Method, device, computer device and storage medium for monitoring rule violations
By sending a probe message corresponding to the category to the terminal and determining the illegal external connection when the platform receives a reply message, the problem of the inability to comprehensively monitor illegal external connections of terminals in the existing technology is solved, and higher monitoring accuracy and comprehensiveness are achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-06-09
- Publication Date
- 2026-04-14
AI Technical Summary
Existing technologies cannot fully monitor whether a terminal has unauthorized external connections, resulting in low monitoring accuracy, especially for access devices that have not pre-installed client software.
By sending multiple probe messages to each target terminal, with the types of probe messages corresponding to different inducement applications, when the first reply message corresponding to the probe message is received, an inducement message containing the address of the illegal external public network platform is sent to the target terminal. The target terminal that receives the inducement message generates a corresponding second reply message and forwards it to the illegal external public network platform according to the address of the illegal external public network platform. Finally, when the illegal external public network platform receives the second reply message, it determines that the target terminal has made an illegal external connection.
It enables comprehensive monitoring of terminals, improves the accuracy of monitoring unauthorized external connections, avoids detection errors caused by the inability of internal and external network cards to directly forward packets, and ensures effective monitoring of devices without installed client software.
Smart Images

Figure CN116567635B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of information security technology, and in particular to methods, devices, computer equipment, and storage media for monitoring unauthorized external connections. Background Technology
[0002] To ensure internal data security, enterprises typically use internal local area networks (LANs) to tightly isolate their internal and external networks, preventing data leaks, hacker attacks, and viruses. However, with the rapid development of wireless networks and the increasing convenience of accessing them, LAN isolation alone is insufficient to effectively prevent wireless devices from connecting to external networks. Therefore, it is necessary to monitor whether internal network terminals are engaging in unauthorized external connections.
[0003] Current monitoring methods deploy a corresponding client on each terminal device connected to the intranet to monitor unauthorized external connections. However, this method cannot monitor access devices without pre-installed clients, thus failing to comprehensively monitor whether terminals are making unauthorized external connections, resulting in low monitoring accuracy.
[0004] There is currently no effective solution to the problem that related technologies cannot fully monitor whether terminals are illegally connected to external networks. Summary of the Invention
[0005] This embodiment provides a method, apparatus, computer equipment, and storage medium for monitoring unauthorized external connections, in order to solve the problem in related technologies that cannot comprehensively monitor whether a terminal has unauthorized external connections.
[0006] Firstly, this embodiment provides a method for monitoring unauthorized external connections, the method comprising:
[0007] Multiple probe messages are sent to each target terminal; the types of probe messages correspond to different inducing applications.
[0008] Upon receiving the first reply message corresponding to the probe message, an inducement message containing the address of the unauthorized external public network platform will be sent to the target terminal corresponding to the first reply message;
[0009] In the target terminal that receives the inducement message, a corresponding second reply message is generated, and the second reply message is forwarded to the illegal external public network platform according to the address of the illegal external public network platform;
[0010] When the platform receiving the second reply message for unauthorized external network access receives the message, it determines that the corresponding target terminal has made an unauthorized external connection.
[0011] In some embodiments, before sending multiple probe messages to each target terminal, the method further includes:
[0012] Asset identification technology is used to probe the target network segment and obtain the probe results;
[0013] Based on the detection results, multiple target terminals in the target network segment are identified;
[0014] Establish an asset profile for each of the target terminals.
[0015] In some embodiments, the step of sending an inducement message containing the address of an unauthorized external public network platform to the target terminal corresponding to the first reply message upon receiving the first reply message includes:
[0016] Upon receiving the first response message corresponding to the probe message, the asset profile of the target terminal is updated based on the first response message;
[0017] Based on a preset time interval, the inducement message containing the address of the illegal external connection platform is sent to the target terminal corresponding to the first reply message.
[0018] In some embodiments, after the illegal external network connection platform receives the second reply message and determines that the corresponding target terminal has made an illegal external connection, the method further includes:
[0019] The illegal external connection information corresponding to the second reply message is displayed on the aforementioned illegal external connection public network platform.
[0020] In some embodiments, the method further includes:
[0021] If the first reply message corresponding to the probe message is not received, a network control message protocol message and a transmission control protocol message containing the address of the illegal external public network platform will be sent to the target terminal that has not returned the first reply message.
[0022] In some embodiments, after sending the inducement message containing the address of the illegal external public network platform to the target terminal corresponding to the first reply message, the method further includes:
[0023] Send a network control message containing the address of a public network platform that is illegally connected to the outside world to the target terminal corresponding to the first reply message;
[0024] In the target terminal that receives the network control message protocol message, a corresponding third reply message is generated, and the third reply message is forwarded to the unauthorized external public network platform according to the address of the unauthorized external public network platform;
[0025] Based on the forwarding path of the third reply message, detect whether the corresponding target terminal has made an unauthorized external connection.
[0026] In some embodiments, after sending the inducement message containing the address of the illegal external public network platform to the target terminal corresponding to the first reply message, the method further includes:
[0027] Send a Transmission Control Protocol (TCP) message containing the address of a platform that illegally connects to the public internet to the target terminal corresponding to the first reply message;
[0028] In the target terminal that receives the Transmission Control Protocol message, a corresponding fourth reply message is generated, and the fourth reply message is forwarded to the unauthorized external public network platform according to the address of the unauthorized external public network platform;
[0029] Based on the forwarding path of the fourth reply message, detect whether the corresponding target terminal has made an unauthorized external connection.
[0030] Secondly, this embodiment provides a device for monitoring unauthorized external connections, the device including a detection module, an induction module, a forwarding module, and a judgment module;
[0031] The detection module is used to send multiple detection messages to each target terminal; the types of the detection messages correspond to different inducement applications.
[0032] The induction module is used to send an induction message containing the address of an illegal external public network platform to the target terminal corresponding to the first response message when it receives the first response message corresponding to the probe message;
[0033] The forwarding module is used to generate a corresponding second reply message in the target terminal that receives the inducement message, and forward the second reply message to the illegal external public network platform according to the address of the illegal external public network platform;
[0034] The judgment module is used to determine that the corresponding target terminal has made an unauthorized external connection when the unauthorized external connection public network platform receives the second reply message.
[0035] Thirdly, this embodiment provides a computer device including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements the illegal external connection monitoring method described in the first aspect above.
[0036] Fourthly, this embodiment provides a storage medium storing a computer program that, when executed by a processor, implements the unauthorized external connection monitoring method described in the first aspect above.
[0037] Compared with related technologies, the illegal external connection monitoring method, device, computer equipment, and storage medium provided in this embodiment send multiple probe messages to each target terminal, with the types of probe messages corresponding to different inducement applications. Upon receiving the first reply message corresponding to the probe message, an inducement message containing the address of the illegal external connection public network platform is sent to the target terminal corresponding to the first reply message. The target terminal receiving the inducement message generates a corresponding second reply message and forwards it to the illegal external connection public network platform based on the illegal external connection public network platform address. Furthermore, upon receiving the second reply message, the illegal external connection public network platform determines that the corresponding target terminal has engaged in illegal external connection. This solves the problem of not being able to comprehensively monitor whether a terminal has engaged in illegal external connection, thereby improving the accuracy of terminal illegal external connection monitoring.
[0038] Details of one or more embodiments of this application are set forth in the following drawings and description to make other features, objects and advantages of this application more readily apparent. Attached Figure Description
[0039] The accompanying drawings, which are included to provide a further understanding of this application and form part of this application, illustrate exemplary embodiments and are used to explain this application, but do not constitute an undue limitation of this application. In the drawings:
[0040] Figure 1 This is a hardware structure block diagram of the terminal device of the illegal external connection monitoring method provided in one embodiment of this application;
[0041] Figure 2 This is a flowchart of a method for monitoring unauthorized external connections provided in an embodiment of this application;
[0042] Figure 3 This is a flowchart illustrating a method for monitoring unauthorized external connections provided in an embodiment of this application;
[0043] Figure 4 This is a flowchart of a preferred embodiment of the method for monitoring unauthorized external connections provided in this application;
[0044] Figure 5 This is a structural block diagram of an embodiment of the illegal external connection monitoring device provided in this application.
[0045] In the diagram: 102, processor; 104, memory; 106, transmission device; 108, input / output device; 10, detection module; 20, induction module; 30, forwarding module; 40, judgment module. Detailed Implementation
[0046] To better understand the purpose, technical solution, and advantages of this application, the application is described and illustrated below in conjunction with the accompanying drawings and embodiments.
[0047] Unless otherwise defined, the technical or scientific terms used in this application shall have the general meaning as understood by one of ordinary skill in the art to which this application pertains. Words such as “a,” “an,” “an,” “the,” “the,” and “these,” used in this application, do not indicate quantitative limitation and may be singular or plural. The terms “comprising,” “including,” “having,” and any variations thereof used in this application are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or device that comprises a series of steps or modules (units) is not limited to the listed steps or modules (units) but may include steps or modules (units) not listed, or may include other steps or modules (units) inherent to such processes, methods, products, or devices. The terms “connected,” “linked,” and “coupled,” used in this application, are not limited to physical or mechanical connections but may include electrical connections, whether direct or indirect. The term “multiple” used in this application refers to two or more. The "and / or" operator describes the relationship between related objects, indicating that three relationships can exist. For example, "A and / or B" can represent three cases: A alone, A and B simultaneously, and B alone. Typically, the character " / " indicates that the objects before and after it are in an "or" relationship. The terms "first," "second," and "third," etc., used in this application are merely for distinguishing similar objects and do not represent a specific ordering of the objects.
[0048] The method embodiments provided in this example can be executed on a terminal, computer, or similar computing device. For example, it can run on a terminal. Figure 1 This is a hardware structure block diagram of the terminal for the unauthorized external connection monitoring method in this embodiment. For example... Figure 1 As shown, a terminal may include one or more ( Figure 1 Only one is shown in the diagram. A processor 102 and a memory 104 for storing data are also included. The processor 102 may be, but is not limited to, a microprocessor (MCU) or a programmable logic device (FPGA). The terminal may also include a transmission device 106 for communication functions and an input / output device 108. Those skilled in the art will understand that… Figure 1 The structure shown is for illustrative purposes only and does not limit the structure of the terminal described above. For example, the terminal may also include components that are larger than... Figure 1 The more or fewer components shown, or having the same Figure 1 The different configurations shown are illustrated.
[0049] The memory 104 can be used to store computer programs, such as application software programs and modules, like the computer program corresponding to the illegal external connection monitoring method in this embodiment. The processor 102 executes various functional applications and data processing by running the computer program stored in the memory 104, thereby implementing the above-described method. The memory 104 may include high-speed random access memory, and may also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 104 may further include memory remotely located relative to the processor 102, and these remote memories can be connected to the terminal via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.
[0050] The transmission device 106 is used to receive or send data via a network. This network includes a wireless network provided by the terminal's communication provider. In one example, the transmission device 106 includes a Network Interface Controller (NIC), which can connect to other network devices via a base station to communicate with the Internet. In another example, the transmission device 106 can be a Radio Frequency (RF) module used for wireless communication with the Internet.
[0051] This embodiment provides a method for monitoring unauthorized external connections. Figure 2 This is a flowchart of the unauthorized external connection monitoring method in this embodiment, as shown below. Figure 2 As shown, the process includes the following steps:
[0052] Step S210: Send multiple probe messages to each target terminal; the types of probe messages correspond to different inducement applications.
[0053] Specifically, when a target terminal in the target network segment is identified that needs to be probed, multiple types of probe messages are sent to each target terminal. Each type of probe message corresponds to a different inducement application, and the purpose of the probe message is to detect whether the target terminal contains an application that can be induced.
[0054] Step S220: Upon receiving the first reply message corresponding to the probe message, a misleading message containing the address of the unauthorized external public network platform is sent to the target terminal corresponding to the first reply message.
[0055] Specifically, if a target terminal receives a probe message and returns a first reply message, an inducement message containing the address of an unauthorized external public network platform will be sent to the target terminal to further detect whether the target terminal has made an unauthorized external connection.
[0056] It is important to know that when sending an inducement message to the target terminal that returns the first reply message, other probe messages can also be sent to the target terminal, including Internet Control Message Protocol (ICMP) messages and Transmission Control Protocol (TCP) messages.
[0057] Step S230: In the target terminal that received the inducement message, a corresponding second reply message is generated, and the second reply message is forwarded to the unauthorized external public network platform according to the address of the unauthorized external public network platform.
[0058] It is important to know that because the inducement message contains the address of an unauthorized external public network platform, when the target terminal generates the corresponding second reply message, it will immediately forward the second reply message to the unauthorized external public network platform through the external network card based on the address of the unauthorized external public network platform.
[0059] Step S240: When the platform receiving the second reply message for unauthorized external connection to the public network receives the message, it is determined that the corresponding target terminal has made an unauthorized external connection.
[0060] Specifically, if the reply message received by the platform that illegally connects to the public network is the same as the second reply message generated by the target terminal, it indicates that the target terminal has made an illegal external connection.
[0061] Current monitoring methods deploy corresponding clients on each terminal device connected to the intranet to monitor unauthorized external connections. However, these methods cannot monitor access devices without pre-installed clients, resulting in incomplete monitoring of unauthorized external connections and low monitoring accuracy. This application, compared to existing technologies, adopts a clientless approach by actively sending inducement packets to detect unauthorized external connections on target terminals. This eliminates the need for client deployment to monitor unauthorized external connections, avoiding the inability to monitor access devices without pre-installed clients and achieving comprehensive monitoring of terminal devices, thereby improving monitoring accuracy. Furthermore, the active sending of inducement packets avoids the situation where the intranet and extranet network cards on the target terminal cannot directly forward packets when using probe packets such as Network Control Message Protocol (NIC) and Transmission Control Protocol (TCP) messages to detect unauthorized external connections, further improving the accuracy of unauthorized external connection detection.
[0062] Specifically, multiple probe messages are sent to each target terminal, and the types of probe messages correspond to different inducement applications. Upon receiving the first reply message corresponding to the probe message, an inducement message containing the address of the illegal external public network platform is sent to the target terminal corresponding to the first reply message. In the target terminal that receives the inducement message, a corresponding second reply message is generated. Based on the address of the illegal external public network platform, the second reply message is forwarded to the illegal external public network platform. Furthermore, when the illegal external public network platform receives the second reply message, it determines that the corresponding target terminal has made an illegal external connection. This solves the problem of not being able to comprehensively monitor whether a terminal has made an illegal external connection, and improves the accuracy of monitoring illegal external connections of terminals.
[0063] In some embodiments, before sending multiple probe messages to each target terminal, the method further includes:
[0064] Step S201: Using asset identification technology, the target network segment is probed to obtain the probe results;
[0065] Step S202: Based on the detection results, identify multiple target terminals in the target network segment;
[0066] Step S203: Establish an asset profile for each target terminal.
[0067] Specifically, when the illegal external connection scanning platform activates the illegal external connection function, it uses asset identification technology to probe the target network segment, identify the live terminal devices in the target network segment that need to be probed, and designate the live terminal devices that need to be probed as the target terminals.
[0068] It is important to know that after identifying multiple target terminals in the target network segment, the asset identification technology remains active to dynamically detect active devices in the target network segment.
[0069] Furthermore, based on the asset identification results of the target network segment, an asset profile is established for each target terminal to facilitate monitoring whether the target terminal contains applications that can be tricked.
[0070] In this embodiment, asset identification technology is used to detect the target network segment, and the detection results are obtained. Based on the detection results, multiple target terminals in the target network segment are identified, and an asset profile of each target terminal is established, so as to accurately and comprehensively obtain relevant information of the target terminal.
[0071] In some embodiments, upon receiving a first reply message corresponding to a probe message, an inducement message containing the address of an unauthorized external public network platform is sent to the target terminal corresponding to the first reply message, including:
[0072] Step S221: Upon receiving the first reply message corresponding to the probe message, update the asset profile of the target terminal based on the first reply message;
[0073] Step S222: Based on a preset time interval, a misleading message containing the address of an unauthorized external platform is sent to the target terminal corresponding to the first reply message.
[0074] Specifically, upon receiving the first response message corresponding to the probe message, it indicates that the target terminal corresponding to the first response message contains an application that can be induced, i.e., an inducement application. The inducement application is then written into the asset profile of the target terminal to update the asset profile.
[0075] Furthermore, based on a preset time interval, a forged inducement message containing the address of an illegal external platform is sent to a target terminal containing an application that can be induced.
[0076] In this embodiment, when a target terminal returns a first reply message, the asset profile of the target terminal is updated based on the first reply message, and based on a preset time interval, an inducement message containing the address of an illegal external connection platform is sent to the target terminal corresponding to the first reply message, thereby realizing the detection of illegal external connections of target terminals containing inducement applications.
[0077] In addition, this embodiment adopts the method of actively sending inducement packets, which avoids the situation where the internal network card and external network card on the target terminal cannot directly forward the packets when using probe packets such as network control message protocol packets and transmission control protocol packets to detect unauthorized external connection behavior, thereby improving the accuracy of unauthorized external connection detection.
[0078] In some embodiments, after the platform receiving the second reply message and determining that the corresponding target terminal has made an unauthorized external connection, the method further includes:
[0079] Step S250: Display the illegal external connection information corresponding to the second reply message on the illegal external connection public network platform.
[0080] Specifically, if the platform that is illegally connecting to the public network receives the second reply message, it will display the illegal connection information of the corresponding target terminal based on the data content of the second reply message, thereby directly and accurately locating the target terminal address where the illegal connection occurred.
[0081] It should be noted that the illegal external connection scanning platform in this embodiment can adapt to complex network environments. When detecting illegal external connection behavior of terminal devices in different Virtual Local Area Networks (VLANs) or different QinQ networks, the illegal external connection scanning platform does not need to be reconfigured.
[0082] Furthermore, the aforementioned illegal external connection scanning platform can enable a self-learning function, learn network segments that are not configured in the illegal external connection monitoring module in the traffic, and monitor them for illegal external connections.
[0083] This embodiment displays the illegal external connection information corresponding to the second reply message on the illegal external connection public network platform, thereby enabling rapid location of the target terminal that has made an illegal external connection, timely handling of the terminal device that made the illegal external connection, blocking the threat of the illegal external connection terminal to the internal network, and avoiding internal data leakage and other situations.
[0084] In some embodiments, the method further includes:
[0085] If no first reply message is received for the probe message, a network control message protocol message and a transmission control protocol message containing the address of the unauthorized external public network platform will be sent to the target terminal that has not returned the first reply message.
[0086] Specifically, after sending a probe message to the target terminal, if no first reply message is received from the target terminal, an ICMP message and a TCP message containing the address of an unauthorized external public network platform are forged and sent to the target terminal that has not returned the first reply message.
[0087] Furthermore, upon receiving an ICMP or TCP message, the target terminal generates a corresponding reply message. Based on the address of the unauthorized external public network platform, the reply message is forwarded to the unauthorized external public network platform. Based on the forwarding path of the reply message, the system detects whether the corresponding target terminal has engaged in unauthorized external connections.
[0088] It's important to know that the reply message forwarding path includes two paths. Path one involves forwarding the reply message through the target terminal's internal network card to its external network card, and then sending it to the unauthorized external public network platform. Path two involves sending the reply message from the target terminal's internal network card and then forwarding it to the unauthorized external public network platform through a routing node within the target terminal's local area network. If the unauthorized external public network platform receives the corresponding reply message, it determines that the target terminal corresponding to the reply message has engaged in unauthorized external connections. Furthermore, when the forwarding path is Path two, it can detect whether the router within the target terminal's local area network is also engaging in unauthorized external connection behavior.
[0089] In this embodiment, when no first reply message corresponding to the probe message is received, a network control message protocol message and a transmission control protocol message containing the address of the illegal external public network platform are sent to monitor the target terminal that does not contain the inducement application, thereby achieving comprehensive monitoring of all terminal devices in the target network segment.
[0090] In some embodiments, after sending the inducement message containing the address of an unauthorized external public network platform to the target terminal corresponding to the first reply message, the method further includes:
[0091] Send a network control message protocol message containing the address of an unauthorized external public network platform to the target terminal corresponding to the first reply message;
[0092] Upon receiving the network control message protocol message, the target terminal generates a corresponding third reply message and forwards the third reply message to the unauthorized external public network platform based on the address of the unauthorized external public network platform.
[0093] Based on the forwarding path of the third reply message, detect whether the corresponding target terminal has made any unauthorized external connections.
[0094] Specifically, when sending an inducement message to the target terminal that received the first reply message, an ICMP message containing the address of an unauthorized external public network platform can also be sent to the target terminal corresponding to the first reply message.
[0095] Furthermore, upon receiving the ICMP message, the target terminal generates a corresponding third reply message. Based on the address of the unauthorized external public network platform, the third reply message is forwarded to the corresponding unauthorized external public network platform. Based on the forwarding path of the reply message, it is detected whether the target terminal has engaged in unauthorized external connections.
[0096] It's important to know that the reply message forwarding path includes two paths. Path one involves forwarding the third reply message through the target terminal's internal network card to its external network card, and then sending it to the unauthorized external public network platform. Path two involves sending the third reply message from the target terminal's internal network card and then forwarding it to the unauthorized external public network platform through a routing node within the target terminal's local area network. If the unauthorized external public network platform receives the third reply message, it determines that the target terminal corresponding to the third reply message has engaged in unauthorized external connections. Furthermore, when the forwarding path is path two, it can detect whether the router within the target terminal's local area network is also engaging in unauthorized external connection behavior.
[0097] In this embodiment, an ICMP message containing the address of a public network platform that is illegally accessing the internet is sent to the target terminal corresponding to the first reply message to detect whether the target terminal is illegally accessing the internet. This is combined with inducement messages and other probe messages to achieve terminal detection and improve the accuracy of monitoring illegal external connections.
[0098] In some embodiments, after sending the inducement message containing the address of an unauthorized external public network platform to the target terminal corresponding to the first reply message, the method further includes:
[0099] Send the Transmission Control Protocol (TCP) message containing the address of the unauthorized external public network platform to the target terminal corresponding to the first reply message;
[0100] Upon receiving the Transmission Control Protocol (TCP) message, the target terminal generates a corresponding fourth reply message and forwards the fourth reply message to the unauthorized external public network platform based on its address.
[0101] Based on the forwarding path of the fourth reply message, detect whether the corresponding target terminal has made any unauthorized external connections.
[0102] Specifically, when sending an inducement message to the target terminal that received the first reply message, a TCP message containing the address of an unauthorized external public network platform can also be sent to the target terminal corresponding to the first reply message.
[0103] Furthermore, in the target terminal that receives the TCP packet, a corresponding fourth reply packet is generated. Based on the address of the unauthorized external public network platform, the fourth reply packet is forwarded to the corresponding unauthorized external public network platform. Based on the forwarding path of the reply packet, it is detected whether the target terminal has made an unauthorized external connection.
[0104] It's important to know that the forwarding path for the reply message includes two paths. Path one involves forwarding the fourth reply message through the target terminal's internal network card to its external network card, and then sending it to the unauthorized external public network platform. Path two involves sending the fourth reply message from the target terminal's internal network card and then forwarding it to the unauthorized external public network platform through a routing node within the target terminal's local area network. If the unauthorized external public network platform receives the fourth reply message, it determines that the target terminal corresponding to the fourth reply message has engaged in unauthorized external connections. Furthermore, when the forwarding path is path two, it can detect whether the router within the target terminal's local area network is also engaging in unauthorized external connection behavior.
[0105] In this embodiment, a TCP packet containing the address of an unauthorized external public network platform is sent to the target terminal corresponding to the first reply packet to detect whether the target terminal has made an unauthorized external connection. This, combined with inducement packets and other probe packets, enables terminal detection and improves the accuracy of unauthorized external connection monitoring.
[0106] Figure 3 This is a flowchart illustrating the unauthorized external connection monitoring method of this embodiment, as shown below. Figure 3 As shown, the specific process of this method includes the following steps:
[0107] Asset identification technology is used to probe the target network segment, and the probe results are obtained (S310). Based on the probe results, multiple target terminals in the target network segment are identified (S320), and an asset profile of each target terminal is established (S330). Multiple first probe messages are sent to each target terminal, and the category of the first probe message corresponds to different inducement applications (S340). It is determined whether a first reply message corresponding to the first probe message has been received (S350). When the first reply message is received, the inducement application is written into the asset profile of the target terminal (S360), and a second probe message containing the illegal external public network platform is sent to the target terminal corresponding to the first reply message (S370). The second probe message includes inducement messages, ICMP messages, and TCP messages. In the target terminal that receives the second probe message, a corresponding reply message is generated, and the reply message is forwarded to the illegal external public network platform according to the address of the illegal external public network platform. If the illegal external public network platform receives the reply message, it is determined that the corresponding target terminal has engaged in illegal external connection (S390).
[0108] If the first reply message is not received, a third probe message containing the address of the unauthorized external public network platform will be sent to the target terminal that has not returned the first reply message. The third probe message includes ICMP messages and TCP messages (S380). Upon receiving the third probe message, the target terminal generates a corresponding reply message, forwards the reply message to the unauthorized external public network platform according to the address of the unauthorized external public network platform, and checks whether the corresponding target terminal has engaged in unauthorized external connection (S390) based on the forwarding path of the reply message.
[0109] The present embodiment will now be described and illustrated through preferred embodiments.
[0110] Figure 4 This is a flowchart of the method for monitoring unauthorized external connections according to a preferred embodiment, such as... Figure 4 As shown, this method for monitoring unauthorized external connections includes the following steps:
[0111] Step S410: Use asset identification technology to probe the target network segment and obtain the probe results;
[0112] Step S420: Based on the detection results, identify multiple target terminals in the target network segment;
[0113] Step S430: Send multiple probe messages to each target terminal; the types of probe messages correspond to different inducement applications;
[0114] Step S440: Upon receiving the first reply message corresponding to the probe message, send an inducement message containing the address of the unauthorized external public network platform to the target terminal corresponding to the first reply message;
[0115] Step S450: In the target terminal that received the inducement message, a corresponding second reply message is generated, and the second reply message is forwarded to the unauthorized external public network platform according to the address of the unauthorized external public network platform;
[0116] Step S460: When the platform receiving the second reply message for unauthorized external connection to the public network receives the message, it is determined that the corresponding target terminal has made an unauthorized external connection.
[0117] Step S470: Display the illegal external connection information corresponding to the second reply message on the illegal external connection public network platform.
[0118] In this embodiment, asset identification technology is used to probe the target network segment and obtain the probe results. Based on the probe results, multiple target terminals in the target network segment are identified, and multiple probe messages are sent to each target terminal. The types of probe messages correspond to different inducement applications to detect whether each target terminal contains inducement applications. When a first reply message corresponding to a probe message is received, an inducement message containing the address of an illegal external public network platform is sent to the target terminal that returned the first reply message. In the target terminal that received the inducement message, a corresponding second reply message is generated. Based on the address of the illegal external public network platform, the second reply message is forwarded to the illegal external public network platform. In this way, by actively sending inducement messages, it is possible to detect whether the target terminal has made an illegal external connection.
[0119] Furthermore, if the platform for unauthorized external network connections receives the second reply message, it determines that the corresponding target terminal has made an unauthorized external connection. The platform then displays the unauthorized external connection information corresponding to the second reply message, thereby accurately locating the target terminal address that made the unauthorized external connection based on the information. This facilitates timely handling of the unauthorized external connection device, blocks the threat posed by the unauthorized external connection terminal to the internal network, and prevents internal data leaks and hacker attacks on the internal network.
[0120] It should be noted that the steps shown in the above process or in the flowchart of the accompanying figures can be executed in a computer system such as a set of computer-executable instructions, and although a logical order is shown in the flowchart, in some cases the steps shown or described may be executed in a different order than that shown here.
[0121] This embodiment also provides a device for monitoring unauthorized external connections, which is used to implement the above embodiments and preferred embodiments; details already described will not be repeated. The terms "module," "unit," "subunit," etc., used below refer to combinations of software and / or hardware that perform a predetermined function. Although the device described in the following embodiments is preferably implemented in software, hardware implementation, or a combination of software and hardware, is also possible and contemplated.
[0122] Figure 5 This is a structural block diagram of the unauthorized external connection monitoring device in this embodiment, as shown below. Figure 5 As shown, the device includes: a detection module 10, a guidance module 20, a forwarding module 30, and a judgment module 40;
[0123] The detection module 10 is used to send multiple detection messages to each target terminal; the types of detection messages correspond to different inducement applications.
[0124] The induction module 20 is used to send an induction message containing the address of an unauthorized external public network platform to the target terminal corresponding to the first reply message when it receives the first reply message corresponding to the probe message;
[0125] The forwarding module 30 is used to generate a corresponding second reply message in the target terminal that receives the inducement message, and forward the second reply message to the illegal external public network platform according to the address of the illegal external public network platform;
[0126] The judgment module 40 is used to determine that the corresponding target terminal has made an unauthorized external connection when the platform receiving the second reply message for unauthorized external connection to the public network receives the message.
[0127] In this embodiment, multiple probe messages are sent to each target terminal, and the types of probe messages correspond to different inducement applications. Upon receiving the first response message corresponding to the probe message, an inducement message containing the address of the illegal external public network platform is sent to the target terminal corresponding to the first response message. In the target terminal that receives the inducement message, a corresponding second response message is generated. Based on the address of the illegal external public network platform, the second response message is forwarded to the illegal external public network platform. Furthermore, when the illegal external public network platform receives the second response message, it determines that the corresponding target terminal has engaged in illegal external connection. This solves the problem of not being able to comprehensively monitor whether a terminal has engaged in illegal external connection, and improves the accuracy of monitoring illegal external connections of terminals.
[0128] In some of these embodiments, in Figure 5 Based on this, the device also includes a module for using asset identification technology to detect the target network segment and obtain the detection results; based on the detection results, identify multiple target terminals in the target network segment; and establish an asset profile for each target terminal.
[0129] In some of these embodiments, in Figure 5 In addition to the above, the device also includes a first sending module, which is used to update the asset profile of the target terminal according to the first reply message when the first reply message corresponding to the probe message is received; and to send an inducement message containing the address of the illegal external connection platform to the target terminal corresponding to the first reply message based on a preset time interval.
[0130] In some of these embodiments, in Figure 5 Based on this, the device also includes a display module, which is used to display the illegal external connection information corresponding to the second reply message on the illegal external connection public network platform.
[0131] In some of these embodiments, in Figure 5 Based on this, the device also includes a second sending module, which, when not receiving the first reply message corresponding to the probe message, sends a network control message protocol message and a transmission control protocol message containing the address of the unauthorized external public network platform to the target terminal corresponding to the first reply message.
[0132] In some of these embodiments, in Figure 5 Based on this, the device also includes a first detection module, which is used to send a network control message protocol message containing the address of an unauthorized external public network platform to the target terminal corresponding to the first reply message; in the target terminal that receives the network control message protocol message, a corresponding third reply message is generated, and the third reply message is forwarded to the unauthorized external public network platform according to the address of the unauthorized external public network platform; based on the forwarding path of the third reply message, it is detected whether the corresponding target terminal has made an unauthorized external connection.
[0133] In some of these embodiments, in Figure 5 Based on this, the device also includes a second detection module, used to send a Transmission Control Protocol (TCP) message containing the address of an unauthorized external public network platform to the target terminal corresponding to the first reply message; in the target terminal that receives the TCP message, a corresponding fourth reply message is generated, and the fourth reply message is forwarded to the unauthorized external public network platform according to the address of the unauthorized external public network platform; based on the forwarding path of the fourth reply message, it is detected whether the corresponding target terminal has made an unauthorized external connection.
[0134] It should be noted that the above modules can be functional modules or program modules, and can be implemented through software or hardware. For modules implemented through hardware, the above modules can reside in the same processor; or the above modules can be located in different processors in any combination.
[0135] This embodiment also provides a computer device, including a memory and a processor, wherein the memory stores a computer program and the processor is configured to run the computer program to perform the steps in any of the above method embodiments.
[0136] Optionally, the computer device may further include a transmission device and an input / output device, wherein the transmission device is connected to the processor and the input / output device is connected to the processor.
[0137] It should be noted that the specific examples in this embodiment can refer to the examples described in the above embodiments and optional implementations, and will not be repeated in this embodiment.
[0138] Furthermore, in conjunction with the illegal external connection monitoring methods provided in the above embodiments, this embodiment can also provide a storage medium for implementation. This storage medium stores a computer program; when executed by a processor, the computer program implements any of the illegal external connection monitoring methods in the above embodiments.
[0139] It should be understood that the specific embodiments described herein are merely illustrative of the application and not intended to limit it. All other embodiments derived by those skilled in the art based on the embodiments provided in this application without inventive effort are within the scope of protection of this application.
[0140] Obviously, the accompanying drawings are merely some examples or embodiments of this application. Those skilled in the art can apply this application to other similar situations based on these drawings without any creative effort. Furthermore, it is understood that although the work done in this development process may be complex and lengthy, for those skilled in the art, certain design, manufacturing, or production modifications made based on the technical content disclosed in this application are merely conventional technical means and should not be considered as insufficient disclosure of this application.
[0141] The term "embodiment" in this application refers to a specific feature, structure, or characteristic described in connection with an embodiment that may be included in at least one embodiment of this application. The appearance of this phrase in various places in the specification does not necessarily imply the same embodiment, nor does it imply that it is mutually exclusive with or independent of other embodiments. It will be clearly or implicitly understood by those skilled in the art that the embodiments described in this application may be combined with other embodiments without conflict.
[0142] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of patent protection. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the appended claims.
Claims
1. A method for monitoring unauthorized external connections, characterized in that, The method includes: Multiple probe messages are sent to each target terminal; the types of probe messages correspond to different inducing applications. Upon receiving the first response message corresponding to the probe message, the inducement application is written into the asset profile of the target terminal to update the asset profile; an inducement message containing the address of the illegal external public network platform is sent to the target terminal corresponding to the first response message; wherein, if the first response message corresponding to the probe message is not received, a network control message protocol message and a transmission control message containing the address of the illegal external public network platform are sent to the target terminal that has not returned the first response message; In the target terminal that receives the inducement message, a corresponding second reply message is generated, and the second reply message is forwarded to the illegal external public network platform according to the address of the illegal external public network platform; When the platform receiving the second reply message for unauthorized external network access receives the message, it determines that the corresponding target terminal has made an unauthorized external connection.
2. The method for monitoring unauthorized external connections according to claim 1, characterized in that, Before sending multiple probe messages to each target terminal, the method further includes: Asset identification technology is used to probe the target network segment and obtain the probe results; Based on the detection results, multiple target terminals in the target network segment are identified; Establish an asset profile for each of the target terminals.
3. The method for monitoring unauthorized external connections according to claim 2, characterized in that, Upon receiving the first reply message corresponding to the probe message, the step of sending an inducement message containing the address of an unauthorized external public network platform to the target terminal corresponding to the first reply message includes: Upon receiving the first response message corresponding to the probe message, the asset profile of the target terminal is updated based on the first response message; Based on a preset time interval, the inducement message containing the address of the illegal external connection platform is sent to the target terminal corresponding to the first reply message.
4. The method for monitoring unauthorized external connections according to claim 1, characterized in that, After the platform receiving the second reply message and determining that the corresponding target terminal has made an unauthorized external connection, the process further includes: The illegal external connection information corresponding to the second reply message is displayed on the aforementioned illegal external connection public network platform.
5. The method for monitoring unauthorized external connections according to claim 1, characterized in that, After sending the inducement message containing the address of an unauthorized external public network platform to the target terminal corresponding to the first reply message, the method further includes: Send a network control message containing the address of a public network platform that is illegally connected to the outside world to the target terminal corresponding to the first reply message; In the target terminal that receives the network control message protocol message, a corresponding third reply message is generated, and the third reply message is forwarded to the unauthorized external public network platform according to the address of the unauthorized external public network platform; Based on the forwarding path of the third reply message, detect whether the corresponding target terminal has made an unauthorized external connection.
6. The method for monitoring unauthorized external connections according to claim 1, characterized in that, After sending the inducement message containing the address of an unauthorized external public network platform to the target terminal corresponding to the first reply message, the method further includes: Send a Transmission Control Protocol (TCP) message containing the address of a platform that illegally connects to the public internet to the target terminal corresponding to the first reply message; In the target terminal that receives the Transmission Control Protocol message, a corresponding fourth reply message is generated, and the fourth reply message is forwarded to the unauthorized external public network platform according to the address of the unauthorized external public network platform; Based on the forwarding path of the fourth reply message, detect whether the corresponding target terminal has made an unauthorized external connection.
7. A monitoring device for unauthorized external connections, characterized in that, The device includes a detection module, a guidance module, a forwarding module, and a judgment module; The detection module is used to send multiple detection messages to each target terminal; the types of the detection messages correspond to different inducement applications. The induction module is configured to, upon receiving the first reply message corresponding to the probe message, write the induction application into the asset profile of the target terminal to update the asset profile; and send an induction message containing the address of the illegal external public network platform to the target terminal corresponding to the first reply message; wherein, if the first reply message corresponding to the probe message is not received, a network control message protocol message and a transmission control message containing the address of the illegal external public network platform are sent to the target terminal that has not returned the first reply message; The forwarding module is used to generate a corresponding second reply message in the target terminal that receives the inducement message, and forward the second reply message to the illegal external public network platform according to the address of the illegal external public network platform; The judgment module is used to determine that the corresponding target terminal has made an unauthorized external connection when the unauthorized external connection public network platform receives the second reply message.
8. A computer device, comprising a memory and a processor, characterized in that, The memory stores a computer program, and the processor is configured to run the computer program to perform the steps of the unauthorized external connection monitoring method according to any one of claims 1 to 6.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the steps of the illegal external connection monitoring method as described in any one of claims 1 to 6.
Citation Information
Patent Citations
Active detection method for various network interconnections based on ICMP protocol
CN107317729A
Method and device for detecting equipment with illegal external connection
CN111130931A
Cross-network boundary equipment detection method, device and equipment and readable storage medium
CN113783757A