Intranet host identification method and device, electronic equipment and storage medium

By deploying traffic probes on NAT devices to monitor user-side traffic data and combine it with data from the security cloud, compromised intranet hosts can be identified. This solves the problem that metropolitan area network security clouds cannot accurately locate intranet hosts, thereby improving the value and accuracy of security services and analysis.

CN116318745BActive Publication Date: 2025-12-12CHINA TELECOM CORP LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211077816.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-09-05
Publication Date
2025-12-12
Estimated Expiration
2042-09-05

AI Technical Summary

Technical Problem

The metropolitan area network security cloud cannot accurately locate the compromised internal network host because after the router performs NAT translation, the captured data packets are the router IP and port after NAT, rather than the internal network IP and port, which reduces the value of the security service.

Method used

Deploy traffic probes on NAT devices to monitor user-side traffic data. Match the target traffic probes with the occurrence time and intruder IP in the security logs to obtain user-side traffic data. Combine this with traffic data from the security cloud to identify compromised internal network hosts.

Benefits of technology

By deploying traffic probes on NAT devices, it is possible to accurately identify the internal network hosts corresponding to the traffic data after NAT translation, thereby enhancing the value of security services, solving the problem of not being able to identify specific internal network hosts, and improving the accuracy and efficiency of security analysis.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116318745B_ABST
    Figure CN116318745B_ABST
Patent Text Reader

Abstract

Embodiments of the present application provide an intranet host identification method and device, electronic equipment and storage medium, the method comprising: receiving a security log sent by a network intrusion detection system when detecting an intrusion event on the user side; the security log includes the occurrence time, the IP of the NAT device and the IP of the intruder; determining the target first traffic probe corresponding to the IP of the NAT device; obtaining the target user-side traffic data matched with the occurrence time and the IP of the intruder from the target first traffic probe; and identifying the target intranet host by using the target user-side traffic data. By deploying a traffic probe on the NAT device, the traffic probe can be used to monitor the user-side traffic data, and by using the occurrence time, the IP of the NAT device and the IP of the intruder, the target user-side traffic data for identifying the target intranet host can be obtained from the corresponding traffic probe, so that the intranet host corresponding to the traffic data after NAT conversion can be identified, thereby improving the value of the security service.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of information security, in particular to a method for identifying an intranet host, an intranet host identification device, an electronic device and a computer readable storage medium. BACKGROUND

[0002] At present, the security cloud of metropolitan area network is more and more favored by government and enterprise broadband users. The security cloud of metropolitan area network is to use the advantage of the metropolitan area network of the operator, and transfer the traffic in the government and enterprise broadband connected to the metropolitan area network to the security resource pool in the security cloud for security analysis at the metropolitan area network convergence node. The greatest value of the security cloud of metropolitan area network is to provide security capabilities to government and enterprise broadband users in the form of services without the need for government and enterprise broadband users to purchase and deploy security devices.

[0003] However, since most of the government and enterprise broadband users are office network environments, most of the hosts of these users are intranet hosts. The intranet hosts are usually connected to the Internet through the router deployed at the exit. However, the router will perform NAT (Network Address Translation) conversion on the intranet IP (Internet Protocol Address) and port before connecting to the Internet, which results in that the data packets captured at the metropolitan area network convergence node are not intranet IP and port, but router IP and port after NAT. If an intrusion event is detected, the security cloud of metropolitan area network cannot locate a certain intranet host that is invaded according to the router IP and port, thereby greatly reducing the value of the security service. SUMMARY

[0004] In view of the above problems, the present application is proposed to provide an intranet host identification method to overcome the above problems or at least partially solve the above problems.

[0005] The present application also provides an intranet host identification device, an electronic device and a storage medium to ensure the implementation of the above method.

[0006] In order to solve the above problems, the present application discloses an intranet host identification method applied to an intranet invaded host identification system. The intranet invaded host identification system is in communication connection with a network intrusion detection system. The intranet invaded host identification system includes a first traffic probe. The first traffic probe is deployed at a NAT device and is used to listen to the user side traffic data of the NAT device. The method comprises the following steps:

[0007] receiving a security log sent by the network intrusion detection system when detecting that an intrusion event occurs on the user side; the security log includes the occurrence time, the IP of the NAT device and the IP of the intruder.

[0008] determining a target first flow probe corresponding to the IP of the NAT device;

[0009] acquiring target user-side flow data matching the occurrence time and the IP of the intruder from the target first flow probe;

[0010] identifying the target intruded internal network host by using the target user-side flow data.

[0011] Optionally, the target first flow probe corresponds to multiple indexes; the acquiring target user-side flow data matching the occurrence time and the IP of the intruder from the target first flow probe comprises:

[0012] determining a target index matching the IP of the intruder from the multiple indexes; the target index corresponds to multiple user-side flow data;

[0013] acquiring target user-side flow data within a preset time period before and after the occurrence time from the multiple user-side flow data; the target user-side flow data comprises multiple.

[0014] Optionally, before the receiving the security log sent by the network intrusion detection system when detecting the user-side intrusion event, the method further comprises:

[0015] collecting multiple first data packets by the first flow probe; the first data packet comprises five-tuple information;

[0016] recombining first data packets with the same five-tuple information into second data packets in time sequence by the first flow probe; the second data packet comprises multiple.

[0017] extracting user-side flow data from the multiple second data packets respectively by the first flow probe; the user-side flow data comprises an external network IP;

[0018] saving the user-side flow data by using the external network IP as an index by the first flow probe.

[0019] Optionally, the internal network intruded host identification system further comprises a second flow probe, the second flow probe is deployed in a security resource pool and is used for listening to security cloud-side flow data of the security resource pool; the identifying the target intruded internal network host by using the target user-side flow data comprises:

[0020] judging whether multiple target user-side flow data are all from the same internal network host;

[0021] If not, the target security cloud side traffic data corresponding to the security log is obtained from the second traffic probe;

[0022] The traffic type of the target security cloud side traffic data is determined;

[0023] Based on the traffic type, the target security cloud side traffic data is matched with each target user side traffic data;

[0024] According to the matching result, the target intruded internal network host is identified.

[0025] Optionally, the target security cloud side traffic data includes a first TCP sequence number, and the each target user side traffic data includes a second TCP sequence number; the matching of the target security cloud side traffic data with each target user side traffic data based on the traffic type includes:

[0026] If the traffic type is TCP protocol, a target second TCP sequence number same as the first TCP sequence number is searched from each second TCP sequence number;

[0027] The target intruded internal network host is identified according to the matching result, including:

[0028] A target internal network IP is extracted from the target user side traffic data corresponding to the target second TCP sequence number;

[0029] An internal network host corresponding to the target internal network IP is identified as the target intruded internal network host.

[0030] Optionally, the matching of the target security cloud side traffic data with each target user side traffic data based on the traffic type includes:

[0031] If the traffic type is UDP protocol, the target security cloud side traffic data is mapped as a first column vector, and each target user side traffic data is mapped as a second column vector;

[0032] Cosine similarity between the first column vector and each second column vector is calculated;

[0033] The target intruded internal network host is identified according to the matching result, including:

[0034] The maximum target cosine similarity is determined;

[0035] A target internal network IP is extracted from the target user side traffic data corresponding to the target cosine similarity;

[0036] An internal network host corresponding to the target internal network IP is identified as the target intruded internal network host.

[0037] Optionally, after judging whether the plurality of target user-side traffic data are from the same intranet host, the method further comprises:

[0038] If yes, extracting a target intranet IP from one of the target user-side traffic data;

[0039] Identifying the intranet host corresponding to the target intranet IP as a target intranet host being invaded.

[0040] The embodiment of the application further discloses an intranet host identification device applied to an intranet invaded host identification system, wherein the intranet invaded host identification system is in communication connection with a network intrusion detection system, the intranet invaded host identification system comprises a first traffic probe, and the first traffic probe is arranged in a NAT device and used for listening to user-side traffic data of the NAT device, and the device comprises:

[0041] A security log receiving module, used for receiving a security log sent by the network intrusion detection system when detecting an invasion event occurring on the user side; the security log comprises an occurrence time, an IP of the NAT device and an invader IP;

[0042] A target first traffic probe determining module, used for determining a target first traffic probe corresponding to the IP of the NAT device;

[0043] A target user-side traffic data obtaining module, used for obtaining target user-side traffic data matched with the occurrence time and the invader IP from the target first traffic probe;

[0044] A target intranet host identification module, used for identifying a target intranet host being invaded by using the target user-side traffic data.

[0045] Optionally, the target first traffic probe corresponds to a plurality of indexes; and the target user-side traffic data obtaining module comprises:

[0046] A target index determining submodule, used for determining a target index matched with the invader IP from the plurality of indexes; the target index corresponds to a plurality of user-side traffic data;

[0047] A target user-side traffic data obtaining submodule, used for obtaining target user-side traffic data within a preset time period before and after the occurrence time from the plurality of user-side traffic data; the target user-side traffic data comprise a plurality of.

[0048] Optionally, before receiving the security log sent by the network intrusion detection system when detecting an invasion event occurring on the user side, the device further comprises:

[0049] The first data packet acquisition module is used to acquire multiple first data packets through the first traffic probe; the first data packet includes five-tuple information.

[0050] The second data packet reassembly module is used to reassemble first data packets with the same five-tuple information into second data packets in chronological order using the first traffic probe; the second data packet includes multiple packets.

[0051] The user-side traffic data extraction module is used to extract user-side traffic data from the plurality of second data packets through the first traffic probe; the user-side traffic data includes external IP addresses.

[0052] The user-side traffic data storage module is used to store the user-side traffic data using the external IP address as an index through the first traffic probe.

[0053] Optionally, the intranet compromised host identification system further includes a second traffic probe, which is deployed in a security resource pool and used to monitor the security cloud-side traffic data of the security resource pool; the target intranet host identification module includes:

[0054] The source determination submodule is used to determine whether traffic data from multiple target users originates from the same internal network host.

[0055] The target security cloud-side traffic data acquisition submodule is used to acquire the target security cloud-side traffic data corresponding to the security log from the second traffic probe if no.

[0056] The traffic type determination submodule is used to determine the traffic type of the target secure cloud-side traffic data;

[0057] The traffic data matching submodule is used to match the target security cloud-side traffic data with the traffic data of each target user side based on the traffic type.

[0058] The first target intranet host identification submodule is used to identify the compromised target intranet host based on the matching results.

[0059] Optionally, the target secure cloud-side traffic data includes a first TCP sequence number, and the traffic data of each target user side includes a second TCP sequence number; the traffic data matching submodule includes:

[0060] The target second TCP sequence number lookup unit is used to look up a target second TCP sequence number that is the same as the first TCP sequence number from each second TCP sequence number if the traffic type is TCP protocol;

[0061] The first target intranet host identification submodule includes:

[0062] a first target intranet IP extraction unit configured to extract a target intranet IP from the target second TCP sequence number corresponding target user side traffic data;

[0063] a first target intranet host identification unit configured to identify the target intranet IP corresponding intranet host as a target intranet host that is invaded.

[0064] Optionally, the traffic data matching sub-module comprises:

[0065] a mapping unit configured to map the target security cloud side traffic data into a first column vector and map each of the target user side traffic data into a second column vector if the traffic type is a UDP protocol;

[0066] a cosine similarity calculation unit configured to calculate a cosine similarity between the first column vector and each of the second column vectors;

[0067] the first target intranet host identification sub-module comprises:

[0068] a target cosine similarity determination unit configured to determine a maximum target cosine similarity;

[0069] a second target intranet IP extraction unit configured to extract a target intranet IP from the target cosine similarity corresponding target user side traffic data;

[0070] a second target intranet host identification unit configured to identify the target intranet IP corresponding intranet host as a target intranet host that is invaded.

[0071] Optionally, after judging whether the multiple target user side traffic data are all from the same intranet host, the target intranet host identification module further comprises:

[0072] a target intranet host extraction sub-module configured to extract a target intranet IP from one of the target user side traffic data if yes;

[0073] a second target intranet host identification sub-module configured to identify the target intranet IP corresponding intranet host as a target intranet host that is invaded.

[0074] An electronic device is also disclosed in the embodiments of the present application, comprising a processor, a communication interface, a memory and a communication bus, wherein the processor, the communication interface and the memory complete communication with each other through the communication bus;

[0075] the memory is used for storing a computer program;

[0076] The processor is used for implementing the intranet host identification method according to the embodiments of the present application when executing the program stored on the memory.

[0077] The embodiments of the present application also disclose one or more computer readable media having instructions stored thereon, which, when executed by one or more processors, cause the processors to perform the intranet host identification method according to the embodiments of the present application.

[0078] Compared with the prior art, the embodiments of the present application have the following advantages:

[0079] In the embodiments of the present application, the receiving network intrusion detection system receives a security log sent by the user side when detecting an intrusion event; the security log includes a time of occurrence, an IP of the NAT device and an IP of the intruder; the IP of the NAT device is determined to correspond to a target first traffic probe; target user-side traffic data matching the time of occurrence and the IP of the intruder is obtained from the target first traffic probe; and the target user-side traffic data is used to identify the target intranet host. By deploying the traffic probe on the NAT device, the user-side traffic data can be monitored by the traffic probe, the target user-side traffic data used to identify the target intranet host is obtained from the corresponding traffic probe through the time of occurrence, the IP of the NAT device and the IP of the intruder, and thus the intranet host corresponding to the traffic data converted by the NAT can be identified, thereby improving the value of the security service. BRIEF DESCRIPTION OF DRAWINGS

[0080] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings needed in the embodiment description. Obviously, the drawings in the following description are only some of the embodiments of the present application, and other drawings can also be obtained by those skilled in the art without any creative effort based on these drawings.

[0081] Figure 1 is a step flow chart of an intranet host identification method provided by the embodiments of the present application;

[0082] Figure 2 is a step flow chart of a traffic data monitoring method provided by the embodiments of the present application;

[0083] Figure 3 is a flow chart of an intranet host identification method provided by the embodiments of the present application;

[0084] Figure 4 is a scene diagram of an intranet host identification method provided by the embodiments of the present application;

[0085] Figure 5 is a structural block diagram of an intranet host identification apparatus provided by the embodiments of the present application. DETAILED DESCRIPTION

[0086] The technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only some of the embodiments of the present application, rather than all the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of the present application.

[0087] Referring to Figure 1 , a step flowchart of a method for identifying an intranet host is shown, which is applied to an intranet-intruded host identification system, the intranet-intruded host identification system is in communication connection with an intrusion detection system, the intranet-intruded host identification system comprises a first traffic probe, the first traffic probe is deployed at a NAT device and is used to listen to user-side traffic data of the NAT device, and the method specifically can comprise the following steps:

[0088] Step 101, receiving a security log sent by the intrusion detection system when detecting that an intrusion event occurs on the user side; the security log comprises a time of occurrence, an IP of the NAT device and an IP of an intruder.

[0089] In the embodiments of the present application, the intranet-intruded host identification system can be applied to an intranet-intruded host identification system, the intranet-intruded host identification system can be deployed at a metropolitan area network security cloud, and the metropolitan area network security cloud can analyze and identify intranet hosts corresponding to traffic data after NAT through the intranet-intruded host identification system.

[0090] The intranet-intruded host identification system can be in communication connection with an intrusion detection system (IDS), the intrusion detection system is a security device and can be deployed at a metropolitan area network security cloud, and the metropolitan area network security cloud can detect whether an intrusion event occurs on the user side through the intrusion detection system.

[0091] The intranet-intruded host identification system comprises a first traffic probe, and the first traffic probe can be deployed at a NAT device. Generally, the NAT device is a broadband router or an export switch of a user, and the NAT device is deployed at an export of an intranet host, that is, the NAT device is deployed at the user side, so that the first traffic probe at the NAT device can be in the same intranet environment as the intranet host, so that the first traffic probe listens to user-side traffic data in a bypass mirroring manner.

[0092] In the embodiments of the present application, the first traffic probe can be registered in the intranet-intruded host identification system, so as to realize management of the first traffic probe by the intranet-intruded host identification system.

[0093] When the network intrusion detection system detects an intrusion event occurring on the user side, the intruded host identification system in the internal network can receive the security log sent by the network intrusion detection system, wherein the security log can include the occurrence time corresponding to the intrusion event, the IP of the NAT device and the IP of the intruder. Since the NAT device will perform NAT conversion on the IP of the internal network host (internal network IP) before connecting to the Internet, the security log contains the IP of the NAT device after NAT, not the internal network IP, so the embodiment of the present application needs to find the target internal network IP corresponding to the security log, so as to locate the target internal network host that is intruded.

[0094] In an optional embodiment of the present application, referring to Figure 2 , a flowchart of the steps of the traffic data monitoring method provided by the embodiment of the present application is shown, and before the security log sent by the network intrusion detection system when detecting an intrusion event occurring on the user side is received, the method can further include:

[0095] Step 201, collecting a plurality of first data packets by the first traffic probe; the first data packet includes five-tuple information;

[0096] Step 202, recombining the first data packets with the same five-tuple information into second data packets in time sequence by the first traffic probe; the second data packet includes a plurality of

[0097] Step 203, extracting user side traffic data from the plurality of second data packets by the first traffic probe respectively; the user side traffic data includes external network IP;

[0098] Step 204, saving the user side traffic data by the first traffic probe using the external network IP as an index.

[0099] Before receiving the security log, the intruded host identification system in the internal network can first collect, extract and save the user side traffic data on the user side through the first traffic probe. Specifically, the first traffic probe has a network card, which can be connected to the mirror port of the user side switch, so that the first traffic probe can monitor the user side traffic data through the network card, that is, the first traffic probe can collect a plurality of first data packets on the user side from the network card. Each first data packet includes five-tuple information, and the five-tuple information includes source IP, destination IP, source port, destination port and protocol.

[0100] The quintuple information can uniquely determine the data packet in the one-time connection session, and the first traffic probe can recombine the data packet according to the unidirectional network connection defined by the quintuple information of the source IP, the destination IP, the source port, the destination port and the protocol. In other words, the first data packet containing the same quintuple information can be recombined in time sequence to obtain a second data packet. Each second data packet constitutes the data of a one-time connection session, so that each network connection corresponds to a group of data packets with the same quintuple information and in time sequence.

[0101] The second data packet can include multiple, and the first traffic probe can extract user-side traffic data from each second data packet. The user-side traffic data can include quintuple information (source IP, destination IP, source port, destination port, protocol), connection initiation time, connection closing time, number of data packet retransmissions in the connection, source address sending byte rate, destination address sending byte rate, source address sending data packet number, destination address sending data packet number, initial source TCP sequence number, and initial destination TCP sequence number.

[0102] It should be noted that in the user-side traffic data, the source IP and the destination IP refer to the internal network IP and the external network IP. The internal and external networks are divided according to the enterprise network boundary. The local area network on the internal side of the NAT device is the internal network, and the Internet accessed through the NAT is the external network. Specifically, whether the source IP or the destination IP is the internal network IP or the external network IP can be determined by the internal network segment. For example, if the internal network segment is configured as the 192.168 network segment, if the source IP is 192.168.0.10, it can be determined that the source IP is the internal network IP, so the destination IP is the external network IP. Alternatively, if the destination IP is 192.168.0.10, it can be determined that the destination IP is the internal network IP, so the source IP is the external network IP.

[0103] When saving the user-side traffic data, the first traffic probe can use the external network IP as an index, so that when analyzing the security log later, the external network IP and the time period can be used as query parameters, and the query result can be returned to the querying party.

[0104] Step 102, determining the target first traffic probe corresponding to the IP of the NAT device.

[0105] The first traffic probe can include multiple, and one first traffic probe can be deployed at each NAT device, so each first traffic probe can correspond to the IP of one NAT device, and then the IP of the NAT device in the security log can be used to locate the corresponding target first traffic probe.

[0106] Step 103, obtaining target user-side traffic data matching the occurrence time and the IP of the intruder from the target first traffic probe.

[0107] The intruded host identification system in the intranet can call a data query interface of the target first traffic probe, and then use the occurrence time and the IP of the intruder in the security log as a query condition to obtain target user-side traffic data matching the query condition from the target first traffic probe.

[0108] In an optional embodiment of the present application, the target first traffic probe corresponds to a plurality of indexes; and step 103 can include the following sub-steps:

[0109] Sub-step S11, determining a target index matching the IP of the intruder from the plurality of indexes; the target index corresponds to a plurality of user-side traffic data;

[0110] Sub-step S12, obtaining target user-side traffic data within a preset time period before and after the occurrence time from the plurality of user-side traffic data; the target user-side traffic data includes a plurality of.

[0111] It should be noted that the intruder comes from the Internet, and the Internet is an external network relative to the intranet host, so the IP of the intruder is an external network IP.

[0112] Before receiving the security log, the intranet intruded host identification system has saved user-side traffic data by the first traffic probe using the external network IP as an index. The NAT device is generally connected to a plurality of intranet hosts, and each intranet host is connected to the Internet, i.e. the user of each intranet host communicates with the user of at least one external network IP, so each first traffic probe corresponds to a plurality of indexes, and the target first traffic probe located also corresponds to a plurality of indexes.

[0113] Each index is an external network IP, and the IP of the intruder belongs to the external network IP, so a target index matching the IP of the intruder can be determined from a plurality of indexes, i.e. the same external network IP as the IP of the intruder is found from a plurality of external network IPs.

[0114] Each index can correspond to a plurality of user-side traffic data, on the one hand because the users of different intranet hosts can communicate with the user of the same external network IP, and on the other hand because each intranet host can have more than one network connection, i.e. each intranet host generates data of at least one connection session, so each index corresponds to a plurality of user-side traffic data, and the determined target index also corresponds to a plurality of user-side traffic data.

[0115] The intranet host invaded by the host recognition system can match the connection initiation time in the user side flow data with the occurrence time in the security log, so as to obtain the target user side flow data in a preset time period before and after the occurrence time from the target index corresponding to a plurality of user side flow data. The target user side flow data can include a plurality of. Exemplarily, assuming that the target index corresponds to 20 user side flow data, if the occurrence time in the security log is 09:00:00, the intranet host invaded by the host recognition system can obtain 10 target user side flow data closest to the occurrence time and within 1 minute from the 20 user side flow data, that is, 10 target user side flow data within 08.59.30-09.00.30.

[0116] In step 104, the target user side flow data is used to identify the target intranet host invaded.

[0117] The user side flow data includes source IP and destination IP, and in the user side flow data, the source IP and the destination IP refer to the intranet IP and the extranet IP, so the target user side flow data obtained is the intranet IP and the extranet IP. The extranet IP in the target user side flow data is the IP of the intruder, so the intranet host invaded can be identified by using the intranet IP in the target user side flow data.

[0118] The embodiment of the application can identify the intranet host corresponding to the flow data converted by the NAT in the metropolitan area network security cloud side, and can solve the problems of: 1) unable to identify specific intranet hosts during security analysis; 2) unable to combine multiple flow sessions for security behavior analysis modeling due to the inability to identify specific intranet hosts; 3) unable to locate the intranet host invaded after discovering the intrusion event; 4) the value of security services is discounted due to the inability to reflect specific intranet hosts in the security analysis report.

[0119] In an optional embodiment of the application, the intranet host invaded by the host recognition system further includes a second flow probe, and the second flow probe is deployed in a security resource pool and is used to listen to the security cloud side flow data of the security resource pool; step 104 can include the following substeps:

[0120] In substep S21, it is judged whether the plurality of target user side flow data is from the same intranet host;

[0121] In substep S22, if not, the target security cloud side flow data corresponding to the security log is obtained from the second flow probe;

[0122] In substep S23, the flow type of the target security cloud side flow data is determined;

[0123] Sub-step S24, matching the target security cloud side flow data with each target user side flow data based on the flow type;

[0124] Sub-step S25, identifying the target intruded internal network host according to the matching result.

[0125] In an optional embodiment of the present application, after judging whether the plurality of target user side flow data are from the same internal network host, the method can further comprise:

[0126] If yes, extracting a target internal network IP from one of the target user side flow data; and identifying the internal network host corresponding to the target internal network IP as the target intruded internal network host.

[0127] In the embodiment of the present application, the target user side flow data can include a plurality of target user side flow data, and whether the plurality of target user side flow data are from the same internal network host can be judged. Specifically, whether the internal network IPs in the plurality of target user side flow data are the same can be judged; if the internal network IPs in the plurality of target user side flow data are the same, it can be determined that the plurality of target user side flow data are from the same internal network host; if the internal network IPs in the plurality of target user side flow data are not the same, it can be determined that the plurality of target user side flow data are not from the same internal network host. Exemplarily, assuming that there are 10 target user side flow data, there are 10 internal network IPs, and whether the 10 internal network IPs are the same can be judged; if the 10 internal network IPs are the same, it can be determined that the 10 target user side flow data are from the same internal network host; if the 10 internal network IPs are not the same, it can be determined that the 10 target user side flow data are not from the same internal network host.

[0128] If the plurality of target user side flow data are from the same internal network host, it can be indicated that the intruder has intruded only one internal network host. Since the internal network IPs in the plurality of target user side flow data are the same, a target internal network IP can be extracted from one of the target user side flow data at random, and the internal network host corresponding to the target internal network IP can be directly identified as the target intruded internal network host, without further analysis, so that the internal network host to which the security log is directed can be directly identified.

[0129] If the plurality of target user side flow data are not from the same internal network host, it can be indicated that the intruder has intruded more than one internal network host. Since the internal network IPs in the plurality of target user side flow data are not the same, and each security log can identify and locate at most one target intruded internal network host, the internal network intruded host identification system needs to further analyze the internal network host to which the currently received security log is directed.

[0130] In the embodiment of the present application, the intranet-intruded host identification system comprises a second traffic probe in addition to the first traffic probe. The second traffic probe can be deployed at a security resource pool, specifically, at a mirror traffic port of a security cloud side security resource pool switch of a metropolitan area network security cloud, so that the second traffic probe listens to security cloud side traffic data in a bypass mirror mode.

[0131] In the embodiment of the present application, the second traffic probe can be registered in the intranet-intruded host identification system, so as to realize management of the second traffic probe by the intranet-intruded host identification system.

[0132] Before receiving the security log, the intranet-intruded host identification system can collect, extract and save security cloud side traffic data at the security cloud side through the second traffic probe. The security cloud side traffic data can include five tuple information (source IP, destination IP, source port, destination port, protocol), connection initiation time, connection closing time, number of data packet retransmissions in the connection, source address sending byte rate, destination address sending byte rate, source address sending data packet number, destination address sending data packet number, initial source TCP sequence number, and initial destination TCP sequence number.

[0133] It should be noted that in the security cloud side traffic data, the source IP and the destination IP refer to the IP of the NAT device and the external network IP. Since the NAT device will perform NAT conversion on the IP (intranet IP) of the intranet host before connecting to the Internet, in the security cloud side traffic data, the source IP and the destination IP refer to the IP of the NAT device and the external network IP.

[0134] In the embodiment of the present application, if the multiple target user side traffic data are not all from the same intranet host, the target security cloud side traffic data corresponding to the security log can be obtained from the second traffic probe. Specifically, the target security cloud side traffic data can be obtained based on the occurrence time and the five tuple information in the security log. The five tuple information in the security log includes source IP, destination IP, source port, destination port, and protocol. In the security log, the source IP and the destination IP also refer to the IP of the NAT device and the external network IP, wherein the external network IP in the security log is the IP of the intruder.

[0135] It should be noted that since each security log identifies and locates at most one intruded target intranet host, based on the occurrence time and the five tuple information in the security log, at most one target security cloud side traffic data is obtained.

[0136] In the embodiment of the present application, the traffic type of the target security cloud-side traffic data can be determined, wherein the traffic type can include one of a TCP (Transmission Control Protocol) protocol and a UDP (User Datagram Protocol) protocol.

[0137] Based on the traffic type, the target security cloud-side traffic data can be matched with each target user-side traffic data, so as to identify the target intruded intranet host according to the matching result. Different traffic types correspond to different matching methods, for example, the TCP protocol corresponds to an accurate matching method, and the UDP protocol corresponds to a fuzzy matching method.

[0138] In an optional embodiment of the present application, the target security cloud-side traffic data includes a first TCP sequence number, and the each target user-side traffic data includes a second TCP sequence number; the sub-step S24 can include the following sub-steps:

[0139] In the sub-step S31, if the traffic type is the TCP protocol, a target second TCP sequence number same as the first TCP sequence number is searched from each second TCP sequence number.

[0140] In an optional embodiment of the present application, the sub-step S25 can include the following sub-steps:

[0141] In the sub-step S41, a target intranet IP is extracted from the target user-side traffic data corresponding to the target second TCP sequence number.

[0142] In the sub-step S42, an intranet host corresponding to the target intranet IP is identified as the target intruded intranet host.

[0143] In a network attack event, some high-risk events that can confirm that the intranet host is intruded, such as webshell connection, C2 server connection, and mining behavior, are communicated by using a connection-oriented method, that is, by using the TCP protocol. The TCP sequence number of the TCP connection is randomly generated locally on the intranet host and will not be changed in the transmission process due to NAT conversion, and thus can be used as the unique identity of the TCP traffic.

[0144] In the embodiment of the present application, the user-side traffic data and the security cloud-side traffic data both include initial source TCP sequence number and initial destination TCP sequence number, so if it is determined that the traffic type of the target security cloud-side traffic data is TCP protocol, a first TCP sequence number can be extracted from the target security cloud-side traffic data, and a second TCP sequence number can be extracted from each target user-side traffic data, then the first TCP sequence number is matched with each second TCP sequence number, and a target second TCP sequence number identical to the first TCP sequence number is searched from the second TCP sequence numbers. The first TCP sequence number is the initial source TCP sequence number and the initial destination TCP sequence number, and the second TCP sequence number is the initial source TCP sequence number and the initial destination TCP sequence number.

[0145] The target user-side traffic data corresponding to the target second TCP sequence number is the user-side traffic data generated by the internal host corresponding to the intrusion event, so a target internal IP can be extracted from the target user-side traffic data corresponding to the target second TCP sequence number, so that the internal host corresponding to the target internal IP can be identified as the target internal host that is invaded.

[0146] In an optional embodiment of the present application, the sub-step S24 can include the following sub-steps:

[0147] In the sub-step S51, if the traffic type is UDP protocol, the target security cloud-side traffic data is mapped into a first column vector, and each target user-side traffic data is mapped into a second column vector.

[0148] In the sub-step S52, the cosine similarity between the first column vector and each second column vector is calculated.

[0149] In an optional embodiment of the present application, the sub-step S25 can include the following sub-steps:

[0150] In the sub-step S61, the maximum target cosine similarity is determined.

[0151] In the sub-step S62, a target internal IP is extracted from the target user-side traffic data corresponding to the target cosine similarity.

[0152] In the sub-step S63, the internal host corresponding to the target internal IP is identified as the target internal host that is invaded.

[0153] In addition to using connection-oriented mode, i.e., using TCP protocol for communication, there are also some attack modes based on UDP protocol.

[0154] In the embodiment of the present application, if it is determined that the flow type of the target security cloud side flow data is the UDP protocol, the target security cloud side flow data can be mapped into a first column vector, and each target user side flow data is mapped into a second column vector respectively, and then the cosine similarity between the first column vector and each second column vector is calculated. For example, assuming that there are 10 target user side flow data, the 10 target user side flow data can be mapped into 10 second column vectors respectively, and the target security cloud side flow data is only one, so a first column vector is mapped, and then the cosine similarity between each second column vector of the user side and the first column vector of the security cloud side is calculated, so that 10 cosine similarity values can be obtained.

[0155] In the specific implementation, the user side flow data and the security cloud side flow data both include connection initiation time, connection closing time, number of packet retransmissions in the connection, source address sending byte rate, destination address sending byte rate, number of source address sending packets, and number of destination address sending packets, so the fields used in the mapping can include the connection initiation time, the connection closing time, the number of packet retransmissions in the connection, the source address sending byte rate, the destination address sending byte rate, the number of source address sending packets, and the number of destination address sending packets.

[0156] It should be noted that the cosine similarity is to use the cosine value of the included angle between two vectors in a vector space as the measure of the difference between the two individuals, and the closer the cosine value is to 1, the closer the included angle is to 0 degrees, that is, the more similar the two vectors are, which is called "cosine similarity".

[0157] After the cosine similarity between the first column vector and each second column vector is calculated, the maximum target cosine similarity can be determined, and the target user side flow data corresponding to the target cosine similarity is the user side flow data generated by the intruded host in the internal network, so the target internal network IP can be extracted from the target user side flow data corresponding to the target cosine similarity, and the internal network host corresponding to the target internal network IP can be identified as the target internal network host that is intruded.

[0158] The embodiment of the present application has the following advantages: 1) without reading the NAT information, that is, without interfacing with any NAT gateway device; 2) capable of supporting both TCP and UDP protocols, wherein TCP can be accurately matched, and UDP is matched based on similarity; 3) the flow probe only extracts flow feature data (user side flow data and security cloud side flow data), and can be deployed in a lightweight and software manner; 4) capable of accurately obtaining the internal network IP of the intruded internal network host while detecting the flow intrusion in the security cloud side, greatly improving the value of the security analysis of the security cloud of the metropolitan area network.

[0159] In summary, in the embodiment of the present application, the receiving network intrusion detection system sends a security log when detecting an intrusion event occurring on the user side; the security log includes the occurrence time, the IP of the NAT device, and the IP of the intruder; the IP of the NAT device is determined to correspond to a target first traffic probe; the target user-side traffic data matching the occurrence time and the IP of the intruder is obtained from the target first traffic probe; and the target user-side traffic data is used to identify the target intruded internal network host. By deploying the traffic probe on the NAT device, the user-side traffic data can be monitored by the traffic probe, the target user-side traffic data used to identify the target intruded internal network host is obtained from the corresponding traffic probe through the occurrence time, the IP of the NAT device, and the IP of the intruder, and thus the internal network host corresponding to the traffic data converted by the NAT can be identified, thereby improving the value of the security service.

[0160] In order for those skilled in the art to better understand the embodiments of the present application, the embodiments of the present application are described below through the following examples:

[0161] Example 1

[0162] Reference Figure 3 Fig. 1 shows an internal network host identification flowchart provided by the embodiments of the present application. After the metropolitan area network security cloud detects a security event of an intrusion attack on the user side, the internal host (internal network host) corresponding to the security event is identified through the following flow:

[0163] 1. Receive a security event from a security device of the metropolitan area network security cloud; wherein the security device can be a network intrusion detection system;

[0164] 2. Extract the occurrence time and five-tuple information in the security event; wherein the five-tuple information includes an external IP and a user IP, the external IP being the IP of the intruder, and the user IP being the public network IP (IP of the NAT device) after NAT on the user side;

[0165] 3. Locate the user-side traffic probe through the user IP;

[0166] 4. Call the data query interface of the user-side traffic probe, and use the external IP and the occurrence time of the security event as the query conditions to search for 10 traffic feature data (target user-side traffic data) satisfying the following conditions:

[0167] ① The external IP is the same as the external IP in the security event;

[0168] ② The 10 traffic feature data are closest to the occurrence time of the security event and within 1 minute;

[0169] 5, judge whether the 10 pieces of flow characteristic data are from the same internal IP; if yes, the internal host corresponding to the security event can be directly identified without further analysis, and the process ends; if not, go to step 6;

[0170] 6, based on the occurrence time of the security event and the five-tuple information (external IP and user IP), search the flow characteristic data (target security cloud side flow data) corresponding to the security event on the security cloud side flow probe;

[0171] 7, determine whether the flow type of the five-tuple information in the flow characteristic data is TCP protocol or UDP protocol; if it is TCP protocol, go to step 8; if it is UDP protocol, go to step 9;

[0172] 8, use the TCP sequence number (initial source TCP sequence number and initial destination TCP sequence number) in the security cloud side flow characteristic data to find the user side flow characteristic data with the same TCP sequence number (initial source TCP sequence number and initial destination TCP sequence number), and the internal IP corresponding to the user side flow characteristic data with the same TCP sequence number found is the internal host corresponding to the security event, thereby identifying the internal host corresponding to the security event, and the process ends;

[0173] 9, map the flow characteristic data of the security cloud side and the user side into column vectors respectively, and go to step 10; wherein the fields used in the mapping include: connection initiation time, connection closing time, number of data packet retransmissions in the connection, source address sending byte rate, destination address sending byte rate, source address sending data packet number, destination address sending data packet number;

[0174] 10, calculate the cosine similarity between the security cloud side column vector and each user side column vector, take the user side flow characteristic data with the largest similarity as the internal host corresponding flow characteristic data, and take the internal IP in the flow characteristic data as the identified internal host IP, thereby identifying the internal host corresponding to the security event, and the process ends.

[0175] Example two

[0176] Reference Figure 4, the scene diagram of the intranet host identification provided by the embodiment of the application is shown, a user-side traffic probe is deployed on a user-side intranet switch to bypass mirror mode to monitor user-side traffic feature data, a security cloud-side traffic probe is deployed on a security cloud-side security resource pool switch to bypass mirror mode to monitor security cloud-side traffic feature data, a network intrusion detection system and an intranet-intruded host identification system are deployed in a metropolitan area network security cloud, the intranet-intruded host identification system receives security logs from the network intrusion detection system, queries and receives traffic feature data from the security cloud-side traffic probe, and queries and receives traffic feature data from the user-side traffic probe;

[0177] Suppose that the public network IP (the IP of the NAT device) configured by the user-side egress router is IP1, the IP of the user intranet host 2 is IP2, and an external attacker has successfully intruded the intranet host 2 and communicates with the intranet host 2 at IP3 at t1 time, then the intranet host 2 corresponding to the security log is identified through the following process:

[0178] 1. After receiving the security log sent by the network intrusion detection system, the intranet-intruded host identification system obtains the sending time t1 and the five-tuple information in the security log; wherein the five-tuple information includes the public network IP1 and the external attacker IP3.

[0179] 2. The public network IP1 corresponding traffic probe is located, the traffic feature data with the external IP IP3 and the connection initiation time interval less than 1 minute from the user-side traffic probe is found, and the 10 traffic feature data closest in time are taken.

[0180] 3. Whether the intranet host IP in the 10 traffic feature data is the same is judged; if yes, the IP taken from one of the traffic feature data is IP2, so that the intranet host 2 is identified, and the process is ended; if not, the process is transferred to step 4.

[0181] 4. If the intranet host IP in the 10 traffic feature data includes more than one IP, it is indicated that the external attacker attacks more than one intranet host, so that the IP corresponding to the current security log still needs to be further determined: the process is transferred to step 5.

[0182] 5. The corresponding traffic feature data is queried from the security cloud-side traffic probe according to the five-tuple information and t1.

[0183] 6. Whether the traffic type of the security cloud-side traffic feature data is TCP protocol or UDP protocol is judged; if it is TCP protocol, the process is transferred to step 7; if it is UDP protocol, the process is transferred to step 8.

[0184] 7. Take the initial source TCP sequence number and the initial destination TCP sequence number in the security cloud side flow feature data, and match them with the initial source TCP sequence number and the initial destination TCP sequence number in each user side flow feature data. If the same is matched, it is the flow feature data of the internal host corresponding to the security log, and the IP taken therefrom is IP2, so that the internal host 2 is identified, and the process ends;

[0185] 8. The security cloud side flow feature data and the user side flow feature data obtained are respectively mapped into column vectors, and are transferred to step 9;

[0186] 9. The cosine similarity between the security cloud side column vector and each user side column vector is calculated. The flow feature data with the largest similarity is taken as the flow feature data of the internal host generating the security log, and the IP taken therefrom is IP2, so that the internal host 2 is identified, and the process ends.

[0187] The above examples are only used to make the person skilled in the art better understand the embodiments of the present application, and the present application is not limited in this regard.

[0188] Reference Figure 5 , a structure block diagram of an internal host identification device provided by an embodiment of the present application is shown, which is applied to an internal host intrusion identification system. The internal host intrusion identification system is in communication connection with a network intrusion detection system. The internal host intrusion identification system comprises a first flow probe. The first flow probe is deployed in a NAT device and is used for listening to user side flow data of the NAT device. Specifically, the first flow probe can comprise the following modules:

[0189] A security log receiving module 501 is used for receiving a security log sent by the network intrusion detection system when detecting that an intrusion event occurs on the user side. The security log comprises an occurrence time, an IP of the NAT device and an IP of an intruder.

[0190] A target first flow probe determining module 502 is used for determining a target first flow probe corresponding to the IP of the NAT device.

[0191] A target user side flow data obtaining module 503 is used for obtaining target user side flow data matched with the occurrence time and the IP of the intruder from the target first flow probe.

[0192] A target internal host identification module 504 is used for identifying a target internal host intruded by using the target user side flow data.

[0193] In an optional embodiment of the present application, the target first flow probe corresponds to a plurality of indexes. The target user side flow data obtaining module 503 can comprise:

[0194] a target index determination submodule configured to determine a target index matching the IP of the intruder from the plurality of indexes; the target index corresponds to a plurality of user-side traffic data;

[0195] a target user-side traffic data acquisition submodule configured to acquire target user-side traffic data within a preset time period before and after the occurrence time from the plurality of user-side traffic data; the target user-side traffic data includes a plurality of.

[0196] In an optional embodiment of the present application, before the security log sent by the receiving network intrusion detection system when detecting that the user side has an intrusion event, the device can further include:

[0197] a first data packet acquisition module configured to acquire a plurality of first data packets through the first traffic probe; the first data packets include quintuple information;

[0198] a second data packet reorganization module configured to reorganize the first data packets with the same quintuple information into second data packets in time sequence through the first traffic probe; the second data packets include a plurality of.

[0199] a user-side traffic data extraction module configured to extract user-side traffic data from the plurality of second data packets through the first traffic probe; the user-side traffic data includes an external network IP;

[0200] a user-side traffic data saving module configured to save the user-side traffic data by taking the external network IP as an index through the first traffic probe.

[0201] In an optional embodiment of the present application, the internal network intruded host identification system further includes a second traffic probe, the second traffic probe is deployed in a security resource pool and is configured to listen to security cloud-side traffic data of the security resource pool; the target internal network host identification module 504 can include:

[0202] a source judgment submodule configured to judge whether the plurality of target user-side traffic data are all from the same internal network host;

[0203] a target security cloud-side traffic data acquisition submodule configured to acquire target security cloud-side traffic data corresponding to the security log from the second traffic probe if the answer is no;

[0204] a traffic type determination submodule configured to determine a traffic type of the target security cloud-side traffic data;

[0205] a traffic data matching submodule configured to match the target security cloud-side traffic data with each target user-side traffic data based on the traffic type;

[0206] The first target intranet host identification submodule is configured to identify the target intranet host that is invaded according to the matching result.

[0207] In an optional embodiment of the present application, the target security cloud-side traffic data comprises a first TCP sequence number, and each target user-side traffic data comprises a second TCP sequence number; the traffic data matching submodule can comprise:

[0208] The target second TCP sequence number searching unit is configured to search for a target second TCP sequence number that is the same as the first TCP sequence number from each second TCP sequence number if the traffic type is a TCP protocol;

[0209] The first target intranet host identification submodule can comprise:

[0210] The first target intranet IP extraction unit is configured to extract a target intranet IP from the target user-side traffic data corresponding to the target second TCP sequence number;

[0211] The first target intranet host identification unit is configured to identify the intranet host corresponding to the target intranet IP as the target intranet host that is invaded.

[0212] In an optional embodiment of the present application, the traffic data matching submodule can comprise:

[0213] The mapping unit is configured to map the target security cloud-side traffic data into a first column vector and map each target user-side traffic data into a second column vector if the traffic type is a UDP protocol;

[0214] The cosine similarity calculation unit is configured to calculate the cosine similarity between the first column vector and each second column vector;

[0215] The first target intranet host identification submodule can comprise:

[0216] The target cosine similarity determination unit is configured to determine the maximum target cosine similarity;

[0217] The second target intranet IP extraction unit is configured to extract a target intranet IP from the target user-side traffic data corresponding to the target cosine similarity;

[0218] The second target intranet host identification unit is configured to identify the intranet host corresponding to the target intranet IP as the target intranet host that is invaded.

[0219] In an optional embodiment of the present application, after judging whether the plurality of target user-side traffic data are from the same intranet host, the target intranet host identification module can further comprise:

[0220] a target internal network host extraction submodule, configured to extract a target internal network IP from one of the target user-side traffic data if yes;

[0221] a second target internal network host identification submodule, configured to identify the internal network host corresponding to the target internal network IP as a target internal network host that is invaded.

[0222] To sum up, in the embodiment of the present application, the receiving network intrusion detection system receives the security log sent by the user side when detecting an intrusion event; the security log includes the occurrence time, the IP of the NAT device and the IP of the intruder; the target first traffic probe corresponding to the IP of the NAT device is determined; the target user-side traffic data matching the occurrence time and the IP of the intruder is obtained from the target first traffic probe; and the target internal network host that is invaded is identified by using the target user-side traffic data. By deploying the traffic probe on the NAT device, the user-side traffic data can be monitored by the traffic probe, the target user-side traffic data used to identify the target internal network host that is invaded is obtained from the corresponding traffic probe by using the occurrence time, the IP of the NAT device and the IP of the intruder, and thus the internal network host corresponding to the traffic data converted by the NAT can be identified, thereby improving the value of the security service.

[0223] For the device embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the related parts refer to the part of the method embodiment.

[0224] The embodiment of the present application also provides an electronic device, which comprises a processor, a memory, a computer program stored in the memory and executable on the processor, and the computer program implements the processes of the above-mentioned internal network host identification method embodiment and achieves the same technical effects when executed by the processor, and details are not repeated here.

[0225] The embodiment of the present application also provides a computer readable storage medium, which stores a computer program, and the computer program implements the processes of the above-mentioned internal network host identification method embodiment and achieves the same technical effects when executed by the processor, and details are not repeated here.

[0226] Each embodiment in the specification is described in a progressive manner, and each embodiment focuses on the difference from other embodiments, and the same and similar parts of each embodiment can be referred to.

[0227] Those skilled in the art will appreciate that embodiments of the present application can be readily used as a method, apparatus, or computer program product. Accordingly, embodiments of the present application can take the form of an entirely hardware embodiment, an entirely software embodiment or an embodiment combining software and hardware aspects. Furthermore, embodiments of the present application can take the form of a computer program product on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROMs, optical storage devices, and the like) embodying computer program instructions.

[0228] Embodiments of the present application are described herein with reference to flowchart illustrations and / or block diagrams of methods, terminal devices (systems), and computer program products according to embodiments of the application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general purpose computer, special purpose computer, embedded processor, or other programmable data processing terminal apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing terminal apparatus, create means for implementing the functions specified in the flowchart illustrations and / or block diagrams. Figure 1 one or more functions specified in the flowchart illustrations and / or block diagrams. Figure 1 one or more functions specified in the flowchart illustrations and / or block diagrams.

[0229] These computer program instructions can also be stored in a computer- readable memory that can direct a computer or other programmable data processing terminal apparatus to function in a particular manner, such that the instructions stored in the computer-readable memory produce an article of manufacture including instructions which implement the functions specified in the flowchart illustrations and / or block diagrams. Figure 1 one or more functions specified in the flowchart illustrations and / or block diagrams. Figure 1 one or more functions specified in the flowchart illustrations and / or block diagrams.

[0230] These computer program instructions can also be loaded onto a computer or other programmable data processing terminal apparatus to cause a series of operational steps to be performed on the computer or other programmable terminal apparatus to produce a computer implemented process such that the instructions which execute on the computer or other programmable terminal apparatus provide steps for implementing the functions specified in the flowchart illustrations and / or block diagrams. Figure 1 one or more functions specified in the flowchart illustrations and / or block diagrams. Figure 1 one or more functions specified in the flowchart illustrations and / or block diagrams.

[0231] While preferred embodiments of the present application have been described, modifications and alterations thereto will occur to those skilled in the art upon reading the preceding description. In particular, it will be apparent to those skilled in the art that parts can be added to, or substituted for, parts of the described embodiments of the present application. Accordingly, the application is intended to be

[0232] Finally, it is to be understood that the phraseology or terminology such as "first" and "second" etc. used herein is merely intended to differentiate one entity or operation from another entity or operation, without necessarily requiring or implying any actual such relationship or order between such entities or operations. Moreover, the terms "comprises", "comprising", or any other variations thereof, are intended to cover a non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements does not include only those elements but can include other elements not expressly listed or inherent to such process, method, article, or apparatus. An element proceeded by "comprises... a" does not, without more constraints, exclude the existence of additional identical elements in the process, method, article, or apparatus that comprises the element.

[0233] The above describes the intranet host identification method, device, electronic equipment and computer readable storage medium provided by the present application in detail. The principles and implementation manners of the present application are described by applying specific examples. The above description of the embodiments is only used to help understand the method of the present application and its core idea. Meanwhile, for those skilled in the art, according to the idea of the present application, the specific implementation manners and application ranges will be changed. In summary, the content of the specification should not be understood as a limitation of the present application.

Claims

1. An intranet host identification method, characterized by, The application is applied to an intranet invaded host identification system, the intranet invaded host identification system is in communication connection with a network intrusion detection system, the intranet invaded host identification system comprises a first traffic probe, the first traffic probe is arranged in a network address translation (NAT) device and is used for listening to user side traffic data of the NAT device, and the method comprises the following steps: receiving a security log sent by the network intrusion detection system when detecting that an intrusion event occurs on the user side; the security log comprises a time of occurrence, an Internet Protocol (IP) of the NAT device and an IP of an intruder; determining a target first traffic probe corresponding to the IP of the NAT device; acquiring target user side traffic data matched with the time of occurrence and the IP of the intruder from the target first traffic probe; identifying a target intranet host invaded by using the target user side traffic data.

2. The method of claim 1, wherein, The target first traffic probe corresponds to a plurality of indexes; the target user side traffic data matched with the time of occurrence and the IP of the intruder is acquired from the target first traffic probe, comprising the following steps: determining a target index matched with the IP of the intruder from the plurality of indexes; the target index corresponds to a plurality of user side traffic data; acquiring target user side traffic data within a preset time period before and after the time of occurrence from the plurality of user side traffic data; the target user side traffic data comprises a plurality of.

3. The method of claim 1, wherein, Before the receiving step, the method further comprises the following steps: collecting a plurality of first data packets by the first traffic probe; the first data packet comprises five-tuple information; recombining first data packets with the same five-tuple information into a second data packet in time sequence by the first traffic probe; the second data packet comprises a plurality of; extracting user side traffic data from the plurality of second data packets by the first traffic probe; the user side traffic data comprises an external network IP; saving the user side traffic data by the first traffic probe by taking the external network IP as an index.

4. The method of claim 2, wherein, The intranet invaded host identification system further comprises a second traffic probe, the second traffic probe is arranged in a security resource pool and is used for listening to security cloud side traffic data of the security resource pool; The method further comprises the following steps: determining whether a plurality of target user side traffic data are all from the same intranet host; if not, acquiring target security cloud side traffic data corresponding to the security log from the second traffic probe; determining a traffic type of the target security cloud side traffic data; matching the target security cloud side traffic data with each target user side traffic data based on the traffic type; identifying a target intranet host invaded according to a matching result.

5. The method of claim 4, wherein, The target security cloud side traffic data comprises a first TCP sequence number, and each target user side traffic data comprises a second TCP sequence number; the matching the target security cloud side traffic data with each target user side traffic data based on the traffic type comprises the following steps: If the flow type is Transmission Control Protocol (TCP), a target second TCP sequence number identical to the first TCP sequence number is searched from each second TCP sequence number; The target internal network host invaded is identified according to the matching result, and the method comprises the steps that: A target internal network IP is extracted from target user-side flow data corresponding to the target second TCP sequence number; An internal network host corresponding to the target internal network IP is identified as the target internal network host invaded.

6. The method of claim 4, wherein, The target security cloud-side flow data is matched with each target user-side flow data based on the flow type, and the method comprises the steps that: If the flow type is User Datagram Protocol (UDP), the target security cloud-side flow data is mapped into a first column vector, and each target user-side flow data is mapped into a second column vector; Cosine similarity between the first column vector and each second column vector is calculated; The target internal network host invaded is identified according to the matching result, and the method comprises the steps that: A maximum target cosine similarity is determined; A target internal network IP is extracted from target user-side flow data corresponding to the target cosine similarity; An internal network host corresponding to the target internal network IP is identified as the target internal network host invaded.

7. The method of claim 4, wherein, After judging whether the plurality of target user-side flow data are from the same internal network host, the method further comprises the steps that: If yes, a target internal network IP is extracted from one of the target user-side flow data; An internal network host corresponding to the target internal network IP is identified as the target internal network host invaded.

8. An intranet host identification apparatus characterized by comprising: The application is applied to an internal network host invaded identification system, the internal network host invaded identification system is in communication connection with a network intrusion detection system, the internal network host invaded identification system comprises a first flow probe, the first flow probe is arranged in a NAT device and is used for listening to user-side flow data of the NAT device, and the device comprises: A security log receiving module is used for receiving a security log sent by the network intrusion detection system when an intrusion event occurs on a user side is detected, the security log comprises an occurrence time, an IP of the NAT device and an IP of an intruder; A target first flow probe determining module is used for determining a target first flow probe corresponding to the IP of the NAT device; A target user-side flow data obtaining module is used for obtaining target user-side flow data matched with the occurrence time and the IP of the intruder from the target first flow probe; A target internal network host identification module is used for identifying a target internal network host invaded by using the target user-side flow data.

9. An electronic device, comprising: The application comprises: A processor, a memory and a computer program stored on the memory and executable on the processor, when the computer program is executed by the processor, steps of an internal network host identification method in any one of claims 1 to 7 are implemented.

10. A computer-readable storage medium, characterized in that, A computer program is stored on the computer readable storage medium, when the computer program is executed by a processor, steps of an internal network host identification method in any one of claims 1 to 7 are implemented.

Citation Information

Patent Citations

  • Method, equipment and system for positioning controlled host in internal network

    CN108632221A

  • Intranet computer network behavior monitoring method, device and equipment

    CN111885087A