Outbound detection method and device, electronic equipment and nonvolatile storage medium
Patent Information
- Application Number
- CN202310432767.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-04-20
- Publication Date
- 2026-08-21
- Estimated Expiration
- 2043-04-20
AI Technical Summary
[0005]本申请实施例提供了一种外联检测方法、装置、电子设备及非易失性存储介质,以至少解决由于相关技术的外联检测方案均需要在内外网部署流量探针,造成的部署成本高,维护成本高的技术问题
[0016]在本申请实施例中,采用确定目标内网中发生过外联行为的目标源地址,其中,外联行为指目标内网中目标源地址与外网中目标目的地址进行联通的行为;依据主机日志,确定目标源地址进行外联行为时所对应的目标目的地址;确定目标源地址和目标目的地址对应的操作信息,其中,操作信息中包括目标源地址和目标目的地址进行外联行为时的目标参数,目标参数用于表征外联行为的状态特征;将操作信息与目标基线库中目标基线进行比较,并在操作信息中任一项目标参数不符合对应的目标基线的情况下,判定外联行为违规,其中,目标基线用于表征外联行为合规的情况下所对应的目标参数的方式,通过网络日志和主机日志联合分析,可以精准匹配出外联网络链接和外联进程,在主机进程级别进行细颗粒度监控。同时,通过防火墙日志里包连接大小和时长,监控外连进程的链接建立的时长以及流量大小,判断外联进程的威胁级别,有利于防守方做出更加及时、精准的防控措施。通过接入威胁情报信息,判别外联目的IP地址的威胁等级,达到了对新外联行为做到精准把控,精准溯源,精准处置,大大提高防守的有效性与及时性的目的,进而解决了由于相关技术的外联检测方案均需要在内外网部署流量探针,造成的部署成本高,维护成本高技术问题。
Smart Images

Figure CN116488895B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network security technology, and more specifically, to an external detection method, apparatus, electronic device, and non-volatile storage medium. Background Technology
[0002] As the importance of cybersecurity grows, the cybersecurity of critical infrastructure has become a key focus for hardening and protection. With the continuous improvement of capabilities on both the offensive and defensive sides, traditional signature-based attacks are no longer considered significant attack methods, and the detection capabilities of protective devices are becoming increasingly easy to bypass. To improve the security of internal networks, connections between the internal network and the internet are prohibited, and physical or logical isolation is implemented to control this and reduce security threats from the internet. However, employees lacking security awareness often connect their terminals to the internet without disconnecting from the internal network, resulting in unauthorized external connections.
[0003] All existing external network detection solutions require the deployment of traffic probes on both internal and external networks, which presents technical challenges such as high deployment and maintenance costs. In addition, in daily use, existing external network detection strategies cannot be dynamically modified, and the detection results cannot be dynamically correlated with other information, resulting in poor display effects.
[0004] There is currently no effective solution to the above problems. Summary of the Invention
[0005] This application provides an external network detection method, apparatus, electronic device, and non-volatile storage medium to at least solve the technical problem of high deployment and maintenance costs caused by the need to deploy traffic probes on both internal and external networks in related external network detection schemes.
[0006] According to one aspect of the embodiments of this application, an external connection detection method is provided, comprising: determining a target source address in a target intranet that has engaged in external connection behavior, wherein the external connection behavior refers to the behavior of a target source address in the target intranet connecting to a target destination address in an external network; determining the target destination address corresponding to the external connection behavior based on host logs; determining operation information corresponding to the target source address and the target destination address, wherein the operation information includes target parameters of the target source address and the target destination address when engaging in external connection behavior, the target parameters being used to characterize the state characteristics of the external connection behavior; comparing the operation information with target baselines in a target baseline library, and determining that the external connection behavior is illegal if any target parameter in the operation information does not conform to the corresponding target baseline, wherein the target baseline is used to characterize the target parameters corresponding to the case where the external connection behavior is compliant.
[0007] Optionally, determining the target source address in the target intranet that has experienced outbound behavior includes: determining the source address in the target intranet that experienced outbound behavior in the first time period but did not experience outbound behavior in the second time period; using the source address as the target source address, wherein the second time period is the time period immediately preceding the first time period, and the duration of the second time period is longer than the duration of the first time period.
[0008] Optionally, the target parameters include at least one of the following: the network connection duration and packet size corresponding to the outbound behavior between the target source address and the target destination address, the target application to which the target source address belongs, and the domain name and geographical location corresponding to the target destination address; determining the operation information corresponding to the target source address and the target destination address includes: obtaining the network connection duration and packet size corresponding to the outbound behavior between the target source address and the target destination address from the network logs; determining the target application to which the target source address belongs and the target level of the target application based on the configuration management data of the target intranet, wherein the target level is used to characterize the importance of the target application; and determining the domain name to which the target destination address belongs and the geographical location corresponding to the target destination address based on the application audit logs.
[0009] Optionally, the target baseline includes at least one of the following: network connection duration baseline and communication packet size baseline; if any target parameter in the operation information does not conform to the corresponding target baseline, the outbound behavior violation is determined by: determining the network connection duration baseline and communication packet size baseline corresponding to the target level of the target application to which the target source address belongs; if the target baseline includes the network connection duration baseline, the outbound behavior violation is determined if the network connection duration corresponding to the outbound behavior exceeds the network connection duration baseline; if the target baseline includes the communication packet size baseline, the outbound behavior violation is determined if the communication packet size corresponding to the outbound behavior exceeds the communication packet size baseline.
[0010] Optionally, the target baseline also includes: a domain name baseline and a geographic location baseline. The domain name baseline contains multiple dangerous domain names identified based on threat intelligence data, and the geographic location baseline contains multiple dangerous geographic locations identified based on threat intelligence data. The threat intelligence data is used to indicate dangerous domain names and dangerous geographic locations that have previously been the subject of security attacks. If any target parameter in the operation information does not conform to the corresponding target baseline, the determination of a violation of the outbound behavior also includes: if the domain name of the target destination address is consistent with any dangerous domain name in the domain name baseline and the geographic location corresponding to the target destination address is consistent with any dangerous geographic location in the geographic location baseline, the outbound behavior is determined to be in violation.
[0011] Optionally, the method further includes: determining the operation information corresponding to the external connection behavior that is judged to be compliant within a preset time range corresponding to the target baseline library; determining a new target baseline based on the target parameters in the operation information; and updating the new target baseline to the target baseline library.
[0012] Optionally, after determining that the external connection behavior is in violation, the process also includes: sending an alarm message and sending the operation information corresponding to the external connection behavior to the front-end interactive interface for display.
[0013] According to another aspect of the embodiments of this application, an external connection detection device is also provided, comprising: an address filtering module, used to determine the target source address in the target intranet that has undergone external connection behavior, wherein the external connection behavior refers to the behavior of the target source address in the target intranet and the target destination address in the external network connecting; an address determination module, used to determine the target destination address corresponding to the target source address when performing the external connection behavior based on host logs; an information association module, used to determine the operation information corresponding to the target source address and the target destination address, wherein the operation information includes target parameters of the target source address and the target destination address when performing the external connection behavior, and the target parameters are used to characterize the state characteristics of the external connection behavior; and a baseline analysis module, used to compare the operation information with the target baseline in the target baseline library, and determine that the external connection behavior is illegal if any target parameter in the operation information does not conform to the corresponding target baseline, wherein the target baseline is used to characterize the target parameters corresponding to the case where the external connection behavior is compliant.
[0014] According to another aspect of the embodiments of this application, an electronic device is also provided, including: a memory and a processor, the processor being configured to run a program stored in the memory, wherein the program executes an external detection method during runtime.
[0015] According to another aspect of the embodiments of this application, a non-volatile storage medium is also provided, the non-volatile storage medium including a stored computer program, wherein the device where the non-volatile storage medium is located executes an external detection method by running the computer program.
[0016] In this embodiment, the method involves identifying the target source address within the target intranet that has engaged in outbound communication, where outbound communication refers to the connection between the target source address within the target intranet and the target destination address within the external network. Based on host logs, the method determines the target destination address corresponding to the outbound communication activity performed by the target source address. It also determines the operation information corresponding to the target source address and the target destination address, including target parameters representing the state characteristics of the outbound communication activity. The operation information is compared with target baselines in a target baseline database, and if any target parameter in the operation information does not conform to the corresponding target baseline, the outbound communication activity is deemed a violation. The target baseline represents the target parameters corresponding to compliant outbound communication activities. Through joint analysis of network logs and host logs, this method can accurately match outbound network links and outbound processes, enabling fine-grained monitoring at the host process level. Simultaneously, by monitoring the connection size and duration of packets in firewall logs, the method monitors the connection establishment duration and traffic volume of outbound processes, determining the threat level of the outbound processes, which helps the defender to take more timely and accurate prevention and control measures. By accessing threat intelligence information and determining the threat level of the target IP address for outbound connections, we can achieve precise control, accurate tracing, and precise handling of new outbound connection behaviors, greatly improving the effectiveness and timeliness of defense. This also solves the technical problem of high deployment and maintenance costs caused by the need to deploy traffic probes on both internal and external networks for outbound connection detection solutions of related technologies. Attached Figure Description
[0017] The accompanying drawings, which are included to provide a further understanding of this application and form part of this application, illustrate exemplary embodiments of this application and are used to explain this application, but do not constitute an undue limitation of this application. In the drawings:
[0018] Figure 1 This is a hardware structure block diagram of a computer terminal (or electronic device) for implementing an external detection method according to an embodiment of this application;
[0019] Figure 2 This is a schematic diagram of an external detection method flow provided according to an embodiment of this application;
[0020] Figure 3 This is a flowchart illustrating an external detection method that associates threat intelligence, network logs, and host logs, according to an embodiment of this application.
[0021] Figure 4 This is a schematic diagram of an external detection device provided according to an embodiment of this application. Detailed Implementation
[0022] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present application, and not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative effort should fall within the scope of protection of the present application.
[0023] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0024] In related technologies, traffic probes need to be deployed on both internal and external networks for external connection detection. Therefore, there is a risk that external connection detection may affect the normal operation of the internal network environment when the traffic is too large. In addition, traffic probes have problems such as high deployment costs and high maintenance costs.
[0025] To address the aforementioned issues, this application provides relevant solutions, which are detailed below.
[0026] According to an embodiment of this application, an embodiment of an external detection method is provided. It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Furthermore, although a logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order than that shown here.
[0027] The method embodiments provided in this application can be executed on a mobile terminal, computer terminal, or similar computing device. Figure 1 A hardware block diagram of a computer terminal (or electronic device) for implementing an external detection method is shown. Figure 1As shown, the computer terminal 10 (or electronic device 10) may include one or more processors 102 (shown as 102a, 102b, ..., 102n in the figure) 102 (processor 102 may include, but is not limited to, a microprocessor MCU or a programmable logic device FPGA, etc.), a memory 104 for storing data, and a transmission device 106 for communication functions. In addition, it may also include: a display, an input / output interface (I / O interface), a universal serial bus (USB) port (which may be included as one of the ports of a BUS bus), a network interface, a power supply, and / or a camera. Those skilled in the art will understand that... Figure 1 The structure shown is for illustrative purposes only and does not limit the structure of the aforementioned electronic device. For example, computer terminal 10 may also include... Figure 1 The more or fewer components shown, or having the same Figure 1 The different configurations shown.
[0028] It should be noted that the aforementioned one or more processors 102 and / or other data processing circuits are generally referred to herein as "data processing circuits". These data processing circuits may be embodied, in whole or in part, in software, hardware, firmware, or any other combination thereof. Furthermore, the data processing circuits may be a single, independent processing module, or may be integrated, in whole or in part, into any other element within the computer terminal 10 (or electronic device). As involved in the embodiments of this application, the data processing circuits serve as a processor control mechanism (e.g., selection of a variable resistor termination path connected to an interface).
[0029] The memory 104 can be used to store software programs and modules of application software, such as the program instructions / data storage device corresponding to the external detection method in this embodiment. The processor 102 executes various functional applications and data processing by running the software programs and modules stored in the memory 104, thereby realizing the aforementioned external detection method. The memory 104 may include high-speed random access memory, and may also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 104 may further include memory remotely located relative to the processor 102, and these remote memories can be connected to the computer terminal 10 via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.
[0030] The transmission device 106 is used to receive or send data via a network. Specific examples of the network described above may include a wireless network provided by the communication provider of the computer terminal 10. In one example, the transmission device 106 includes a Network Interface Controller (NIC), which can connect to other network devices via a base station to communicate with the Internet. In another example, the transmission device 106 may be a Radio Frequency (RF) module, used for wireless communication with the Internet.
[0031] The display may be, for example, a touchscreen liquid crystal display (LCD) that allows the user to interact with the user interface of the computer terminal 10 (or electronic device).
[0032] Under the above operating environment, this application provides an external detection method. Figure 2 This is a schematic diagram of an external detection method flow provided according to an embodiment of this application, such as... Figure 2 As shown, the method includes the following steps:
[0033] Step S202: Determine the target source address in the target intranet that has experienced outbound connection behavior, where outbound connection behavior refers to the behavior of connecting the target source address in the target intranet with the target destination address in the external network;
[0034] In the technical solution provided in step S202, determining the target source address in the target intranet that has experienced external connection behavior includes the following steps: determining the source address in the target intranet that has experienced external connection behavior in the first time period but has not experienced external connection behavior in the second time period; using the source address as the target source address, wherein the second time period is the time period immediately preceding the first time period, and the duration of the second time period is longer than the duration of the first time period.
[0035] For example, we can count the source IPs (i.e., the source addresses) that made outbound connections on day T-1 (i.e., the first time period mentioned above) but did not make outbound connections on day (T-31, T-1) (i.e., the second time period mentioned above), where T represents the current date.
[0036] Step S204: Based on the host logs, determine the target destination address corresponding to the outbound connection behavior of the target source address;
[0037] Specifically, the target source address and host log output in step S202 above are correlated and analyzed to obtain the process records and network connection records at the system layer for each pair of target source address and target destination address (communication pair). The host log can be automatically generated by the operating system in the target intranet and is closely related to the operating system behavior, recording various events that occur in the system.
[0038] Step S206: Determine the operation information corresponding to the target source address and the target destination address. The operation information includes the target parameters when the target source address and the target destination address perform outbound behavior. The target parameters are used to characterize the state characteristics of the outbound behavior.
[0039] In some embodiments of this application, the target parameters include at least one of the following: the network connection duration and packet size corresponding to the outbound behavior between the target source address and the target destination address, the target application to which the target source address belongs, and the domain name and geographical location corresponding to the target destination address;
[0040] To detect abnormal outbound behavior and determine the operation information corresponding to the target source address and target destination address, the following steps are included: obtaining the network connection duration and communication packet size corresponding to the outbound behavior between the target source address and the target destination address from the network logs; determining the target application to which the target source address belongs and the target level of the target application based on the configuration management data of the target intranet, where the target level is used to characterize the importance of the target application; and determining the domain name to which the target destination address belongs and the geographical location corresponding to the target destination address based on the application audit logs.
[0041] Specifically, network logs are used for correlation analysis to obtain time-series records of network connection duration and packet size for each communication pair (i.e., the aforementioned target source address and target destination address pair). Basic data from the CMDB (Configuration Management Database) (i.e., the aforementioned configuration management data) is used for correlation analysis to obtain records such as the application (i.e., the aforementioned target application) and importance level (i.e., the aforementioned target level) of the source IP (i.e., the aforementioned target source address). Threat intelligence data is used for correlation analysis to obtain records such as the geographical location, threat type, and domain name of the destination IP. Application audit logs are used for correlation analysis to obtain the domain name of the destination IP (i.e., the aforementioned target destination address). The network logs can be automatically generated by the system to record network communication events within the target's internal network, while the application audit logs can be generated by the log auditing system corresponding to the target's internal network.
[0042] Step S208: Compare the operation information with the target baselines in the target baseline library, and determine that the external connection behavior is in violation if any target parameter in the operation information does not conform to the corresponding target baseline. The target baseline is used to characterize the target parameter corresponding to the case where the external connection behavior is compliant.
[0043] In some embodiments of this application, the target baseline includes at least one of the following: a network connection duration baseline and a communication packet size baseline. If any target parameter in the operation information does not conform to the corresponding target baseline, determining an outbound behavior violation includes the following steps: determining the network connection duration baseline and the communication packet size baseline corresponding to the target level of the target application to which the target source address belongs; when the target baseline includes the network connection duration baseline, determining an outbound behavior violation if the network connection duration corresponding to the outbound behavior exceeds the network connection duration baseline; when the target baseline includes the communication packet size baseline, determining an outbound behavior violation if the communication packet size corresponding to the outbound behavior exceeds the communication packet size baseline.
[0044] In some embodiments of this application, the target baseline further includes: a domain name baseline and a geographic location baseline, wherein the domain name baseline includes multiple dangerous domain names identified based on threat intelligence data, and the geographic location baseline includes multiple dangerous geographic locations identified based on threat intelligence data. The threat intelligence data is used to indicate dangerous domain names and dangerous geographic locations that have previously been subjected to security attacks. If any target parameter in the operation information does not conform to the corresponding target baseline, determining that the outbound behavior is in violation also includes: if the domain name to which the target destination address belongs is consistent with any dangerous domain name in the domain name baseline and the geographic location corresponding to the target destination address is consistent with any dangerous geographic location in the geographic location baseline, then the outbound behavior is determined to be in violation.
[0045] To improve the flexibility and accuracy of detecting unauthorized external connections, the method also includes the following steps: determining the operational information corresponding to the external connection behaviors that are judged to be compliant within a preset time range corresponding to the target baseline library; determining a new target baseline based on the target parameters in the operational information, and updating the new target baseline to the target baseline library. That is, the target baseline library can be automatically updated by analyzing the operational information within a certain time range.
[0046] As an optional implementation, after determining that the external connection behavior is in violation, the following steps are also included: sending alarm information and sending the operation information corresponding to the external connection behavior to the front-end interactive interface for display.
[0047] The external detection method in steps S202 to S208 of the embodiments of this application will be further described below.
[0048] Figure 3 This is a flowchart illustrating an external detection method for coordinating threat intelligence, network logs, and host logs, provided according to an embodiment of this application. Figure 3 As shown, this method primarily utilizes audit logs from the network and system layers combined with threat intelligence data, and employs baseline and statistical analysis methods to detect abnormal outbound behavior. Specifically, it includes the following steps:
[0049] Step 1: Count the source IPs (i.e., the source addresses) that made outbound connections in day T-1 (i.e., the first time period above) but did not make outbound connections in day (T-31, T-1) (i.e., the second time period above), where T represents the current date;
[0050] Step 2: Perform correlation analysis on the target source address and host log output in Step 1 above to obtain the process record and network connection record at the system layer for each pair of target source address and target destination address (communication pair);
[0051] Step 3: Use network log correlation analysis to obtain the time-series records of network connection duration and communication packet size for each communication pair (i.e., the aforementioned pair of target source address and target destination address);
[0052] Step 4: Use the basic data of CMDB (Configuration Management Database) (i.e., the configuration management data mentioned above) to perform correlation analysis to find the application to which the source IP (i.e., the target source address mentioned above) belongs (i.e., the target application mentioned above), the importance level (i.e., the target level mentioned above), and other records.
[0053] Step 5: Use application audit logs to correlate and analyze the domain name to which the destination IP (i.e., the target destination address mentioned above) belongs;
[0054] Step 6: Use threat intelligence data to analyze and determine the geographical location, threat type, and domain name of the target IP (i.e., the target address mentioned above);
[0055] Step 7: Perform correlation analysis by integrating the above data types to display sudden external connection situations (i.e., illegal external connection behaviors).
[0056] This application presents a method for analyzing abnormal behavior in network security. It uses a baseline method to detect sudden behavior in time-series logs; employs statistical analysis to perform multi-faceted correlation analysis on time-series logs and dynamic configuration data; and appropriately utilizes data preprocessing methods at each analysis node to improve the efficiency of big data analysis.
[0057] Specifically, this method mainly uses the SPL language for data parsing, processing and calculation, combined with a custom Python script for data preprocessing. It has good statistical analysis, big data baseline generation and data cleaning capabilities, and is suitable for joint temporal and spatial analysis and mining of network security scenarios with abnormal external behavior in massive logs. It is more comprehensive than isolated log analysis, and also combines isolated logs to effectively improve the network security level of critical infrastructure.
[0058] Through the above steps, combined analysis of network logs and host logs allows for precise matching of external network links and processes, enabling granular monitoring at the host process level. Simultaneously, by monitoring connection size and duration in firewall logs, the connection establishment time and traffic volume of external processes can be assessed to determine their threat level, facilitating more timely and accurate defense measures. By accessing threat intelligence information and determining the threat level of the target IP address for external connections, precise control, tracing, and handling of new external connection activities are achieved, significantly improving the effectiveness and timeliness of defense. This also solves the technical problem of high deployment and maintenance costs caused by the need to deploy traffic probes on both internal and external networks for related external connection detection solutions.
[0059] According to an embodiment of this application, an embodiment of an external detection device is also provided. Figure 4 This is a schematic diagram of an external detection device provided according to an embodiment of this application. For example... Figure 4 As shown, the device includes:
[0060] Address filtering module 40 is used to determine the target source address in the target intranet that has had external connection behavior, wherein external connection behavior refers to the behavior of the target source address in the target intranet and the target destination address in the external network connecting;
[0061] Address determination module 42 is used to determine the target destination address corresponding to the target source address when performing outbound behavior based on the host log;
[0062] The information association module 44 is used to determine the operation information corresponding to the target source address and the target destination address. The operation information includes the target parameters when the target source address and the target destination address perform outbound behavior. The target parameters are used to characterize the state characteristics of the outbound behavior.
[0063] The baseline analysis module 46 is used to compare the operation information with the target baselines in the target baseline library, and to determine that the external connection behavior is in violation if any target parameter in the operation information does not conform to the corresponding target baseline. The target baseline is used to characterize the target parameter corresponding to the case where the external connection behavior is compliant.
[0064] It should be noted that each module in the aforementioned external detection device can be a program module (e.g., a set of program instructions to implement a specific function) or a hardware module. For the latter, it can take the following forms, but is not limited to them: each of the above modules is represented by a processor, or the functions of each of the above modules are implemented by a processor.
[0065] It should be noted that the external detection device provided in this embodiment can be used to perform... Figure 2The external detection method shown above is also applicable to the embodiments of this application, and will not be repeated here.
[0066] This application embodiment also provides a non-volatile storage medium, which includes a stored computer program. The device containing the non-volatile storage medium executes the following outbound connection detection method by running the computer program: determining the target source address in the target intranet where outbound connection behavior has occurred, wherein outbound connection behavior refers to the behavior of connecting the target source address in the target intranet with the target destination address in the external network; determining the target destination address corresponding to the outbound connection behavior based on host logs; determining the operation information corresponding to the target source address and the target destination address, wherein the operation information includes target parameters of the target source address and the target destination address when performing outbound connection behavior, and the target parameters are used to characterize the state characteristics of the outbound connection behavior; comparing the operation information with target baselines in the target baseline library, and determining that the outbound connection behavior is illegal if any target parameter in the operation information does not conform to the corresponding target baseline, wherein the target baseline is used to characterize the target parameters corresponding to compliant outbound connection behavior.
[0067] The sequence numbers of the embodiments in this application are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.
[0068] In the above embodiments of this application, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments.
[0069] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. The device embodiments described above are merely illustrative; for example, the division of units can be a logical functional division, and in actual implementation, there may be other division methods. For instance, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the displayed or discussed mutual coupling, direct coupling, or communication connection may be through some interfaces; the indirect coupling or communication connection between units or modules may be electrical or other forms.
[0070] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0071] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0072] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as a USB flash drive, read-only memory (ROM), random access memory (RAM), portable hard drive, magnetic disk, or optical disk.
[0073] The above description is only a preferred embodiment of this application. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principle of this application, and these improvements and modifications should also be considered within the scope of protection of this application.
Claims
1. An external detection method, characterized in that, include: Determining the target source address in the target intranet that has experienced outbound communication includes: determining the source address in the target intranet that experienced the outbound communication during a first time period but did not experience the outbound communication during a second time period; using the source address as the target source address, wherein the second time period is the time period immediately preceding the first time period, and the duration of the second time period is longer than the duration of the first time period, and the outbound communication refers to the behavior of connecting the target source address in the target intranet with the target destination address in the external network; Based on the host logs, determine the target destination address corresponding to the target source address when performing the outbound connection behavior; Determine the operation information corresponding to the target source address and the target destination address, wherein the operation information includes target parameters when the target source address and the target destination address perform the outbound behavior, and the target parameters are used to characterize the state characteristics of the outbound behavior; The target parameters include at least one of the following: the network connection duration and packet size corresponding to the outbound behavior between the target source address and the target destination address; the target application to which the target source address belongs; and the domain name and geographical location corresponding to the target destination address. Determining the operation information corresponding to the target source address and the target destination address includes: obtaining the network connection duration and packet size corresponding to the outbound behavior between the target source address and the target destination address from network logs; determining the target application to which the target source address belongs and the target level of the target application based on the configuration management data of the target intranet, wherein the target application is used to characterize the importance of the target application; determining the domain name to which the target destination address belongs based on application audit logs; and determining the geographical location corresponding to the target destination address based on threat intelligence data. The operation information is compared with the target baseline in the target baseline library, and if any of the target parameters in the operation information does not conform to the corresponding target baseline, the external connection behavior is determined to be illegal. The target baseline is used to characterize the target parameter corresponding to the case where the external connection behavior is compliant.
2. The external detection method according to claim 1, characterized in that, The target baseline includes at least one of the following: network connection duration baseline, communication packet size baseline; if any of the target parameters in the operation information does not conform to the corresponding target baseline, the external connection behavior is deemed to be in violation, including: Determine the network connection duration baseline and the communication packet size baseline corresponding to the target level of the target application to which the target source address belongs; When the target baseline includes the network connection duration baseline, if the network connection duration corresponding to the outbound behavior exceeds the network connection duration baseline, the outbound behavior is determined to be in violation. When the target baseline includes the communication packet size baseline, if the communication packet size corresponding to the outbound action exceeds the communication packet size baseline, the outbound action is determined to be in violation.
3. The external detection method according to claim 1, characterized in that, The target baseline further includes: a domain name baseline and a geographic location baseline, wherein the domain name baseline includes multiple dangerous domain names identified based on threat intelligence data, and the geographic location baseline includes multiple dangerous geographic locations identified based on threat intelligence data, wherein the threat intelligence data is used to indicate the dangerous domain names and dangerous geographic locations that have previously been the subject of security attacks; if any of the target parameters in the operation information does not conform to the corresponding target baseline, determining that the external connection behavior is in violation further includes: If the domain name to which the target destination address belongs is consistent with any of the dangerous domain names in the domain name baseline, and the geographical location corresponding to the target destination address is consistent with any of the dangerous geographical locations in the geographical location baseline, the outbound linking behavior is determined to be in violation.
4. The external detection method according to claim 1, characterized in that, The method further includes: Within a preset time range corresponding to the target baseline library, determine the corresponding operation information for external connections that are deemed compliant. Based on the target parameters in the operation information, a new target baseline is determined, and the new target baseline is updated to the target baseline library.
5. The external detection method according to claim 1, characterized in that, After determining that the aforementioned external contact behavior is in violation, the following also applies: Send an alarm message and send the operation information corresponding to the external connection behavior to the front-end interactive interface for display.
6. An external detection device, characterized in that, include: The address filtering module is used to determine the target source address in the target intranet that has experienced outbound connection behavior, including: determining the source address in the target intranet that experienced the outbound connection behavior in a first time period but did not experience the outbound connection behavior in a second time period; using the source address as the target source address, wherein the second time period is the time period immediately preceding the first time period, and the duration of the second time period is longer than the duration of the first time period, and the outbound connection behavior refers to the behavior of connecting the target source address in the target intranet with the target destination address in the external network; The address determination module is used to determine the target destination address corresponding to the outbound behavior when the target source address performs the outbound behavior, based on the host logs. An information association module is used to determine the operation information corresponding to the target source address and the target destination address, wherein the operation information includes target parameters when the target source address and the target destination address perform the outbound behavior, and the target parameters are used to characterize the state features of the outbound behavior; The target parameters include at least one of the following: the network connection duration and packet size corresponding to the outbound behavior between the target source address and the target destination address; the target application to which the target source address belongs; and the domain name and geographical location corresponding to the target destination address. Determining the operation information corresponding to the target source address and the target destination address includes: obtaining the network connection duration and packet size corresponding to the outbound behavior between the target source address and the target destination address from network logs; determining the target application to which the target source address belongs and the target level of the target application based on the configuration management data of the target intranet, wherein the target application is used to characterize the importance of the target application; determining the domain name to which the target destination address belongs based on application audit logs; and determining the geographical location corresponding to the target destination address based on threat intelligence data. The baseline analysis module is used to compare the operation information with the target baselines in the target baseline library, and to determine that the external connection behavior is in violation if any of the target parameters in the operation information does not conform to the corresponding target baseline. The target baseline is used to characterize the target parameters corresponding to the case where the external connection behavior is compliant.
7. An electronic device, characterized in that, include: A memory and a processor, the processor being configured to run a program stored in the memory, wherein the program, when running, performs the external detection method according to any one of claims 1 to 5.
8. A non-volatile storage medium, characterized in that, The non-volatile storage medium includes a stored computer program, wherein the device containing the non-volatile storage medium executes the external detection method according to any one of claims 1 to 5 by running the computer program.
Citation Information
Patent Citations
Illegal external connection monitoring method based on wireless and wired data flow similarity analysis
CN110120948A
Access relationship determination method, device and equipment and medium
CN111371791A
Illegal external connection detection method, device and equipment for industrial control and storage medium
CN111935167A
Abnormal external connection statistical alarm method and device, computer equipment and storage medium
CN114257404A