A comprehensive situation management system and method based on cross-domain secure communication

CN116488859BActive Publication Date: 2026-06-02THE QUARTERMASTER RES INST OF THE GENERAL LOGISTICS DEPT OF THE CPLA

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
THE QUARTERMASTER RES INST OF THE GENERAL LOGISTICS DEPT OF THE CPLA
Filing Date
2023-03-20
Publication Date
2026-06-02

Smart Images

  • Figure CN116488859B_ABST
    Figure CN116488859B_ABST
Patent Text Reader

Abstract

The application discloses a kind of integrated situation management method and system based on cross-domain security communication, and the way of trust transmission is proposed in cross-domain equipment, so that the equipment and terminal of cross-domain security communication are all through trusted authentication, only the equipment that passes authentication and is controlled can provide cross-domain security communication service;The security alarm information of existing firewall, network probe, security probe is unified and integrated, and the security alarm of cross-domain data in link transmission process is situationally displayed;By the active submission of terminal cross-domain service business intercommunication request, the controllability is stronger, and the controlled service intensity is refined to the regular implementation to service end side;Integrated situation management monitors the service behavior of cross-domain equipment and terminal from the whole global angle, and the monitoring state of link security equipment, and is displayed in a unified way, to provide better global situation for administrator.The application can carry out controllable service security transmission in the environment based on existing multi-network domain.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of cross-domain secure communication technology, and in particular to an implementation and method of a comprehensive situational management system based on cross-domain secure communication. Background Technology

[0002] Cross-domain secure communication is a key support service that provides controlled interaction between networks with different security levels, different service-bearing networks, and different administrative management networks. Its benefits include the ability to integrate services on a large scale, improving the efficiency and convenience of integrated collaborative operations. However, the convergence of multiple services inevitably brings security risks such as leakage, data smuggling, diffusion, and uncontrollability. Management and security measures are crucial for improving cross-domain secure communication. Issues that need to be considered in cross-domain secure interaction include: how to interconnect across domains, what kind of business data can be exchanged, what terminals can interconnect across domains, how to discover potential risks in interconnected data, how to display the current interconnection status, and how to manage the interconnection status.

[0003] Existing technologies for detecting potential data risks include firewalls, IDS, network probes, and security probes. However, the associated management actions are limited to local areas and cannot provide overall situational awareness or pinpoint key business data. Cross-domain interconnection currently employs firewalls and gateways, but these technologies each have their limitations in network isolation, protocol isolation, on-the-ground inspection, unified management, and business transparency. For example, how can firewalls perform on-the-ground inspections, and how can gateways provide unified management and business transparency? Current technologies for access terminals primarily use 802.1X and access authentication, but these also involve local authentication. Current business authorization methods mainly involve single authorization on specific devices. The limitation is that when routing changes or the direction of business data flow changes, it's unclear whether other security devices should authorize specific services. All of these centralized protection methods have significant limitations and cannot be coordinated in integrated cross-domain secure communication operations. Therefore, we propose a comprehensive situational awareness management method and system for cross-domain secure communication. Summary of the Invention

[0004] The purpose of this invention is to provide a comprehensive situation management method and system based on cross-domain secure communication. Through effective authentication and transmission, centralized service authorization, distributed management of cross-domain devices, distributed collection of security situation data, and comprehensive situation presentation, it achieves comprehensive situation management in the context of multi-domain interconnection, ensuring controllable and secure service transmission in the existing multi-domain environment.

[0005] The technical solution for achieving the objective of this invention is: a comprehensive situational awareness management system based on cross-domain secure communication, the system comprising:

[0006] Select the domain with the highest management authority among multiple domains, and deploy multiple servers in this domain. Install comprehensive situation management software on the servers. This software provides trusted authentication nodes for each domain and performs centralized policy control, cross-domain business authorization, centralized security situation message collection, and comprehensive situation management display functions for all boundary isolation devices that provide cross-domain communication services. The software provides distributed deployment, forming a control situation cloud among itself.

[0007] Install cross-domain proxy service software on terminals or servers that have cross-domain requirements in various network domains to handle cross-domain interconnection access authentication of terminals, confirm identity authorization, and provide cross-domain transmission services for business data that requires cross-domain interaction.

[0008] In the business bearer network of each business domain, security situation message servers are deployed in parallel. After collecting security monitoring alarms reported by lower-level security devices, the security situation message servers will periodically upload the reports to the integrated situation management software.

[0009] Deploy boundary isolation devices at the edges of different network domains to provide controlled transmission services for cross-domain services. This service includes authentication of cross-domain services, authentication of cross-domain terminals, authentication of cross-domain authorization time, and physical landing, content format checking, concealment checking, feature dictionary checking, and transmission protocol isolation of cross-domain service data. Log the processed data and report it to the integrated situation management software periodically.

[0010] A comprehensive situational awareness management method based on cross-domain secure communication is as follows:

[0011] First, install integrated situation management software on multiple servers and configure an authentication baseline on each server's integrated situation management software, using a combination of certificate, hardware information, and IP address information for authentication; then configure the target authentication server IP address to be the IP address of another integrated situation management software, and then perform pairwise two-way authentication; through this process, mutual security and trust are achieved, thereby forming an integrated situation management cloud and establishing authentication root nodes for cross-domain secure communication;

[0012] Before providing secure and controlled cross-domain transmission services, boundary isolation devices deployed at the edge of various network domains need to be connected to the integrated situation management cloud. First, the device management IP address, internet domain identifier, internet domain business interface IP address, and access authentication service IP address are configured on the device. Then, the authentication certificate, device hardware information, and device IP address are imported from the external source. After that, an access application is submitted to the integrated situation management cloud. The approval results are obtained periodically, and access authentication is performed after the approval results are obtained.

[0013] After the boundary isolation device is connected to the authentication integrated situation management and control cloud, it is also integrated into the security access authentication server, providing access authentication services to lower-level terminals and security situation message servers, forming a gradual diffusion of authentication transmission;

[0014] The security situation message servers distributed across various network domains submit access authentication applications to the adjacent integrated situation management and control cloud or border isolation device according to the authentication steps of the border isolation device: if there is an integrated situation management and control cloud in the current network domain, the application is submitted to that cloud; if there is no integrated situation management and control cloud in the current network domain, the application is submitted to the border isolation device. The servers also periodically obtain the approval results. After approval, the servers initiate the access authentication process to the authentication server. After successful authentication, the servers are also integrated into the security access authentication server to provide access authentication services to lower-level terminals.

[0015] Terminals or servers distributed across various network domains that have cross-domain business interoperability needs should also submit access authentication applications to adjacent boundary isolation devices or security status message servers according to the authentication steps of the security status message server, and obtain the approval results periodically. After the approval is passed, they should initiate the access authentication process to the authentication server to complete the authentication.

[0016] After completing the lower-level authentication, the boundary isolation device and the security situation message server report the entity information of the authenticated end to the integrated situation management and control cloud level by level, forming a global situation of security authentication on the integrated situation management and control cloud; through the gradual completion of authentication by each end and device, a network-wide authenticated access situation is formed.

[0017] When a cross-domain business terminal or server is ready to communicate with other cross-domain services after the access authentication is completed, it needs to specify the target IP, target port and protocol of the cross-domain communication service. The communication request is submitted to the authentication server through the cross-domain proxy service software. The authentication server is the server for terminal authentication, which is either a boundary isolation device or a security situation message server. The submitted information includes four elements: local IP, target IP, target port and protocol.

[0018] After receiving a cross-domain communication request from a cross-domain business terminal or server, the boundary isolation device or security situation message server will submit the request upwards step by step, and finally submit it to the integrated situation management cloud.

[0019] After receiving a cross-domain communication request from a terminal, the integrated situation management software approves the request. Once approved, the result is sent to the boundary isolation device in the form of an interoperability policy. The boundary isolation device stores the user's business policy information. The boundary isolation device then sends the approval result to the cross-domain business terminal or the cross-domain proxy on the server.

[0020] Compared with the prior art, the significant advantages of this invention are:

[0021] (1) A trust transfer method is proposed for cross-domain devices, so that all devices and terminals for cross-domain secure communication are trusted and authenticated. Only authenticated and controlled devices can provide cross-domain secure communication services.

[0022] (2) The security alarm information of existing firewalls, network probes and security probes has been unified and integrated, and the security alarms of cross-domain data during the link transmission process are displayed in a situational manner.

[0023] (3) The cross-domain business of the terminal actively submits the business interoperability request, and the controlled business intensity is refined to the standardization and implementation on the business end side, which makes it more controllable.

[0024] (4) Comprehensive situational awareness management monitors the business behavior of cross-domain devices and terminals, as well as the monitoring status of link security devices, from a holistic global perspective. This information is then displayed in a unified manner, providing administrators with a better overall situational awareness. Attached Figure Description

[0025] Figure 1 This is a network deployment diagram of an integrated situational management system based on cross-domain secure communication.

[0026] Figure 2 This is an authentication block diagram for cross-domain secure communication.

[0027] Figure 3 It is a tree diagram of authentication reporting.

[0028] Figure 4 This is a comprehensive flowchart of a comprehensive situational management method based on cross-domain secure communication. Detailed Implementation

[0029] It is readily understood that, based on the technical solution of this invention, those skilled in the art can conceive of various embodiments of this invention without altering its essential spirit. Therefore, the following specific embodiments and accompanying drawings are merely illustrative examples of the technical solution of this invention and should not be considered as the entirety of this invention or as limitations or restrictions on its technical solution.

[0030] Various exemplary embodiments of the present invention will now be described in detail with reference to the accompanying drawings. It should be noted that, unless otherwise specifically stated, the relative arrangement, numerical expressions, and values ​​of the components and steps set forth in these embodiments do not limit the scope of the invention.

[0031] The following description of at least one exemplary embodiment is merely illustrative and is in no way intended to limit the invention or its application or use.

[0032] Techniques, methods, and equipment known to those skilled in the art may not be discussed in detail, but where appropriate, such techniques, methods, and equipment should be considered part of the specification.

[0033] In all the examples shown and discussed herein, any specific values ​​should be interpreted as merely exemplary and not as limitations. Therefore, other examples of exemplary embodiments may have different values.

[0034] This invention discloses a comprehensive situational awareness management system based on cross-domain secure communication, the system comprising:

[0035] Select the domain with the highest management authority among multiple domains, and deploy multiple servers in this domain. Install comprehensive situation management software on the servers. This software provides trusted authentication nodes for each domain and performs centralized policy control, cross-domain business authorization, centralized security situation message collection, and comprehensive situation management display functions for all boundary isolation devices that provide cross-domain communication services. The software provides distributed deployment, forming a control situation cloud among itself.

[0036] Install cross-domain proxy service software on terminals or servers that have cross-domain requirements in various network domains to handle cross-domain interconnection access authentication of terminals, confirm identity authorization, and provide cross-domain transmission services for business data that requires cross-domain interaction.

[0037] In the business bearer network of each business domain, security situation message servers are deployed in parallel. After collecting security monitoring alarms reported by lower-level security devices, the security situation message servers will periodically upload the reports to the integrated situation management software.

[0038] Deploy boundary isolation devices at the edges of different network domains to provide controlled transmission services for cross-domain services. This service includes authentication of cross-domain services, authentication of cross-domain terminals, authentication of cross-domain authorization time, and physical landing, content format checking, concealment checking, feature dictionary checking, and transmission protocol isolation of cross-domain service data. Log the processed data and report it to the integrated situation management software periodically.

[0039] As a specific example, in the system networking, the integrated situation management software is deployed on multiple servers to form a situation management cloud, with each server providing data backup for the others; cross-domain agents are installed on edge terminals, and security situation message servers are deployed in parallel and bypassed in various network domains, with boundary isolation devices deployed at the interconnection edges of each network domain; the various parts of the system networking work together to provide cross-domain security communication integrated situation management services.

[0040] As a specific example, the domain with the highest administrative privileges refers to the domain with the highest network security level.

[0041] As a specific example, security posture message servers are deployed in parallel within the business bearer networks of various business domains. Specifically, they are deployed next to the local area network egress firewall, network probes, and security probes. These servers are used to collect and receive security monitoring alarms from security devices in a distributed manner, and to filter the received security monitoring alarms. The filtering strategy is based on a triple: source IP + protocol + destination port. The source IP is the IP address of the terminal that has been connected to the cross-domain interconnection, and the protocol + destination port is the authorized cross-domain interconnection service.

[0042] This invention provides a comprehensive situational awareness management method based on cross-domain secure communication, as detailed below:

[0043] First, install integrated situation management software on multiple servers and configure an authentication baseline on each server's integrated situation management software, using a combination of certificate, hardware information, and IP address information for authentication; then configure the target authentication server IP address to be the IP address of another integrated situation management software, and then perform pairwise two-way authentication; through this process, mutual security and trust are achieved, thereby forming an integrated situation management cloud and establishing authentication root nodes for cross-domain secure communication;

[0044] Before providing secure and controlled cross-domain transmission services, boundary isolation devices deployed at the edge of various network domains need to be connected to the integrated situation management cloud. First, the device management IP address, internet domain identifier, internet domain business interface IP address, and access authentication service IP address are configured on the device. Then, the authentication certificate, device hardware information, and device IP address are imported from the external source. After that, an access application is submitted to the integrated situation management cloud. The approval results are obtained periodically, and access authentication is performed after the approval results are obtained.

[0045] After the boundary isolation device is connected to the authentication integrated situation management and control cloud, it is also integrated into the security access authentication server, providing access authentication services to lower-level terminals and security situation message servers, forming a gradual diffusion of authentication transmission;

[0046] The security situation message servers distributed across various network domains submit access authentication applications to the adjacent integrated situation management and control cloud or border isolation device according to the authentication steps of the border isolation device: if there is an integrated situation management and control cloud in the current network domain, the application is submitted to that cloud; if there is no integrated situation management and control cloud in the current network domain, the application is submitted to the border isolation device. The servers also periodically obtain the approval results. After approval, the servers initiate the access authentication process to the authentication server. After successful authentication, the servers are also integrated into the security access authentication server to provide access authentication services to lower-level terminals.

[0047] Terminals or servers distributed across various network domains that have cross-domain business interoperability needs should also submit access authentication applications to adjacent boundary isolation devices or security status message servers according to the authentication steps of the security status message server, and obtain the approval results periodically. After the approval is passed, they should initiate the access authentication process to the authentication server to complete the authentication.

[0048] After completing the lower-level authentication, the boundary isolation device and the security situation message server report the entity information of the authenticated end to the integrated situation management and control cloud level by level, forming a global situation of security authentication on the integrated situation management and control cloud; through the gradual completion of authentication by each end and device, a network-wide authenticated access situation is formed.

[0049] When a cross-domain business terminal or server is ready to communicate with other cross-domain services after the access authentication is completed, it needs to specify the target IP, target port and protocol of the cross-domain communication service. The communication request is submitted to the authentication server through the cross-domain proxy service software. The authentication server is the server for terminal authentication, which is either a boundary isolation device or a security situation message server. The submitted information includes four elements: local IP, target IP, target port and protocol.

[0050] After receiving a cross-domain communication request from a cross-domain business terminal or server, the boundary isolation device or security situation message server will submit the request upwards step by step, and finally submit it to the integrated situation management cloud.

[0051] After receiving a cross-domain communication request from a terminal, the integrated situation management software approves the request. Once approved, the result is sent to the boundary isolation device in the form of an interoperability policy. The boundary isolation device stores the user's business policy information. The boundary isolation device then sends the approval result to the cross-domain business terminal or the cross-domain proxy on the server.

[0052] As a specific example, the extracted device hardware information includes the hard drive serial number and the CPU serial number.

[0053] As a specific example, the integrated situational awareness management software can configure policies for cross-domain controlled services on the certified boundary isolation devices. The configuration methods are divided into unified configuration for all devices and configuration for individual devices. The configured policies include: service activation time and activated services. This policy is a minimum configuration. The minimum configuration only identifies the services that the device may be able to provide. At this time, it is not bound to the cross-domain terminal. Therefore, after the policy is configured on the device, the device does not yet have the ability to provide cross-domain controlled transmission services.

[0054] As a specific example, after receiving the approval result, the cross-domain agent of the cross-domain business terminal or server starts the cross-domain transmission service, performs cross-domain tunnel encapsulation on the cross-domain message, and sends the cross-domain tunnel target address from the business end to the boundary isolation device.

[0055] As a concrete example, after receiving cross-domain tunnel data from the service end, the boundary isolation device first checks the tunnel; then, it checks the policy of the cross-domain service's five-tuple source address, destination address, protocol, source port, and destination port. The policy checked includes two parts: first, the user's approval policy: source IP, destination IP, protocol, and destination port; second, the minimum policy set by the comprehensive situation management for the interconnection device: protocol and destination port; then, it performs data persistence on the service protocol, checking for format, inclusions, and feature dictionaries, discarding abnormal data, and generating log records that are uploaded to the comprehensive management and control software; finally, it re-encapsulates the persisted data to achieve transmission protocol isolation.

[0056] As a specific example, the security posture message server passively receives security monitoring alarms from link security devices via syslog. Link security devices include firewalls, network probes, and security probes.

[0057] The monitoring and alarm messages received by the security situation message server include: security alarm information, time, data quintuple, and alarm level; after receiving the alarm information, it synchronously sends the monitoring and alarm information to the authentication superior until it is sent to the integrated situation management software;

[0058] After receiving logs and alarm information from the boundary isolation device and the security situation message server, the integrated situation management software performs local data behavior analysis, combines cross-domain behavior logs and alarm information to obtain cross-domain business behavior logs, communication traffic, security situation, and behavior warnings, and comprehensively displays them to operation and maintenance management personnel.

[0059] The present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments.

[0060] Example

[0061] This embodiment addresses the security risks and technical shortcomings of cross-domain communication arising from the integration of existing multi-domain interconnected services by providing an implementation and method for a comprehensive situational management system based on cross-domain secure communication.

[0062] To achieve the above-mentioned objectives, the technical solution adopted by this invention is as follows:

[0063] The first aspect provides a comprehensive situational awareness management system based on cross-domain secure communication, which includes the following components:

[0064] Select the domain with the highest management privileges among multiple domains, such as the domain with the highest network security level, and deploy multiple servers in this domain, installing comprehensive situational awareness management software on the servers. This software provides trusted authentication nodes for each domain and performs centralized policy control, cross-domain business authorization, centralized security situational awareness message collection, and comprehensive situational awareness management and display functions for all boundary isolation devices that provide cross-domain interoperability services. The software provides distributed deployment, forming a control and situational awareness cloud among itself.

[0065] Install cross-domain proxy service software on terminals or servers in various network domains that have cross-domain requirements. This software is used to handle cross-domain interconnection access authentication of terminals, confirm identity authorization, and provide cross-domain transmission services for business data that requires cross-domain interaction.

[0066] In the business bearer networks of various business domains, security situation message servers are deployed in parallel, such as near LAN egress firewalls, network probes, and security probes. These servers are used for distributed collection and reception of security monitoring alarms from security devices, and for filtering the received alarms. The filtering strategy is based on a triple (source IP + protocol + destination port), where the source IP is the IP address of a terminal already connected to the cross-domain interconnection, and the protocol + destination port represents authorized cross-domain interconnection services. After collecting security monitoring alarms reported by lower-level security devices, the security situation message server periodically uploads the reports to the integrated situation management software.

[0067] Boundary isolation devices are deployed at the edges of different network domains to provide controlled cross-domain service transmission. This service includes authentication of cross-domain services, authentication of cross-domain terminals, and authentication of cross-domain authorization time. It also performs entity-based authentication, content format checks, concealment checks, and feature dictionary checks on cross-domain service data, as well as transmission protocol isolation. The processed data is logged and periodically reported to the integrated situational awareness software. The system network deployment diagram is shown below. Figure 1 .

[0068] In the system networking, the integrated situation management software is deployed on multiple servers to form a situation management cloud. They serve as data backups for each other. Cross-domain agents are installed on edge terminals, and security situation message servers are deployed in parallel in each network domain. Boundary isolation devices are deployed at the interconnection edge of each network domain. They work together to provide cross-domain secure communication and integrated situation management services.

[0069] The second aspect provides a comprehensive situational management method based on cross-domain secure communication, which includes:

[0070] First, install the integrated situation management software on multiple servers and configure an authentication baseline on each server's software, using a combination of certificate, hardware information, and IP address information for authentication. Then, configure the target authentication server's IP address, which can be the IP address of another integrated situation management software server, and then perform mutual authentication between them. This process achieves mutual security and trust, thus forming an integrated situation management cloud and establishing an authentication root node for cross-domain secure communication. The specific authentication diagram is as follows: Figure 2 .

[0071] Border isolation devices deployed at the edge of various network domains need to connect to the integrated situational awareness cloud before providing secure and controlled cross-domain transmission services. This requires configuring the device's management IP address, internet domain identifier, internet domain service interface IP address, and access authentication service IP address on the device. Then, the authentication certificate, device hardware information (e.g., hard drive serial number + CPU serial number), and device IP address are imported from external sources. Finally, an access application is submitted to the integrated situational awareness cloud. Approval results are periodically retrieved, and access authentication is performed upon receiving the approval.

[0072] After the boundary isolation device is connected to the authentication integrated situation management and control cloud, the device is also integrated into the secure access authentication service. It can provide access authentication services to lower-level terminals and security situation message servers, forming a gradual diffusion of authentication transmission.

[0073] The security situation message servers distributed across various network domains submit access authentication applications to the adjacent integrated situation management and control cloud or the boundary isolation device, following the authentication steps of the boundary isolation device. (If the network domain has an integrated situation management and control cloud, the application is submitted to that cloud; otherwise, it is submitted to the boundary isolation device.) They periodically retrieve approval results, and upon successful approval, initiate the access authentication process to the authentication server. After successful authentication, they are also integrated into the security access authentication server, providing access authentication services to lower-level terminals. See the boundary isolation device's flowchart for the authentication process diagram.

[0074] Terminals or servers distributed across various network domains that require cross-domain business interoperability submit access authentication applications to adjacent boundary isolation devices or security status message servers, following the authentication steps of the security status message server. They periodically retrieve approval results, and upon successful approval, initiate the access authentication process to the authentication server to complete the authentication. See the boundary isolation device's flowchart for the authentication process diagram.

[0075] After completing lower-level authentication, the boundary isolation devices and security situation message server report the entity information of the authenticated endpoints to the integrated situation management and control cloud level by level, forming a global security authentication situation on the integrated situation management and control cloud. Authentication is completed step by step through various endpoints and devices, forming a network-wide authenticated access situation. The specific authentication reporting tree diagram is as follows: Figure 3 .

[0076] The integrated situational awareness management software allows for policy configuration of cross-domain controlled services on certified boundary isolation devices. Configuration methods include unified configuration for all devices and configuration for individual devices. The configured policies include: service activation time and activated services (protocol + port). This policy is a minimum-level configuration. Minimum-level configuration only identifies the services that the device may be able to provide; it does not yet finely bind to the cross-domain terminal. Therefore, after this policy is configured on the device, the device does not yet have the capability to provide cross-domain controlled transmission services.

[0077] After the cross-domain business terminal / server completes access authentication, when preparing for cross-domain business interoperability, it is necessary to specify the target IP, target port and protocol of the cross-domain interoperability business, and submit the interoperability request to the authentication server through the cross-domain proxy service software (the server here is the terminal authentication server, which can be a border isolation device or a security situation message server). The submitted information includes four elements: local IP, target IP, target port and protocol.

[0078] After receiving a cross-domain communication request from a cross-domain business terminal / server, the boundary isolation device or security situation message server will submit the request upwards step by step, and finally submit it to the integrated situation management cloud.

[0079] After receiving a cross-domain communication request from a terminal, the integrated situational management software approves the request. Upon approval, the result is sent to the border isolation device as an interoperability policy, where the user-specific business policy information is stored. The border isolation device then sends the approval result to the cross-domain proxy on the cross-domain service client / server.

[0080] After receiving the approval result, the cross-domain proxy of the cross-domain business terminal / server starts the cross-domain transmission service, performs cross-domain tunnel encapsulation on the cross-domain message, and sends the cross-domain tunnel target address from the business terminal to the boundary isolation device.

[0081] After receiving cross-domain tunnel data from the service end, the boundary isolation device first checks the tunnel; then it checks the cross-domain service five-tuple (source address, destination address, protocol, source port, destination port) for policy. The policy here includes two parts: 1. the user's approval policy (source IP, destination IP, protocol, destination port), 2. the minimum policy set for the interconnection device by the comprehensive situation management (protocol, destination port); then it performs data persistence on the service protocol, checks the format, inclusions, and feature dictionaries, discards abnormal data, and generates log records that are uploaded to the comprehensive management and control software; finally, it re-encapsulates the persisted data to achieve transmission protocol isolation.

[0082] The security posture message server passively receives security monitoring alarms from link security devices via syslog. Link security devices include firewalls, network probes, and security probes. The monitoring alarm messages received by the security posture message server mainly include: security alarm information, time, data tuple, and alarm level. Upon receiving an alarm message, the server synchronously sends the monitoring alarm information to the authentication superior, until it reaches the integrated posture management software.

[0083] After receiving logs and alarm information from the boundary isolation device and the security status message server, the integrated situation management software performs local data behavior analysis. It combines cross-domain behavior logs and alarm information to obtain cross-domain business behavior logs, communication traffic, security status, and behavior alerts, which are then comprehensively displayed to operations and maintenance personnel. The system's overall flowchart is as follows: Figure 4 .

[0084] The above description is only a preferred embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any changes or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in the present invention should be included within the scope of protection of the present invention.

[0085] It should be understood that, in order to simplify the present invention and help those skilled in the art understand its various aspects, in the above description of exemplary embodiments of the present invention, various features of the present invention are sometimes described in a single embodiment or with reference to a single figure. However, the present invention should not be construed as including all features in the exemplary embodiments as essential technical features of the claims of this patent.

Claims

1. A comprehensive situational awareness management system based on cross-domain secure communication, characterized in that, The system includes: Select the domain with the highest management authority among multiple domains, and deploy multiple servers in this domain. Install comprehensive situation management software on the servers. This software provides trusted authentication nodes for each domain and performs centralized policy control, cross-domain business authorization, centralized security situation message collection, and comprehensive situation management display functions for all boundary isolation devices that provide cross-domain communication services. The software provides distributed deployment, forming a control situation cloud among itself. Install cross-domain proxy service software on terminals or servers that have cross-domain requirements in various network domains to handle cross-domain interconnection access authentication of terminals, confirm identity authorization, and provide cross-domain transmission services for business data that requires cross-domain interaction. In the business bearer network of each business domain, security situation message servers are deployed in parallel. After collecting security monitoring alarms reported by lower-level security devices, the security situation message servers will periodically upload the reports to the integrated situation management software. Deploy boundary isolation devices at the edges of different network domains to provide controlled transmission services for cross-domain services. This service includes authentication of cross-domain services, authentication of cross-domain terminals, authentication of cross-domain authorization time, and physical landing, content format checking, concealment checking, feature dictionary checking, and transmission protocol isolation of cross-domain service data. Log the processed data and report it to the integrated situation management software periodically.

2. The integrated situation management system based on cross-domain secure communication according to claim 1, characterized in that, In the system network, the integrated situation management software is deployed on multiple servers to form a situation management cloud, with each server providing data backup for the others. Cross-domain agents are installed on edge terminals, and security situation message servers are deployed in parallel and bypassed in various network domains. Boundary isolation devices are deployed at the interconnection edges of each network domain. The various parts of the system network work together to provide cross-domain security communication and integrated situation management services.

3. The integrated situation management system based on cross-domain secure communication according to claim 1, characterized in that, The domain with the highest administrative privileges refers to the domain with the highest network security level.

4. The integrated situation management system based on cross-domain secure communication according to claim 1, characterized in that, In the business bearer networks of each business domain, security situation message servers are deployed in parallel, specifically next to the local area network egress firewall, network probes, and security probes. These servers are used to collect and receive security monitoring alarms from security devices in a distributed manner, and to filter the received security monitoring alarms. The filtering strategy is based on a triple: source IP + protocol + destination port. The source IP is the IP address of the terminal that has been connected to the cross-domain interconnection, and the protocol + destination port is the authorized cross-domain interconnection service.

5. A comprehensive situational awareness management method based on cross-domain secure communication, characterized in that, Specifically as follows: First, install the integrated situation management software on multiple servers, and configure the authentication baseline on the integrated situation management software on each server. Authentication is performed using a combination of certificate, hardware information, and IP address information. Then, configure the target authentication server IP address to be the IP address of another integrated situation management software, and then perform pairwise two-way authentication. This process enables mutual security and trust, thereby forming a comprehensive situational management cloud and establishing authentication and tracking nodes for cross-domain secure communication. Before providing secure and controlled cross-domain transmission services, boundary isolation devices deployed at the edge of various network domains need to be connected to the integrated situation management cloud. First, the device management IP address, internet domain identifier, internet domain business interface IP address, and access authentication service IP address are configured on the device. Then, the authentication certificate, device hardware information, and device IP address are imported from the external source. After that, an access application is submitted to the integrated situation management cloud. The approval results are obtained periodically, and access authentication is performed after the approval results are obtained. After the boundary isolation device is connected to the authentication integrated situation management and control cloud, it is also integrated into the security access authentication server, providing access authentication services to lower-level terminals and security situation message servers, forming a gradual diffusion of authentication transmission; The security situation message servers distributed across various network domains submit access authentication applications to the adjacent integrated situation management and control cloud or border isolation device according to the authentication steps of the border isolation device: if there is an integrated situation management and control cloud in this network domain, the application is submitted to that cloud; if there is no integrated situation management and control cloud in this network domain, the application is submitted to the border isolation device; and the approval results are obtained periodically. After the approval is passed, the access authentication process is initiated to the authentication server. After successful authentication, it is also integrated into the secure access authentication server to provide access authentication services to lower-level terminals; Terminals or servers distributed across various network domains that have cross-domain business interoperability needs should also submit access authentication applications to adjacent boundary isolation devices or security status message servers according to the authentication steps of the security status message server, and obtain the approval results periodically. After the approval is passed, they should initiate the access authentication process to the authentication server to complete the authentication. After completing the lower-level authentication, the boundary isolation device and the security situation message server report the entity information of the authenticated end to the integrated situation management and control cloud level by level, forming a global situation of security authentication on the integrated situation management and control cloud; through the gradual completion of authentication by each end and device, a network-wide authenticated access situation is formed. When a cross-domain business terminal or server is ready to communicate with other cross-domain services after the access authentication is completed, it needs to specify the target IP, target port and protocol of the cross-domain communication service. The communication request is submitted to the authentication server through the cross-domain proxy service software. The authentication server is the server for terminal authentication, which is either a boundary isolation device or a security situation message server. The submitted information includes four elements: local IP, target IP, target port and protocol. After receiving a cross-domain communication request from a cross-domain business terminal or server, the boundary isolation device or security situation message server will submit the request upwards step by step, and finally submit it to the integrated situation management cloud. After receiving a cross-domain communication request from a terminal, the integrated situation management software approves the request. Once approved, the result is sent to the boundary isolation device in the form of an interoperability policy. The boundary isolation device stores the user's business policy information. The boundary isolation device then sends the approval result to the cross-domain business terminal or the cross-domain proxy on the server.

6. The integrated situation management method based on cross-domain secure communication according to claim 5, characterized in that, The extracted device hardware information includes the hard drive serial number and the CPU serial number.

7. The integrated situational awareness management method based on cross-domain secure communication according to claim 5, characterized in that, The integrated situational awareness management software can configure policies for cross-domain controlled services on certified boundary isolation devices. The configuration methods are divided into unified configuration for all devices and configuration for individual devices. The configured policies include: service activation time and activated services. This policy is a minimum configuration. The minimum configuration only identifies the services that the device may be able to provide. At this time, it is not bound to the cross-domain terminal. Therefore, after the policy is configured on the device, the device does not yet have the ability to provide cross-domain controlled transmission services.

8. The integrated situational awareness management method based on cross-domain secure communication according to claim 5, characterized in that, After receiving the approval result, the cross-domain agent of the cross-domain business terminal or server starts the cross-domain transmission service, performs cross-domain tunnel encapsulation on the cross-domain message, and sends the cross-domain tunnel target address from the business end to the boundary isolation device.

9. The integrated situation management method based on cross-domain secure communication according to claim 5, characterized in that, After receiving cross-domain tunnel data from the service end, the boundary isolation device first checks the tunnel; then it checks the policy of the cross-domain service five-tuple source address, destination address, protocol, source port, and destination port. The policy checked includes two parts: First, the user's approval policy: source IP, destination IP, protocol, and destination port. Second, the minimum threshold policy for interconnected devices set by comprehensive situational management: protocol, target port; Next, the business protocol data is stored, and the format, inclusions, and feature dictionaries are checked. Abnormal data is discarded, and log records are generated and uploaded to the integrated management and control software. Finally, the stored data is re-encapsulated to achieve transmission protocol isolation.

10. The integrated situation management method based on cross-domain secure communication according to claim 5, characterized in that, The security posture message server passively receives security monitoring alarms from link security devices via syslog. Link security devices include firewalls, network probes, and security probes. The monitoring and alarm messages received by the security situation message server include: security alarm information, time, data quintuple, and alarm level; after receiving the alarm information, it synchronously sends the monitoring and alarm information to the authentication superior until it is sent to the integrated situation management software; After receiving logs and alarm information from the boundary isolation device and the security situation message server, the integrated situation management software performs local data behavior analysis, combines cross-domain behavior logs and alarm information to obtain cross-domain business behavior logs, communication traffic, security situation, and behavior warnings, and comprehensively displays them to operation and maintenance management personnel.