IP address blocking processing method and device, electronic equipment and storage medium

By identifying the IP address of the attack source and its network device, and combining this with the network topology to generate a blocking strategy and send it to the firewall, the problem of poor network defense effectiveness in existing technologies is solved, and more flexible and precise IP address blocking is achieved.

CN116260618BActive Publication Date: 2026-01-27CHINA UNITED NETWORK COMM GRP CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202211661128.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-23
Publication Date
2026-01-27
Estimated Expiration
2042-12-23

AI Technical Summary

Technical Problem

Existing technologies have poor network defense capabilities, making it difficult to accurately locate and effectively block malicious IP addresses, resulting in ineffective handling of network security incidents.

Method used

By identifying the source IP address of the attack and the source network device to which it belongs, as well as the destination network device where the IP address of the attacked target is located, and combining this with the network system topology, a blocking policy is generated and sent to the firewalls in the attack path to achieve flexible blocking of the source IP address of the attack.

Benefits of technology

It improves the effectiveness of network defense and is more flexible than fixed-egress firewalls. It can dynamically adjust blocking strategies according to attack paths, thus improving the accuracy and efficiency of blocking.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116260618B_ABST
    Figure CN116260618B_ABST
Patent Text Reader

Abstract

The application provides a blocking processing method and device of an IP address, an electronic device and a storage medium. The method comprises the following steps: when it is determined that a network system accessed into the blocking system exists a network attack, determining an attack source IP address; determining a source network device to which the attack source IP address belongs and a destination network device where an attacked object IP address is located; determining an attack path of an attack source according to a network topology structure of the source network device, the destination network device and the network system; generating a corresponding blocking strategy according to the attack source IP address, the attacked object IP address and device information of at least one firewall; and sending the blocking strategy to at least one firewall in the attack path, so that the at least one firewall can perform blocking processing on the attack source IP address according to the corresponding blocking strategy when the attack source IP address appears again in the network system. The method can improve the network defense effect.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to network security technology, and in particular to a method, apparatus, electronic device, and storage medium for blocking IP addresses. Background Technology

[0002] With the development of network security technology, IP address blocking methods have emerged to improve the security of network systems.

[0003] When blocking IP addresses, operations engineers often manually input information to configure firewalls and routers to block malicious IPs in order to achieve secure operations. However, in handling network security incidents, operations engineers commonly use fixed exit firewalls for blocking, which makes it difficult to achieve optimal blocking results and lacks accurate location and analysis of malicious IP attacks, thus significantly reducing the effectiveness of network defense. Summary of the Invention

[0004] This application provides a method, apparatus, electronic device, and storage medium for blocking IP addresses, in order to solve the technical problem of poor network defense effectiveness in the prior art.

[0005] Firstly, this application provides a method for blocking IP addresses, comprising:

[0006] When it is determined that a network system connected to the blocking system is under attack, the IP address of the attack source is determined;

[0007] Determine the source network device to which the attack source IP address belongs, and the destination network device to which the attacked target IP address is located;

[0008] Based on the network topology of the source network device, the destination network device, and the network system, the attack path of the attack source is determined. The attack path includes multiple network devices between the source network device and the destination network device, and at least one firewall is included among the multiple network devices.

[0009] Based on the attack source IP address, the attacked target IP address, and the device information of the at least one firewall, a corresponding blocking strategy is generated.

[0010] The blocking policy is sent to at least one firewall in the attack path. When the attack source IP address reappears in the network system, the at least one firewall can block the attack source IP address according to the corresponding blocking policy.

[0011] In one embodiment, determining the source network device to which the attack source IP address belongs includes:

[0012] Scan the routing information of all gateway devices in the network system to determine directly connected routes;

[0013] The direct route is matched with the attack source IP address to determine the source network device to which the attack source IP address belongs.

[0014] In one embodiment, determining the target network device where the IP address of the attacked object is located includes:

[0015] Starting with the network device to which the attack source IP address belongs, the network devices in the network system are traversed one by one until the target network device where the attacked target IP address is located is determined.

[0016] In one embodiment, determining the attack path of the attack source based on the network topology of the source network device, the destination network device, and the network system includes:

[0017] Based on the network topology of the source network device, the destination network device, and the network system, candidate attack paths for the attack source are obtained.

[0018] If it is determined that there is no loop on the candidate attack path of the attack source, then the candidate attack path of the attack source is determined as the attack path of the attack source.

[0019] Secondly, this application provides an IP address blocking processing device, comprising:

[0020] The attack source IP address determination module is used to determine the attack source IP address when it is determined that a network system connected to the blocking system is under network attack.

[0021] The network device determination module is used to determine the source network device to which the attack source IP address belongs, and the destination network device to which the attacked target IP address is located.

[0022] An attack path determination module is used to determine the attack path of the attack source based on the source network device, the destination network device, and the network topology of the network system. The attack path includes multiple network devices between the source network device and the destination network device, and the multiple network devices include at least one firewall.

[0023] The blocking policy generation module is used to generate a corresponding blocking policy based on the attack source IP address, the attacked target IP address, and the device information of the at least one firewall.

[0024] A blocking policy sending module is used to send the blocking policy to at least one firewall in the attack path. When the attack source IP address reappears in the network system, the at least one firewall can block the attack source IP address according to the corresponding blocking policy.

[0025] Thirdly, this application provides an electronic device, including: a processor, and a memory communicatively connected to the processor;

[0026] The memory stores computer-executed instructions;

[0027] The processor executes computer execution instructions stored in the memory to implement the method as described in the first aspect.

[0028] Fourthly, this application provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, are used to implement the method described in the first aspect.

[0029] The IP address blocking method, apparatus, electronic device, and storage medium provided in this application, when determining that a network system connected to the blocking system is under attack, determines the attack source IP address; determines the source network device to which the attack source IP address belongs, and the destination network device where the attacked target IP address is located; determines the attack path of the attack source based on the source network device, the destination network device, and the network topology of the network system, the attack path including multiple network devices between the source network device and the destination network device, the multiple network devices including at least one firewall; generates a corresponding blocking policy based on the attack source IP address, the attacked target IP address, and the device information of the at least one firewall; sends the blocking policy to the at least one firewall in the attack path, and when the attack source IP address reappears in the network system, enables the at least one firewall to block the attack source IP address according to the corresponding blocking policy. In network defense, the attack path of the attack source is determined based on the attack source IP address and the IP address of the attacked target. At least one firewall is determined based on the attack path of the attack source, which is the network device through which the attack source IP address passes. Therefore, the attack source IP address is blocked based on the at least one firewall and the corresponding blocking policy. This is more flexible than the method of blocking only a fixed exit firewall, and thus can improve the effectiveness of network defense. Attached Figure Description

[0030] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.

[0031] Figure 1 This is an application scenario diagram illustrating the IP address blocking method described in this application embodiment;

[0032] Figure 2 This is a flowchart illustrating an embodiment of the IP address blocking method of this application;

[0033] Figure 3 This is a flowchart illustrating another embodiment of the IP address blocking method of this application;

[0034] Figure 4 This is a schematic diagram of the network topology of a network system in one embodiment of this application;

[0035] Figure 5 This is a schematic diagram of the structure of the IP address blocking processing device implemented in this application;

[0036] Figure 6 This is a schematic diagram of the electronic device used to implement the IP address blocking method.

[0037] The accompanying drawings illustrate specific embodiments of this application, which will be described in more detail below. These drawings and descriptions are not intended to limit the scope of the concept in any way, but rather to illustrate the concept of this application to those skilled in the art through reference to particular embodiments. Detailed Implementation

[0038] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.

[0039] To clearly understand the technical solution of this application, the solutions of the prior art will be described in detail first.

[0040] In the traditional approach, IP address blocking is handled manually by operations engineers when configuring firewalls and routers to block malicious IPs for secure operations. However, in handling network security incidents, operations engineers often use fixed exit firewalls for blocking, which makes it difficult to achieve optimal blocking results and lacks accurate location and analysis of malicious IP attacks, thus significantly reducing the effectiveness of network defense.

[0041] Therefore, when faced with the technical problems of existing technologies, the inventors, through creative research, discovered that in order to improve the effectiveness of network system defense, when it is determined that a network system connected to the blocking system is under attack, the attacker's source IP address is first identified, along with the source network device to which the attacker's source IP address belongs and the destination network device where the attacked target's IP address is located. Then, the attack path of the attacker's source is obtained to identify at least one firewall present in the attack path. Finally, a corresponding blocking policy is generated so that at least one firewall can block the attacker's source IP address according to the corresponding blocking policy. Since the attack path of the attacker's source is determined based on the attacker's source IP address and the attacked target's IP address, and at least one firewall is determined based on the attack path (i.e., the network device through which the attacker's source IP address passes), blocking the attacker's source IP address based on at least one firewall and the corresponding generated blocking policy is more flexible than using only a fixed exit firewall, thus improving the effectiveness of network defense.

[0042] like Figure 1 As shown in the embodiment of this application, the application scenario of the IP address blocking method includes an electronic device 10 in the corresponding network architecture. The electronic device 10 is equipped with a blocking system, and a network system is connected to the blocking system. When the electronic device 10 determines that a network attack exists in the network system connected to the blocking system, it determines the attack source IP address. It then determines the source network device to which the attack source IP address belongs, and the destination network device where the attacked target IP address is located. Based on the source network device, the destination network device, and the network topology of the network system, the attack path of the attack source is determined. Based on the attack source IP address, the attacked target IP address, and the device information of at least one firewall, a corresponding blocking policy is generated. The blocking policy is sent to at least one firewall in the attack path. When the attack source IP address reappears in the network system, at least one firewall can block the attack source IP address according to the corresponding blocking policy.

[0043] The technical solution of this application and how the technical solution of this application solves the above-mentioned technical problems are described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments. The embodiments of this application will now be described with reference to the accompanying drawings.

[0044] Figure 2 This application provides an embodiment of an IP address blocking method, such as... Figure 2As shown, the execution subject of the IP address blocking method provided in this embodiment is an electronic device. Therefore, the IP address blocking method provided in this embodiment includes the following steps:

[0045] Step 101: When it is determined that a network system connected to the blocking system is under network attack, determine the IP address of the attack source.

[0046] A blocking system is a system that blocks the IP addresses that launch attacks when a network system is under attack. A blocking system can connect to multiple clients' network systems, providing network defense services to each client individually. The attack source IP address is the IP address that launches the attack on the network system.

[0047] Electronic devices monitor the network system's status in real time, thus enabling them to determine immediately whether a network attack is occurring. When a network attack is detected, an alarm 5-tuple is received, confirming the attack. This alarm 5-tuple includes the source IP address, source port, destination IP address, destination port, and transport layer protocol. The source IP address is the same as the attack source IP address. In other words, the attack can be determined based on the alarm 5-tuple.

[0048] Step 102: Determine the source network device to which the attack source IP address belongs, and the destination network device to which the attacked target IP address is located.

[0049] In this context, the source network device is a network device within the network system, specifically the network device to which the attack source IP address belongs. The network device to which the attack source IP address belongs refers to the network device that owns the network segment containing the attack source IP address. The destination network device is also a network device within the network system, specifically the network device containing the IP address of the target being attacked. The target IP address refers to the IP address of the object that the attack source intends to attack, i.e., the destination IP address in the five-tuple of the alarm information.

[0050] Optionally, based on the routing information of each network device in the network system, the network device to which the attack source IP address belongs and the network device to which the attacked target IP address is located can be determined.

[0051] Step 103: Determine the attack path of the attack source based on the source network device, the destination network device, and the network topology of the network system.

[0052] The attack path is the route that the attacking source IP address takes from the source network device to the destination network device. Therefore, the attack path includes multiple network devices between the source and destination network devices, and these multiple network devices include at least one firewall.

[0053] The blocking system adopts a bypass mode to achieve unified access for various types of devices such as firewalls, switches, and routers. It also uses SSH (Secure Shell) and Telnet remote terminal protocols to configure the accessed network devices and generate a service-based network topology map, thereby obtaining the network topology structure of the network system.

[0054] Step 104: Generate a corresponding blocking strategy based on the attack source IP address, the attacked target IP address, and the device information of the at least one firewall.

[0055] The firewall's device information includes its model and version. The blocking policy informs the firewall how to respond to attacking source IP addresses. Different blocking policies can be set based on the severity and frequency of the attack. A blocking policy might block requests from the attacking source IP address, enable CAPTCHAs when a request is received, or simply log the request without processing it. For example, a blocking policy for highly dangerous attacking source IP addresses might simply block their requests. In situations with multiple firewalls, the attacking source IP address can be blocked by the first firewall it passes through, significantly improving network defense effectiveness.

[0056] Step 105: Send the blocking policy to at least one firewall in the attack path. When the attack source IP address reappears in the network system, the at least one firewall can block the attack source IP address according to the corresponding blocking policy.

[0057] Since the blocking policy relies on firewalls for execution, after generating the corresponding blocking policy, it is sent to at least one firewall in the attack path. Upon receiving the blocking policy, the firewall can then block the attack source IP address according to the policy, intercepting the data packets carried by that IP address and preventing them from being processed. Blocking refers to taking appropriate measures against the attack source IP address based on the blocking policy, such as blocking requests from the attack source IP address, enabling CAPTCHAs when a request is received, or simply logging the request without processing it.

[0058] In this application, when it is determined that a network system connected to the blocking system is under attack, the following steps are taken: The attack source IP address is determined; the source network device to which the attack source IP address belongs, and the destination network device where the attacked target IP address is located; based on the source network device, the destination network device, and the network topology of the network system, the attack path of the attack source is determined, the attack path including multiple network devices between the source network device and the destination network device, and at least one firewall among these multiple network devices; a corresponding blocking policy is generated based on the attack source IP address, the attacked target IP address, and the device information of the at least one firewall; the blocking policy is sent to the at least one firewall in the attack path, and when the attack source IP address reappears in the network system, the at least one firewall can block the attack source IP address according to the corresponding blocking policy. In network defense, the attack path of the attack source is determined based on the attack source IP address and the IP address of the attacked target. At least one firewall is determined based on the attack path of the attack source, which is the network device through which the attack source IP address passes. Therefore, the attack source IP address is blocked based on the at least one firewall and the corresponding blocking policy. This is more flexible than the method of blocking only a fixed exit firewall, and thus can improve the effectiveness of network defense.

[0059] As an alternative implementation method, such as Figure 3 As shown, in this embodiment, step 102 includes the following steps:

[0060] Step 201: Scan the routing table information of all network devices in the network system to identify network devices in multiple network segments that contain the IP addresses of electronic devices.

[0061] Each network device's routing table information includes at least one routing entry for that device. A complete routing entry includes Destination / Mask (the destination network address and network mask), Proto (the protocol type of the route), Pre (the routing protocol priority), Cost (the route cost), NextHop (the next-hop address), and Interface (the outgoing interface of this route). For the same destination, there may be multiple routes with different next hops, outgoing interfaces, etc. These different routes may be discovered by different routing protocols (such as OSPF and RIP), and different routing protocols have different priorities. The route with the lowest pre value becomes the current optimal route.

[0062] For example, if the attack source IP address is 192.168.8.19, the most accurate route entry that can be matched is shown in Table 1:

[0063] Table 1

[0064] Destination / Mask Proto Pre Cost NextHop Interface 192.168.8.0 / 24 Direct 0 0 192.168.8.1 Vlan8

[0065] That is, the source network device to which the source IP address of the attack belongs has a destination network address and network mask of 192.168.8.0 / 24, a direct route protocol type, the highest priority of the routing protocol, the lowest routing cost, and a next-hop address of 192.168.8.1. The outgoing interface of the source network device is VLAN 8, and the data will be forwarded from VLAN 8.

[0066] A network segment can include multiple IP addresses, and each network device has a corresponding network segment. By scanning the routing table information of all network devices in the network system, it is possible to determine which network devices have network segments containing the IP addresses of electronic devices, thus identifying the network devices with multiple network segments containing the IP addresses of electronic devices.

[0067] Step 202: From the network devices containing the IP addresses of electronic devices in the multiple network segments, determine the network device whose routing protocol with the electronic device is direct connection routing as the source network device to which the attack source IP address belongs.

[0068] In this process, after identifying the network devices that contain the IP addresses of electronic devices in multiple network segments, the network device whose routing protocol with the electronic devices is direct connection is identified from among the network devices that contain the IP addresses of electronic devices in multiple network segments as the source network device to which the attack source IP address belongs.

[0069] In this embodiment, the routing table information of all network devices in the network system is scanned to identify network devices in multiple network segments that contain the IP addresses of electronic devices. From these network devices, the network device whose routing protocol to the electronic device is a direct connection is identified as the source network device to which the attack source IP address belongs. Since the source network device to which the attack source IP address belongs is determined based on scanning the routing table information of all network devices in the network system, the source network device can be accurately identified.

[0070] As an optional implementation, in this embodiment, step 102 includes: starting with the source network device, traversing one by one the network devices in the network system whose routing table information contains the IP address of the attacked object, until the destination network device where the IP address of the attacked object is located is determined.

[0071] Specifically, for attacks originating from an internal network where the source network device and electronic devices are directly connected by a route, the source network device can be used as the starting point. First, based on the routing table information of the source network device, the route entry containing the attacked target's IP address is identified, and the user is redirected to the next-hop address in that route entry. After redirection, the network device containing that next-hop address is used as the starting point again, and its routing table information is used to identify the route entry containing the attacked target's IP address, and the user is redirected to the next-hop address in that route entry. This process is repeated sequentially until the next-hop address matches the attacked target's IP address, thus determining the destination network device containing the attacked target's IP address.

[0072] If a network device contains multiple routing entries for the IP address of the target, the static routing entry is given the highest priority. The next-hop address is then determined based on this highest-priority routing entry.

[0073] In this embodiment, starting with the source network device, the routing table information of each network device in the network system containing the IP address of the attacked target is traversed one by one until the destination network device containing the IP address of the attacked target is determined. Since the destination network device containing the IP address of the attacked target is determined by starting from the source network device and traversing each network device in the network system whose routing table information contains the IP address of the attacked target, the accuracy of the destination network device can be guaranteed.

[0074] In one embodiment, if the attack originates from the public network, the IP address of the attack source cannot be determined. The solution can begin by traversing the network devices whose routing tables contain the IP address of the attacked target, starting with those directly connected via a route. This process continues until a network device or a public network boundary device with a directly connected route to the attack source's IP address is identified.

[0075] As an optional implementation, in this embodiment, the steps include the following:

[0076] Step 301: Based on the network topology of the source network device, the destination network device, and the network system, obtain the candidate attack path of the attack source.

[0077] The network topology of the network system is obtained before step 101, meaning the blocking system has already been established. Figure 4As shown, it includes a first switch directly connected to an electronic device (i.e., the host shown in the figure), a first firewall connected to the first switch, a first router connected to the first firewall, a second router connected to the first router, a second firewall connected to the second router, and a second switch connected to the second firewall. The second switch is connected to a specific business system.

[0078] In the process of determining the destination network device based on the routing table information of the source network device and other network devices, it is possible to determine the candidate attack paths of the attack source IP address when it reaches the destination network device from the source network device.

[0079] Step 302: If it is determined that there is no loop on the candidate attack path of the attack source, then the candidate attack path of the attack source is determined as the attack path of the attack source.

[0080] Among the attack sources, candidate attack paths may exhibit loop networks, meaning that a particular network device is repeatedly traversed as the attack source's IP address. To ensure that the final determined attack path conforms to tree-like reasoning and avoids repeated traversal of a particular network device as the attack source's IP address, loop-free pruning is required to eliminate loops within the attack source's path. Therefore, an attack path is only confirmed as the attack source's attack path if it is free of loops.

[0081] Still with Figure 4 Taking the network topology of a network system as an example, the attack path from the first switch to the second switch can be considered as the attack source. A loop can be understood as starting from the first firewall, passing through the first router, and then returning from the first router to the first firewall, forming a loop (not shown in the diagram). The first firewall here refers to the aforementioned network device that repeatedly acquires data.

[0082] In this embodiment, candidate attack paths for the attack source are obtained based on the network topology of the source network device, the destination network device, and the network system. If it is determined that there is no loop on the candidate attack path, then the candidate attack path is determined as the attack path of the attack source. Since the attack path of the attack source is determined when there is no loop, the obtained attack path of the attack source is guaranteed to be loop-free. This prevents one or more network devices from being repeatedly used as network devices traversed by the attack source IP address, thus ensuring the accuracy of the attack path.

[0083] As an optional implementation, in this embodiment, if the candidate attack path of the attack source has at least one loop, the IP address blocking method further includes the following steps:

[0084] Step 401: Prune at least one loop on the candidate attack path of the attack source to obtain an attack path without loops.

[0085] If the candidate attack path of the attack source includes at least one loop, the aforementioned electronic device can trim or cut the loop to obtain an attack path without loops. For example, in the previous case, the route from the first router back to the first firewall is cut off, thus obtaining an attack path without loops.

[0086] Step 402: The attack path without loops is determined as the attack path of the attack source.

[0087] In this embodiment, if the candidate attack path of the attack source has at least one loop, the at least one loop on the candidate attack path of the attack source is pruned to obtain an attack path without loops; the attack path without loops is then determined as the attack path of the attack source. Since at least one loop exists on the candidate attack path of the attack source, the loop is pruned, thereby obtaining an attack path without loops.

[0088] As an optional implementation, in this embodiment, after step 103, the following steps are also included:

[0089] Step 501: Remove multiple backup network devices from the attack path of the attack source, and retain multiple primary network devices from the attack path of the attack source.

[0090] In this network system, all network devices operate in a primary / backup mode, meaning each network device includes one primary network device and at least one backup network device. The determination of at least one firewall is based on multiple primary network devices remaining in the attack path of the attack source. If there are two firewalls among these primary network devices, then these two firewalls constitute the at least one firewall described in step 104.

[0091] Multiple backup network devices are removed from the attack path of the attack source because only one firewall needs to be identified based on the attack path of a single attack source. The presence of multiple backup network devices ensures that the attack source also has alternative routes, but this only increases the computational workload.

[0092] Step 502: Obtain at least one firewall based on the plurality of primary network devices.

[0093] Specifically, one or more firewalls among multiple primary network devices are identified as the at least one firewall.

[0094] In this embodiment, multiple backup network devices in the attack path of the attack source are removed, while multiple primary network devices in the attack path of the attack source are retained; the at least one firewall is obtained based on the multiple primary network devices. Since the at least one firewall is determined based on the multiple primary network devices, the accuracy of the at least one firewall can be guaranteed.

[0095] As an optional implementation, in this embodiment, step 104 includes: generating a corresponding blocking strategy based on the attack source IP address, the attacked target IP address, and the model and version of the at least one firewall.

[0096] This process involves generating a corresponding blocking policy for at least one firewall based on the attack source IP address, the attacked target IP address, and the model and version of at least one firewall. This allows the firewall to identify the attack source IP address to be blocked and execute appropriate actions against the attack source according to the corresponding blocking policy. For the at least one firewall, differences in version and model do not lead to differences in the blocking policy content. The main difference lies in the encapsulation format of the blocking policy, which must correspond to the version and model of the at least one firewall. This correspondence ensures that the at least one firewall can correctly parse the corresponding blocking policy. The blocking policy also includes the firewall's security domain information, which determines the network segment on which the firewall executes the blocking policy.

[0097] In this embodiment, a corresponding blocking policy is generated based on the attack source IP address, the attacked target IP address, and the model and version of at least one firewall. Since the blocking policy is generated based on the version and model of at least one firewall, it ensures that at least one firewall can successfully parse the corresponding blocking policy. Furthermore, different brands of firewalls and routers have different standards for policy orchestration. Existing technologies place very high demands on network operations engineers, requiring them to possess professional knowledge of policy orchestration methods and IP blocking distribution methods for multiple vendors' devices. This is time-consuming, labor-intensive, and carries the risk of human error, potentially causing network outages. Moreover, it fails to achieve timely blocking, and its timeliness cannot meet the requirements of security operations. Using the method described in this embodiment, since the blocking policy is automatically determined based on the model and version of each firewall without manual intervention, human error can be reduced, and the timeliness can meet the requirements of security operations.

[0098] Figure 5 This is a schematic diagram of the structure of an IP address blocking processing device provided in an embodiment of this application, as shown below. Figure 5As shown, the IP address blocking processing device 40 provided in this embodiment is located in an electronic device. Therefore, the IP address blocking processing device 40 provided in this embodiment includes:

[0099] The attack source IP address determination module 41 is used to determine the attack source IP address when it is determined that a network system connected to the blocking system is under network attack.

[0100] The network device determination module 42 is used to determine the source network device to which the attack source IP address belongs, and the destination network device to which the attacked target IP address is located.

[0101] Attack path determination module 43 is used to determine the attack path of the attack source based on the source network device, the destination network device and the network topology of the network system. The attack path includes multiple network devices between the source network device and the destination network device, and the multiple network devices include at least one firewall.

[0102] The blocking policy generation module 44 is used to generate a corresponding blocking policy based on the attack source IP address, the attacked target IP address, and the device information of the at least one firewall.

[0103] The blocking policy sending module 45 is used to send the blocking policy to at least one firewall in the attack path. When the attack source IP address reappears in the network system, the at least one firewall can block the attack source IP address according to the corresponding blocking policy.

[0104] Optionally, determining the source network device to which the attack source IP address belongs is specifically used for: scanning the routing table information of all network devices in the network system to determine network devices in multiple network segments that contain the IP addresses of electronic devices; and from the network devices in the multiple network segments that contain the IP addresses of electronic devices, determining the network device to which the attack source IP address belongs as the network device whose routing protocol with the electronic device is direct connection.

[0105] Optionally, determining the destination network device where the IP address of the attacked object is located is specifically used to: starting from the source network device, traverse one by one the network devices in the network system whose routing table information contains the IP address of the attacked object, until the destination network device where the IP address of the attacked object is located is determined.

[0106] Optionally, determining the attack path of the attack source based on the network topology of the source network device, the destination network device, and the network system specifically involves: obtaining candidate attack paths of the attack source based on the network topology of the source network device, the destination network device, and the network system; if it is determined that there is no loop on the candidate attack path of the attack source, then the candidate attack path of the attack source is determined as the attack path of the attack source.

[0107] Optionally, if the candidate attack path of the attack source has at least one loop, when determining the attack path of the attack source, the electronic device is used to: prune at least one loop on the candidate attack path of the attack source to obtain an attack path without loops; and determine the attack path without loops as the attack path of the attack source.

[0108] Optionally, multiple backup network devices in the attack path of the attack source are removed, while multiple primary network devices in the attack path of the attack source are retained; the at least one firewall is obtained based on the multiple primary network devices.

[0109] Optionally, the blocking policy generation module 44 is specifically used to generate a corresponding blocking policy based on the attack source IP address, the attacked target IP address, and the model and version of the at least one firewall.

[0110] Figure 6 This is a block diagram illustrating an electronic device according to an exemplary embodiment, the device being as follows: Figure 6 As shown, the electronic device includes: a memory 51 and a processor 52; the memory 51 is a memory for storing processor-executable instructions; the processor 52 is used to run computer programs or instructions to implement the IP address blocking processing method provided in any of the above embodiments.

[0111] The memory 51 is used to store programs. Specifically, the program may include program code, which includes computer operation instructions. The memory 51 may include high-speed RAM, and may also include non-volatile memory, such as at least one disk storage device.

[0112] The processor 52 may be a central processing unit (CPU), an application specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of this disclosure.

[0113] Optionally, in specific implementations, if the memory 51 and processor 52 are implemented independently, then the memory 51 and processor 52 can be interconnected via bus 53 to complete mutual communication. Bus 53 can be an Industry Standard Architecture (ISA) bus 53, a Peripheral Component Interconnect (PCI) bus 53, or an Extended Industry Standard Architecture (EISA) bus 53, etc. Bus 53 can be divided into address bus 53, data bus 53, control bus 53, etc. For ease of representation, Figure 6 The bus 53 is represented by a single thick line, but this does not mean that there is only one bus 53 or only one type of bus 53.

[0114] Optionally, in a specific implementation, if the memory 51 and the processor 52 are integrated on a single chip, then the memory 51 and the processor 52 can communicate with each other through an internal interface.

[0115] A non-transitory computer-readable storage medium, wherein when the instructions in the storage medium are executed by the processor of an electronic device, the electronic device is able to execute the aforementioned method for blocking the IP address of the electronic device.

[0116] Other embodiments of this application will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of this application that follow the general principles of this application and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of this application are indicated by the following claims.

[0117] It should be understood that this application is not limited to the precise structure described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of this application is limited only by the appended claims.

Claims

1. A method for blocking IP addresses, characterized in that, The method is applied to electronic devices, wherein the electronic devices are equipped with a blocking system; the blocking system adopts a bypass mode and configures and generates a service-based network topology for the accessed network devices via Secure Shell Protocol (SSH) and Telnet remote terminal protocol; the method includes: When it is determined that a network system connected to the blocking system is under attack, the IP address of the attack source is determined; Scan the routing table information of all network devices in the network system to identify network devices in multiple network segments that contain the IP address of the electronic device; From the network devices in the multiple network segments that contain the IP address of the electronic device, the network device whose routing protocol with the electronic device is direct connection is identified as the source network device to which the attack source IP address belongs; Starting with the source network device, the routing table information of each network device in the network system that contains the IP address of the attacked target is traversed one by one until the destination network device where the IP address of the attacked target is located is determined. If there are multiple routing entries containing the IP address of the attacked target in a certain network device, the priority of the routing entry that is in the static routing mode is set to the highest priority, and the next hop address is determined according to the routing entry with the highest priority until the destination network device where the IP address of the attacked target is determined. Based on the network topology of the source network device, the destination network device, and the network system, the attack path of the attack source is determined. The attack path includes multiple network devices between the source network device and the destination network device, and at least one firewall is included among the multiple network devices. Based on the attack source IP address, the attacked target IP address, and the model and version of at least one firewall, a corresponding blocking strategy is generated; The blocking policy is sent to at least one firewall in the attack path. When the attack source IP address reappears in the network system, the at least one firewall can block the attack source IP address according to the corresponding blocking policy.

2. The method according to claim 1, characterized in that, Determining the attack path of the attack source based on the network topology of the source network device, the destination network device, and the network system includes: Based on the network topology of the source network device, the destination network device, and the network system, candidate attack paths for the attack source are obtained. If it is determined that there is no loop on the candidate attack path of the attack source, then the candidate attack path of the attack source is determined as the attack path of the attack source.

3. The method according to claim 2, characterized in that, If the candidate attack path of the attack source has at least one loop, determining the attack path of the attack source includes: At least one loop on the candidate attack path of the attack source is pruned to obtain an attack path without loops. The attack path that does not have a loop is determined as the attack path of the attack source.

4. The method according to claim 3, characterized in that, After determining the attack path of the attack source based on the source network device, the destination network device, and the network topology of the network system, the method further includes: Remove multiple backup network devices from the attack path of the attack source, and retain multiple primary network devices from the attack path of the attack source. The at least one firewall is obtained based on the plurality of primary network devices.

5. An IP address blocking processing device, characterized in that, The IP address blocking processing device is used to execute the IP address blocking processing method according to any one of claims 1-4, the device comprising: The attack source IP address determination module is used to determine the attack source IP address when it is determined that a network system connected to the blocking system is under network attack. The network device determination module is used to determine the source network device to which the attack source IP address belongs, and the destination network device to which the attacked target IP address is located. An attack path determination module is used to determine the attack path of the attack source based on the source network device, the destination network device, and the network topology of the network system. The attack path includes multiple network devices between the source network device and the destination network device, and the multiple network devices include at least one firewall. The blocking policy generation module is used to generate a corresponding blocking policy based on the attack source IP address, the attacked target IP address, and the device information of the at least one firewall. A blocking policy sending module is used to send the blocking policy to at least one firewall in the attack path. When the attack source IP address reappears in the network system, the at least one firewall can block the attack source IP address according to the corresponding blocking policy.

6. An electronic device, comprising: A processor, and a memory communicatively connected to the processor; The memory stores computer-executed instructions; The processor executes computer execution instructions stored in the memory to implement the method as described in any one of claims 1-4.

7. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the method as described in any one of claims 1-4.

Citation Information

Patent Citations

  • Information blocking method and device, computing equipment and computer storage medium

    CN113079128A