Security protection method and device, computer device and storage medium
Patent Information
- Application Number
- CN202310584192.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-05-23
- Publication Date
- 2026-09-08
- Estimated Expiration
- 2043-05-23
AI Technical Summary
[0002]随着计算机技术的发展,运行信创操作系统的个人计算机终端在不同的网络环境中运行时,往往会受到网络环境外信息的干扰,从而导致个人计算机终端信息泄露,因此如何提升个人计算机终端在不同网络环境中的网络安全防护效果是当前研究的重点
[0055] The aforementioned real-time protection method, apparatus, computer equipment, storage medium, and computer program product, in response to a network environment access request message sent by a server, and based on the environment information in the current network environment, determine the isolation trigger conditions for the current network environment, and send a response message containing the isolation trigger conditions to the server. The response message instructs the server to update the isolation trigger conditions based on new environment information of the current network environment, obtaining updated isolation trigger conditions, and then send an isolation trigger condition update request message containing the updated isolation trigger conditions to the client. Based on the updated isolation trigger conditions contained in the network policy update request message, the isolation trigger conditions of the current network environment are replaced, and network isolation processing is performed on the current network environment when the operating status information of the current network environment meets the isolation trigger conditions. By establishing isolation trigger conditions for each network environment based on its environment information and monitoring the operating status information of the current network environment in real time, it ensures that the network environment can operate normally even when the isolation trigger conditions are not met, avoiding the process of real-time security isolation of each communication process, thereby improving the network security protection efficiency for different network environments.
Smart Images

Figure CN116488930B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of information security technology, and in particular to a security protection method, device, computer equipment, and storage medium. Background Technology
[0002] With the development of computer technology, personal computer terminals running domestically developed operating systems are often subject to interference from information outside the network environment when operating in different network environments, which can lead to information leakage of personal computer terminals. Therefore, how to improve the network security protection effect of personal computer terminals in different network environments is the focus of current research.
[0003] Traditional security protection methods require the personal computer terminal to perform secure isolation processing (such as using data encryption) on the communication processes between the personal computer terminal and various network environment modules in different network environments when the personal computer terminal enters different network environments, so as to ensure that the personal computer terminal's information is not leaked. However, this method requires real-time secure isolation of each communication process, which consumes a lot of costs, resulting in low network security protection efficiency in different network environments. Summary of the Invention
[0004] Therefore, it is necessary to provide a security protection method, device, computer equipment, computer-readable storage medium, and computer program product to address the aforementioned technical problems.
[0005] Firstly, this application provides a security protection method. The method includes:
[0006] In response to a network environment access request message sent by the server, and based on the environment information in the current network environment, determine the isolation triggering conditions for the current network environment;
[0007] Send a response message containing the isolation trigger condition to the server; the response message is used to instruct the server to update the isolation trigger condition based on the new environment information of the current network environment, obtain the updated isolation trigger condition, and send an isolation trigger condition update request message containing the updated isolation trigger condition to the client.
[0008] Based on the updated isolation triggering conditions contained in the network policy update request message, the isolation triggering conditions of the current network environment are replaced, and network isolation processing is performed on the current network environment if the operating status information of the current network environment meets the isolation triggering conditions.
[0009] Optionally, determining the isolation triggering conditions for the current network environment based on environmental information in the current network environment includes:
[0010] Identify each network environment module contained in the environmental information, and for each network environment module, parse the normal operating parameter information of the network environment module;
[0011] Based on the normal operating parameter information of the network environment module, a security isolation parameter range for the network environment module is established, and the security isolation parameter range of all network environment modules is used as the isolation trigger condition for the current network environment.
[0012] Optionally, establishing the security isolation parameter range for the network environment module based on its normal operating parameter information includes:
[0013] Obtain abnormal operating parameter information of the network environment module, and determine the range of abnormal operating parameters of the network environment module based on the abnormal operating parameter information of the network environment module;
[0014] In the normal operating parameter information of the network environment module, the operating parameter information other than the abnormal operating parameter range of the network environment module is taken as the normal operating parameter range of the network environment module, and the normal operating parameter range is taken as the security isolation parameter range of the network environment module.
[0015] Optionally, when the operating status information of the current network environment meets the isolation triggering condition, performing network isolation processing on the current network environment includes:
[0016] For each network environment module, identify the fluctuation range of the current operating parameters of the network environment module, and stop the communication process with the network environment module if the fluctuation range of the current operating parameters of the network environment module does not match the security isolation parameter range of the network environment module;
[0017] The system displays all network environment modules whose communication processes have stopped on the client's display interface, and shows the progress information of the current communication process of each of the network environment modules whose communication processes have stopped.
[0018] Secondly, this application provides a security protection method. The method includes:
[0019] In response to a user's operation to access the network environment, a network environment access request message containing environment information of the current network environment is sent to the client;
[0020] Receive a response message sent by the client; the response message contains the isolation trigger conditions of the current network environment;
[0021] Reacquire new environment information of the current network environment, and if the new environment information does not match the isolation trigger condition, update the isolation trigger condition to obtain the updated isolation trigger condition;
[0022] Send an isolation trigger condition update request message containing the updated isolation trigger condition to the client; the isolation trigger condition update request message is used to instruct the client to replace the current isolation trigger condition of the network environment with the updated isolation trigger condition contained in the network policy update request message.
[0023] Optionally, updating the isolation trigger condition to obtain the updated isolation trigger condition when the new environment information does not match the isolation trigger condition includes:
[0024] For each new network environment module included in the new environment information, obtain the normal operating parameter information of the new network environment module and the abnormal operating parameter information of the new network environment module in the operating database, and determine the normal operating parameter range of the new network environment module based on the normal operating parameter information and the abnormal operating parameter information of the new network environment module.
[0025] If the normal operating parameter range of the new network environment module differs from the security isolation parameter range of the network environment module corresponding to the new network environment module, the normal operating parameter range of the new network environment module shall be used as the security isolation parameter range of the network environment module to obtain the updated isolation triggering condition.
[0026] Thirdly, this application also provides a safety protection device. The device includes:
[0027] The first receiving module is used to respond to the network environment access request message sent by the server, and determine the isolation triggering condition of the current network environment based on the environment information in the current network environment.
[0028] The first sending module is used to send a response message containing the isolation trigger condition to the server; the response message is used to instruct the server to update the isolation trigger condition based on the new environment information of the current network environment, obtain the updated isolation trigger condition, and send an isolation trigger condition update request message containing the updated isolation trigger condition to the client.
[0029] The processing module is used to replace the isolation triggering conditions of the current network environment with the updated isolation triggering conditions contained in the network policy update request message, and to perform network isolation processing on the current network environment when the operating status information of the current network environment meets the isolation triggering conditions.
[0030] Optionally, the first receiving module is specifically used for:
[0031] Identify each network environment module contained in the environmental information, and for each network environment module, parse the normal operating parameter information of the network environment module;
[0032] Based on the normal operating parameter information of the network environment module, a security isolation parameter range for the network environment module is established, and the security isolation parameter range of all network environment modules is used as the isolation trigger condition for the current network environment.
[0033] Optionally, the first receiving module is specifically used for:
[0034] Obtain abnormal operating parameter information of the network environment module, and determine the range of abnormal operating parameters of the network environment module based on the abnormal operating parameter information of the network environment module;
[0035] In the normal operating parameter information of the network environment module, the operating parameter information other than the abnormal operating parameter range of the network environment module is taken as the normal operating parameter range of the network environment module, and the normal operating parameter range is taken as the security isolation parameter range of the network environment module.
[0036] Optionally, the processing module is specifically used for:
[0037] For each network environment module, identify the fluctuation range of the current operating parameters of the network environment module, and stop the communication process with the network environment module if the fluctuation range of the current operating parameters of the network environment module does not match the security isolation parameter range of the network environment module;
[0038] The system displays all network environment modules whose communication processes have stopped on the client's display interface, and shows the progress information of the current communication process of each of the network environment modules whose communication processes have stopped.
[0039] Fourthly, this application also provides a safety protection device. The device includes:
[0040] The second sending module is used to send a network environment access request message containing environmental information in the current network environment to the client;
[0041] The second receiving module is used to receive a response message sent by the client; the response message contains the isolation triggering conditions of the current network environment;
[0042] The update module is used to reacquire new environmental information of the current network environment, and update the isolation triggering condition if the new environmental information does not match the isolation triggering condition, so as to obtain the updated isolation triggering condition;
[0043] The third sending module is used to send an isolation trigger condition update request message containing the updated isolation trigger condition to the client; the isolation trigger condition update request message is used to instruct the client to replace the current network environment's isolation trigger condition with the updated isolation trigger condition contained in the network policy update request message.
[0044] Optionally, the update module is specifically used for:
[0045] For each new network environment module included in the new environment information, obtain the normal operating parameter information of the new network environment module and the abnormal operating parameter information of the new network environment module in the operating database, and determine the normal operating parameter range of the new network environment module based on the normal operating parameter information and the abnormal operating parameter information of the new network environment module.
[0046] If the normal operating parameter range of the new network environment module differs from the security isolation parameter range of the network environment module corresponding to the new network environment module, the normal operating parameter range of the new network environment module shall be used as the security isolation parameter range of the network environment module to obtain the updated isolation triggering condition.
[0047] Fifthly, this application also provides a security protection system. The system includes a server and a client:
[0048] The server is used to send a network environment access request message containing environmental information in the current network environment to the client;
[0049] The client is configured to respond to a network environment access request message sent by the server, obtain environment information in the current network environment, determine the isolation trigger condition of the current network environment based on the environment information in the current network environment, and send a response message containing the isolation trigger condition to the server.
[0050] The server is configured to receive a response message sent by the client; reacquire new environment information of the current network environment, and update the isolation trigger condition if the new environment information does not match the isolation trigger condition, thereby obtaining the updated isolation trigger condition; and send an isolation trigger condition update request message containing the updated isolation trigger condition to the client.
[0051] The client is configured to replace the isolation trigger conditions of the current network environment with the updated isolation trigger conditions contained in the network policy update request message, and to perform network isolation processing on the current network environment when the operating status information of the current network environment meets the isolation trigger conditions.
[0052] Sixthly, this application provides a computer device. The computer device includes a memory and a processor, the memory storing a computer program, and the processor executing the computer program to implement the steps of the method described in either the first or second aspect.
[0053] In a seventh aspect, this application provides a computer-readable storage medium having a computer program stored thereon that, when executed by a processor, implements the steps of the method described in any one of the first or second aspects.
[0054] Eighthly, this application provides a computer program product. The computer program product includes a computer program that, when executed by a processor, implements the steps of the method described in either the first or second aspect.
[0055] The aforementioned real-time protection method, apparatus, computer equipment, storage medium, and computer program product, in response to a network environment access request message sent by a server, and based on the environment information in the current network environment, determine the isolation trigger conditions for the current network environment, and send a response message containing the isolation trigger conditions to the server. The response message instructs the server to update the isolation trigger conditions based on new environment information of the current network environment, obtaining updated isolation trigger conditions, and then send an isolation trigger condition update request message containing the updated isolation trigger conditions to the client. Based on the updated isolation trigger conditions contained in the network policy update request message, the isolation trigger conditions of the current network environment are replaced, and network isolation processing is performed on the current network environment when the operating status information of the current network environment meets the isolation trigger conditions. By establishing isolation trigger conditions for each network environment based on its environment information and monitoring the operating status information of the current network environment in real time, it ensures that the network environment can operate normally even when the isolation trigger conditions are not met, avoiding the process of real-time security isolation of each communication process, thereby improving the network security protection efficiency for different network environments. Attached Figure Description
[0056] Figure 1 This is a diagram illustrating the application environment of a security protection method in one embodiment;
[0057] Figure 2 This is a flowchart illustrating a security protection method in one embodiment;
[0058] Figure 3 This is a flowchart illustrating a security protection method in another embodiment;
[0059] Figure 4 This is a flowchart illustrating a security protection example in one embodiment;
[0060] Figure 5 This is a flowchart illustrating a security protection interaction example in one embodiment;
[0061] Figure 6 This is a structural block diagram of a safety protection device in one embodiment;
[0062] Figure 7 This is a structural block diagram of the safety protection device in another embodiment;
[0063] Figure 8 This is an internal structural diagram of a computer device in one embodiment. Detailed Implementation
[0064] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.
[0065] The security protection method provided in this application embodiment can be applied to, for example, Figure 1 In the application environment shown, client 101 communicates with server 102 via a network. Client 101 establishes isolation trigger conditions for each network environment based on its environmental information and monitors the current network environment's operational status in real time. This ensures that the network environment can continue to operate normally even when the isolation trigger conditions are not met, avoiding the need for real-time security isolation of each communication process and thus improving network security protection efficiency across different network environments. Client 101 can be, but is not limited to, various personal computers, laptops, smartphones, and tablets. Server 102 can be implemented using a standalone server or a server cluster consisting of multiple servers.
[0066] In one embodiment, such as Figure 2 As shown, a security protection method is provided. Taking the application of this method to a client as an example, the method includes the following steps:
[0067] Step S201: In response to the network environment access request message sent by the server, based on the environment information in the current network environment, establish the isolation trigger condition for the current network environment, and send a response message containing the isolation trigger condition to the server.
[0068] In this embodiment, the client receives a network environment access request message sent by the server and obtains the environment information of the current network environment contained in the request message. This environment information includes parameter information for each network environment module within the current network environment. The current network environment can be, but is not limited to, an intranet environment or an extranet environment. Network environment modules include router modules, firewall modules, network operation modules, and network hardware modules, and can be further divided and adjusted according to actual needs. Based on the parameter information of each network environment module, the client establishes isolation trigger conditions for the current network environment. These isolation trigger conditions include the security isolation parameter range for each network environment module. The specific establishment process will be described in detail later. The client is a personal computer terminal running a domestically developed operating system.
[0069] Step S202: Send a response message containing the isolation trigger condition to the server.
[0070] The response message is used to instruct the server to update the isolation trigger conditions based on the new environment information of the current network environment, obtain the updated isolation trigger conditions, and send an isolation trigger condition update request message containing the updated isolation trigger conditions to the client.
[0071] In this embodiment, the client sends a response message containing the isolation trigger conditions of the current network environment to the server.
[0072] Step S203: Based on the updated isolation trigger conditions contained in the network policy update request message, replace the current network environment's isolation trigger conditions, and perform network isolation processing on the current network environment if the current network environment's operating status information meets the isolation trigger conditions.
[0073] In this embodiment, the client receives updated isolation trigger conditions from the server and monitors the running status of each network environment module in the current network environment in real time. If the running status information of the current network environment meets the isolation trigger conditions, the client performs network isolation processing on the current network environment to prevent the network environment from leaking the client's relevant information. Network isolation processing involves one or more combined processes such as file isolation, file encryption, network isolation, and process isolation. File isolation is implemented using mount namespaces, which restricts access permissions to files in specific directories within the current network environment. File encryption is implemented using FUSE, which performs targeted encryption on specific files of the client. Network isolation is implemented using network namespaces, LSM (Linux Security Module), etc., to restrict communication processes within the network. Process isolation is implemented using namespaces and cgroups, which restricts other clients from querying the process information of clients within the network environment, allowing only clients within the network environment to view each other's process information.
[0074] Based on the above scheme, isolation trigger conditions for each network environment are established based on the environmental information of each network environment, and the current operating status information of the network environment is monitored in real time. This ensures that the network environment can operate normally even if the isolation trigger conditions are not met, avoiding the process of real-time security isolation of each communication process, thereby improving the network security protection efficiency of different network environments.
[0075] Optionally, based on the environmental information in the current network environment, establish isolation trigger conditions for the current network environment, including: identifying each network environment module contained in the environmental information, and for each network environment module, parsing the normal operating parameter information of the network environment module; based on the normal operating parameter information of the network environment module, establishing the security isolation parameter range of the network environment module, and using the security isolation parameter range of all network environment modules as the isolation trigger conditions for the current network environment.
[0076] In this embodiment, the client identifies each network environment module contained in the environment information and parses the normal operating parameter information (i.e., parameter information) of each network environment module. The normal operating parameter information refers to the parameter fluctuation range during the normal operation of the network environment module, and includes both normal operating parameter information and abnormal operating parameter information. For each network environment module, the client uses the normal operating parameter information from the normal operating parameter information of that network environment module as the security isolation parameter range for that network environment module. The client then uses the security isolation parameter ranges of all network environment modules as the security isolation policy for the current network environment.
[0077] Based on the above scheme, the isolation triggering conditions of the current network environment are determined by using the normal operating parameter information of each network environment module, thereby improving the accuracy of the isolation triggering conditions.
[0078] Optionally, based on the normal operating parameter information of the network environment module, a security isolation parameter range for the network environment module is established, including: obtaining abnormal operating parameter information of the network environment module, and determining the abnormal operating parameter range of the network environment module based on the abnormal operating parameter information; in the normal operating parameter information of the network environment module, the operating parameter information other than the abnormal operating parameter range of the network environment module is taken as the normal operating parameter range of the network environment module, and the normal operating parameter range is taken as the security isolation parameter range of the network environment module.
[0079] In this embodiment, the client obtains abnormal operating parameter information for each network environment module, where the operating database is a database containing historical operating parameters of multiple network environments. Based on the abnormal operating parameter information of the network environment module, the client determines the range of abnormal operating parameters for that network environment module. From the normal operating parameter information of the network environment module, the client filters out operating parameter information outside the range of abnormal operating parameters and uses this as the normal operating parameter information for that network environment module. Based on the normal operating parameter information of the network environment module, the client identifies the normal operating parameter range of that network environment module and obtains the security isolation parameter range for that network environment module.
[0080] Based on the above scheme, by filtering the normal operating parameter information from the normal operating parameter information, the range of security isolation parameters for the network environment module is determined, thereby improving the accuracy of the range of security isolation parameters for the network environment module.
[0081] Optionally, if the current network environment's operating status information meets the isolation triggering conditions, network isolation processing is performed on the current network environment, including: for each network environment module, identifying the fluctuation range of the current operating parameters of the network environment module, and stopping the communication process with the network environment module if the fluctuation range of the current operating parameters of the network environment module does not match the security isolation parameter range of the network environment module; displaying all network environment modules whose communication processes have stopped to the client's display interface, and displaying the progress information of the current communication process of each network environment module whose communication processes have stopped.
[0082] In this embodiment, the client obtains the current network environment's operational status information in real time. For each obtained network environment status information, it identifies the fluctuation range of the current operating parameters for each network environment module. For each network environment module, the client determines whether the fluctuation range of its current operating parameters matches the security isolation parameter range of that module. If the fluctuation range matches, the client returns to the step of obtaining the current network environment's operational status information in real time. If the fluctuation range does not match, the client stops the communication process of that network environment module through file isolation, file encryption, network isolation, and process isolation. Similarly, through the above steps, the client stops the communication processes of all network environment modules whose current operating parameter fluctuation ranges do not match the security isolation parameter ranges of each network environment module. The client displays the progress information of the current communication processes of all stopped network environment modules on its display interface.
[0083] Based on the above scheme, by identifying the fluctuation range of the current operating parameters of each network environment module, it is determined whether to isolate the communication process of that network environment module, thereby improving the accuracy of isolation of the current network environment.
[0084] In one embodiment, such as Figure 3 As shown, a security protection method is provided. Taking the application of this method to a server as an example, the method includes the following steps:
[0085] Step S301: In response to the user's operation to access the network environment, a network environment access request message containing environment information of the current network environment is sent to the client.
[0086] In this embodiment, when a user needs to access different network environments, the server responds to the user's network environment access operation by obtaining the environment information of the current network environment that the user needs to access, and sends a network environment access request message containing the environment information of the current network environment to the client. The server is a personal computer terminal running a domestically developed operating system.
[0087] Step S302: Receive the response message sent by the client.
[0088] The response message contains the isolation trigger conditions of the current network environment.
[0089] In this embodiment, the server receives the response message sent by the client and parses the isolation trigger condition in the response message.
[0090] Step S303: Reacquire the new environment information of the current network environment, and if the new environment information does not match the isolation trigger conditions, update the isolation trigger conditions to obtain the updated isolation trigger conditions.
[0091] In this embodiment, the server re-acquires the environment information of the network environment currently to be accessed and uses this information as the new environment information for the current network environment. The server determines whether the parameter information of each new network environment module in the new environment information matches the isolation trigger condition sent by the client. If the parameter information of each new network environment module in the new environment information matches the isolation trigger condition sent by the client, the server does not update the isolation trigger condition. If the parameter information of each new network environment module in the new environment information does not match the isolation trigger condition sent by the client, the server updates the isolation trigger condition based on the parameter information of each new network environment module, thus obtaining the updated isolation trigger condition. The specific update process will be described in detail later.
[0092] Step S304: Send an isolation trigger condition update request message containing the updated isolation trigger conditions to the client.
[0093] The Isolation Trigger Condition Update Request Message is used to instruct the client to replace the current isolation trigger condition with the updated isolation trigger condition contained in the Network Policy Update Request Message.
[0094] In this embodiment, the server sends an isolation trigger condition update request message containing the updated isolation trigger conditions to the client.
[0095] Based on the above solution, the isolation trigger conditions are updated in real time by the server to ensure the network security protection effect in different network environments.
[0096] Optionally, if the new environment information does not match the isolation triggering conditions, the isolation triggering conditions are updated to obtain the updated isolation triggering conditions. This includes: for each new network environment module included in the new environment information, obtaining the normal operating parameter information of the new network environment module and the abnormal operating parameter information of the new network environment module in the operating database; and determining the normal operating parameter range of the new network environment module based on the normal operating parameter information and the abnormal operating parameter information of the new network environment module; if the normal operating parameter range of the new network environment module is different from the security isolation parameter range of the network environment module corresponding to the new network environment module, the normal operating parameter range of the new network environment module is used as the security isolation parameter range of the network environment module to obtain the updated isolation triggering conditions.
[0097] In this embodiment, for each new network environment module included in the new environment information, the server obtains the normal operating parameter information of the new network environment module and the abnormal operating parameter information of the new network environment module in the operating database. Based on the normal and abnormal operating parameter information of the new network environment module, the server determines the normal operating parameter range of the new network environment module. The server identifies the network environment module corresponding to each new network environment module based on its module identifier. It then determines whether the normal operating parameter range of the new network environment module is the same as the security isolation parameter range of the network environment module corresponding to it. If the normal operating parameter range of the new network environment module is the same as the security isolation parameter range of the network environment module corresponding to it, the server determines not to update the security isolation parameter range of that network environment module. If the normal operating parameter range of the new network environment module is different from the security isolation parameter range of the network environment module corresponding to it, the server uses the normal operating parameter range of the new network environment module as the security isolation parameter range of the network environment module, thus obtaining the updated security isolation parameter range. The server uses the updated security isolation parameter ranges of all network environment modules as updated isolation trigger conditions.
[0098] Based on the above scheme, the isolation trigger conditions are updated by using the normal operating parameter information of the new network environment module to ensure the network security protection effect in different network environments.
[0099] In one embodiment, such as Figure 1 As shown, a security protection system is provided, which includes a server 102 and a client 101:
[0100] Server 102 is used to send a network environment access request message containing environment information in the current network environment to the client.
[0101] Client 101 is used to respond to the network environment access request message sent by the server, obtain the environment information in the current network environment, establish the isolation trigger conditions for the current network environment based on the environment information in the current network environment, and send a response message containing the isolation trigger conditions to the server.
[0102] Server 102 is used to receive response messages sent by clients; re-acquire new environment information of the current network environment, and update the isolation trigger conditions if the new environment information does not match the isolation trigger conditions, so as to obtain the updated isolation trigger conditions; and send an isolation trigger condition update request message containing the updated isolation trigger conditions to the client.
[0103] Client 101 is used to replace the current network environment's isolation trigger conditions with the updated isolation trigger conditions contained in the network policy update request message, and to perform network isolation processing on the current network environment if the current network environment's operating status information meets the isolation trigger conditions.
[0104] In this embodiment, a communication connection is established between server 102 and client 101. Server 102 is used to send a network environment access request message containing environment information in the current network environment to client 101. Client 101 is used to receive a response message sent by server 102 and send an isolation trigger condition update request message containing the updated isolation trigger conditions to server 102.
[0105] This application also provides an example of security protection, such as Figure 4 As shown, the specific processing procedure includes the following steps:
[0106] Step S401: In response to the network environment access request message sent by the server, and based on the environment information in the current network environment, establish the isolation trigger conditions for the current network environment.
[0107] Step S402: Send a response message containing the isolation trigger conditions to the server.
[0108] Step S403: Identify each network environment module contained in the environment information, and for each network environment module, parse the normal operating parameter information of the network environment module.
[0109] Step S404: Obtain abnormal operating parameter information of the network environment module, and determine the range of abnormal operating parameters of the network environment module based on the abnormal operating parameter information of the network environment module.
[0110] Step S405: In the normal operating parameter information of the network environment module, the operating parameter information other than the abnormal operating parameter range of the network environment module is taken as the normal operating parameter range of the network environment module, and the normal operating parameter range is taken as the security isolation parameter range of the network environment module.
[0111] Step S406: Use the security isolation parameter range of all network environment modules as the isolation trigger condition for the current network environment.
[0112] Step S407: Receive an isolation trigger condition update request message from the server containing the updated isolation trigger conditions.
[0113] Step S408: Replace the current isolation trigger conditions of the network environment with the updated isolation trigger conditions contained in the network policy update request message.
[0114] Step S409: For each network environment module, identify the fluctuation range of the current operating parameters of the network environment module, and stop the communication process with the network environment module if the fluctuation range of the current operating parameters of the network environment module does not match the security isolation parameter range of the network environment module.
[0115] Step S410: Display all network environment modules with stopped communication processes to the client's display interface, and display the current communication process progress information of each network environment module with stopped communication processes.
[0116] This application also provides an example of security protection, such as Figure 5 As shown, the specific processing procedure includes the following steps:
[0117] In step S501, the server sends a network environment access request message containing environment information of the current network environment to the client.
[0118] In step S502, the client sends a response message containing the isolation trigger condition to the client.
[0119] In step S503, the server sends an isolation trigger condition update request message containing the updated isolation trigger conditions to the client.
[0120] It should be understood that although the steps in the flowcharts of the embodiments described above are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the embodiments described above may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages of other steps.
[0121] Based on the same inventive concept, this application also provides a security protection device for implementing the security protection method described above. The solution provided by this device is similar to the solution described in the above method; therefore, the specific limitations in one or more security protection device embodiments provided below can be found in the limitations of the security protection method described above, and will not be repeated here.
[0122] In one embodiment, such as Figure 6 As shown, a security protection device is provided, including: a first receiving module 610, a first transmitting module 620, and a processing module 630, wherein:
[0123] The first receiving module 610 is used to respond to a network environment access request message sent by the server, and determine the isolation triggering condition of the current network environment based on the environment information in the current network environment.
[0124] The first sending module 620 is used to send a response message containing the isolation trigger condition to the server; the response message is used to instruct the server to update the isolation trigger condition based on the new environment information of the current network environment, obtain the updated isolation trigger condition, and send an isolation trigger condition update request message containing the updated isolation trigger condition to the client.
[0125] The processing module 630 is used to replace the isolation triggering conditions of the current network environment with the updated isolation triggering conditions contained in the network policy update request message, and to perform network isolation processing on the current network environment when the operating status information of the current network environment meets the isolation triggering conditions.
[0126] Optionally, the first transmitting module 620 is specifically used for:
[0127] Identify each network environment module contained in the environmental information, and for each network environment module, parse the normal operating parameter information of the network environment module;
[0128] Based on the normal operating parameter information of the network environment module, a security isolation parameter range for the network environment module is established, and the security isolation parameter range of all network environment modules is used as the isolation trigger condition for the current network environment.
[0129] Optionally, the first transmitting module 620 is specifically used for:
[0130] Obtain abnormal operating parameter information of the network environment module, and determine the range of abnormal operating parameters of the network environment module based on the abnormal operating parameter information of the network environment module;
[0131] In the normal operating parameter information of the network environment module, the operating parameter information other than the abnormal operating parameter range of the network environment module is taken as the normal operating parameter range of the network environment module, and the normal operating parameter range is taken as the security isolation parameter range of the network environment module.
[0132] Optionally, the processing module 630 is specifically used for:
[0133] For each network environment module, identify the fluctuation range of the current operating parameters of the network environment module, and stop the communication process with the network environment module if the fluctuation range of the current operating parameters of the network environment module does not match the security isolation parameter range of the network environment module;
[0134] The system displays all network environment modules whose communication processes have stopped on the client's display interface, and shows the progress information of the current communication process of each of the network environment modules whose communication processes have stopped.
[0135] In one embodiment, such as Figure 7 As shown, a security protection device is provided, comprising: a second transmitting module 710, a second receiving module 720, an updating module 730, and a third transmitting module 740, wherein:
[0136] The second sending module 710 is used to send a network environment access request message containing environment information in the current network environment to the client.
[0137] The second receiving module 720 is used to receive a response message sent by the client; the response message contains the isolation triggering conditions of the current network environment;
[0138] The update module 730 is used to reacquire new environment information of the current network environment, and update the isolation trigger condition if the new environment information does not match the isolation trigger condition, so as to obtain the updated isolation trigger condition;
[0139] The third sending module 740 is used to send an isolation trigger condition update request message containing the updated isolation trigger condition to the client; the isolation trigger condition update request message is used to instruct the client to replace the current network environment's isolation trigger condition with the updated isolation trigger condition contained in the network policy update request message.
[0140] Optionally, the update module 730 is specifically used for:
[0141] For each new network environment module included in the new environment information, obtain the normal operating parameter information of the new network environment module and the abnormal operating parameter information of the new network environment module in the operating database, and determine the normal operating parameter range of the new network environment module based on the normal operating parameter information and the abnormal operating parameter information of the new network environment module.
[0142] If the normal operating parameter range of the new network environment module differs from the security isolation parameter range of the network environment module corresponding to the new network environment module, the normal operating parameter range of the new network environment module shall be used as the security isolation parameter range of the network environment module to obtain the updated isolation triggering condition.
[0143] Each module in the aforementioned security protection device can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in the processor of a computer device in hardware form or independent of it, or stored in the memory of the computer device in software form, so that the processor can call and execute the operations corresponding to each module.
[0144] In one embodiment, a computer device is provided, which may be a client, and its internal structure diagram may be as follows: Figure 8As shown, the computer device includes a processor, memory, communication interface, display screen, and input devices connected via a system bus. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs stored in the non-volatile storage media. The communication interface is used for wired or wireless communication with external clients; wireless communication can be achieved through Wi-Fi, mobile cellular networks, NFC (Near Field Communication), or other technologies. When the computer program is executed by the processor, it implements a security protection method. The display screen can be an LCD screen or an e-ink screen. The input devices can be a touch layer covering the display screen, buttons, a trackball, or a touchpad located on the computer device's casing, or an external keyboard, touchpad, or mouse.
[0145] Those skilled in the art will understand that Figure 8 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device to which the present application is applied. Specific computer devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.
[0146] In one embodiment, a computer device is provided, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the steps of the method described in any one of the first or second aspects.
[0147] In one embodiment, a computer-readable storage medium is provided having a computer program stored thereon, which, when executed by a processor, implements the steps of the method described in any one of the first or second aspects.
[0148] In one embodiment, a computer program product is provided, including a computer program that, when executed by a processor, implements the steps of the method described in any one of the first or second aspects.
[0149] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties.
[0150] Those skilled in the art will understand that all or part of the processes in the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium. When executed, the computer program can include the processes of the embodiments described above. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM). The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, etc., and are not limited to these.
[0151] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0152] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are specific and detailed, they should not be construed as limiting the scope of this patent application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this application should be determined by the appended claims.
Claims
1. A security protection method, characterized in that, The method includes: In response to a network environment access request message sent by the server, the system identifies each network environment module contained in the environment information and parses the normal operating parameter information of each network environment module. Obtain abnormal operating parameter information of the network environment module, and determine the range of abnormal operating parameters of the network environment module based on the abnormal operating parameter information of the network environment module; In the normal operating parameter information of the network environment module, the operating parameter information other than the abnormal operating parameter range of the network environment module is taken as the normal operating parameter range of the network environment module, and the normal operating parameter range is taken as the security isolation parameter range of the network environment module. The security isolation parameter range of all network environment modules is taken as the isolation trigger condition of the current network environment. Send a response message containing the isolation trigger condition to the server; The server re-acquires the environment information of the network environment that needs to be accessed, and uses this environment information as the new environment information of the current network environment. For each new network environment module included in the new environment information, the server obtains the normal operating parameter information of the new network environment module and the abnormal operating parameter information of the new network environment module in the operating database. Based on the normal operating parameter information and the abnormal operating parameter information of the new network environment module, the server determines the normal operating parameter range of the new network environment module. If the normal operating parameter range of the new network environment module is different from the security isolation parameter range of the network environment module corresponding to the new network environment module, the server uses the normal operating parameter range of the new network environment module as the security isolation parameter range of the network environment module, obtains the updated isolation triggering condition, and sends an isolation triggering condition update request message containing the updated isolation triggering condition to the client. Based on the updated isolation triggering conditions contained in the network policy update request message, the isolation triggering conditions of the current network environment are replaced, and network isolation processing is performed on the current network environment if the operating status information of the current network environment meets the isolation triggering conditions.
2. The method according to claim 1, characterized in that, When the operating status information of the current network environment meets the isolation triggering condition, network isolation processing is performed on the current network environment, including: For each network environment module, identify the fluctuation range of the current operating parameters of the network environment module, and stop the communication process with the network environment module if the fluctuation range of the current operating parameters of the network environment module does not match the security isolation parameter range of the network environment module; The system displays all network environment modules whose communication processes have stopped on the client's display interface, and shows the progress information of the current communication process of each of the network environment modules whose communication processes have stopped.
3. A security protection method, characterized in that, The method includes: In response to a user's operation to access the network environment, a network environment access request message containing environment information of the current network environment is sent to the client so that the client can identify each network environment module contained in the environment information, and for each network environment module, the normal operating parameter information of the network environment module is parsed. Obtain abnormal operating parameter information of the network environment module, and determine the abnormal operating parameter range of the network environment module based on the abnormal operating parameter information of the network environment module; in the normal operating parameter information of the network environment module, take the operating parameter information other than the abnormal operating parameter range of the network environment module as the normal operating parameter range of the network environment module, take the normal operating parameter range as the security isolation parameter range of the network environment module, and take the security isolation parameter range of all network environment modules as the isolation trigger condition of the current network environment; Receive a response message sent by the client; the response message contains the isolation trigger conditions of the current network environment; The system reacquires the environment information of the network environment that needs to be accessed and uses this information as the new environment information for the current network environment. For each new network environment module included in the new environment information, it acquires the normal operating parameter information of the new network environment module and the abnormal operating parameter information of the new network environment module in the operating database. Based on the normal operating parameter information and the abnormal operating parameter information of the new network environment module, it determines the normal operating parameter range of the new network environment module. If the normal operating parameter range of the new network environment module is different from the security isolation parameter range of the network environment module corresponding to the new network environment module, it uses the normal operating parameter range of the new network environment module as the security isolation parameter range of the network environment module to obtain the updated isolation triggering condition. Send an isolation trigger condition update request message containing the updated isolation trigger condition to the client; the isolation trigger condition update request message is used to instruct the client to replace the current isolation trigger condition of the network environment with the updated isolation trigger condition contained in the network policy update request message.
4. A security protection system, characterized in that, The system includes a client and a server: The server is used to send a network environment access request message containing environmental information in the current network environment to the client; The client is configured to respond to a network environment access request message sent by the server, obtain environment information in the current network environment; identify each network environment module contained in the environment information, and for each network environment module, parse the normal operating parameter information of the network environment module; obtain the abnormal operating parameter information of the network environment module, and determine the abnormal operating parameter range of the network environment module based on the abnormal operating parameter information of the network environment module; in the normal operating parameter information of the network environment module, take the operating parameter information other than the abnormal operating parameter range of the network environment module as the normal operating parameter range of the network environment module, take the normal operating parameter range as the security isolation parameter range of the network environment module, take the security isolation parameter range of all network environment modules as the isolation trigger condition of the current network environment, and send a response message containing the isolation trigger condition to the server; The server is used to receive response messages sent by the client; The system reacquires the environment information of the network environment to be accessed and uses this information as the new environment information. For each new network environment module included in the new environment information, it acquires the normal operating parameter information of the new network environment module and the abnormal operating parameter information of the new network environment module in the operating database. Based on the normal operating parameter information and the abnormal operating parameter information of the new network environment module, it determines the normal operating parameter range of the new network environment module. If the normal operating parameter range of the new network environment module differs from the security isolation parameter range of the corresponding network environment module, the normal operating parameter range of the new network environment module is used as the security isolation parameter range of the network environment module to obtain the updated isolation trigger condition. Finally, it sends an isolation trigger condition update request message containing the updated isolation trigger condition to the client. The client is configured to replace the isolation trigger conditions of the current network environment with the updated isolation trigger conditions contained in the network policy update request message, and to perform network isolation processing on the current network environment when the operating status information of the current network environment meets the isolation trigger conditions.
5. A safety protection device, characterized in that, The device includes: The first receiving module is used to respond to the network environment access request message sent by the server, identify each network environment module contained in the environment information, and parse the normal operating parameter information of each network environment module. Obtain abnormal operating parameter information of the network environment module, and determine the range of abnormal operating parameters of the network environment module based on the abnormal operating parameter information of the network environment module; In the normal operating parameter information of the network environment module, the operating parameter information other than the abnormal operating parameter range of the network environment module is taken as the normal operating parameter range of the network environment module, and the normal operating parameter range is taken as the security isolation parameter range of the network environment module. The security isolation parameter range of all network environment modules is taken as the isolation trigger condition of the current network environment. The first sending module is used to send a response message containing the isolation trigger condition to the server; the server re-acquires the environment information of the network environment that needs to be accessed, and uses this environment information as the new environment information of the current network environment; for each new network environment module contained in the new environment information, the server obtains the normal operating parameter information of the new network environment module and the abnormal operating parameter information of the new network environment module in the operating database; and determines the normal operating parameter range of the new network environment module based on the normal operating parameter information and the abnormal operating parameter information of the new network environment module; if the normal operating parameter range of the new network environment module is different from the security isolation parameter range of the network environment module corresponding to the new network environment module, the normal operating parameter range of the new network environment module is used as the security isolation parameter range of the network environment module to obtain the updated isolation trigger condition, and sends an isolation trigger condition update request message containing the updated isolation trigger condition to the client; The processing module is used to replace the isolation triggering conditions of the current network environment with the updated isolation triggering conditions contained in the network policy update request message, and to perform network isolation processing on the current network environment when the operating status information of the current network environment meets the isolation triggering conditions.
6. A safety protection device, characterized in that, The device includes: The second sending module is used to send a network environment access request message containing environment information of the current network environment to the client so that the client can identify each network environment module contained in the environment information, and for each network environment module, parse the normal operating parameter information of the network environment module; obtain the abnormal operating parameter information of the network environment module, and determine the abnormal operating parameter range of the network environment module based on the abnormal operating parameter information; in the normal operating parameter information of the network environment module, take the operating parameter information other than the abnormal operating parameter range of the network environment module as the normal operating parameter range of the network environment module, take the normal operating parameter range as the security isolation parameter range of the network environment module, and take the security isolation parameter range of all network environment modules as the isolation trigger condition of the current network environment; The second receiving module is used to receive a response message sent by the client; the response message contains the isolation triggering conditions of the current network environment; The update module is used to reacquire the environment information of the network environment that needs to be accessed, and use this environment information as the new environment information of the current network environment. For each new network environment module included in the new environment information, it acquires the normal operating parameter information of the new network environment module and the abnormal operating parameter information of the new network environment module in the operation database. Based on the normal operating parameter information and the abnormal operating parameter information of the new network environment module, it determines the normal operating parameter range of the new network environment module. If the normal operating parameter range of the new network environment module is different from the security isolation parameter range of the network environment module corresponding to the new network environment module, the normal operating parameter range of the new network environment module is used as the security isolation parameter range of the network environment module, and the updated isolation triggering condition is obtained. The third sending module is used to send an isolation trigger condition update request message containing the updated isolation trigger condition to the client; the isolation trigger condition update request message is used to instruct the client to replace the current network environment's isolation trigger condition with the updated isolation trigger condition contained in the network policy update request message.
7. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 2 or 3.
8. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 2 or 3.
9. A computer program product, comprising a computer program, characterized in that, When executed by a processor, the computer program implements the steps of the method according to any one of claims 1 to 2 or 3.
Citation Information
Patent Citations
A security defense system and method
CN109167795A