Intranet virtual private network access point detection method, device and related equipment
By classifying user behaviors of the access scenarios of intranet VPN access points and using deep message detection information for access scenario detection, the problem of incomplete detection coverage in the existing technology is solved, comprehensive and efficient detection of intranet VPN access points is achieved, and network security is enhanced.
Patent Information
- Application Number
- CN202211658474.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-22
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2042-12-22
AI Technical Summary
In the prior art, the detection and scanning coverage of intranet VPN access points is incomplete, and it is impossible to effectively identify and monitor potential network security risks.
By classifying the access scenarios of intranet VPN access points by user behavior and obtaining deep message detection (DPI) information, the access scenarios of the access points to be detected based on this information. The method includes divided into proxy server type, network address conversion type, non-proxy service type and hybrid scenarios, and is accurately identified through standardized and customized processing DPI information.
It realizes comprehensive and efficient detection of intranet VPN access points, breaks through the limitations of detection based on specific protocol layer, can actively discover potential access risk points, accurately locate penetration sources and penetration methods, and enhances the security isolation capabilities of the intranet.
Smart Images

Figure CN116032794B_ABST
Abstract
Description
Background Art
[0002] Privately accessing an external VPN service access point within the intranet will bring network security risks. It allows external users to enter the intranet through the node springboard for unrestricted access. Therefore, security detection and identification of VPN access points are required.
[0003] In the prior art, although the technology of scanning and identifying VPN users on the external network or installing agent software on the internal network device is simple to implement, there is a problem of incomplete scanning coverage.
[0004] It should be noted that the information disclosed in the above background technology section is only used to enhance the understanding of the background of the present disclosure, and therefore may include information that does not constitute the prior art known to ordinary technicians in the field. Summary of the invention
[0005] The purpose of the present disclosure is to provide a method, device, computer-readable storage medium and electronic device for detecting an intranet virtual private network access point, so as to at least solve the technical problem of incomplete detection and scanning coverage of intranet VPN access points in the related art.
[0006] Other features and advantages of the present disclosure will become apparent from the following detailed description, or may be learned in part by the practice of the present disclosure.
[0007] The technical solution of the present disclosure is as follows:
[0008] According to one aspect of the present disclosure, a method for detecting an intranet virtual private network access point is provided, the method comprising: classifying access scenarios of the intranet virtual private network access points according to user behaviors; obtaining deep packet inspection (DPI) information of the access points to be detected of the intranet virtual private network; and detecting the access scenarios of the access points to be detected based on the DPI information.
[0009] In some embodiments of the present disclosure, the step of classifying access scenarios of an intranet virtual private network access point according to user behavior includes: dividing the access scenarios into proxy server type scenarios and non-proxy service type scenarios according to whether the access point performs forwarding of application requests; dividing the access scenarios into network address translation type scenarios and non-network address translation type scenarios according to whether the access point uses a network address translation method; combining the proxy service type scenarios and non-network address translation type scenarios into a first hybrid scenario; and combining the proxy service type scenarios and the network address translation type scenarios into a second hybrid scenario.
[0010] In some embodiments of the present disclosure, the step of detecting the access scenario of the access point to be detected based on the DPI information includes: detecting the access scenario of the access point to be detected based on the original record in the DPI information; detecting the access scenario of the access point to be detected based on the DPI information after standardized secondary processing; and detecting the access scenario of the access point to be detected based on the DPI information after customized processing.
[0011] In some embodiments of the present disclosure, the step of detecting the access scenario of the access point to be detected based on the original record in the DPI information includes: if there is a situation where a single MAC corresponds to multiple IPs, determining that the access scenario of the access point to be detected is a non-network address translation scenario; if there is a situation where multiple TTL hops appear in the request message under the same IP segment, the access scenario of the access point to be detected is a non-network address translation scenario; if there is a situation where the initial TTL and TTL hops of the request message under the same IP change, determining that the access scenario of the access point to be detected is a network address translation scenario; if there is a situation where the Proxy-Connection request field appears in the application request header, determining that the access scenario of the access point to be detected is a proxy service scenario; and determining whether it is a mixed scenario according to the detection result of the access point to be detected.
[0012] In some embodiments of the present disclosure, the step of detecting the access scenario of the access point to be detected based on the DPI information after standardized secondary processing includes: if there is a situation where multiple TCP sessions are connected to a single IP, and there are no multiple User-Agent terminal operating systems under a single IP, then determining that the access scenario of the access point to be detected is a network address translation scenario; if there is no situation where multiple TCP sessions are connected to a single IP, and there are multiple User-Agent terminal operating systems under a single IP, then determining that the access scenario of the access point to be detected is a proxy service scenario; if there is a situation where multiple TCP sessions are connected to a single IP, and there are multiple User-Agent terminal operating systems under a single IP, then determining that the access scenario of the access point to be detected is a second hybrid scenario.
[0013] In some embodiments of the present disclosure, the step of detecting the access scenario of the access point to be detected based on the customized DPI information includes: if the number of logged-in users corresponding to a single IP of the access point to be detected does not exceed the user threshold value, estimating the one-way delay from the network to the single IP based on the ICMP response time to the single IP; determining the access scenario of the access point to be detected based on the difference between the one-way delay and the delay of other terminal devices in the same network segment; and determining the access scenario of the access point to be detected based on the difference between the one-way delay and the actual session delay; and determining whether it is a mixed scenario based on the detection result of the access point to be detected.
[0014] In some embodiments of the present disclosure, the step of determining the access scenario of the access point to be detected based on the difference between the one-way delay and the delay of other terminal devices in the same network segment includes: if the one-way delay is greater than the sum of the average one-way delay in the same network segment and a first threshold value, then determining that the access scenario of the access point to be detected is a non-network address translation scenario.
[0015] In some embodiments of the present disclosure, the step of determining the access scenario of the access point to be detected according to the difference between the one-way delay and the actual session delay includes: if the delay of the TCP three-way handshake under the single IP is greater than the sum of 3 times the single-way delay and a second threshold value, then determining that the access scenario of the access point to be detected is a network address translation scenario; if the interval between the TCP ack message to the first application request message under the single IP is greater than the sum of 3 times the single-way delay and a third threshold value, then determining that the access scenario of the access point to be detected is a proxy service scenario.
[0016] According to another aspect of the present disclosure, a device for detecting an intranet virtual private network access point is provided, the device comprising: a classification module, used to classify access scenarios of the intranet virtual private network access points according to user behaviors; a DPI information acquisition module, used to acquire DPI information of the access points to be detected of the intranet virtual private network; and a detection module, used to detect the access scenarios of the access points to be detected based on the DPI information.
[0017] According to another aspect of the present disclosure, an electronic device is provided, comprising: a processor; and a memory for storing executable instructions of the processor; wherein the processor is configured to execute the above-mentioned intranet virtual private network access point detection method by executing the executable instructions.
[0018] According to another aspect of the present disclosure, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the above-mentioned method for detecting an intranet virtual private network access point is implemented.
[0019] The method of the embodiment of the present disclosure breaks through the limitation of detection based on a specific protocol layer by performing user behavior profiling based on different VPN access scenarios and proposes a full protocol stack solution, thereby making detection more comprehensive and efficient.
[0020] Furthermore, the disclosed embodiment integrates the access scenarios of related intranet VPNs, and studies intranet VPN access as a system, rather than being limited to a single identification technology. It also does not require prior knowledge of a single access node as a learning sample, and the detection method is simple, effective and versatile.
[0021] Furthermore, the disclosed method can be applied to uniformly monitor and analyze the access security of the intranet, proactively discover potential access risk points, and accurately locate infiltration sources and infiltration methods; it can also serve as an important extension of security components to solve the north-south and east-west security isolation problems of the intranet, and has good application prospects.
[0022] It is to be understood that the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] The accompanying drawings herein are incorporated into the specification and constitute a part of the specification, illustrate embodiments consistent with the present disclosure, and together with the specification are used to explain the principles of the present disclosure. Obviously, the accompanying drawings described below are only some embodiments of the present disclosure, and for ordinary technicians in this field, other accompanying drawings can be obtained based on these accompanying drawings without creative work.
[0024] Figure 1 A flow chart of a method for detecting an intranet virtual private network access point according to an embodiment of the present disclosure is shown.
[0025] Figure 2 A flow chart of a method for classifying access points of an intranet virtual private network according to access scenarios in an embodiment of the present disclosure is shown.
[0026] Figure 3 A schematic diagram of five access scenarios of an access point in an embodiment of the present disclosure is shown.
[0027] Figure 4 A flow chart of a method for detecting an access scenario of an access point to be detected based on DPI information in an embodiment of the present disclosure is shown.
[0028] Figure 5 A flow chart of a method for detecting access scenarios of access points based on original records of DPI messages in an embodiment of the present disclosure is shown.
[0029] Figure 6 A message field showing a correspondence between IP and MAC in an embodiment of the present disclosure is shown.
[0030] Figure 7 A message field of a TTL value in an embodiment of the present disclosure is shown.
[0031] Figure 8 The message fields defined by an HTTP proxy server in an embodiment of the present disclosure are shown.
[0032] Fig. 9 A flow chart of a method for detecting access scenarios of access points based on standardized secondary processed DPI information in an embodiment of the present disclosure is shown.
[0033] Fig.10 The message fields of an HTTP user agent in an embodiment of the present disclosure are shown.
[0034] Fig.11 A flow chart of a method for detecting an access scenario of an access point to be detected based on customized DPI information in an embodiment of the present disclosure is shown.
[0035] Fig.12 A flow chart of a method for detecting an access scenario of an access point to be detected based on customized DPI information in an embodiment of the present disclosure is shown.
[0036] Fig.13 The message fields of a three-way handshake sequence in an embodiment of the present disclosure are shown.
[0037] Fig.14 The message fields of a proxy server-side proxy interaction in an embodiment of the present disclosure are shown.
[0038] Fig.15 A schematic structural diagram of an intranet virtual private network access point detection device in an embodiment of the present disclosure is shown.
[0039] Fig.16 A schematic block diagram of an electronic device showing a method for detecting an intranet virtual private network access point in an embodiment of the present disclosure. DETAILED DESCRIPTION
[0040] Example embodiments will now be described more fully with reference to the accompanying drawings. However, example embodiments can be implemented in a variety of forms and should not be construed as limited to the examples set forth herein; rather, these embodiments are provided so that the disclosure will be more comprehensive and complete and to fully convey the concepts of the example embodiments to those skilled in the art. The described features, structures, or characteristics may be combined in any suitable manner in one or more embodiments.
[0041] In addition, the accompanying drawings are only schematic illustrations of the present disclosure and are not necessarily drawn to scale. The same reference numerals in the figures represent the same or similar parts, and their repeated description will be omitted. Some of the block diagrams shown in the accompanying drawings are functional entities and do not necessarily correspond to physically or logically independent entities. These functional entities can be implemented in software form, or implemented in one or more hardware modules or integrated circuits, or implemented in different networks and / or processor devices and / or microcontroller devices.
[0042] In addition, the terms "first" and "second" are used for descriptive purposes only and should not be understood as indicating or implying relative importance or implicitly indicating the number of the indicated technical features. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of the features. In the description of the present disclosure, the meaning of "plurality" is at least two, such as two, three, etc., unless otherwise clearly and specifically defined.
[0043] In view of the technical problems existing in the above-mentioned related technologies, an embodiment of the present disclosure provides a method for detecting an intranet virtual private network access point, so as to solve at least one or all of the above-mentioned technical problems.
[0044] It should be pointed out that the nouns or terms involved in the embodiments of the present application can refer to each other and will not be repeated here.
[0045] The technical solutions in the embodiments of the present application will be described below in conjunction with the drawings in the embodiments of the present application.
[0046] Figure 1 A flow chart of a method for detecting an intranet virtual private network access point in an embodiment of the present disclosure is shown. Figure 1 As shown, the method 100 may include the following steps:
[0047] In step S110, access scenarios of intranet virtual private network access points are classified according to user behaviors.
[0048] Among them, the access scenarios can be divided into 5 categories according to the user's access behavior, including three basic scenarios, and the latter two are hybrid scenarios under the combination of basic scenarios. Among them, the basic scenarios can include scenarios using the Network Address Translation method (NAT), scenarios not using the NAT method, scenarios using the proxy server method; and scenarios using a combination of the three methods.
[0049] In step S120, the deep packet inspection (DPI) information of the access point to be detected of the intranet virtual private network is obtained.
[0050] In step S130, an access scenario of the access point to be detected is detected based on the DPI information.
[0051] The method of the embodiment of the present disclosure breaks through the limitation of detection based on a specific protocol layer by performing user behavior profiling based on different VPN access scenarios and proposes a full protocol stack solution, thereby making detection more comprehensive and efficient.
[0052] Furthermore, the disclosed embodiment integrates the access scenarios of related intranet VPNs, and studies intranet VPN access as a system, rather than being limited to a single identification technology. It also does not require prior knowledge of a single access node as a learning sample, and the detection method is simple, effective and versatile.
[0053] Furthermore, the disclosed method can be applied to uniformly monitor and analyze the access security of the intranet, proactively discover potential access risk points, and accurately locate infiltration sources and infiltration methods; it can also serve as an important extension of security components to solve the north-south and east-west security isolation problems of the intranet, and has good application prospects.
[0054] In some embodiments of the present disclosure, step S110 may include: dividing the access scenario into a proxy server type scenario and a non-proxy service type scenario according to whether the access point performs forwarding of application requests; dividing the access scenario into a network address translation type scenario and a non-network address translation type scenario according to whether the access point uses a network address translation method; combining the proxy service type scenario and the non-network address translation type scenario into a first hybrid scenario; and combining the proxy service type scenario and the network address translation type scenario into a second hybrid scenario.
[0055] For example Figure 2 A flow chart of a method for classifying access points of an intranet virtual private network according to access scenarios is shown, such as Figure 2 As shown, the method 200 may include the following steps:
[0056] In step S210, it is determined whether the access point forwards the application request.
[0057] If yes, the access scenario of the access point is a proxy service scenario.
[0058] If not, the access scenario of the access point is a non-proxy service scenario.
[0059] In step S220, it is determined whether the access point uses a network address translation method.
[0060] If yes, the access scenario of the access point is a network scenario conversion scenario.
[0061] If not, the access scenario of the access point is a network address translation scenario.
[0062] In step S230, if the access point is in both a proxy service scenario and a non-NAT scenario, the access scenario of the access point is a first hybrid scenario.
[0063] In step S240, if the access point is in both a proxy service type scenario and a NAT type scenario, the access scenario of the access point is a second hybrid scenario.
[0064] Among them, the scene diagrams of the five access scenarios of the access point are as follows Figure 3 As shown:
[0065] The non-NAT scenario 310 is to configure the intranet IP on the remote terminal 311, through the tunnel external terminal 311, the Internet 312 and the VPN access point 313, and the VPN access point 313 strips the tunnel to retain the intranet IP and establish a two-way routing, so that the remote terminal 311 can use its own intranet IP to directly connect to the application service 315 of the intranet 314. In this way, the remote terminal 311 can use its own IP alone to achieve two-way access to the application service 315.
[0066] In the NAT type scenario 320, NAT address mapping is performed at the VPN access point. After the traffic of the remote terminal 321 reaches the VPN access point 323 through the tunnel of the external terminal 321, the Internet 322 and the VPN access point 323, the VPN access point 323 uses NAT to transform the IP address and communicates using the intranet side IP and the application service 325 of the intranet 324.
[0067] The proxy service scenario 330 is a scenario using an application proxy server, such as using an http proxy. The external terminal 331 submits the application request message to the proxy server 333 via the Internet 332, and the proxy server 333 completes the intranet 334 connection and communication interaction with the application server 335.
[0068] The hybrid scenarios 340 and 350 are respectively formed by the combination of the non-NAT type 310 and the proxy service type scenario 330, and the NAT type 320 and the proxy service type scenario 330, and therefore both have the traffic characteristic behaviors of the first three.
[0069] The hybrid scenario 340 is a combination scenario of the non-NAT type 310 and the proxy service type scenario 330. The external terminal 341 directly communicates with the proxy server 342 and forwards the corresponding application service request to the proxy server 342. The proxy server 342 configures the intranet IP, converts the request of the external terminal 341 into its own request forwarding, and uses the encapsulated tunnel proxy server 342, the Internet 343 and the VPN access point 344, and the VPN access point 344 strips the tunnel to retain the intranet IP, and establishes a two-way routing method, so that the proxy server 342 uses its own intranet IP to directly connect with the application service 346 of the intranet 345.
[0070] The hybrid scenario 350 is a combination scenario of the NAT type 320 and the proxy service type scenario 330, in which the external terminal 351 forwards the corresponding application service request to the proxy server 352; the proxy server 352 is configured with an intranet IP, converts the request of the external terminal 351 into its own request and forwards the message, and sends the message to the tunnel proxy server 352, the Internet 353 and the VPN access point 354, and the VPN access point 354 uses NAT to transform the IP address, and uses the VPN access point 354 to communicate with the application service 356 of the intranet 355 using the intranet side IP.
[0071] The method of the embodiment of the present disclosure is divided into different access scenarios according to traffic behavior characteristics, is applicable to multiple VPN access scenarios, and broadens the applicability of detection.
[0072] In some embodiments of the present disclosure, step S130 may include: Figure 4 A method for detecting an access scenario of an access point to be detected based on DPI information is shown, such as Figure 4 As shown, method 400 may include the following steps:
[0073] In step S410, the access scenario of the access point to be detected is detected based on the original record in the DPI information.
[0074] In step S420, the access scenario of the access point to be detected is detected based on the DPI information after the standardized secondary processing.
[0075] In step S430, the access scenario of the access point to be detected is detected based on the customized DPI information.
[0076] Through the depth of message-based protocol analysis and the degree of customization of information processing, the data judgment method is divided into three stages, which are progressive according to the complexity of information processing, and determine whether there is VPN intranet access and corresponding access scenarios.
[0077] Different from existing similar research patents that only rely on a single protocol feature (such as Time To Live (TTL)), the method of the embodiment of the present disclosure defines analysis and judgment rules (such as Table 1) according to the classification rules of the access scenario and the traffic characteristics of the application protocol. The analysis rules profile user traffic and end node characteristics based on DPI data, involving the IP network layer, TCP session layer and Http application layer, and classify and judge in combination with the corresponding layer protocol parameters to achieve comprehensive and accurate VPN access detection.
[0078] Among them, the analysis and judgment rules are shown in Table 1:
[0079]
[0080]
[0081] Steps S410 , S420 and S430 will be described in detail below with reference to the accompanying drawings.
[0082] In some embodiments of the present disclosure, step S410 may be as follows: Figure 5 The method 500 shown has the following process:
[0083] In step S502, the MAC address corresponding to the IP is recorded.
[0084] The message definition is as follows: Figure 6 shown.
[0085] In step S504, it is determined whether there is a scenario where multiple IPs correspond to the same physical end node.
[0086] If there is no situation where a single MAC corresponds to multiple ICs, step S508 is directly executed.
[0087] In step S506, if there is a situation where a single MAC corresponds to multiple IPs, the access scenario of the access point to be detected is a non-network address translation scenario.
[0088] In step S508, the survival time TTL corresponding to the IP is recorded.
[0089] The message definition is as follows: Figure 7 shown.
[0090] In step S510, it is determined whether a request message has multiple TTL hops in the same IP segment.
[0091] If the request message does not have multiple TTL hops under the same IP segment, step S514 is directly executed.
[0092] In step S512, if there is a situation where a request message under the same IP segment has multiple TTL hops, it is determined that the access scenario of the access point to be detected is a non-network address translation NAT scenario.
[0093] In step S514, it is determined whether the TTL value in the same IP segment has changed, that is, it is determined whether the initial TTL and TTL hop number of the request message in the same IP segment have changed.
[0094] The initial TTL is a number selected from a number set (64, 128, 256) that is closest to the current TTL value.
[0095] If the TTL value does not change under the same IP segment, directly execute step S518.
[0096] In step S516, if there is a situation where the initial TTL and TTL hop number of the request message under the same IP change, it is determined that the access scenario of the access point to be detected is a network address translation scenario.
[0097] In step S518, the http request message header is recorded.
[0098] The message definition is as follows: Figure 8 shown.
[0099] In step S520, it is determined whether the http request contains proxy path information, that is, whether the Proxy-Connection request field appears in the Http request message.
[0100] If the proxy path information is not included, the access point detection process ends directly.
[0101] In step S522, if the Proxy-Connection request field appears in the application request header, it is determined that the access scenario of the access point to be detected is a proxy service scenario.
[0102] In step S524, it is determined whether the detection result of the access point to be detected is a hybrid scenario.
[0103] If there is no hybrid scenario, the access point detection process ends directly.
[0104] In step S526, if it exists, it is determined whether it is the first hybrid scene or the second hybrid scene.
[0105] This detection phase makes direct judgments based on the original records of the message, and analyzes the corresponding fields at the IP and Http layers to achieve comprehensive and accurate VPN access detection.
[0106] In some embodiments of the present disclosure, step S420 may further include: if there is a situation where a single IP is connected to multiple TCP sessions, and there are not multiple User-Agent terminal operating systems under a single IP, it can be determined that the access scenario of the access point to be detected is a network address translation scenario; if there is no situation where a single IP is connected to multiple TCP sessions, and there are multiple User-Agent terminal operating systems under a single IP, then the access scenario of the access point to be detected is a proxy service scenario; if there is a situation where a single IP is connected to multiple TCP sessions, and there are multiple User-Agent terminal operating systems under a single IP, then the access scenario of the access point to be detected is a second hybrid scenario.
[0107] Specifically, for example Fig. 9 The method 900 shown has the following process:
[0108] In step S910, terminal tracks are distinguished according to TCP timestamps.
[0109] In step S920, it is determined whether a single IP terminal is connected to multiple TCP sessions.
[0110] Specifically, the calculation process is defined as follows:
[0111] Assume that the start time of the session record of two DPIs of a single IP terminal is T 1 and T 2 , the corresponding TCP timestamp is T S1 and T S2 , determine whether two TCP sessions come from the same IP terminal using the following formula (1):
[0112]
[0113] If the value is approximately 1, the two call records are determined to be from the same terminal. Otherwise, they are determined to be from two terminals. All call records for a single IP are merged and calculated in sequence to confirm whether there is a scenario where a single IP is connected to multiple TCP session terminals.
[0114] In some embodiments of the present disclosure, if there is no situation where a single IP is connected to multiple TCP sessions, step S940 is directly executed.
[0115] In step S930, if there is a situation where a single IP is connected to multiple TCP sessions, it is determined that the access scenario of the access point to be detected is a network address translation scenario.
[0116] In step S940, the HTTP User-agent system information is recorded.
[0117] The User-agent message is defined as follows: Fig.10 shown.
[0118] In step S950, it is determined whether there are multiple User-Agent terminal operating systems under the same TCP session.
[0119] In some embodiments of the present disclosure, if there is no multiple system information, the access point detection process is directly terminated.
[0120] In step S960, if there are multiple User-Agent terminal operating systems under the same TCP session (single IP), it is determined that the access scenario of the access point to be detected is a proxy service scenario.
[0121] In step S970, it is determined whether the detection result of the access point to be detected is a hybrid scenario.
[0122] If it is not a hybrid scenario, the access point detection process ends.
[0123] In step S980, if it is a hybrid scenario, it is determined that the access point to be detected is a second hybrid scenario.
[0124] Comprehensive and accurate VPN access detection is achieved through integrated analysis based on the session layer TCP timestamp and HTTP User-Agent fields.
[0125] In some embodiments of the present disclosure, step S430 may also include, for example Fig.11 A flow chart of a method for detecting access scenarios of access points to be detected based on customized DPI information is shown. Fig.11 As shown, method 1100 may include the following steps:
[0126] In step S1110, it is determined whether the number of logged-in users corresponding to a single IP of the access point to be detected exceeds a user threshold.
[0127] In some embodiments of the present disclosure, if the number of logged-in users exceeds the user threshold, it is determined that the node does not provide normal access, and the access point detection process ends.
[0128] For example, by searching for keyword information including user names in the http URI requests of critical applications, we can intercept and analyze the rationality of specific IP access sources, record vectors [average number of concurrent online accounts per unit time, historical number of online accounts], and determine whether the node provides normal access based on the account access records per unit time.
[0129] In step S1120, if the number of logged-in users corresponding to a single IP of the access point to be detected does not exceed the user threshold, the one-way delay from the network to the single IP is estimated based on the Internet Control Message Protocol (ICMP) response time to the single IP.
[0130] For example, an ICMP request is sent to a single IP, or a TCP connection request is initiated to its known port. The average one-way delay of a single IP is confirmed based on the returned message and marked as D, which is used as the basis for subsequent judgments.
[0131] In step S1130, the access scenario of the access point to be detected is determined according to the difference between the one-way delay and the delay of other terminal devices in the same network segment.
[0132] In step S1140, the access scenario of the access point to be detected is determined according to the difference between the one-way delay and the actual session delay.
[0133] In step S1150, it is determined whether it is a hybrid scenario according to the detection result of the access point to be detected.
[0134] This is achieved through customized data field analysis, application layer and active testing, and comprehensive and accurate VPN access detection. Furthermore, the VPN access determination method for different scenarios based on one-way delay also ensures the security of intranet VPN access.
[0135] In some embodiments of the present disclosure, step S1130 may include: if the one-way delay is greater than the sum of the one-way delay average in the same network segment and the first threshold value, the access scenario of the access point to be detected is a non-network address translation scenario.
[0136] The value of the first threshold may be one-way delay*1 / 4.
[0137] In some embodiments of the present disclosure, step S1140 may include: if the delay of the TCP three-way handshake under a single IP is greater than the sum of 3 times the single-item delay and the second threshold value, the access scenario of the access point to be detected is a network address translation scenario; if the interval between the TCP ack message to the first application request message under a single IP is greater than the sum of 3 times the single-item delay and the third threshold value, the access scenario of the access point to be detected is a proxy service scenario.
[0138] The second threshold and the third threshold may be set to one-way delay*1 / 4.
[0139] It should be noted that in the NAT scenario, the three interactive messages of SYN\ACK\SYNACK are completed by the application server and the remote terminal. For details, see Fig.13 The time interval between the first and third messages is shown. TCP three-way handshake delay = one-way delay in LAN*3+one-way delay in Internet*3.
[0140] It should also be noted that in the proxy service scenario, since the TCP three-way handshake is a direct interaction between the proxy server and the application server, there is no obvious difference in the intranet. Therefore, the delay difference is the time interval from the server sending the [syn, ack] message to the end user sending the first application request message. For details, see Fig.14 The time interval between message No. 6 and message No. 11 shown is actually only three one-way message transmissions on the application server side.
[0141] In some embodiments of the present disclosure, step S430 may also include, for example Fig.12 FIG. 2 shows another method flow chart for detecting an access scenario of an access point to be detected based on customized DPI information. Fig.12 As shown, the method 1200 may include the following steps:
[0142] In step S1202, the user login information of the corresponding application on the IP is recorded.
[0143] In step S1204, it is determined whether the number of users logged in to the application corresponding to a single IP exceeds the threshold.
[0144] If yes, the access point detection process ends directly.
[0145] In step S1206, if the number of logged-in users corresponding to the specific IP of the access point to be detected does not exceed the user threshold, the one-way delay from the network to the specified IP is estimated based on the Internet Control Message Protocol (ICMP) response time to the specified IP.
[0146] In step S1208, it is determined whether the one-way delay D is greater than the sum of the one-way delay average value in the same network segment and the first threshold value.
[0147] In step S1210, if the one-way delay D is greater than the sum of the one-way delay average value in the same network segment and the first threshold value, it is determined that the access scenario of the access point to be detected is a non-network address translation scenario.
[0148] In step S1212, it is determined whether the delay of the TCP three-way handshake under a single IP is greater than the sum of three times the single-way delay and the second threshold value.
[0149] If the delay of the TCP three-way handshake under a single IP is not greater than the sum of three times the single-way delay and the second threshold value, step S1216 is directly executed.
[0150] In step S1214, if the delay of the TCP three-way handshake under a single IP is greater than the sum of three times the single-item delay and the second threshold value, it is determined that the access scenario of the access point to be detected is a proxy service scenario.
[0151] In step S1216, it is determined whether the interval from TCP ack to the first application request message under a single IP is greater than the sum of three times the single-item delay and the third threshold.
[0152] If the interval between TCP ack and the first application request message under a single IP is not greater than the sum of 3 times the single-item delay and the third threshold, the access point detection process is terminated directly.
[0153] In step S1218, if the interval between TCP ack and the first application request message under a single IP is greater than the sum of 3 times the single-item delay and the third threshold, it is determined that the access scenario of the access point to be detected is a proxy service scenario.
[0154] In step S1220, it is determined whether it is a hybrid scenario according to the detection result of the access point to be detected.
[0155] If it is not a hybrid scenario, the access point detection process ends.
[0156] In step S1222, if it is a mixed scenario, it is determined that the access point to be detected is a first or second mixed scenario.
[0157] The following is an example of monitoring the security access of internal applications:
[0158] 1. First, establish DPI traffic mirroring analysis for key application access at the core point, collect real-time data and track it for a period of time.
[0159] 2. Perform basic message data analysis, such as: if the TTL value of an IP request changes or does not match the actual TTL hops to it, it can be determined that the IP provides VPN access service; if an IP http request message carries proxy connection information, it can be determined that the IP provides application proxy service.
[0160] 3. In order to prevent the access point from concealing the aforementioned information, the user-agent and TCP timestamp information in the http header can be further combined for correlation analysis. First, analyze whether there are multi-threaded tracks in the TCP timestamp under a single IP to determine whether the actual TCP session is a single one. Then query whether the operating system and terminal identifiers in the user-agent information are consistent. Finally, based on the combination of the two, comprehensively determine whether the IP address access is normal and the corresponding access scenario. For example, if a single IP has only one timestamp but multiple user-agents, it can be determined as proxy service access.
[0161] 4. If the above information is still likely to be hidden, it can be mined and analyzed in combination with the network delay characteristics and application characteristic information, that is, to check whether there are multiple application accounts accessing a single node at the same time, and to check whether the delay of the TCP three-way handshake and the delay characteristics from the handshake to the first application request are consistent with the delay characteristics of the existing network segment.
[0162] Fig.15 A schematic diagram of an intranet virtual private network access point detection device according to an embodiment of the present disclosure is shown. Fig.15 As shown, the device 1500 includes:
[0163] The classification module 1510 is used to classify the access scenarios of the intranet virtual private network access points according to user behavior; the DPI information acquisition module 1520 is used to obtain the DPI information of the access points to be detected of the intranet virtual private network; and the detection module 1530 is used to detect the access scenarios of the access points to be detected based on the DPI information.
[0164] In some embodiments of the present disclosure, the classification module 1510 is also used to divide the access scenario into a proxy server type scenario and a non-proxy service type scenario according to whether the access point performs forwarding of application requests; divide the access scenario into a network address translation type scenario and a non-network address translation type scenario according to whether the access point uses a network address translation method; combine the proxy service type scenario and the non-network address translation type scenario into a first hybrid scenario; and combine the proxy service type scenario and the network address translation type scenario into a second hybrid scenario.
[0165] In some embodiments of the present disclosure, the detection module 1530 also includes a first detection module, which is used to detect the access scenario of the access point to be detected based on the original record in the DPI information; a second detection module, which is used to detect the access scenario of the access point to be detected based on the DPI information after standardized secondary processing; and a third detection module, which is used to detect the access scenario of the access point to be detected based on the DPI information after customized processing.
[0166] In some embodiments of the present disclosure, the first detection module may also be used to determine that if a single MAC corresponds to multiple IPs, the access scenario of the access point to be detected is a non-network address translation scheme; if multiple TTL hops appear in the request message under the same IP segment, the access scenario of the access point to be detected is a non-network address translation scenario; if the initial TTL and TTL hops of the request message under the same IP vary, the access scenario of the access point to be detected is a network address translation scenario; if a Proxy-Connection request field appears in the application request header, the access scenario of the access point to be detected is a proxy service scenario; and determine whether it is a mixed scenario based on the detection result of the access point to be detected.
[0167] In some embodiments of the present disclosure, the second detection module can also be used for if there is a situation where a single IP is connected to multiple TCP sessions, and there are no multiple User-Agent terminal operating systems under a single IP, then the access scenario of the access point to be detected is a network address translation scenario; if there is no situation where a single IP is connected to multiple TCP sessions, and there are multiple User-Agent terminal operating systems under a single IP, then the access scenario of the access point to be detected is a proxy service scenario; if there is a situation where a single IP is connected to multiple TCP sessions, and there are multiple User-Agent terminal operating systems under a single IP, then the access scenario of the access point to be detected is a second hybrid scenario.
[0168] In some embodiments of the present disclosure, the third detection module can also be used to estimate the one-way delay from the network to a single IP based on the ICMP response time to the single IP if the number of logged-in users corresponding to a single IP of the access point to be detected does not exceed the user threshold value; determine the access scenario of the access point to be detected according to the difference between the one-way delay and the delay of other terminal devices in the same network segment; and determine the access scenario of the access point to be detected according to the difference between the one-way delay and the actual session delay; and determine whether it is a mixed scenario based on the detection result of the access point to be detected.
[0169] In some embodiments of the present disclosure, the third detection module may also be used to determine that the access scenario of the access point to be detected is a non-network address translation scenario if the one-way delay is greater than the sum of the one-way delay average in the same network segment and the first threshold value.
[0170] In some embodiments of the present disclosure, the third detection module can be used to: if the delay of the TCP three-way handshake under the single IP is greater than the sum of 3 times the single-item delay and the second threshold value, then the access scenario of the access point to be detected is a network address translation scenario; if the interval between the TCP ack message to the first application request message under the single IP is greater than the sum of 3 times the single-item delay and the third threshold value, then the access scenario of the access point to be detected is a proxy service scenario.
[0171] Regarding the intranet virtual private network access point detection device 1500 in the above embodiment, the specific manner in which each module performs operations has been described in detail in the embodiment of the method, and will not be elaborated here.
[0172] Those skilled in the art will appreciate that various aspects of the present disclosure may be implemented as systems, methods or program products. Therefore, various aspects of the present disclosure may be specifically implemented in the following forms, namely: complete hardware implementation, complete software implementation (including firmware, microcode, etc.), or a combination of hardware and software, which may be collectively referred to herein as "circuits", "modules" or "systems".
[0173] Refer to the following Fig.16 1600 according to this embodiment of the present disclosure is described. Fig.16 The electronic device 1600 shown is merely an example and should not bring any limitation to the functions and scope of use of the embodiments of the present disclosure.
[0174] like Fig.16 As shown, the electronic device 1600 is in the form of a general computing device. The components of the electronic device 1600 may include but are not limited to: at least one processing unit 1610, at least one storage unit 1620, and a bus 1630 connecting different system components (including the storage unit 1620 and the processing unit 1610).
[0175] The storage unit stores program codes, which can be executed by the processing unit 1610, so that the processing unit 1610 performs the steps described in the above “Exemplary Method” section of this specification according to various exemplary embodiments of the present disclosure. For example, the processing unit 1610 can perform the following steps: Figure 1 In step S110 shown in the figure, the access scenarios of the intranet virtual private network access points are classified according to user behaviors; in step S120, deep packet inspection DPI information of the access points to be detected of the intranet virtual private network is obtained; in step S130, the access scenarios of the access points to be detected are detected based on the DPI information.
[0176] The storage unit 1620 may include a readable medium in the form of a volatile storage unit, such as a random access memory unit (RAM) 1621 and / or a cache memory unit 1622 , and may further include a read-only memory unit (ROM) 1623 .
[0177] The storage unit 1620 may also include a program / utility 1624 having a set (at least one) of program modules 1625, such program modules 1625 including but not limited to: an operating system, one or more application programs, other program modules, and program data, each of which or some combination may include an implementation of a network environment.
[0178] Bus 1630 may represent one or more of several types of bus structures, including a memory unit bus or memory unit controller, a peripheral bus, an accelerated graphics port, a processing unit, or a local bus using any of a variety of bus architectures.
[0179] The electronic device 1600 may also communicate with one or more external devices (e.g., keyboards, pointing devices, Bluetooth devices, etc.), may also communicate with one or more devices that enable a user to interact with the electronic device 1600, and / or communicate with any device that enables the electronic device 1600 to communicate with one or more other computing devices (e.g., routers, modems, etc.). Such communication may be performed via an input / output (I / O) interface 1650. Furthermore, the electronic device 1600 may also communicate with one or more networks (e.g., a local area network (LAN), a wide area network (WAN), and / or a public network, such as the Internet) via a network adapter 1660. As shown, the network adapter 1660 communicates with other modules of the electronic device 1600 via a bus 1630. It should be understood that, although not shown in the figure, other hardware and / or software modules may be used in conjunction with the electronic device 1600, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems.
[0180] In an exemplary embodiment of the present disclosure, a computer-readable storage medium is also provided, on which a program product capable of implementing the above method of the present specification is stored. In some possible implementations, various aspects of the present disclosure may also be implemented in the form of a program product, which includes a program code, and when the program product is run on a terminal device, the program code is used to enable the terminal device to execute the steps according to various exemplary implementations of the present disclosure described in the above "Exemplary Method" section of the present specification.
[0181] The program product for implementing the above method according to the embodiment of the present disclosure may adopt a portable compact disk read-only memory (CD-ROM) and include program code, and may be run on a terminal device, such as a personal computer. However, the program product of the present disclosure is not limited thereto, and in this document, a readable storage medium may be any tangible medium containing or storing a program, which may be used by or in combination with an instruction execution system, a server, a terminal or a device.
[0182] The program product may be any combination of one or more readable media. The readable medium may be a readable signal medium or a readable storage medium. The readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, server, terminal, or device, or any combination thereof. More specific examples (non-exhaustive list) of readable storage media include: an electrical connection with one or more wires, a portable disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof.
[0183] Computer readable signal media may include data signals propagated in baseband or as part of a carrier wave, wherein readable program code is carried. Such propagated data signals may take a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. Readable signal media may also be any readable medium other than a readable storage medium, which may send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, server, terminal, or device.
[0184] The program code embodied on the readable medium may be transmitted using any appropriate medium, including but not limited to wireless, wired, optical cable, RF, etc., or any suitable combination of the foregoing.
[0185] Program code for performing the operations of the present disclosure may be written in any combination of one or more programming languages, including object-oriented programming languages such as Java, C++, etc., and conventional procedural programming languages such as "C" or similar programming languages. The program code may be executed entirely on the user computing device, partially on the user device, as a separate software package, partially on the user computing device and partially on a remote computing device, or entirely on a remote computing device or server. In cases involving a remote computing device, the remote computing device may be connected to the user computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computing device (e.g., through the Internet using an Internet service provider).
[0186] According to one aspect of the present disclosure, a computer program product or a computer program is provided, the computer program product or the computer program including computer instructions, the computer instructions being stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the computer device executes the methods provided in various optional implementations of the above-mentioned embodiments.
[0187] It should be noted that, although several modules or units of the device for action execution are mentioned in the above detailed description, this division is not mandatory. In fact, according to the embodiments of the present disclosure, the features and functions of two or more modules or units described above can be embodied in one module or unit. On the contrary, the features and functions of one module or unit described above can be further divided into multiple modules or units to be embodied.
[0188] In addition, although the steps of the method in the present disclosure are described in a specific order in the drawings, this does not require or imply that the steps must be performed in this specific order, or that all the steps shown must be performed to achieve the desired results. Additionally or alternatively, some steps may be omitted, multiple steps may be combined into one step, and / or one step may be decomposed into multiple steps, etc.
[0189] Through the description of the above implementation, it is easy for those skilled in the art to understand that the example implementation described here can be implemented by software, or by software combined with necessary hardware. Therefore, the technical solution according to the implementation of the present disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, including several instructions to enable a computing device (which can be a personal computer, a server, a mobile terminal, or a network device, etc.) to execute the method according to the implementation of the present disclosure.
[0190] Those skilled in the art will readily appreciate other embodiments of the present disclosure after considering the specification and practicing the invention disclosed herein. This application is intended to cover any modification, use or adaptation of the present disclosure, which follows the general principles of the present disclosure and includes common knowledge or customary techniques in the art that are not disclosed in the present disclosure. The specification and examples are intended to be exemplary only, and the true scope and spirit of the present disclosure are indicated by the appended claims.
Claims
1. A method for detecting an intranet virtual private network access point, characterized in that: The method comprises: Classify the access scenarios of intranet virtual private network access points according to user behavior; Obtaining deep packet inspection (DPI) information of the access point to be detected of the intranet virtual private network; and Detecting an access scenario of the access point to be detected based on the DPI information; The step of detecting the access scenario of the access point to be detected based on the DPI information includes: Detecting the access scenario of the access point to be detected based on the original record in the DPI information; The step of detecting the access scenario of the access point to be detected based on the original record in the DPI information includes: If there is a situation where a single MAC corresponds to multiple IPs, determining that the access scenario of the access point to be detected is a non-network address translation scenario; If there are multiple TTL hops in the request message under the same IP segment, the access scenario of the access point to be detected is a non-network address translation scenario; If there is a situation where the initial TTL and TTL hop number of the request message under the same IP change, it is determined that the access scenario of the access point to be detected is a network address translation scenario; If there is a Proxy-Connection request field in the application request header, determining that the access scenario of the access point to be detected is a proxy service scenario; and Whether it is a mixed scenario is determined according to the detection result of the access point to be detected.
2. The method for detecting an intranet virtual private network access point according to claim 1, characterized in that: The steps of classifying the access scenarios of the intranet virtual private network access points according to user behavior include: Depending on whether the access point performs application request forwarding, the access scenarios are divided into proxy server type scenarios and non-proxy service type scenarios; The access scenarios are divided into network address translation scenarios and non-network address translation scenarios according to whether the access point uses the network address translation method; The proxy service scenario and the non-network address translation scenario are combined into a first hybrid scenario; and The proxy service scenario and the network address translation scenario are combined into a second hybrid scenario.
3. The method for detecting an intranet virtual private network access point according to claim 2, characterized in that: The step of detecting the access scenario of the access point to be detected based on the DPI information further includes: Detecting the access scenario of the access point to be detected based on the DPI information after standardized secondary processing; and The access scenario of the access point to be detected is detected based on the customized DPI information.
4. The method for detecting an intranet virtual private network access point according to claim 3, characterized in that: The step of detecting the access scenario of the access point to be detected based on the DPI information after the standardized secondary processing includes: If there is a situation where multiple TCP sessions are connected to a single IP, and there is no situation where there are multiple User-Agent terminal operating systems under a single IP, it is determined that the access scenario of the access point to be detected is a network address translation scenario; If there is no situation where multiple TCP sessions are connected to a single IP, and there is a situation where multiple User-Agent terminal operating systems are connected to a single IP, it is determined that the access scenario of the access point to be detected is a proxy service scenario; If there is a situation where a single IP is connected to multiple TCP sessions, and there are multiple User-Agent terminal operating systems under the single IP, it is determined that the access scenario of the access point to be detected is the second hybrid scenario.
5. The method for detecting an intranet virtual private network access point according to claim 4, characterized in that: The step of detecting the access scenario of the access point to be detected based on the customized DPI information includes: If the number of logged-in users corresponding to a single IP of the access point to be detected does not exceed the user threshold, the one-way delay from the network to the single IP is estimated based on the ICMP response time to the single IP; Determining the access scenario of the access point to be detected according to the difference between the one-way delay and the delay of other terminal devices in the same network segment; and Determining the access scenario of the access point to be detected according to the difference between the one-way delay and the actual session delay; and Whether it is a mixed scenario is determined according to the detection result of the access point to be detected.
6. The method for detecting an intranet virtual private network access point according to claim 5, characterized in that: The step of determining the access scenario of the access point to be detected according to the difference between the one-way delay and the delay of other terminal devices in the same network segment includes: If the one-way delay is greater than the sum of the one-way delay average value in the same network segment and the first threshold value, it is determined that the access scenario of the access point to be detected is a non-network address translation scenario.
7. An intranet virtual private network access point detection device, characterized in that: The device comprises: A classification module, used to classify the access scenarios of the intranet virtual private network access points according to user behaviors; A DPI information acquisition module is used to acquire DPI information of the access point to be detected of the intranet virtual private network; and A detection module, configured to detect an access scenario of the access point to be detected based on the DPI information; The detection module is further used to detect the access scenario of the access point to be detected based on the original record in the DPI information; The detection module is further used to determine that the access scenario of the access point to be detected is a non-network address translation scenario if there is a situation where a single MAC corresponds to multiple IPs; If there are multiple TTL hops in the request message under the same IP segment, the access scenario of the access point to be detected is a non-network address translation scenario; If there is a situation where the initial TTL and TTL hop number of the request message under the same IP change, it is determined that the access scenario of the access point to be detected is a network address translation scenario; If there is a Proxy-Connection request field in the application request header, determining that the access scenario of the access point to be detected is a proxy service scenario; and Whether it is a mixed scenario is determined according to the detection result of the access point to be detected.
8. An electronic device, characterized in that: include: processor; as well as A memory, configured to store executable instructions of the processor; The processor is configured to execute the method for detecting an intranet virtual private network access point according to any one of claims 1 to 6 by executing the executable instructions.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the method for detecting an intranet virtual private network access point according to any one of claims 1 to 6 is implemented.
Citation Information
Patent Citations
Network sharing device detection method and system based on DPI technology
CN106411644A