Service access traffic control method, device, equipment and medium
Through the access proxy components and security management server of the zero-trust security management system, the problem of inability to flexibly set traffic management boundaries in traditional network area management solutions is solved, and fine-grained access control and security management are achieved.
Patent Information
- Application Number
- CN202111244639.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-10-25
- Publication Date
- 2025-08-08
- Estimated Expiration
- 2041-10-25
AI Technical Summary
Traditional network area management solutions cannot flexibly set traffic management boundaries, making it difficult for enterprises to implement fine-grained access control and cannot effectively audit and monitor the business resources of terminal devices using external networks to access enterprise.
The access proxy component based on the zero-trust security management system is adopted to intercept service access requests through terminal devices, and access permission management is carried out based on the 4T principles of trusted identity, trusted equipment, trusted applications and trusted links. The security management server is used to verify the legality and obtain the service response results.
It realizes security management of service access in any network environment, ensures the legality and security of access, flexibly sets traffic management boundaries, and realizes fine-grained access control.
Smart Images

Figure CN116032500B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure generally relates to the field of computers, and more particularly to methods, devices, equipment, and media for controlling service access traffic. Background Art
[0002] Traditional solutions for managing application traffic based on fixed network zones typically strictly distinguish between the external network and the internal network. Management methods typically use peripheral network devices, such as switches, to collect and capture traffic for auditing and monitoring. For example, when a terminal device uses the internal network, all traffic passing through the switch is typically audited and monitored. However, when the terminal device uses the external network, there is no controlled switch and no auditing and monitoring. This makes it impossible to audit and monitor access to enterprise business resources, which requires auditing and monitoring, such as when the terminal device uses the external network. Therefore, due to the over-reliance on network location boundaries, enterprise managers cannot flexibly set traffic management boundaries. The granularity of traffic control is not fine enough, making it difficult to implement more fine-grained access control. Summary of the Invention
[0003] In view of the above-mentioned defects or deficiencies in the prior art, it is desired to provide a business access traffic control method, apparatus, device and medium so that enterprise managers can flexibly set traffic management boundaries.
[0004] In a first aspect, an embodiment of the present application provides a method for controlling service access traffic, the method comprising:
[0005] Intercepting business access requests associated with business applications;
[0006] Based on the network control boundary defined in the access traffic control policy, identifying a service access request belonging to the target network area as a target service access request; the access traffic control policy defines the target network area based on the network control boundary;
[0007] Sending an authentication request corresponding to the target service access request to a security management server, so that the security management server performs a legitimacy check on the target service access request and obtains a legitimacy check result;
[0008] When the legality verification result indicates that the target service access request is legal, a service response result corresponding to the target service access request is obtained from a service server.
[0009] In a second aspect, an embodiment of the present application provides a service access traffic control device, the device comprising:
[0010] An acquisition module, used to intercept business access requests associated with business applications;
[0011] a determination module configured to identify a service access request belonging to a target network area as a target service access request based on a network control boundary defined in an access traffic control policy; the access traffic control policy defines the target network area based on the network control boundary;
[0012] a sending module, configured to send an authentication request corresponding to the target service access request to a security management server, so that the security management server performs a legitimacy check on the target service access request and obtains a legitimacy check result;
[0013] The receiving module is configured to obtain a service response result corresponding to the target service access request from a service server when the legality verification result indicates that the target service access request is legal.
[0014] In a third aspect, an embodiment of the present application provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the method described in the embodiment of the present application when executing the program.
[0015] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium on which a computer program is stored, which, when executed by a processor, implements the method described in the embodiment of the present application.
[0016] In a fifth aspect, an embodiment of the present application provides a computer program product, including a computer program, characterized in that when the computer program is executed by a processor, it implements the method described in the embodiment of the present application.
[0017] This application proposes a business traffic data control method, which flexibly sets the traffic management boundary according to the access proxy control mode set by the administrator, and then intercepts and forwards network traffic through the access proxy component provided by the zero-trust security management client installed on the terminal, effectively performing process-level traffic management from the source of application traffic.
[0018] Additional aspects and advantages of the present invention will be set forth in part in the description which follows and, in part, will be obvious from the description which follows, or may be learned through practice of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] Other features, objects and advantages of the present application will become more apparent upon reading the detailed description of non-limiting embodiments made with reference to the following drawings:
[0020] Figure 1 This is a schematic diagram of a network architecture provided by an embodiment of the present application;
[0021] Figure 2 This is a schematic diagram of an access rights configuration strategy provided by an embodiment of the present application;
[0022] Figure 3 This is a schematic diagram of configuring an access traffic control policy provided by an embodiment of the present application;
[0023] Figure 4 This is a configuration diagram of a trusted application provided in an embodiment of the present application;
[0024] Figure 5 This is a schematic diagram of a login interface of a target client provided in an embodiment of the present application;
[0025] Figure 6 This is a schematic diagram of detailed information of a trusted application provided in an embodiment of the present application;
[0026] Figure 7 This is a schematic diagram of an application for limiting access to devices with access rights provided by an embodiment of the present application;
[0027] Figure 8 This is a schematic diagram of the zero-trust access management principle provided by an embodiment of the present application;
[0028] Figure 9 This is a schematic diagram of the zero-trust access management principle provided by an embodiment of the present application;
[0029] Figure 10 This is a flow chart of a method for managing and controlling business traffic data provided by an embodiment of the present application;
[0030] Figure 11 This is a flowchart of another method for managing and controlling business traffic data provided by an embodiment of the present application;
[0031] Figure 12 This is a schematic diagram of the business traffic data control principle provided by an embodiment of the present application;
[0032] Figure 13 This is another schematic diagram of the business traffic data control principle provided by an embodiment of the present application;
[0033] Figure 14 This is a block diagram of a service flow data control device provided in an embodiment of the present application;
[0034] Figure 15 A schematic diagram of the structure of a computer system of an electronic device or a security management server suitable for implementing an embodiment of the present application is shown. DETAILED DESCRIPTION
[0035] The present application will be further described in detail below with reference to the accompanying drawings and examples. It should be understood that the specific embodiments described herein are merely for the purpose of explaining the relevant invention and are not intended to limit the invention. It should also be noted that, for ease of description, only portions relevant to the invention are shown in the accompanying drawings.
[0036] It should be noted that, in the absence of conflict, the embodiments and features of the embodiments in this application can be combined with each other. The present application will be described in detail below with reference to the accompanying drawings and in combination with the embodiments.
[0037] See Figure 1 , Figure 1 This is a schematic diagram of the network structure for implementing a service access traffic control method proposed in an embodiment of the present application.
[0038] like Figure 1 As shown, the network architecture may include a security management server 1 and a user terminal cluster 2. The user terminal cluster may include one or more user terminals, and the number of user terminals is not limited here. The user terminal cluster may specifically include user terminal 2a, user terminal 2b, ..., user terminal 2n.
[0039] like Figure 1 As shown, the user terminal 2a, the user terminal 2b, ..., the user terminal 2n can respectively establish a network connection with the security management server 1, so that each user terminal can exchange data with the security management server 1 through the network.
[0040] Among them, each user terminal in the user terminal cluster may include but is not limited to smart phones, tablet computers, laptops, desktop computers, wearable devices, smart homes, head-mounted devices, vehicle-mounted devices and other smart terminals with business data access functions.
[0041] It should be understood that if Figure 1 Each user terminal in the user terminal cluster 2 shown can be installed with a business application and a target client (i.e., a zero-trust security management system client, for example, an iOA client). When the zero-trust security management system client runs in each user terminal, it can be respectively connected to the above-mentioned Figure 1 The security management server 1 shown here performs data interaction. Among them, the zero trust security management system client here may include a proxy client component for intercepting traffic.
[0042] The business applications (i.e., business application clients) involved in the embodiments of the present application may be social clients, office clients, search clients (such as browser clients), live broadcast clients, news clients, shopping clients (such as e-commerce clients), and other application clients.
[0043] The security management server 1 is the security management server corresponding to the zero-trust security management client, that is, the iOA background security management server. The security management server 1 can be an independent physical security management server, or a security management server cluster or distributed system composed of multiple physical security management servers. It can also be a cloud security management server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms.
[0044] The business traffic data control method provided in the embodiment of the present application can be implemented based on the zero-trust security management system client. The zero-trust security management method executed by the zero-trust security management system client breaks the traditional region-based credit control method, and adopts the "4T principle" based on trusted identity, trusted device, trusted application and trusted link to grant access rights, and forces all access to be authenticated, authorized and encrypted, truly practicing the "zero trust" design concept, thereby effectively ensuring that no matter where the access user is located, when and what device he uses, he can have secure access.
[0045] In one or more embodiments, the business traffic management administrator can pre-configure the zero trust policy through the zero trust security management system client, and send the configured zero trust policy to the target client logged in by each account. The zero trust policy is used to determine whether the access requests of each application in the user terminal device where the target client is installed need to be traffic regulated.
[0046] like Figure 2 As shown, the above zero trust strategy is configured by three aspects: users (or user groups) in the organizational structure, trusted applications (i.e. the target clients mentioned above), and business systems.
[0047] Trusted applications are applications authorized by the target client, allowing the corresponding terminal device to access internal business systems. This may include the application name, MD5 (a message digest algorithm), and signature information. Business systems are configured based on business traffic data management requirements, including but not limited to internal enterprise business systems. For example, when traffic control is limited to enterprise business system resources, only the enterprise business system can be configured. When traffic control is applied to all user terminal traffic, the entire business system can be configured.
[0048] The organizational structure is a user tree composed of users, used to express the relationship between users and user groups. The granularity of the zero-trust policy is individual users. If a zero-trust policy is issued for a user group, all users in that user group share the same zero-trust policy.
[0049] Specifically, the administrator of the business traffic management can pre-configure the trusted applications and business systems corresponding to the users. For example, the administrator of the business traffic management can Figure 2 Configure user A under the test group directory in the user tree system on the left. When any application in the XX operating system in the upper right corner and business system XX in the lower right corner are checked, it means that user A can access the selected business system XX when using any application in the XX operating system.
[0050] The above-mentioned business system includes at least one business server. The business system is generally composed of the enterprise's internal OA site, development and testing environment, operation and maintenance, and formal production environment. It is the object that the access subject (person / device / application) needs to access. Among them, the access subject accesses the access object. The access subject is the party that initiates the data access request in the data access request, the person / device / application that accesses the business resources, and the access object is the party accessed in the data access request. For example, it can be the business resources, data, development and testing environment, operation and maintenance environment, etc. in the business server.
[0051] like Figure 3 As shown, you can access the business system by editing the settings. Figure 3 Specifically, when making accessible business system settings, the website address information of the business system, such as *.com, can be edited in the business system, and the method for determining the accessible business system, such as the IP address, can be edited in the category. When selecting the IP address, the designated IP of the accessible business system or the IP segment corresponding to the accessible system can be further edited. The designated IP of the accessible business system can be multiple, and the designated IP address of the accessible business system can be increased by adding IPs. It should be understood that when editing the accessible business system, the domain name of the business system can also be used, that is, when editing the category, the domain name category is selected, and the designated domain name data needs to be supplemented and edited. In one embodiment, the configuration for the trusted application can be as follows: Figure 4 As shown in the figure, it specifically includes the configuration of process name, signature information, version, process MD5 and sha256 (a cryptographic hash algorithm). In other words, the administrator can set the process name in advance. Figure 3 and Figure 4 Configure trusted applications and accessible business systems in the interface shown. Then, when configuring the zero trust policy for user A, the configured trusted applications are displayed in a list on the Figure 2In the upper right corner, the administrator can select one or more trusted applications that have been configured through the list. Similarly, the business systems that the administrator has configured are displayed in the list. Figure 2 In the lower right part, administrators can select one or more configured business systems from the list to complete the zero-trust policy configuration for user A.
[0052] After the administrator has configured the business system and trusted applications, they only need to select the access rights to which the zero-trust policy needs to be issued (including access rights information that records the access rights of trusted applications) to complete the issuance of the zero-trust policy. Specifically, the administrator configures the zero-trust policy corresponding to each user or user group in the organizational structure on their terminal device and uploads it to the security management server. The security management server then sends it to the zero-trust security management system client corresponding to each user account, so that the zero-trust security management system client can monitor and manage terminal traffic.
[0053] Correspondingly, the terminal user can realize the zero-trust office function by logging into the target client. Figure 5 As shown, users can log in to the target client by scanning the code or other methods.
[0054] After logging in, Figure 6 As shown, the logged-in user can see the detailed information of the secure office protection issued by the management user. Specifically, the target client informs the logged-in user through a pop-up window that zero-trust security management has been enabled, and displays the specific contents of the real-time protection strategy, antivirus protection strategy and security reinforcement strategy. Among them, the real-time protection strategy includes application entry protection and underlying protection. Application entry protection includes but is not limited to desktop icon protection, camera protection, disk insertion protection, file download protection and web firewall. Bottom-level protection includes but is not limited to file system protection, registry protection, process protection, driver protection and hacker intrusion protection.
[0055] like Figure 7 As shown, according to the user-level policy issued by the administrator, the logged-in user has access rights to the designated business server. Specifically, a pop-up window on the target client informs the logged-in user that the trusted software has been configured, and the trusted software label and intercepted software label inform the user of the trusted software that can be used during the zero-trust security protection process and the intercepted software that will be intercepted and cannot be used. In this embodiment, the trusted software is any application.
[0056] The target client may be, for example, an iOA client, which is a client based on a zero-trust policy. The zero-trust policy records the processes and accessible business sites (or business security management servers, or business servers, etc.) that the logged-in user of the iOA client can use, and the granularity of the zero-trust policy is the logged-in user.
[0057] When the terminal device logs in to the target client and requests access to the business server, the network request of the business server is hijacked, wherein the hijacking of the network request is performed by the proxy client included in the terminal device, so that the proxy client can intercept the network request. It can be understood that any business device (such as the above-mentioned business server) under the protection of the zero-trust policy needs to verify the access request before being accessed (that is, verify the access credentials carried in the access request), and perform the access after the verification is passed, so as to ensure the security of the accessed business device. Among them, based on the hijacking of the network request, the target client (or proxy client) that intercepts the network request can obtain the source Internet Protocol (IP), source port, destination IP, destination port, process identification (PID) of the target client and other parameters, wherein IP can also be called a domain name, the source IP is the IP of the target client, and the destination IP is the IP of the business server.
[0058] In one or more embodiments, the hijacking of network requests is performed by a proxy client, such as Figure 8 As shown, the proxy client (such as Figure 8 After intercepting the network request, the client (the client marked by mark 20) can send the source IP, source port, destination IP, destination port, application process PID and other parameters to the target client (iOA client, such as Figure 8 The target client 21 can collect the MD5 of the process, the process path, the last modification time of the process, copyright information, signature information, etc. through the process PID sent by the proxy client 20, and can also connect the source IP (source domain name), source port, destination IP, and destination port of the network request passed by the proxy client to the security management server (such as Figure 8 The security management server 22 (marked by 22 in the figure) sends a request for applying for an access credential, wherein if the application is successful, the security management server 22 sends the access credential, the maximum number of uses of the access credential, and the validity period of the access credential as a response to the target client 21, and the target client 21 forwards the access credential, the maximum number of uses of the access credential, and the validity period of the access credential to the proxy client 20.
[0059] The access credential can also be called a network request credential (receipt). The access credential is the authorization information issued by the security management server 22 for a single network request (or access request) and is used to identify the authorization status of the network request. The proxy client 20 is used to receive the access credential and send it to the intelligent gateway (such as Figure 8 The data access request may be a request based on the Hyper Text Transfer Protocol over Secure Socket Layer (HTTPS) (or an Http request), wherein when the proxy client 20 sends the Http request to the intelligent gateway 23, the access credential may be included in the authorization header field of the HTTPS request. The intelligent gateway 23 receives the data access request, parses the data access request to obtain the access credential, adds the access credential to the verification request, and sends it to the security management server 22. The security management server 22 may verify the access credential. If the security management server 22 successfully verifies the access credential, the intelligent gateway 23 successfully establishes a connection with the proxy client 20, and then the proxy client 20 may proxy the target client (such as Figure 8 Any application marked by 24 in the Figure 8 Access any business security management server marked by 25).
[0060] When the target client 21 applies to the security management server 22 for access credentials, in order to fully verify whether the access process to the business server 25 is a malicious process, the target client 21 will initiate a process inspection request to the security management server 22. The request parameters include the identifier of the destination uniform resource locator system (Uniform Resource Locator, URL) of the business server 25 requested for access, process MD5, hash code, process path, certificate chain details, etc. Among them, the certificate chain details include: digest algorithm, root certificate name, root certificate serial number, root certificate expiration time, intermediate certificate name, intermediate certificate serial number, intermediate certificate expiration time, signature certificate name, signature certificate serial number, signature certificate expiration time, signature status, name of the signing user, timestamp, signature verification error information. After receiving this information, the security management server 22 can regularly check the service security information of the threat intelligence cloud, tav (an antivirus engine) (such as Figure 8 If the file is a malicious process file, the security management server 22 will notify the target client 21 and interrupt the target client 24's access request to the business server 25 to prohibit the target client 24 from accessing the business server 25.
[0061] In one or more embodiments, the intelligent gateway 23 is deployed at the entrance of the business server (or the application of the i business server) and the data resource, and is responsible for the verification, authorization and forwarding of each session request to access the business server. The target client 21 is a security agent (Agent) installed on the terminal device, which is responsible for verifying the trusted identity of the user logged in on the terminal device, verifying whether the terminal device is trustworthy and whether the target client is trustworthy, and submitting unknown processes (such as access requests or access processes to the security management server, etc.) to the security management server for inspection. The proxy client 20 hijacks the network request through the TUN / TAP (a virtual network device in the operating system kernel) virtual network card, and is responsible for forwarding the access request to the intelligent gateway after authentication by the target client 21. If the authentication fails, the connection is directly terminated. The security management server 22 includes a policy center, an inspection service and a certificate (or ticket) center. The policy center uses a policy control engine to securely schedule business traffic and authorize it according to the granularity of people-device-software-application; the security management server regularly initiates file inspection to the threat intelligence cloud inspection service Anzhi or tav based on the inspection service, and notifies the target client to perform asynchronous blocking operations after identifying malicious processes. The certificate center is used to generate and issue certificates. In addition, the security management server also includes various modules. The identity authentication module is used to verify the user identity, the device trust module verifies the device hardware information and device security status, and the application detection module detects whether the application process is safe, such as whether there are vulnerabilities, viruses, Trojans, etc.
[0062] In one or more embodiments, when the target client 21 is acting as a proxy for data access to the business server 25, the target client 21 may first send a data access request carrying access credentials to the security management server 22. After receiving the data access request, the security management server 22 may determine the access credentials for the business server from the data access request and verify the access credentials. Only after the security management server 22 has passed the verification of the access credentials will the target client 21 be allowed to proxy access to the business server, which can effectively ensure the security of the target client 21's access to the business server.
[0063] In one or more embodiments, after determining the access credential from the received data access request, the security management server 22 may first determine the credential data used by the security management server 22 when generating the access credential, the credential data including the aforementioned parameters, etc., and then the security management server 22 may process the credential data according to the algorithm used when generating the access credential, thereby regenerating a reference access credential, wherein the generated reference access credential is a trusted access credential. When verifying the access credential sent by the target client, the security management server 22 may use the reference access credential to verify the access credential sent by the target client, such as by comparing the reference access credential with the access credential sent by the target client, and then determining whether the access credential sent by the target client has been verified based on the comparison result. If the comparison result indicates that the reference access credential is consistent with the access credential sent by the target client, or if the comparison result indicates that the similarity between the reference access credential and the access credential sent by the target client meets a preset similarity threshold (e.g., 98%), then the access credential sent by the target client may be considered to have been verified.
[0064] In one or more embodiments, the target client 21 requests a unique local ticket from the security management server 22 based on the source process and destination service server corresponding to the data access request, and directly responds to the proxy client. The unique ticket contains a valid usage count and a maximum expiration date, which the proxy client uses to build a ticket cache. Specifically, after receiving the unique ticket corresponding to the current access, the proxy client builds a cache based on the maximum usage count and expiration date. Subsequent accesses by the same process to resources or data on the same service server will not require repeated ticket requests from the target client 21 within the cache's validity period.
[0065] In one or more embodiments, after the target client 21 receives the data access request from the access proxy, it uses an algorithm agreed upon with the server to generate a random string staggered session ticket based on device information, login user information, application process, business server, network session information, etc. for traffic that has passed the access control policy inspection and is compliant, and responds to the proxy client.
[0066] In one or more embodiments, Figure 9As shown, the zero-trust security management system is based on a zero-trust agent (such as the target client or proxy client mentioned above) and an intelligent gateway, providing a unified entrance for the access subject (such as the target client mentioned above) to access the resources of the object (such as the business server mentioned above) through the network request. Among them, the zero-trust security management system (specifically the security management server in the zero-trust security management system) provides authentication operations for the unified entrance. Only network requests that pass the authentication can be forwarded by the zero-trust agent to the intelligent gateway, and access to the actual business system can be proxied by the access gateway. Among them, the zero-trust security management system can adapt to medium-sized enterprises, institutions and governments through a single deployment method, and can also adapt to large enterprise groups and multi-level vertical government e-government systems through a distributed cascade deployment method.
[0067] In one or more embodiments, Figure 10 As shown, the service access traffic control method proposed in the embodiment of the present application includes the following steps:
[0068] Step 101: intercepting a service access request associated with a service application.
[0069] It should be noted that the business application receives the user's instruction information and generates a corresponding business access request according to the instruction information. The target client monitors the business access request to obtain the business access request associated with the business application.
[0070] Step 102: Based on the network control boundary defined in the access traffic control policy, identify the service access request belonging to the target network area as the target service access request, and the access traffic control policy defines the target network area based on the network control boundary.
[0071] Among them, the access traffic control boundary is used to delineate the target network area, that is, if the address to be accessed corresponding to the access request belongs to the target network area, then the business access request is determined to be within the access traffic control boundary and is a target business access request that requires access traffic control. If the address to be accessed corresponding to the access request does not belong to the target network area, then the business access is determined to be not within the access traffic control boundary and is a non-target business access request that does not require access traffic control.
[0072] It should be noted that enterprises can integrate their existing business systems and deploy specific access traffic control strategies through security management systems (such as iOA clients). As the network environment in which the terminal is located changes, the terminal type, and the company's control over network access traffic vary, the focus and control ideas for terminal traffic will vary. Therefore, the boundaries that require traffic control can be set through the iOA client, so that business access requests that require traffic control can be intercepted and authenticated.
[0073] In one or more embodiments, the access traffic control strategy includes a resource strategy, the resource strategy includes a target IP segment corresponding to the target business access request, and the method includes: when the IP to be accessed corresponding to the business access request is within the target IP segment, determining that the business access request is a target business access request; when the IP to be accessed corresponding to the business access request is not within the target IP segment, determining that the business access request is a non-target business access request.
[0074] Furthermore, when configuring access traffic management policies, enterprises usually have two settings: one is the full traffic hijacking mode, and the other is the enterprise business resource hijacking mode. Among them, the full traffic hijacking mode is to hijack all business access requests of the terminal to the proxy client, and the proxy client determines the processing method of the business access request after communicating and authenticating with the iOA client, such as forwarding through the intelligent gateway or sending it directly to the business server. In the enterprise business resource hijacking mode, enterprise managers configure the domain name, IP or IP segment matching rules of the enterprise business system containing data, interfaces and functions on the management side. When the destination IP in the business access request matches the set IP or belongs to the set IP segment, it is considered that the access subject is trying to access the enterprise business resources. At this time, the business access request needs to be hijacked to the proxy client, and the proxy client will determine the processing method of the business access request after communicating and authenticating with the iOA client. If the destination IP in the business access request does not match the set IP or does not belong to the set IP segment, the proxy client can directly send the business access request to the business server.
[0075] For example, an enterprise can determine whether to perform traffic control on all business access requests of terminal traffic or only on access to enterprise business resources based on actual needs. When traffic control is required for all business access requests, the default address in the host routing table of the terminal device can be set to the virtual network card address of the proxy client, thereby effectively improving the setting efficiency. When traffic control is only performed on access to enterprise business resources, the host routing table address corresponding to the IP or IP segment corresponding to the enterprise business resource address is set to the virtual network card address of the proxy client.
[0076] In one or more embodiments, the functional policy is a state policy of the zero-trust access function corresponding to the target client. When the zero-trust access function is in a valid state, the candidate business access request is determined to be a target business access request. When the zero-trust access function is in an invalid state, the candidate business access request is determined to be a non-target business access request.
[0077] In other words, access traffic control for business applications can also be controlled by terminal users. When the user logs in to the iOA client or turns on the zero-trust access function or runs the zero-trust access function in the background, the candidate business access requests intercepted by the proxy client can be subject to traffic control, that is, authentication through the security management server and forwarding to the business server through the intelligent gateway.
[0078] In other words, the access traffic control policy can give decision-making power to end users. When end users start using the zero-trust network access function, traffic tracking, management and monitoring will be carried out. When end users turn off the zero-trust network access function, the access traffic control policy will end.
[0079] In one or more embodiments, the proxy client intercepts a business access request and sends the business access request to the target client when the zero-trust access function of the target client is in a valid state; the target client identifies that the IP to be accessed corresponding to the business access request is within the target IP segment, and determines that the business access request is a target business access request. The target client sends the target business access request to the security management server, so that the security management server performs a legitimacy verification on the target business access request and obtains a legitimacy verification result corresponding to the target business access request; the target client sends the legitimacy verification result corresponding to the target business access request to the proxy client; based on the legitimacy verification result, the proxy client sends the business access request to the intelligent gateway, so that the intelligent gateway sends the business access request to the business server.
[0080] Alternatively, in one or more embodiments, the target client controls the proxy client to intercept the service access request and sends the service access request to the target client; the target client identifies that the IP to be accessed corresponding to the service access request is not in the target IP segment, determines that the service access request is a target service access request, and the target client sends the target service access request to the security management server, so that the security management server performs a legitimacy verification on the target service access request and obtains a legitimacy verification result corresponding to the target service access request; the target client sends the legitimacy verification result corresponding to the target service access request to the proxy client; based on the legitimacy verification result, the proxy client sends the service access request to the intelligent gateway, so that the intelligent gateway sends the service access request to the service server.
[0081] In one or more embodiments, when a business access request is determined to be a non-target business access request based on the access traffic control policy issued by the target client, the business access request is sent directly to the business server; or when the legality verification result indicates that the target business access policy is not legal, a re-authentication instruction or access blocking instruction issued by the security management server is received.
[0082] In one or more embodiments, the proxy client intercepts the business access request and sends the business access request to the target client when the zero-trust access function of the target client is in a valid state; the target client identifies that the IP to be accessed corresponding to the business access request does not match the target IP, and determines that the business access request is a non-target business access request. The target client sends the identification result that the business access request is a non-target business access request to the proxy client; the proxy client sends the business access request to the business server.
[0083] Alternatively, in one or more embodiments, after intercepting the service access request, the proxy client identifies that the target client is in an invalid state; the proxy client sends the service access request to the service server.
[0084] In one or more embodiments, the process of the proxy client hijacking the service access request can be controlled by the target client, that is, when the target client exits, a control instruction on whether to continue hijacking is sent to the proxy client, so that the proxy client continues to hijack the service access request or stops hijacking.
[0085] For example, when the target client controls the proxy client to exit and open the target client at the same time, and a terminal user authenticates by logging in on the iOA client, or clicks on a button like "Start Work" or "Start Office" on the terminal interface to enable the Zero Trust Network Access feature, the proxy client's hijacking process is launched by the iOA client and begins to hijack, forward, and report traffic, thereby tracking and automatically auditing traffic on the security management server. When the terminal user logs out of the iOA client or clicks on a button like "Stop Work" or "Stop Office" on the terminal interface to stop the Zero Trust Network Access feature, the iOA client sends a stop command to the proxy client, causing the proxy client to terminate the managed network session, stop its own process, and simultaneously stop traffic hijacking and traffic forwarding. In this strategy, the proxy client is not permanently resident on the user's terminal. It starts when the Zero Trust Network Access feature is enabled and ends when the Zero Trust Network Access feature is disabled. The iOA client performs user-defined monitoring and management, such as full traffic monitoring or enterprise business resource monitoring, during the period from when the Zero Trust Network Access feature is enabled to when it is disabled.
[0086] It should be understood that in the strategy where the target client controls the proxy client to exit and start the target client at the same time, when the proxy client is stopped, the service access request executes the original access process, such as being sent directly to the service server through the physical gateway, and the service access request passes neither through the proxy client nor the intelligent gateway.
[0087] Alternatively, when the target client controls the proxy client to exit and start at the same time as the target client, the proxy client will continue to hijack the business access request and forward it to the iOA client. When the iOA client authenticates the business access request, the business access request will be sent to the intelligent gateway via the proxy client, so that the intelligent gateway can forward the business access request to the business server. When the iOA client is logged out or when the zero-trust network access function is stopped by clicking controls such as "Stop Working" or "Stop Office" on the terminal interactive interface, the iOA client sends a full direct connection instruction to the proxy client, so that the proxy client will forward all intercepted business access requests directly to the corresponding business server. In other words, under this policy, when the iOA client is logged out, the business access request passes through the proxy client but not the intelligent gateway.
[0088] In one or more embodiments, different traffic management can also be implemented according to the network area where the terminal is located. For example, when the user terminal is in an external network environment, the enterprise business resource hijacking mode can be adopted, and when the user terminal is in the enterprise intranet, the full traffic hijacking mode can be adopted.
[0089] That is to say, the iOA client can continuously detect the network area where the user terminal is located, and implement different traffic control strategies through different network areas. For example, when the network area where the user terminal is located is the enterprise intranet or the enterprise sensitive network area, the proxy terminal process resides in the terminal and always hijacks the business access requests of the user's internal and external website sites. The iOA client controls the access rights of the enterprise business resources, that is, the terminal user can access the enterprise business resources only after logging in to the iOA client and the access ticket is authenticated. When the network area where the user is located is the public network or non-sensitive network area, the iOA client controls the start and stop of the access proxy client process. When the proxy client is started, the user can access the enterprise business resources. At the same time, the iOA client reports the business access requests hijacked by the proxy client to the security management server for traffic tracking and monitoring. When the proxy client is stopped, the user can only access non-enterprise business resources and cannot access enterprise business resources, and the iOA client automatically ignores the management of access traffic to non-enterprise business resources.
[0090] Step 103: Send an authentication request corresponding to the target service access request to the security management server, so that the security management server performs a validity check on the target service access request and obtains a validity check result.
[0091] Step 104 : When the legality check result indicates that the target service access request is legal, a service response result corresponding to the target service access request is obtained from the service server.
[0092] Furthermore, when the business access request is determined to be a non-target business access request based on the access traffic control policy issued by the target client, the business access request is sent directly to the business server, or when the legality verification result indicates that the target business access policy is not legal, a re-authentication instruction or access blocking instruction issued by the security management server is received.
[0093] Therefore, the business access traffic control method proposed in the embodiment of the present application can intercept and forward business access requests of different ranges in a targeted manner according to the access traffic control strategy, so that enterprises can flexibly set traffic management boundaries while effectively managing business access requests securely.
[0094] In one or more embodiments, Figure 11 As shown, it also includes:
[0095] Step 201: The service application generates a service request data packet corresponding to a service access request, and sends the service request data packet to the kernel protocol stack.
[0096] That is to say, when the terminal initiates network access through an application (business application) by the access subject, the network data is transmitted from the network layer of the application to the transport layer, and then sent down to the network layer. Each layer adds the header data of the corresponding level, and then sends the network data packet to the kernel protocol stack of the terminal device via the socket component.
[0097] In step 202 , the kernel protocol stack extracts the destination address corresponding to the service request from the service request data packet, and searches for the next hop address corresponding to the destination address according to the access traffic control policy issued by the target client.
[0098] Step 203: When the next hop address is the virtual network card of the proxy client, the proxy client intercepts the service access request.
[0099] That is to say, when the iOA client administrator sets the access traffic control policy, the address of the TUN / TAP virtual network card of the input proxy client is configured into the routing table, so that when the kernel protocol stack parses the service request data packet, it determines that the next hop route indication corresponding to the IP or IP segment in the service request data packet is the virtual network card of the proxy client, and then sends the service access request (service access request data packet) to the proxy client, so that the proxy client can intercept the service access request.
[0100] Furthermore, after the TUN / TAP virtual network card of the proxy client receives the service access request data packet, it notifies the user-mode proxy process in the iOA client to obtain the data sent by the kernel protocol stack to the virtual network card, thereby realizing data exchange between the kernel protocol stack and the user layer.
[0101] After the user-mode proxy process in the iOA client obtains the service request data packet, it parses the data packet and sends the parsing result (credential ticket) to the security management server for authentication. If the service access request data packet is authenticated, a new data packet with a source address of Ethernet address and a destination address of the intelligent gateway connection address is constructed based on the original service request data packet through the socket component, and the new data packet is sent to the intelligent gateway so that the intelligent gateway forwards the service access request to the service server. If the service access request data packet is not authenticated, a new data packet with a source address of Ethernet address and a destination address of the target access site is constructed based on the original service request data packet through the socket component to send the service access request directly to the service server corresponding to the target access site.
[0102] In one or more embodiments, when a service access request is intercepted, structured data is generated according to the service access request, so that the security management server performs a validity check based on the structured data and generates structured control flow information.
[0103] That is, after the proxy client and intelligent gateway complete the forwarding of service access requests and proxy access, they automatically generate structured data. Core data includes, but is not limited to, the request time of the original service access request, terminal characteristics (such as device name and device unique identifier), application name and process characteristic information (such as process information, copyright information, hash, etc.) that initiated the service access request, iOA client login user information (such as user name, user ID, etc.), source IP and source port, remote target IP (intelligent gateway or service server), remote target port, service system request results, request method, request URL, traffic unique identifier, etc. Structured data can serve as data flow records.
[0104] In one or more embodiments, after the target client sends the identification result that the target business access request is a non-target business access request to the proxy client, the target client generates structured data corresponding to the control flow; or the proxy client generates structured data corresponding to the data flow based on the business response result corresponding to the target business access request obtained from the business server, and sends the structured data corresponding to the data flow to the target client; the target client uploads the structured data corresponding to the data flow and optional structured data corresponding to the control flow to the security management server to be stored as structured audit data.
[0105] As a possible embodiment, Figure 12As shown, in the case where the business access request is determined to be a direct access request, as in the process of number 1, after the proxy client hijacks the business access request, it sends the business access request to the iOA client, so that the iOA client communicates with the security management server to authenticate the business access request. The iOA client determines that the business access request is a non-target business access request according to the access traffic control policy, that is, the business access request is a direct access request. The iOA client returns the identification result of the business access request as a direct access request to the proxy client. The iOA client determines that the business access request is a direct access request according to the access traffic control policy and generates structured data corresponding to the control flow. As in the process of number 2, the proxy access client sends the business access request to the business server to complete the direct access process. After sending the business access request to the business server, the proxy client generates structured data corresponding to the business access request based on the structured data corresponding to the control flow feedback from the iOA client and the local log generated by forwarding the business access request to the business server, and sends the structured data corresponding to the business access request to the iOA client. As in process number 3, the iOA client sends the structured data corresponding to the business access request to the security management server for storage to form audit data corresponding to the business access request, and receives the audit results sent by the security management server.
[0106] In one or more embodiments, after the target client sends the legal verification result corresponding to the target business access request to the proxy client, it also includes: the target client generates structured data corresponding to the control flow based on the legal verification result; the proxy client generates structured data corresponding to the data flow based on the business response result corresponding to the target business access request obtained from the intelligent gateway, and sends the structured data corresponding to the data flow to the target client; the target client uploads the structured data corresponding to the control flow and the structured data corresponding to the data flow to the security management server to store them as structured audit data.
[0107] As another possible embodiment, Figure 13As shown, when the service request is determined to be a proxy access request executed by the intelligent gateway, as in the process of number 1, after the proxy client hijacks the service access request, it sends the service access request to the iOA client, so that the iOA client communicates with the security management server to authenticate the service access request. The iOA client determines that the service access request is a target service access request based on the access traffic control policy. The iOA client further sends an authentication request to the security management server based on the request information corresponding to the target service access request, and after the authentication is passed, it determines that the service access request is a proxy access request executed by the intelligent gateway. The iOA client returns the identification result of the service access request as a continuous access request to the proxy client. The iOA client determines that the service access request is a processing process and result of the proxy access request based on the access traffic control policy to generate structured data corresponding to the control flow. As in the process of number 2, the proxy access client sends the service access request to the intelligent gateway. As in the process of number 3, the intelligent gateway sends the service access request to the service server to complete the proxy access process. After the proxy client sends the business access request to the intelligent gateway, which then sends the business access request to the business server, as in process number 4, the intelligent gateway generates structured data corresponding to the business access request based on the structured data corresponding to the control flow fed back to the proxy client by the iOA client and the local log generated by forwarding the business access request to the business server via the intelligent gateway. The proxy client sends the structured data corresponding to the business access request to the iOA client, and as in process number 5, the structured data corresponding to the business access request is sent to the security management server through the iOA client for storage to form audit data corresponding to the business access request, and receives the audit results sent by the security management server.
[0108] In one or more embodiments, after obtaining the business response result corresponding to the target business access request, structured data corresponding to the business access request is generated and sent to the security management server; the security management server audits the structured data to identify abnormal business access requests, and issues a re-authentication instruction or access blocking instruction after identifying the abnormal business access request.
[0109] Furthermore, the security management server can also synchronously generate structured control flow information based on the authentication process of structured data, including but not limited to access time, terminal characteristics (such as device name and device unique identifier, etc.), application name and process characteristic information (such as process information, copyright information, hash, etc.) that initiates the business access request, iOA client login user information (such as user name, user ID, etc.), policy hit information, access control processing details, terminal environment perception information, traffic unique identifier, etc.
[0110] Furthermore, the security management server can automatically compare and count the data flow and control flow structured data reported by the iOA client, proxy client and intelligent gateway (the two types of data are associated through a unique traffic identifier), generate different types of traffic monitoring charts on the management and control end, and then build a zero-trust operation data indicator model.
[0111] At the same time, the results of automated comparisons are used to automatically detect whether there are any abnormal indicator data in the terminal's access sessions to corporate business resources. If, based on the results of the automated comparisons, it is determined that there are abnormal access sessions that exceed the set values, it is necessary to manually or automatically blacklist specific terminals, enforce compliance dynamic detection, or implement relevant preventive measures such as adjusting access control policies. Based on the zero-trust operational data indicator model, traffic characteristics can be detected in real time. If abnormal behavior is detected, the current business access is terminated, and the terminal user is reminded to complete secondary verification before continuing access, or implement real-time processing including terminating or revoking the current and subsequent sessions.
[0112] Therefore, this application automatically and asynchronously generates traffic feature structured data with low latency through the proxy client and the intelligent gateway, which can effectively solve the problems of high performance overhead and possible sensitive data leakage caused by frequent traffic data collection, or the diverse log formats and low data utilization value caused by multiple data collections. At the same time, the security management server can generate structured control information based on structured data, and automatically compare and identify traffic features that do not conform to the set rules, and then send re-authentication or access blocking instructions to the terminal, thereby realizing zero-trust access monitoring and management of business access requests.
[0113] To sum up, the business access traffic control method proposed in the embodiment of the present application can intercept and forward business access requests of different ranges in a targeted manner according to the access traffic control strategy, so that enterprises can flexibly set traffic management boundaries while effectively managing business access requests securely.
[0114] It should be noted that although the operations of the present method are described in a particular order in the drawings, this does not require or imply that the operations must be performed in this particular order, or that all illustrated operations must be performed to achieve desirable results.
[0115] Figure 14 This is a schematic diagram of the structure of a service access flow control device proposed in an embodiment of the present application. Figure 14 As shown, the service access traffic control device 10 proposed in the embodiment of the present application includes:
[0116] An acquisition module 11 is configured to acquire a service access request associated with a service application;
[0117] A determination module 12 is configured to identify a service access request belonging to a target network area as a target service access request based on a network control boundary defined in an access traffic control policy; the access traffic control policy defines the target network area based on the network control boundary;
[0118] The sending module 13 is used to send an authentication request corresponding to the target service access request to the security management server, so that the security management server performs a legitimacy check on the target service access request and obtains a legitimacy check result;
[0119] The receiving module 14 is configured to obtain a service response result corresponding to the target service access request from a service server when the legality verification result indicates that the target service access request is legal.
[0120] In some embodiments, the access traffic control policy includes a resource policy, and the resource policy is used to determine the target IP address that requires access traffic control. The determination module 11 is further used to:
[0121] When the IP address to be accessed corresponding to the service access request matches the target IP address, determining that the service access request is a target service access request;
[0122] When the IP to be accessed corresponding to the service access request does not match the target IP, it is determined that the service access request is a non-target service access request.
[0123] In some embodiments, the access traffic control policy includes a functional policy, where the functional policy is a state policy of a zero-trust access function corresponding to the target client. The determining module 11 is further configured to:
[0124] When the zero-trust access function is in a valid state, determining that the service access request is the target service access request;
[0125] When the zero-trust access function is in an invalid state, determining that the business access request is a non-target business access request.
[0126] In some embodiments, the target terminal includes a proxy client and a target client device further used for: the proxy client intercepts the business access request and sends the business access request to the target client when the zero-trust access function of the target client is in a valid state; the target client identifies that the IP to be accessed corresponding to the business access request is within the target IP segment, determines that the business access request is a target business access request, and the target client sends the target business access request to the security management server, so that the security management server performs a legitimacy verification on the target business access request and obtains a legitimacy verification result corresponding to the target business access request; the target client sends the legitimacy verification result corresponding to the target business access request to the proxy client; based on the legitimacy verification result, the proxy client sends the business access request to the smart gateway, so that the smart gateway sends the business access request to the business server.
[0127] In some embodiments, the target client controls the proxy client to intercept the business access request and sends the business access request to the target client; the target client identifies that the IP to be accessed corresponding to the business access request is within the target IP segment, determines that the business access request is a target business access request, and the target client sends the target business access request to the security management server, so that the security management server performs a legitimacy verification on the target business access request and obtains a legitimacy verification result corresponding to the target business access request; the target client sends the legitimacy verification result corresponding to the target business access request to the proxy client; based on the legitimacy verification result, the proxy client sends the business access request to the intelligent gateway, so that the intelligent gateway sends the business access request to the business server.
[0128] In some embodiments, the target client generates structured data corresponding to the control flow based on the legal verification result; the proxy client generates structured data corresponding to the data flow based on the business response result corresponding to the target business access request obtained from the intelligent gateway, and sends the structured data corresponding to the data flow to the target client; the target client uploads the structured data corresponding to the control flow and the structured data corresponding to the data flow to the security management server to store them as structured audit data.
[0129] In some embodiments, when a business access request is determined to be a non-target business access request based on an access traffic control policy, the business access request is sent directly to the business server; or when the legality verification result indicates that the target business access policy is not legal, a re-authentication instruction or access blocking instruction issued by the security management server is received.
[0130] In some embodiments, the proxy client intercepts the business access request and sends the business access request to the target client when the zero-trust access function of the target client is in a valid state; the target client identifies that the IP to be accessed corresponding to the business access request is not in the target IP segment, and determines that the business access request is a non-target business access request. The target client sends the identification result that the business access request is a non-target business access request to the proxy client; the proxy client sends the business access request to the business server.
[0131] In some embodiments, after intercepting the service access request, the proxy client identifies that the target client is in an invalid state; and the proxy client sends the service access request to the service server.
[0132] In some embodiments, after the target client sends the identification result that the target business access request is a non-target business access request to the proxy client, the target client generates structured data corresponding to the control flow; or the proxy client generates structured data corresponding to the data flow based on the business response result corresponding to the target business access request obtained from the business server, and sends the structured data corresponding to the data flow to the target client; the target client uploads the structured data corresponding to the data flow and optional structured data corresponding to the control flow to the security management server to be stored as structured audit data.
[0133] In some embodiments, structured data corresponding to the business access request is generated based on the business response result and sent to the security management server; the security management server audits the structured data to identify abnormal business access requests, and issues re-authentication instructions or access blocking instructions after identifying abnormal business access requests.
[0134] It should be understood that the units or modules recorded in the service access flow control device 10 are the same as those in the reference Figure 10 The various steps in the described method correspond to each other. Therefore, the operations and features described above for the method are also applicable to the service access traffic control device 10 and the units contained therein, and will not be repeated here. The service access traffic control device 10 can be pre-implemented in the browser or other security applications of the electronic device, or can be loaded into the browser or its security application of the electronic device by downloading or other means. The corresponding units in the service access traffic control device 10 can cooperate with the units in the electronic device to implement the solution of the embodiment of the present application.
[0135] The several modules or units mentioned in the detailed description above are not necessarily divided into one module or unit. In fact, according to the embodiments of the present disclosure, the features and functions of two or more modules or units described above can be embodied in one module or unit. Conversely, the features and functions of one module or unit described above can be further divided into multiple modules or units to be embodied.
[0136] To sum up, the business access traffic control device proposed in the embodiment of the present application can intercept and forward business access requests of different ranges in a targeted manner according to the access traffic control strategy, so that enterprises can flexibly set traffic management boundaries while effectively managing business access requests securely.
[0137] It should be noted that for details not disclosed in the service access traffic control device of the embodiment of the present application, please refer to the details disclosed in the above embodiments of the present application, and no further details will be given here.
[0138] Reference below Figure 14 , Figure 14 A schematic diagram of the structure of a computer system of an electronic device or a security management server suitable for implementing an embodiment of the present application is shown.
[0139] like Figure 14 As shown, the computer system includes a central processing unit (CPU) 1401, which can perform various appropriate actions and processes according to the program stored in the read-only memory (ROM) 1402 or the program loaded from the storage part 1408 into the random access memory (RAM) 1403. Various programs and data required for the operation instructions of the system are also stored in the RAM 1403. The CPU 1401, ROM 1402 and RAM 1403 are connected to each other via a bus 1404. An input / output (I / O) interface 1405 is also connected to the bus 1404.
[0140] The following components are connected to the I / O interface 1405: an input section 1406 including a keyboard, a mouse, and the like; an output section 1407 including devices such as a cathode ray tube (CRT), a liquid crystal display (LCD), and a speaker; a storage section 1408 including devices such as a hard disk; and a communication section 1409 including a network interface card such as a LAN card or a modem. The communication section 1409 performs communication processing via a network such as the Internet. A drive 1410 is also connected to the I / O interface 1405 as needed. Removable media 1411, such as a magnetic disk, an optical disk, a magneto-optical disk, or a semiconductor memory, is installed in the drive 1410 as needed, so that computer programs read therefrom can be installed in the storage section 1408 as needed.
[0141] In particular, according to the embodiment of the present application, the above reference flow chart Figure 2 The described process can be implemented as a computer software program. For example, an embodiment of the present application includes a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program includes a program code for executing the method shown in the flowchart. In such an embodiment, the computer program includes a program code for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from a network via the communication section 1409, and / or installed from a removable medium 1411. When the computer program is executed by the central processing unit (CPU) 1401, the above-mentioned functions defined in the system of the present application are executed.
[0142] It should be noted that the computer-readable medium shown in this application can be a computer-readable signal medium or a computer-readable storage medium, or any combination of the two. The computer-readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device, or device, or any combination of the above. More specific examples of computer-readable storage media can include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In this application, a computer-readable storage medium can be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, device, or device. In this application, a computer-readable signal medium can include a data signal propagated in baseband or as part of a carrier wave, which carries computer-readable program code. This propagated data signal can take a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. A computer-readable signal medium may also be any computer-readable medium other than a computer-readable storage medium that can transmit, propagate, or transfer a program for use by or in conjunction with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium may be transmitted using any suitable medium, including but not limited to wireless, wire, optical cable, RF, or any suitable combination thereof.
[0143] The flowcharts and block diagrams in the accompanying drawings illustrate the possible implementation architecture, functions and operating instructions of the systems, methods and computer program products according to various embodiments of the present application. In this regard, each box in the flowchart or block diagram can represent a module, program segment, or a part of code, and the aforementioned module, program segment, or a part of code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a different order than the order marked in the accompanying drawings. For example, the boxes represented by two connections can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flowchart, and the combination of the boxes in the block diagram and / or flowchart, can be implemented using a dedicated hardware-based system that performs the specified function or operating instruction, or can be implemented using a combination of dedicated hardware and computer instructions.
[0144] The units or modules involved in the embodiments described in the present application may be implemented in software or in hardware. The units or modules described may also be provided in a processor. For example, they may be described as: a processor including a determination module, a forwarding module, and an acquisition module. In some cases, the names of these units or modules do not constitute a limitation on the units or modules themselves. For example, the determination module may also be described as "when a business access request associated with a business application is intercepted, the business access request is determined to be a target business access request based on the access traffic control policy issued by the target client, wherein the access traffic control policy is used to determine the access traffic control boundary."
[0145] As another aspect, the present application further provides a computer-readable storage medium, which may be included in the electronic device described in the above embodiments, or may exist independently without being incorporated into the electronic device. The computer-readable storage medium stores one or more programs, which, when used by one or more processors, execute the service access traffic control method described in the present application.
[0146] The above description is merely a preferred embodiment of the present application and an illustration of the technical principles employed. Those skilled in the art should understand that the scope of disclosure in this application is not limited to the technical solutions formed by a specific combination of the above-mentioned technical features, but also encompasses other technical solutions formed by any combination of the above-mentioned technical features or their equivalents without departing from the aforementioned disclosed concepts. For example, a technical solution formed by replacing the above-mentioned features with (but not limited to) technical features with similar functions disclosed in this application.
Claims
1. A method for controlling business access traffic, characterized in that: The method comprises: The proxy client intercepts the service access request associated with the service application; The target client identifies, based on a network control boundary defined in an access traffic control policy, a service access request belonging to a target network area as a target service access request, wherein the access traffic control policy defines the target network area based on the network control boundary; The target client sends an authentication request corresponding to the target service access request to the security management server, so that the security management server performs a legitimacy check on the target service access request and obtains a legitimacy check result; The target client sends the legality verification result to the proxy client and generates structured data corresponding to the control flow according to the legality verification result; When the legality verification result indicates that the target service access request is legal, the proxy client obtains a service response result corresponding to the target service access request from the service server; The proxy client generates structured data corresponding to the data flow according to the service response result, and sends the structured data corresponding to the data flow to the target client; the structured data corresponding to the control flow and the structured data corresponding to the data flow are associated with each other through a unique traffic identifier; The target client uploads the structured data corresponding to the control flow and the structured data corresponding to the data flow to the security management server, so that the security management server compares and determines whether there is an abnormal access session exceeding a set value.
2. The method according to claim 1, characterized in that The access traffic control policy includes a resource policy, the resource policy includes a target IP segment corresponding to the target service access request, and the method includes: When the IP to be accessed corresponding to the service access request is within the target IP segment, determining that the service access request is a target service access request; When the to-be-accessed IP corresponding to the service access request is not within the target IP segment, it is determined that the service access request is a non-target service access request.
3. The method according to claim 1, characterized in that The access traffic control policy includes a functional policy, which is a state policy of a zero-trust access function corresponding to the target client. The method includes: When the zero-trust access function is in a valid state, determining that the service access request is the target service access request; When the zero-trust access function is in an invalid state, determining that the business access request is a non-target business access request.
4. The method according to claim 1, wherein The target terminal includes a proxy client and a target client, and the method includes: The proxy client intercepts the service access request and sends the service access request to the target client when the zero-trust access function of the target client is in a valid state; The target client identifies that the IP address to be accessed corresponding to the service access request is within the target IP segment, determines that the service access request is a target service access request, and sends the target service access request to the security management server, so that the security management server performs a validity check on the target service access request and obtains the validity check result corresponding to the target service access request; The target client sends the legality verification result corresponding to the target service access request to the proxy client; The proxy client sends the service access request to the intelligent gateway based on the legality verification result, so that the intelligent gateway sends the service access request to the service server.
5. The method according to claim 1, wherein The target terminal includes a proxy client and a target client, and the method includes: The target client controls the proxy client to intercept the service access request and send the service access request to the target client; The target client identifies that the IP address to be accessed corresponding to the service access request is within the target IP segment, determines that the service access request is a target service access request, and sends the target service access request to the security management server, so that the security management server performs a validity check on the target service access request and obtains the validity check result corresponding to the target service access request; The target client sends the legality verification result corresponding to the target service access request to the proxy client; The proxy client sends the service access request to the intelligent gateway based on the legality verification result, so that the intelligent gateway sends the service access request to the service server.
6. The method according to claim 4 or 5, characterized in that The method further comprises: The proxy client generates structured data corresponding to the data stream according to the service response result corresponding to the target service access request obtained from the intelligent gateway.
7. The method according to claim 1, characterized in that The method comprises: When it is determined based on the access traffic control policy that the service access request is a non-target service access request, directly sending the service access request to the service server; or When the legality check result indicates that the target service access request is not legal, a re-authentication instruction or an access blocking instruction sent by the security management server is received.
8. The method according to claim 7, characterized in that The target terminal includes a proxy client and a target client, and the method includes: The proxy client intercepts the service access request and sends the service access request to the target client when the zero-trust access function of the target client is in a valid state; The target client identifies that the to-be-accessed IP address corresponding to the service access request is not within the target IP segment, determines that the service access request is a non-target service access request, and sends the identification result that the service access request is a non-target service access request to the proxy client; The proxy client sends the service access request to the service server.
9. The method according to claim 7, characterized in that The target terminal includes a proxy client and a target client, and the method includes: After intercepting the service access request, the proxy client identifies that the target client is in an invalid state; The proxy client sends the service access request to the service server.
10. The method according to claim 8 or 9, characterized in that The method further comprises: After the target client sends the identification result that the service access request is a non-target service access request to the proxy client, the target client generates structured data corresponding to the control flow; or The proxy client generates structured data corresponding to the data stream according to a service response result corresponding to the target service access request obtained from the service server, and sends the structured data corresponding to the data stream to the target client; The target client uploads the structured data corresponding to the data flow and optionally the structured data corresponding to the control flow to the security management server to be stored as structured audit data.
11. The method according to claim 1, wherein After obtaining the service response result corresponding to the target service access request, the method further includes: Generating structured data corresponding to the service access request according to the service response result, and sending the structured data to the security management server; The security management server audits the structured data to identify abnormal business access requests, and issues a re-authentication instruction or an access blocking instruction after identifying the abnormal business access request.
12. A service access flow control device, characterized in that: The device comprises: An acquisition module is used to intercept service access requests associated with service applications on behalf of the client; A determination module, configured for a target client to identify a service access request belonging to a target network area as a target service access request based on a network control boundary defined in an access traffic control policy, wherein the access traffic control policy defines the target network area based on the network control boundary; a sending module, configured for the target client to send an authentication request corresponding to the target service access request to the security management server, so that the security management server performs a validity check on the target service access request and obtains a validity check result; the target client sends the validity check result to the proxy client and generates structured data corresponding to the control flow based on the validity check result; A receiving module is used to, when the legality verification result indicates that the target business access request is legal, the proxy client obtains the business response result corresponding to the target business access request from the business server; the proxy client generates structured data corresponding to the data flow based on the business response result, and sends the structured data corresponding to the data flow to the target client; the structured data corresponding to the control flow and the structured data corresponding to the data flow are associated through a unique traffic identifier; the target client uploads the structured data corresponding to the control flow and the structured data corresponding to the data flow to the security management server, so that the security management server compares them and determines whether there is an abnormal access session that exceeds the set value.
13. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the program, it implements the service access traffic control method as described in any one of claims 1-11.
14. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the service access traffic control method as described in any one of claims 1 to 11 is implemented.
15. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the service access traffic control method described in any one of claims 1 to 11 is implemented.
Citation Information
Patent Citations
Service data access method and device, equipment, and storage medium
CN111935169A