Abnormal proxy connection recognition method, device, equipment and storage medium
By detecting and recording Socks5 proxy connection information of intranet asset data and analyzing it in association with security incidents, the problem that the prior art cannot effectively block abnormal proxy connections is solved, and the security of the network is improved.
Patent Information
- Application Number
- CN202310014240.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-01-05
- Publication Date
- 2025-06-10
- Estimated Expiration
- 2043-01-05
AI Technical Summary
The prior art cannot effectively block Socks proxy forwarding when detecting and blocking abnormal proxy connections, resulting in attackers being able to detect or intrude into the intranet, and the network security is low.
By detecting that intranet asset data flows through the gateway device, determine whether its destination IP address is the external network address. If not, determine whether its proxy protocol is the Socks5 proxy protocol, and record the proxy connection information. Obtain security events generated by the security engine for threat detection of intranet asset data, associate the attacker's IP address or the IP address of the attacker with the proxy connection information, and determine the proxy connection information of the target IP address is abnormal.
It can record the attacker's actions or active time when the first time the agent is connected to the host on the host, helping network administrators identify and analyze the risks in the network, take timely defense measures, avoid attackers from intruding into the intranet, and improve network security.
Smart Images

Figure CN116132145B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the technical fields of network communication and network security, and in particular, to a method, apparatus, device, and storage medium for identifying abnormal proxy connections. Background Art
[0002] With the popularization of the Internet in people's lives, more and more users are concerned about the security of network communication. During the process of intranet penetration by attackers, after successfully attacking a host, they usually use the attacked host as a springboard to continue attacking other hosts.
[0003] Since it is easy to detect the installation of attack tools on the host used as a springboard, a proxy is usually set up on the host used as a springboard, and the attacker uses the proxy to attack other hosts, so there may be abnormal proxy access between hosts in the network.
[0004] Related technologies use abnormal proxy detection strategies such as network intrusion prevention and access control policy management to block or warn against Socks proxy forwarding for springboard attacks. However, when the actions of abnormal proxy detection strategies such as network intrusion prevention and access control policy management are configured as warnings, the Socks proxy forwarding cannot be successfully blocked, and the attacker can still detect or intrude into the intranet, resulting in risks in the network and low network security. Summary of the Invention
[0005] In view of this, embodiments of the present disclosure provide a method, apparatus, device, and storage medium for identifying abnormal proxy connections, which can record the actions or active times of the attacker's first connection to the proxy on the host, so as to facilitate network administrators to manage and analyze these abnormal proxy connection events, help administrators identify and analyze the risks existing in the network, take defensive measures in a timely manner, prevent attackers from intruding into the intranet, and improve network security.
[0006] In a first aspect, embodiments of the present disclosure provide a method for identifying abnormal proxy connections, adopting the following technical solution:
[0007] When it is detected that the intranet asset data flows through the gateway device and the destination IP address of the intranet asset data is not an external network address, determine whether the proxy protocol of the intranet asset data is the Socks5 proxy protocol;
[0008] When the proxy protocol is the Socks5 proxy protocol, record the proxy connection information of the destination IP address into the proxy connection data table;
[0009] Obtain the security events generated by the security engine for threat detection of the intranet asset data;
[0010] Associate the IP address of the attacker or the IP address of the attacked object in the security event with the proxy connection information;
[0011] When the IP address of the attacker or the IP address of the attacked object is successfully associated with the proxy connection information, determine that the proxy connection information of the target IP address is abnormal.
[0012] In some embodiments, when the proxy protocol is the Socks5 proxy protocol, record the proxy connection information of the destination IP address into the proxy connection data table, including:
[0013] Query whether the destination IP address exists in the proxy connection data table;
[0014] When the destination IP address exists in the proxy connection data table, update the historical proxy connection information of the destination IP address, where the historical proxy connection information includes at least one of the historical active time and the historical connection IP address of the destination IP address;
[0015] When the destination IP address does not exist in the proxy connection data table, record the first proxy connection information of the destination IP address, where the first proxy connection information includes at least one of the destination IP address, the first detection date of the destination IP address, the first connection IP address, the historical active time, and the historical connection IP address.
[0016] In some embodiments, associating the IP address of the attacker or the IP address of the attacked object in the security event with the proxy connection information includes:
[0017] Match the IP address of the attacker or the IP address of the attacked object with the destination IP address, the first connection IP address, and the historical connection IP address in the proxy connection data table;
[0018] When the IP address of the attacker is the union set of the destination IP address, the first connection IP address, and the historical connection IP address, confirm that the IP address of the attacker is successfully associated with the proxy connection information;
[0019] When the IP address of the attacked object is the union set of the destination IP address, the first connection IP address, and the historical connection IP address, confirm that the IP address of the attacked object is successfully associated with the proxy connection information.
[0020] In some embodiments, obtaining the security events generated by the security engine for threat detection of the internal network asset data includes:
[0021] Obtain the threat information of the attack source obtained by the security engine for threat detection of the intranet asset data, where the threat information includes at least one of the attacker's IP address, the IP address of the attacked object, the attack direction, the threat level of the attack event, and the attack chain stage level;
[0022] Generate a security event according to the threat information.
[0023] In some embodiments, when the attacker's IP address or the IP address of the attacked object is successfully associated with the proxy connection information, it is determined that the proxy connection information of the target IP address is abnormal, including:
[0024] When the attacker's IP address or the IP address of the attacked object is successfully associated with the proxy connection information, obtain the threat level of the attack event, the attack chain stage level, and the attack direction in the threat information;
[0025] When the attack direction is the destination IP address, and the threat level of the attack event or the attack chain stage level reaches the preset risk level threshold, it is determined that the intranet asset data has the risk of being network attacked by the attacker and the proxy connection information of the target IP address is abnormal.
[0026] In a second aspect, the embodiments of the present disclosure also provide an abnormal proxy connection recognition device, which adopts the following technical solutions:
[0027] A detection unit, configured to determine whether the proxy protocol of the intranet asset data is the Socks5 proxy protocol when it is detected that the intranet asset data flows through the gateway device and the destination IP address of the intranet asset data is not an external network address;
[0028] An information recording unit, configured to record the proxy connection information of the destination IP address into the proxy connection data table when the proxy protocol is the Socks5 proxy protocol;
[0029] An acquisition unit, configured to acquire the security event generated by the security engine for threat detection of the intranet asset data;
[0030] An association unit, configured to associate the attacker's IP address or the IP address of the attacked object in the security event with the proxy connection information;
[0031] An abnormal recognition unit, configured to determine that the proxy connection information of the target IP address is abnormal when the attacker's IP address or the IP address of the attacked object is successfully associated with the proxy connection information.
[0032] In some embodiments, the information recording unit includes:
[0033] A query module, configured to query whether the destination IP address exists in the proxy connection data table;
[0034] An update module, configured to update the historical proxy connection information of the destination IP address when the destination IP address exists in the proxy connection data table, where the historical proxy connection information includes at least one of the historical active time and the historical connection IP address of the destination IP address;
[0035] An addition module, configured to record the first proxy connection information of the destination IP address when the destination IP address does not exist in the proxy connection data table, where the first proxy connection information includes at least one of the destination IP address, the first detection date of the destination IP address, the first connection IP address, the historical active time, and the historical connection IP address.
[0036] In some embodiments, the association unit includes:
[0037] A matching module, configured to match the IP address of the attacker or the IP address of the attacked object with the destination IP address, the first connection IP address, and the historical connection IP address in the proxy connection data table;
[0038] An attacker association module, configured to confirm that the IP address of the attacker is successfully associated with the proxy connection information when the IP address of the attacker is the union set of the destination IP address, the first connection IP address, and the historical connection IP address;
[0039] An attacked object association module, configured to confirm that the IP address of the attacked object is successfully associated with the proxy connection information when the IP address of the attacked object is the union set of the destination IP address, the first connection IP address, and the historical connection IP address.
[0040] In a third aspect, an embodiment of the present disclosure further provides an electronic device, adopting the following technical solution:
[0041] The electronic device includes:
[0042] At least one processor; and,
[0043] A memory communicatively connected to the at least one processor; wherein,
[0044] The memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute any one of the above abnormal proxy connection recognition methods.
[0045] In a fourth aspect, embodiments of the present disclosure further provide a computer-readable storage medium storing computer instructions for causing a computer to execute the abnormal proxy connection recognition method described in any one of the above.
[0046] An abnormal proxy connection recognition method, apparatus, device, and storage medium provided by embodiments of the present disclosure, when detecting that internal network asset data flows through a gateway device, determine whether the destination IP address of the internal network asset data is an external network address. When the destination IP address is an external network address, determine whether the proxy protocol of the internal network asset data is the Socks5 proxy protocol. If it is the Socks5 proxy protocol, record the proxy connection information of the destination IP address in the proxy connection data table, and obtain security events generated by a security engine for threat detection of the internal network asset data; associate the IP address of the attacker or the IP address of the attacked object in the security event with the proxy connection information; when the IP address of the attacker or the IP address of the attacked object is successfully associated with the proxy connection information, determine that the proxy connection information of the target IP address is abnormal. Embodiments of the present disclosure can record the actions or active times of an attacker's first connection to a proxy on a host, and perform correlation analysis on security events and proxy connection information, so as to facilitate network administrators to manage and analyze these abnormal proxy connection events, help administrators identify and analyze risks existing in the network, take defensive measures in a timely manner, prevent attackers from invading the internal network, and improve network security.
[0047] The above description is only an overview of the technical solutions of the present disclosure. In order to understand the technical means of the present disclosure more clearly, it can be implemented according to the content of the specification. In order to make the above and other purposes, features, and advantages of the present disclosure more obvious and understandable, the following specific preferred embodiments are given, and in conjunction with the accompanying drawings, the details are described as follows. BRIEF DESCRIPTION OF THE DRAWINGS
[0048] In order to more clearly illustrate the technical solutions of the embodiments of the present disclosure, the accompanying drawings required for the embodiments will be briefly introduced below. Obviously, the accompanying drawings in the following description are only some embodiments of the present disclosure. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0049] Figure 1 It is a flowchart showing a method for recognizing an abnormal proxy connection provided by an embodiment of the present disclosure;
[0050] Figure 2 It is a structural diagram showing an apparatus for recognizing an abnormal proxy connection provided by an embodiment of the present disclosure;
[0051] Figure 3 It is a structural diagram showing another apparatus for recognizing an abnormal proxy connection provided by an embodiment of the present disclosure;
[0052] Figure 4 A structural schematic diagram of another abnormal proxy connection recognition device provided by an embodiment of the present disclosure;
[0053] Figure 5 A principle block diagram of an electronic device provided by an embodiment of the present disclosure. Specific embodiments
[0054] The embodiments of the present disclosure will be described in detail below with reference to the accompanying drawings.
[0055] It should be clear that the following uses specific specific examples to illustrate the implementation manners of the present disclosure, and those skilled in the art can easily understand other advantages and effects of the present disclosure from the content disclosed in this specification. Obviously, the described embodiments are only a part of the embodiments of the present disclosure, rather than all the embodiments. The present disclosure can also be implemented or applied through other different specific implementation manners, and various details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of the present disclosure. It should be noted that, without conflict, the following embodiments and the features in the embodiments can be combined with each other. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present disclosure without creative efforts belong to the scope of protection of the present disclosure.
[0056] It should be noted that the following describes various aspects of embodiments within the scope of the appended claims. It should be apparent that the aspects described herein can be embodied in a wide variety of forms, and any specific structure and / or function described herein is illustrative only. Based on the present disclosure, those skilled in the art should understand that one aspect described herein can be implemented independently of any other aspect, and two or more of these aspects can be combined in various ways. For example, any number of aspects described herein can be used to implement the device and / or practice the method. In addition, this device and / or this method can be implemented using other structures and / or functions in addition to one or more of the aspects described herein.
[0057] It should also be noted that the diagrams provided in the following embodiments only illustrate the basic concept of the present disclosure schematically, and only the components related to the present disclosure are shown in the diagrams, rather than being drawn according to the number, shape and size of the components in actual implementation. The type, quantity and proportion of each component in its actual implementation can be an arbitrary change, and the component layout type may also be more complex.
[0058] In addition, in the following description, specific details are provided to facilitate a thorough understanding of the examples. However, those skilled in the art will understand that the described aspects can be practiced without these specific details.
[0059] As shown Figure 1 in the figure, an embodiment of the present disclosure provides an abnormal proxy connection recognition method, including the following steps:
[0060] S101. When it is detected that the intranet asset data flows through the gateway device, determine whether the destination IP address of the intranet asset data is an external network address. If the destination IP address is not an external network address, execute step S102; if the destination IP address is an external network address, execute step S107.
[0061] S102. Determine whether the proxy protocol of the intranet asset data is the Socks5 proxy protocol. If the proxy protocol of the intranet asset data is the Socks5 proxy protocol, execute step S103; if the proxy protocol of the intranet asset data is not the Socks5 proxy protocol, execute step S107.
[0062] S103. Record the proxy connection information of the destination IP address into the proxy connection data table.
[0063] S104. Obtain the security events generated by the security engine for threat detection of the intranet asset data.
[0064] When the intranet asset data flows through the gateway device, the security engine performs threat detection on the intranet asset data. When the threat information of the attack source is detected, security events are generated.
[0065] Optionally, the security engine such as IPS, WAF, botnet, virus, ADS, DLP, advanced threat, etc. can be used to perform threat detection on the intranet asset data, and the embodiments of the present disclosure do not limit this.
[0066] S105. Associate the IP address of the attacker or the IP address of the attacked object in the security event with the proxy connection information.
[0067] S106. When the IP address of the attacker or the IP address of the attacked object is successfully associated with the proxy connection information, determine that the proxy connection information of the target IP address is abnormal.
[0068] S107. End.
[0069] The embodiments of the present disclosure can record the actions or active times of the attacker's first connection to the proxy on the host, and perform correlation analysis on the security events and the proxy connection information, so as to facilitate network administrators to manage and analyze these abnormal proxy connection events, help administrators identify and analyze the risks existing in the network, take defensive measures in a timely manner, avoid attackers from intruding into the intranet, and improve network security.
[0070] In some embodiments, in step S103 above, when the proxy protocol is the Socks5 proxy protocol, recording the proxy connection information of the destination IP address into the proxy connection data table includes:
[0071] Querying whether there is a destination IP address in the proxy connection data table;
[0072] When there is a destination IP address in the proxy connection data table, updating the historical proxy connection information of the destination IP address, where the historical proxy connection information includes at least one of the historical active time of the destination IP address and the historical connection IP address;
[0073] When there is no destination IP address in the proxy connection data table, recording the first proxy connection information of the destination IP address, where the first proxy connection information includes at least one of the destination IP address, the first detection date of the destination IP address, the first connection IP address, the historical active time, and the historical connection IP address.
[0074] Optionally, the historical active time may be the active time of the destination IP address at the previous time node, and the historical connection IP address may be the connection IP address of the destination IP address at the previous time node.
[0075] In some embodiments, step S105, associating the IP address of the attacker or the IP address of the attacked object in the security event with the proxy connection information, includes:
[0076] Matching the IP address of the attacker or the IP address of the attacked object with the destination IP address, the first connection IP address, and the historical connection IP address in the proxy connection data table;
[0077] When the IP address of the attacker is the union set of the destination IP address, the first connection IP address, and the historical connection IP address, it is confirmed that the IP address of the attacker is successfully associated with the proxy connection information;
[0078] When the IP address of the attacked object is the union set of the destination IP address, the first connection IP address, and the historical connection IP address, it is confirmed that the IP address of the attacked object is successfully associated with the proxy connection information.
[0079] In some embodiments, in step S104 above, obtaining the security events generated by the security engine for threat detection of the intranet asset data includes:
[0080] Obtaining the threat information of the attack source obtained by the security engine for threat detection of the intranet asset data, where the threat information includes at least one of the IP address of the attacker, the IP address of the attacked object, the attack direction, the threat level of the attack event, and the attack chain stage level;
[0081] Generate security events based on threat information.
[0082] In some embodiments, in step S106 above, when the IP address of the attacker or the IP address of the attacked object is successfully associated with the proxy connection information, determining that the proxy connection information of the target IP address is abnormal includes:
[0083] When the IP address of the attacker or the IP address of the attacked object is successfully associated with the proxy connection information, obtain the threat level of the attack event, the attack chain phase level, and the attack direction in the threat information;
[0084] When the attack direction is the destination IP address, and the threat level of the attack event or the attack chain phase level reaches the preset risk level threshold, determine that the intranet asset data has the risk of being attacked by the attacker and the proxy connection information of the target IP address is abnormal.
[0085] In the embodiments of the present disclosure, by tracking the proxy connection protocol of the intranet asset data, the proxy connection information of the destination IP address is generated by obtaining the destination IP address, the first detection date of the destination IP address, the first connected IP address of the destination IP address, the active time of the previous time node of the destination IP address, and the connected IP address of the previous time node of the destination IP address, and the proxy connection information is recorded in the proxy connection data table.
[0086] Perform correlation analysis on the proxy connection data table and the security events, and determine whether the proxy connection is abnormal according to the correlation analysis result. This facilitates network administrators to manage and analyze these abnormal proxy events, helps administrators identify and analyze the risks existing in the network, take defensive measures in a timely manner, and improve the security of the network.
[0087] As Figure 2 shown, the embodiments of the present disclosure also provide an abnormal proxy connection recognition device, including:
[0088] A detection unit 21, configured to determine whether the proxy protocol of the intranet asset data is the Socks5 proxy protocol when it is detected that the intranet asset data flows through the gateway device and the destination IP address of the intranet asset data is not an external network address;
[0089] An information recording unit 22, configured to record the proxy connection information of the destination IP address in the proxy connection data table when the proxy protocol is the Socks5 proxy protocol;
[0090] An obtaining unit 23, configured to obtain the security events generated by the security engine for threat detection of the intranet asset data;
[0091] The association unit 24 is configured to associate the IP address of the attacker or the IP address of the attacked object in the security event with the proxy connection information;
[0092] The anomaly recognition unit 25 is configured to determine that the proxy connection information of the target IP address is abnormal when the IP address of the attacker or the IP address of the attacked object is successfully associated with the proxy connection information.
[0093] As Figure 3 shown, in some embodiments, the information recording unit 22 includes:
[0094] The query module 221 is configured to query whether there is a destination IP address in the proxy connection data table;
[0095] The update module 222 is configured to update the historical proxy connection information of the destination IP address when there is a destination IP address in the proxy connection data table, where the historical proxy connection information includes at least one of the historical active time and the historical connection IP address of the destination IP address;
[0096] The addition module 223 is configured to record the first proxy connection information of the destination IP address when there is no destination IP address in the proxy connection data table, where the first proxy connection information includes at least one of the destination IP address, the first detection date of the destination IP address, the first connection IP address, the historical active time, and the historical connection IP address.
[0097] As Figure 4 shown, in some embodiments, the association unit 24 includes:
[0098] The matching module 241 is configured to match the IP address of the attacker or the IP address of the attacked object with the destination IP address, the first connection IP address, and the historical connection IP address in the proxy connection data table;
[0099] The attacker association module 242 is configured to confirm that the IP address of the attacker is successfully associated with the proxy connection information when the IP address of the attacker is the union set of the destination IP address, the first connection IP address, and the historical connection IP address;
[0100] The attacked object association module 243 is configured to confirm that the IP address of the attacked object is successfully associated with the proxy connection information when the IP address of the attacked object is the union set of the destination IP address, the first connection IP address, and the historical connection IP address.
[0101] An electronic device according to an embodiment of the present disclosure includes a memory and a processor. The memory is used to store non-transitory computer-readable instructions. Specifically, the memory may include one or more computer program products, and the computer program products may include various forms of computer-readable storage media, such as volatile memory and / or non-volatile memory. The volatile memory may include, for example, random access memory (RAM) and / or cache memory, etc. The non-volatile memory may include, for example, read-only memory (ROM), hard disk, flash memory, etc.
[0102] The processor may be a central processing unit (CPU) or other forms of processing units having data processing capabilities and / or instruction execution capabilities, and may control other components in the electronic device to perform desired functions. In an embodiment of the present disclosure, the processor is used to run the computer-readable instructions stored in the memory, so that the electronic device executes all or part of the steps of the abnormal proxy connection recognition method according to the foregoing embodiments of the present disclosure.
[0103] Those skilled in the art should understand that, in order to solve the technical problem of how to obtain good user experience effects, known structures such as communication buses and interfaces may also be included in this embodiment, and these known structures should also be included in the protection scope of the present disclosure.
[0104] As Figure 5 FIG. is a schematic structural diagram of an electronic device provided by an embodiment of the present disclosure. It shows a schematic structural diagram of an electronic device suitable for implementing the electronic device in the embodiments of the present disclosure. Figure 5 The shown electronic device is only an example and should not bring any limitation to the functions and usage scope of the embodiments of the present disclosure.
[0105] As Figure 5 As shown, the electronic device may include a processing device (such as a central processing unit, a graphics processing unit, etc.), which may perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) or a program loaded from a storage device into a random access memory (RAM). In the RAM, various programs and data required for the operation of the electronic device are also stored. The processing device, ROM, and RAM are connected to each other through a bus. The input / output (I / O) interface is also connected to the bus.
[0106] Generally, the following devices may be connected to the I / O interface: an input device including, for example, a sensor or a visual information acquisition device, etc.; an output device including, for example, a display screen, etc.; a storage device including, for example, a magnetic tape, a hard disk, etc.; and a communication device. The communication device may allow the electronic device to communicate with other devices (such as edge computing devices) wirelessly or wiredly to exchange data. Although Figure 5An electronic device having various devices is shown, but it should be understood that it is not required to implement or have all the shown devices. Instead, more or fewer devices may be implemented or had.
[0107] In particular, according to an embodiment of the present disclosure, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, an embodiment of the present disclosure includes a computer program product that includes a computer program carried on a non-transitory computer-readable medium, and the computer program includes program codes for performing the methods shown in the flowcharts. In such an embodiment, the computer program can be downloaded and installed from a network through a communication device, or installed from a storage device, or installed from a ROM. When the computer program is executed by a processing device, all or part of the steps of the abnormal proxy connection recognition method according to the embodiments of the present disclosure are executed.
[0108] For a detailed description of this embodiment, reference may be made to the corresponding descriptions in the foregoing embodiments, and details are not repeated herein.
[0109] A computer-readable storage medium according to an embodiment of the present disclosure stores non-temporary computer-readable instructions. When the non-temporary computer-readable instructions are run by a processor, all or part of the steps of the abnormal proxy connection recognition methods according to the foregoing embodiments of the present disclosure are executed.
[0110] The above-mentioned computer-readable storage media include but are not limited to: optical storage media (such as CD-ROMs and DVDs), magneto-optical storage media (such as MOs), magnetic storage media (such as magnetic tapes or external hard drives), media having built-in rewritable non-volatile memories (such as memory cards), and media having built-in ROMs (such as ROM cartridges).
[0111] For a detailed description of this embodiment, reference may be made to the corresponding descriptions in the foregoing embodiments, and details are not repeated herein.
[0112] The basic principles of the present disclosure have been described above in conjunction with specific embodiments. However, it should be noted that the advantages, benefits, effects, etc. mentioned in the present disclosure are only examples and not limitations, and it cannot be considered that these advantages, benefits, effects, etc. are essential for each embodiment of the present disclosure. In addition, the above-mentioned specific details are only for illustrative purposes and for the purpose of facilitating understanding, and are not limitations. The above details do not limit the present disclosure to necessarily adopt the above specific details for implementation.
[0113] In this disclosure, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. The block diagrams of the devices, apparatuses, equipment, and systems involved in this disclosure are only illustrative examples and do not intend to require or imply that they must be connected, arranged, and configured in the manner shown in the block diagrams. As those skilled in the art will recognize, these devices, apparatuses, equipment, and systems can be connected, arranged, and configured in any manner. Words such as "including", "comprising", "having", etc. are open-ended terms, meaning "including but not limited to", and can be used interchangeably with each other. The words "or" and "and" used herein refer to the word "and / or" and can be used interchangeably with it, unless the context clearly indicates otherwise. The word "such as" used herein refers to the phrase "such as but not limited to" and can be used interchangeably with it.
[0114] In addition, as used herein, the "or" used in the listing of items starting with "at least one" indicates a disjunctive listing. So, for example, the listing of "at least one of A, B, or C" means A or B or C, or AB or AC or BC, or ABC (i.e., A and B and C). Furthermore, the term "exemplary" does not mean that the examples described are preferred or better than other examples.
[0115] It should also be noted that in the systems and methods of this disclosure, each component or each step can be decomposed and / or recombined. These decompositions and / or recombinations should be regarded as equivalent solutions of this disclosure.
[0116] Various changes, substitutions, and alterations to the technologies described herein can be made without departing from the teachings defined by the appended claims. In addition, the scope of the claims of this disclosure is not limited to the specific aspects of the processes, machines, manufactures, compositions of events, means, methods, and acts described above. Current or later-developed processes, machines, manufactures, compositions of events, means, methods, or acts that perform substantially the same function or achieve substantially the same result as the corresponding aspects described herein can be utilized. Thus, the appended claims include such processes, machines, manufactures, compositions of events, means, methods, or acts within their scope.
[0117] The above description of the disclosed aspects is provided to enable any person skilled in the art to make or use this disclosure. Various modifications to these aspects are very obvious to those skilled in the art, and the general principles defined herein can be applied to other aspects without departing from the scope of this disclosure. Therefore, this disclosure is not intended to be limited to the aspects shown herein, but rather to the broadest scope consistent with the principles and novel features disclosed herein.
[0118] The foregoing description has been presented for purposes of illustration and description. In addition, this description is not intended to limit embodiments of the present disclosure to the form disclosed herein. Although several example aspects and embodiments have been discussed above, those skilled in the art will recognize some of their variations, modifications, alterations, additions, and subcombinations.
Claims
1. An abnormal proxy connection identification method, characterized in that, it includes: When it is detected that the internal network asset data flows through the gateway device and the destination IP address of the internal network asset data is not an external network address, determine whether the proxy protocol of the internal network asset data is the Socks5 proxy protocol; When the proxy protocol is the Socks5 proxy protocol, record the proxy connection information of the destination IP address into the proxy connection data table; Obtain the security events generated by the security engine for threat detection of the internal network asset data; Associate the IP address of the attacker or the IP address of the attacked object in the security event with the proxy connection information; When the IP address of the attacker or the IP address of the attacked object is successfully associated with the proxy connection information, determine that the proxy connection information of the destination IP address is abnormal; When the proxy protocol is the Socks5 proxy protocol, recording the proxy connection information of the destination IP address into the proxy connection data table includes: Query whether the destination IP address exists in the proxy connection data table; When the destination IP address exists in the proxy connection data table, update the historical proxy connection information of the destination IP address, where the historical proxy connection information includes at least one of the historical active time and the historical connection IP address of the destination IP address; When the destination IP address does not exist in the proxy connection data table, record the first proxy connection information of the destination IP address, where the first proxy connection information includes at least one of the destination IP address, the first detection date of the destination IP address, the first connection IP address, the historical active time, and the historical connection IP address.
2. The abnormal proxy connection identification method according to claim 1, characterized in that, Associating the IP address of the attacker or the IP address of the attacked object in the security event with the proxy connection information includes: Matching the IP address of the attacker or the IP address of the attacked object with the destination IP address, the first connection IP address, and the historical connection IP address in the proxy connection data table; When the IP address of the attacker is the union set of the destination IP address, the first connection IP address, and the historical connection IP address, confirm that the IP address of the attacker is successfully associated with the proxy connection information; When the IP address of the attacked object is the union set of the destination IP address, the first connection IP address, and the historical connection IP address, confirm that the IP address of the attacked object is successfully associated with the proxy connection information.
3. The abnormal proxy connection identification method according to claim 1, characterized in that, Obtaining the security events generated by the security engine for threat detection of the internal network asset data includes: Obtaining the threat information of the attack source obtained by the security engine for threat detection of the internal network asset data, where the threat information includes at least one of the IP address of the attacker, the IP address of the attacked object, the attack direction, the threat level of the attack event, and the attack chain stage level; Generate a security event based on the threat information.
4. The abnormal proxy connection identification method according to claim 3, wherein, when the IP address of the attacker or the IP address of the attacked object is successfully associated with the proxy connection information, determining that the proxy connection information of the destination IP address is abnormal, including: when the IP address of the attacker or the IP address of the attacked object is successfully associated with the proxy connection information, obtaining the threat level of the attack event, the stage level of the attack chain, and the attack direction in the threat information; when the attack direction is the destination IP address, and the threat level of the attack event or the stage level of the attack chain reaches a preset risk level threshold, determining that the internal network asset data has a risk of being attacked by the attacker and the proxy connection information of the destination IP address is abnormal.
5. An abnormal proxy connection identification device, wherein, comprising: a detection unit, configured to determine whether the proxy protocol of the internal network asset data is the Socks5 proxy protocol when it is detected that the internal network asset data flows through the gateway device and the destination IP address of the internal network asset data is not an external network address; an information recording unit, configured to record the proxy connection information of the destination IP address into the proxy connection data table when the proxy protocol is the Socks5 proxy protocol; an obtaining unit, configured to obtain a security event generated by the security engine for threat detection of the internal network asset data; an association unit, configured to associate the IP address of the attacker or the IP address of the attacked object in the security event with the proxy connection information; an abnormality identification unit, configured to determine that the proxy connection information of the destination IP address is abnormal when the IP address of the attacker or the IP address of the attacked object is successfully associated with the proxy connection information; the information recording unit includes: a query module, configured to query whether the destination IP address exists in the proxy connection data table; an update module, configured to update the historical proxy connection information of the destination IP address when the destination IP address exists in the proxy connection data table, where the historical proxy connection information includes at least one of the historical active time and the historical connection IP address of the destination IP address; an addition module, configured to record the first proxy connection information of the destination IP address when the destination IP address does not exist in the proxy connection data table, where the first proxy connection information includes at least one of the destination IP address, the first detection date of the destination IP address, the first connection IP address, the historical active time, and the historical connection IP address.
6. The abnormal proxy connection identification device according to claim 5, wherein, the association unit includes: a matching module, configured to match the IP address of the attacker or the IP address of the attacked object with the destination IP address, the first connection IP address, and the historical connection IP address in the proxy connection data table; An attacker association module, configured to confirm that the IP address of the attacker is successfully associated with the proxy connection information when the IP address of the attacker is the union set of the destination IP address, the first connection IP address, and the historical connection IP address; A target under attack association module, configured to confirm that the IP address of the target under attack is successfully associated with the proxy connection information when the IP address of the target under attack is the union set of the destination IP address, the first connection IP address, and the historical connection IP address.
7. An electronic device, characterized in that, the electronic device includes: at least one processor; and, a memory communicatively connected to the at least one processor; wherein, the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the abnormal proxy connection identification method according to any one of claims 1 to 4.
8. A computer-readable storage medium, characterized in that, the computer-readable storage medium stores computer instructions for causing a computer to execute the abnormal proxy connection identification method according to any one of claims 1 to 4.
Citation Information
Patent Citations
Network access abnormity detection method and device
CN107395608A
Reverse tracing method and device of proxy host
CN108881271A