a to-be-forwarded packet matching the service port, if it is determined that the security protection function has been enabled for the service port, it is determined whether there is a correspondence between the service port and the address information of the to-be-forwarded packet in the authorization list; if so, the to-be-forwarded packet is forwarded, and if not, the to-be-forwarded packet is discarded; Among them, if the to-be-forwarded packet is a packet received from the service port, the address information corresponding to the to-be-forwarded packet is the source address information of the to-be-forwarded packet; If the to-be-forwarded packet is a packet to be forwarded from the service port, the address information corresponding to the to-be-forwarded packet is the destination address information of the to-be-forwarded packet.

7. A safety protection control device, characterized in that, Applied to a management device, the device includes: A determination module, configured to determine a service port corresponding to a target network device, where the service port is a port on the target network device that is connected to a terminal device, and enable a security protection function for the service port; An acquisition module, configured to acquire address information of at least one terminal device connected under the service port; A processing module, for each terminal device, if the protection policy corresponding to the terminal device is an authorized protection policy, add the correspondence between the service port and the address information of the terminal device to the authorization list; send the authorization list to the target network device, so that the target network device performs security protection on the service port based on the authorization list after determining that the security protection function has been enabled for the service port; Among them, the determination module is further configured to determine a backbone port corresponding to the target network device, where the backbone port is a port on the target network device that is connected to other network devices, and prohibit enabling the security protection function for the backbone port.

8. The device according to claim 7, wherein Among them, When determining the service port corresponding to the target network device and the backbone port corresponding to the target network device, the determining module is specifically configured to: obtain the MAC address table from each network device, where the MAC address table includes the correspondence between ports and MAC addresses, and the MAC address table is the forwarding entry of the network device; determine the service port and the backbone port corresponding to the target network device based on the MAC address tables corresponding to each network device; where the target network device is any one of all network devices. Among them, when the obtaining module obtains the address information of at least one terminal device connected under the service port, it is specifically configured to: collect the address information of multiple terminal devices based on the target protocol, and obtain the MAC address table from the target network device; where the address information of the terminal device includes the IP address and the MAC address; the target protocol includes at least one of the following: SADP multicast protocol, ONVIF multicast protocol, mDNS multicast protocol; the MAC address table includes the correspondence between the service port and the MAC address; if the address information of the terminal device includes the MAC address corresponding to the service port, then determine the address information of the terminal device as the address information of the terminal device connected under the service port. Among them, the processing module is further configured to, for each terminal device, if the protection policy corresponding to the terminal device is the unauthorized protection policy, then prohibit adding the correspondence between the service port and the address information of the terminal device to the authorization list. Among them, the processing module is further configured to, if the terminal device is on the control list, then prohibit setting the protection policy corresponding to the terminal device to the authorized protection policy or the unauthorized protection policy, and the control list is used to record the information of unauthorized terminal devices; if the terminal device is not on the control list, then allow setting the protection policy corresponding to the terminal device to the authorized protection policy or the unauthorized protection policy; where, if an authorized protection policy indication message for the terminal device is received, then set the protection policy corresponding to the terminal device to the authorized protection policy; if an unauthorized protection policy indication message for the terminal device is received, then set the protection policy corresponding to the terminal device to the unauthorized protection policy.

9. A management device, characterized in that, Including: A processor and a machine-readable storage medium, where the machine-readable storage medium stores machine-executable instructions that can be executed by the processor; where the processor is configured to execute the machine-executable instructions to implement the method according to any one of claims 1-6.

Citation Information

Patent Citations

  • Method and device for preventing ARP (Address Resolution Protocol) attack

    CN107438068A