Micro-isolation protection methods and related hardware

By using the correspondence between client time grouping and resource grouping, the processing pressure on the access controller is reduced, hardware group-level security protection is achieved, the problem of excessive processing pressure on the access controller in large-scale network systems is solved, and the security and efficiency of the network system are improved.

CN116633617BActive Publication Date: 2025-09-26CHINA TELECOM CO LTD SHANGHAI RES INST +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310590028.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-05-23
Publication Date
2025-09-26
Estimated Expiration
2043-05-23

AI Technical Summary

Technical Problem

In a large network system, the access controller needs to handle the access control requirements of a large number of clients and resource data, resulting in excessive processing pressure and consumption of a large amount of performance resources.

Method used

By grouping the clients according to the sending time of the first request information and determining the corresponding resource group for the client group, the first gateway only releases the second access request of the target client to the corresponding target resource group to the access controller, thereby reducing the number of request information control operations processed by the access controller.

Benefits of technology

It reduces the processing pressure on the access controller and the requirements for performance resources, and prevents malicious clients from bypassing and accessing other resource servers through hardware group-level protection rules, thereby improving the security and efficiency of the network system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116633617B_ABST
    Figure CN116633617B_ABST
Patent Text Reader

Abstract

An embodiment of the present invention provides a micro-isolation protection method and related hardware. The method groups clients according to the sending time of the first request information and determines the corresponding resource group for the client group. The first gateway then only releases the second access request of the target client to the corresponding target resource group to the access controller, so that the access controller can perform subsequent control operations, thereby reducing the number of request information control operations that the access controller needs to process and reducing the processing pressure of the access controller. In addition, by using the sending time of the first request information as the basis for grouping, there is almost no significant pattern in the members of the client group and resource group obtained in each grouping. It is difficult for malicious clients controlled by criminals to bypass the hardware group-level protection of the client group-resource group and invade and destroy the vast majority of other resource servers that do not belong to the resource group corresponding to the malicious client. This more effectively achieves the security protection of the network system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular to a micro-isolation protection method and related hardware. Background Art

[0002] Microsegmentation is an emerging network security technology that divides an unstructured, borderless network into numerous logically small segments. This ensures that each segment has only one computing resource, and all traffic entering and exiting the microsegment must pass through an access controller. Based on workload identity, microsegmentation implements fine-grained isolation and refined access control for workloads (physical machines, virtual machines, containers, etc.), applications, and programs located in local or cloud data centers through access control policies or encryption rules. This reduces exposure and prevents lateral attack.

[0003] Currently, micro-segmentation technology primarily implements protection at the application level. This involves an access controller controlling whether clients are allowed to access resource data by regulating the access rules between them. However, when the overall network architecture is large, the numerous access control requests between a large number of clients and a large amount of resource data must be handled by the access controller. This places significant pressure on the access controller and consumes significant performance resources. Summary of the Invention

[0004] An embodiment of the present invention provides a micro-isolation protection method and related hardware to reduce the access control processing pressure of an access controller in a network protection system.

[0005] In a first aspect, an embodiment of the present invention provides a micro-isolation protection method applied to an access controller, comprising:

[0006] receiving a first request message sent by at least one client and forwarded by a first gateway, and dividing the at least one client into at least one client group; wherein the clients sending the first request message within the same preset time period belong to the same client group;

[0007] For any client group, the resource servers corresponding to the respective clients in the client group are divided into the same resource group; for any client, the resource server corresponding to the client is determined according to the first request information of the client;

[0008] Sending the hardware group correspondence between the client group and the resource group to the first gateway; so that when the first gateway receives a second request message from the target client to the resource server to be processed and forwards it to the resource server, if it is determined based on the hardware group correspondence that the resource server to be processed belongs to the target resource group, the second request message is forwarded to the access controller; wherein the target resource group is the resource group corresponding to the client group to which the target client belongs;

[0009] The second request information is received, and the legal second request information is controlled to be sent to a to-be-processed resource server corresponding to the second request information.

[0010] Optionally, the controlling the legitimate second request information to be sent to a to-be-processed resource server corresponding to the second request information includes:

[0011] Notifying the second gateway to send the legitimate second request information to the to-be-processed resource server corresponding to the second request information; wherein the second gateway receives the second request information from the first gateway;

[0012] Alternatively, the legal second request information is sent to a third gateway, so that the third gateway forwards the second request information to a to-be-processed resource server corresponding to the second request information.

[0013] Optionally, before controlling the sending of the legal second request information to the to-be-processed resource server corresponding to the second request information, the method further includes:

[0014] For any pending resource server, the pending resource server is notified to allow the corresponding target client to access the server.

[0015] Optionally, the method further includes:

[0016] For any resource server to be processed, when it is determined that the resource server to be processed has ended communication with the target client, the resource server to be processed is notified to not allow the target client to access.

[0017] Optionally, the notifying the to-be-processed resource server to allow the corresponding target client to access the resource includes:

[0018] A first firewall rule is issued to the resource server to be processed, where the first firewall rule is used to control the resource server to be processed to allow a corresponding target client to access the resource.

[0019] Optionally, notifying the to-be-processed resource server that any client is not allowed to access the resource includes:

[0020] A second firewall rule is issued to the resource server to be processed, where the second firewall rule is used to control the resource server to be processed to not allow the target client to access the resource.

[0021] Optionally, before controlling the sending of the legal second request information to the to-be-processed resource server corresponding to the second request information, the method further includes:

[0022] When determining that the second request information is information that complies with the preset access rule, determining that the second request information is legal second request information;

[0023] The preset access rules include at least one of the following:

[0024] The hardware correspondence between the client and the resource server that the client is allowed to access;

[0025] The corresponding relationship between the client application corresponding to the second request information and the port of the resource server allowed to be accessed by the application.

[0026] Optionally, for any target client, the first request information and / or the second request information of the target client includes at least one of the following:

[0027] The sending time of the first request information;

[0028] The identification information of the target client;

[0029] Address information of the target client;

[0030] The port number of the target client;

[0031] Access application identification information of the target client;

[0032] The identity identification information of the corresponding resource server to be processed;

[0033] The address information of the corresponding resource server to be processed;

[0034] The port number of the corresponding resource server to be processed.

[0035] In a second aspect, based on the same inventive concept, an embodiment of the present invention further provides a micro-isolation protection method, applied to a first gateway, comprising:

[0036] Receive a first request message sent by at least one client and forward it to an access controller; so that the access controller divides the at least one client into at least one client group, and for any client group, divides the resource servers corresponding to the clients in the client group into the same resource group; wherein the clients that send the first request message within the same preset time period belong to the same client group; and for any client, the resource server corresponding to the client is determined based on the first request message of the client;

[0037] receiving a hardware group correspondence between a client group and a resource group sent by the access controller;

[0038] Receive a second request message from the target client to the resource server to be processed. If it is determined that the resource server to be processed belongs to the target resource group based on the hardware group correspondence, forward the second request message to the access controller so that the second request message, which is legally controlled by the access controller, is sent to the resource server to be processed corresponding to the second request message; wherein the target resource group is a resource group corresponding to the client group to which the target client is located.

[0039] Optionally, the method further includes:

[0040] If it is determined according to the hardware group correspondence that the resource server to be processed does not belong to the target resource group, the second request information is discarded, and / or a response error prompt information is returned to the target client.

[0041] Optionally, after forwarding the second request information to the access controller, the method further includes:

[0042] Forwarding the second request information to the second gateway; so that the second gateway sends the legal second request information to the to-be-processed resource server corresponding to the second request information under the control of the access controller.

[0043] Optionally, receiving first request information sent by at least one client and forwarding it to the access controller includes:

[0044] receiving a first request message sent by at least one client, and forwarding the first request message sent by using a first preset communication method to the access controller;

[0045] Before determining that the resource server to be processed belongs to the target resource group according to the hardware group correspondence, the method further includes:

[0046] It is determined that the second request information is sent using a second preset communication method.

[0047] Optionally, for any target client, the first request information and / or the second request information of the target client includes at least one of the following:

[0048] The sending time of the first request information;

[0049] The identification information of the target client;

[0050] Address information of the target client;

[0051] The port number of the target client;

[0052] Access application identification information of the target client;

[0053] The identity identification information of the corresponding resource server to be processed;

[0054] The address information of the corresponding resource server to be processed;

[0055] The port number of the corresponding resource server to be processed.

[0056] In a third aspect, based on the same inventive concept, an embodiment of the present invention further provides a micro-isolation protection system, including:

[0057] An access controller used to implement the micro-isolation protection method as described in the first aspect;

[0058] A first gateway used to implement the micro-isolation protection method according to the second aspect;

[0059] Furthermore, the micro-isolation protection system further includes at least one of the following:

[0060] The second gateway is configured to receive the second request information sent by the first gateway; receive a notification from the access controller, and send the legitimate second request information to a pending resource server corresponding to the second request information;

[0061] The third gateway is configured to receive the legitimate second request information sent by the access controller, and forward the second request information to a to-be-processed resource server corresponding to the second request information.

[0062] In a fourth aspect, based on the same inventive concept, an embodiment of the present invention further provides an access controller, including:

[0063] a client grouping module, configured to receive a first request message sent by at least one client and forwarded by the first gateway, and divide the at least one client into at least one client group; wherein the clients sending the first request message within the same preset time period belong to the same client group;

[0064] A resource server grouping module is configured to group resource servers corresponding to each client in any client group into the same resource group; for any client, the resource server corresponding to the client is determined based on the first request information of the client;

[0065] a hardware group-level protection module, configured to send a hardware group correspondence between a client group and a resource group to the first gateway, so that when the first gateway receives a second request message from a target client to a resource server to be processed and forwards it to the resource server, if the first gateway determines, based on the hardware group correspondence, that the resource server to be processed belongs to a target resource group, the second request message is forwarded to the access controller; wherein the target resource group is the resource group corresponding to the client group to which the target client belongs;

[0066] The application-level protection module is used to receive the second request information and control the legal second request information to be sent to the to-be-processed resource server corresponding to the second request information.

[0067] In a fifth aspect, based on the same inventive concept, an embodiment of the present invention further provides a first gateway, including:

[0068] An access module, configured to receive a first request message sent by at least one client and forward it to an access controller; so that the access controller divides the at least one client into at least one client group, and for any client group, divides the resource servers corresponding to the respective clients in the client group into the same resource group; wherein the clients that send the first request message within the same preset time period belong to the same client group; and for any client, the resource server corresponding to the client is determined based on the first request message of the client;

[0069] A configuration module, configured to receive a hardware group correspondence between a client group and a resource group sent by the access controller;

[0070] The protection module is used to receive a second request information from a target client to a resource server to be processed, and if it is determined that the resource server to be processed belongs to a target resource group based on the hardware group correspondence, the protection module forwards the second request information to the access controller so that the second request information, which is legally controlled by the access controller, is sent to the resource server to be processed corresponding to the second request information; wherein the target resource group is a resource group corresponding to the client group to which the target client is located.

[0071] In a sixth aspect, based on the same inventive concept, an embodiment of the present invention further provides an electronic device, comprising: a processor and a memory for storing instructions executable by the processor;

[0072] The processor is configured to execute the instructions to implement the micro-isolation protection method as described in the first aspect, and / or to implement the micro-isolation protection method as described in the second aspect.

[0073] In the seventh aspect, based on the same inventive concept, an embodiment of the present invention also provides a computer-readable storage medium, which stores a computer program, and the computer program is used to implement the micro-isolation protection method as described in the first aspect, and / or implement the micro-isolation protection method as described in the second aspect.

[0074] The beneficial effects of the present invention are as follows:

[0075] The micro-isolation protection method and related hardware provided by the embodiment of the present invention, by grouping the clients according to the sending time of the first request information and determining the corresponding resource group for the client group, the first gateway then only releases the second access request of the target client to the corresponding target resource group to the access controller, so that the access controller can perform subsequent control operations, thereby reducing the number of request information control operations that the access controller needs to process, reducing the processing pressure of the access controller, and reducing the performance resource requirements for the access controller. In addition, by using the sending time of the first request information as the basis for grouping, there is almost no significant pattern in the members of the client group and resource group obtained in each grouping, and it is difficult for malicious clients controlled by criminals to bypass the hardware group-level protection of the client group-resource group, and invade and destroy the vast majority of other resource servers that do not belong to the resource group corresponding to the malicious client. Thus, the security protection of the network system is more effectively achieved. BRIEF DESCRIPTION OF THE DRAWINGS

[0076] Figure 1 This is a schematic diagram of the structure of the micro-isolation protection system provided by an embodiment of the present invention;

[0077] Figure 2 The second structural diagram of the micro-isolation protection system provided by an embodiment of the present invention;

[0078] Figure 3 The third structural diagram of the micro-isolation protection system provided by an embodiment of the present invention;

[0079] Figure 4 One of the workflow diagrams of the micro-isolation protection system provided by an embodiment of the present invention;

[0080] Figure 5 The second workflow diagram of the micro-isolation protection system provided by the embodiment of the present invention;

[0081] Figure 6 This is a data flow diagram of some steps of the micro-isolation protection system provided by an embodiment of the present invention;

[0082] Figure 7 The second diagram of the data flow of some steps of the micro-isolation protection system provided by an embodiment of the present invention;

[0083] Figure 8 A flowchart of a micro-isolation protection method applied to an access controller provided by an embodiment of the present invention;

[0084] Figure 9 A flowchart of a micro-isolation protection method applied to a first gateway provided in an embodiment of the present invention;

[0085] Figure 10 This is a schematic diagram of the connection correspondence between the client and the resource server within a certain period of time in an embodiment of the present invention;

[0086] Figure 11 A schematic diagram of the structure of an access controller provided by an embodiment of the present invention;

[0087] Figure 12 A schematic structural diagram of a first gateway provided in an embodiment of the present invention;

[0088] Figure 13 A schematic structural diagram of an electronic device provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0089] In order to make the above-mentioned objects, features and advantages of the present invention more obvious and easy to understand, the present invention will be further described below with reference to the accompanying drawings and examples. However, the example embodiments can be implemented in various forms and should not be understood as being limited to the embodiments described herein; on the contrary, these embodiments are provided to make the present invention more comprehensive and complete, and to fully convey the concepts of the example embodiments to those skilled in the art. The same figure marks in the figures represent the same or similar structures, and their repeated descriptions will be omitted. The words expressing position and direction described in the present invention are all explained with reference to the accompanying drawings as examples, but changes can be made as needed, and the changes made are all included in the scope of protection of the present invention. The drawings of the present invention are only used to illustrate the relative position relationship and do not represent the true proportion.

[0090] It should be noted that specific details are set forth in the following description to facilitate a full understanding of the present invention. However, the present invention can be implemented in a variety of ways different from those described herein, and those skilled in the art can make similar generalizations without violating the connotation of the present invention. Therefore, the present invention is not limited to the specific embodiments disclosed below. The subsequent description of the specification is a preferred embodiment of the present application, but the description is for the purpose of illustrating the general principles of the present application and is not intended to limit the scope of the present application. The scope of protection of the present application shall be determined as defined by the appended claims.

[0091] The following is a detailed description of the micro-isolation protection method and related hardware provided by the embodiments of the present invention in conjunction with the accompanying drawings.

[0092] In the first aspect, an embodiment of the present invention provides a micro-isolation protection system S. Figures 1 to 3 As shown, the micro-isolation protection system includes an access controller D and a first gateway G1. The micro-isolation protection system S is connected to the resource server R and is connected to the client C through the first gateway G1. In addition, the first gateway G1 is connected to the access controller D.

[0093] In a specific implementation, the access controller D and the first gateway G1 can be hardware devices, for example, two independent hardware servers; alternatively, the access controller D and the first gateway G1 can be virtual machines generated on the hardware devices using virtualization technology; this is not limited here. The accompanying drawings illustrate the example of the access controller D and the first gateway G1 being two independent hardware servers.

[0094] During the specific implementation process, the first gateway G1 can be implemented as a zero-trust security gateway. The zero-trust security gateway is used to be deployed at the network entrance or the front end of the application service to separate users and resources and enforce access control policies on all traffic. The zero-trust security gateway usually includes components such as a dynamic access control engine, an intelligent security brain, and identity management. It uses application proxy, single-page application (SPA) single-package authorization, enhanced identity management, artificial intelligence (AI) and other technologies. It has application access proxy, application resource hiding, multi-dimensional authentication of access subjects, dynamic access control, data security transmission, access log auditing, application programming interface (API) security protection and other functions. While improving application access security, it simplifies the access process and improves business efficiency.

[0095] Below is Figure 4 and Figure 5 The schematic process explains the role of the access controller D and the first gateway G1. Figure 4 and Figure 5 As shown, the micro-isolation protection system S specifically performs the following process:

[0096] S1010: A first gateway receives first request information sent by at least one client.

[0097] S1020: The first gateway forwards the first request information to the access controller.

[0098] S1030: The access controller receives the first request information forwarded by the first gateway, divides the at least one client into at least one client group, and then, for any client group, divides the resource servers corresponding to each client in the client group into the same resource group.

[0099] The clients that send the first request information within the same preset time period belong to the same client group. For any client, the resource server corresponding to the client is determined based on the first request information of the client.

[0100] In specific implementations, when determining the corresponding resource server for each client, the access controller may not only consider the resource server indicated by the first request information, but also further determine the resource server based on the pre-set access permission relationship between the client and the resource servers that the client is authorized to access. For example, if a client sends a first request information requesting access to both resource server 1 and resource server 2, but the pre-set access permission relationship between the client and the resource servers that the client is authorized to access determines that the client is only authorized to access resource server 2, then resource server 2 will be used as the corresponding resource server for the client.

[0101] During implementation, each preset time period can be set to a time period of equal length. For example, starting from midnight each day, each 1-minute period is a preset time period. Alternatively, each preset time period can be a time period in which at least some of the preset time periods are of unequal length. For example, during times when client traffic is high (e.g., daytime), the preset time period can be set to a shorter time period; while during times when client traffic is low (e.g., nighttime), the preset time period can be set to a longer time period. This ensures that the number of clients in the client groups obtained by grouping is more balanced.

[0102] S1040: The access controller sends the hardware group correspondence between the client group and the resource group to the first gateway.

[0103] S1060: The first gateway receives second request information from the target client to the resource server to be processed.

[0104] The target client is any client among the at least one client. For ease of explanation, the client group to which the target client belongs is referred to as the target client group, the resource group corresponding to the target client group is referred to as the target resource group, and the resource server corresponding to the target client is referred to as the target resource server. This will not be repeated below.

[0105] S1080: The first gateway determines whether the resource server to be processed belongs to a target resource group according to the hardware group correspondence.

[0106] The target resource group is a resource group (ie, target resource group) corresponding to the client group (ie, target client group) where the target client is located.

[0107] If the result of step S1080 is yes, the first gateway executes step S1091.

[0108] S1091. The first gateway forwards the second request information to the access controller.

[0109] S1110 : The access controller controls the legitimate second request information to be sent to the to-be-processed resource server (ie, the target resource server) corresponding to the second request information.

[0110] Afterwards, the target resource server receives the corresponding second request information, performs corresponding business processing according to the second request information, responds, etc. The subsequent process is not the focus of the embodiment of the present invention, so it will not be described in detail.

[0111] In this way, by grouping the clients according to the sending time of the first request information and determining the corresponding resource group for the client group, the first gateway then performs preliminary control on the second request information sent by the target client. For any target client, only the second access request of the target client to the corresponding target resource group is released to the access controller, so that the access controller can perform subsequent control operations. The micro-isolation protection system ensures high credibility of the client group and the identity of the clients within the group by adding hardware group-level control rules for the client group-resource group correspondence and having the first gateway perform preliminary control on the second request information. This enables the access controller to no longer need to perform corresponding control operations on the second request information that does not conform to the client group-resource group correspondence, thereby reducing the number of request information control operations that the access controller needs to process, reducing the processing pressure on the access controller, and reducing the performance resource requirements for the access controller. Furthermore, because the timing of client access to resource servers in large-scale network systems, especially those targeting users with diverse usage habits, is not highly regular, using the time of first request information transmission as the grouping basis makes it virtually impossible for the client groups and resource group memberships generated during each grouping to exhibit significant regularity. This makes it difficult for malicious clients controlled by lawless actors to bypass the hardware group-level protections associated with client groups and resource groups, and to invade and damage the vast majority of resource servers not belonging to the malicious client's corresponding resource group. This effectively prevents clients from unauthorized access to other resource groups, further enhancing network system security.

[0112] Optionally, for any target client, the first request information and / or the second request information of the target client includes at least one of the following:

[0113] ① The time when the first request information is sent.

[0114] It is understood that the first request message, by carrying the sending time of the first request message, facilitates the access controller to group clients by time. The second request message, by carrying the sending time of the first request message, not only facilitates the access controller to directly determine the target resource group corresponding to the target client corresponding to the second request message based on this time, but also allows the access controller to verify this time with the sending time carried in the first request message previously received from the target client, thereby preventing fraud by forged second request messages.

[0115] ② The identity identification information of the target client.

[0116] In a specific implementation process, the identity identification information of the target client may be an identity identification number (ID) of the target client, a device name, a user account logged in by the target client, and the like.

[0117] ③The address information of the target client.

[0118] ④The port number of the target client.

[0119] ⑤ The access application identification information of the target client.

[0120] During specific implementation, the access application identification information may include the application name, version number, etc. of the access application.

[0121] ⑥ The identity identification information of the corresponding resource server to be processed.

[0122] During specific implementation, the identity identification information of the resource server to be processed may include an ID, a device name, and the like.

[0123] ⑦ Address information of the corresponding resource server to be processed.

[0124] ⑧The port number of the corresponding resource server to be processed.

[0125] In a specific implementation process, the address information (including the address information of the target client and the address information of the resource server to be processed) can be a Media Access Control (MAC) address, an Internet Protocol (IP) address, or the like.

[0126] For example, the first request information and the second request information of the target client may adopt the following format:

[0127] Table 1 Request information structure

[0128]

[0129] Furthermore, the micro-isolation protection system S also includes a second gateway G2 (such as Figure 2 As shown) and the third gateway G3 (as Figure 3 The second gateway G2 and the third gateway G3 are described below respectively.

[0130] As an optional implementation, if the micro-isolation protection system further includes a second gateway G2, then Figure 6 As shown, if the result of step S1080 is yes, the first gateway further executes step S1092.

[0131] S1092: The first gateway forwards the second request information to the second gateway.

[0132] The step S1110 specifically includes the following process:

[0133] S1111. The access controller notifies the second gateway to send the legal second request information to the to-be-processed resource server corresponding to the second request information.

[0134] S1112. The second gateway forwards the second request information to the to-be-processed resource server corresponding to the second request information.

[0135] As another optional implementation, if the micro-isolation protection system further includes a third gateway G3, then Figure 7 As shown, step S1110 specifically includes the following process:

[0136] S1113. The access controller sends the legal second request information to the third gateway.

[0137] S1114. The third gateway forwards the second request information to the to-be-processed resource server corresponding to the second request information.

[0138] In specific implementations, the second gateway G2 or the third gateway G3 can be a single gateway or a gateway cluster consisting of multiple gateways, without limitation. For any second gateway G2 or third gateway G3, the second gateway G2 / third gateway G3 can be a hardware device, such as an independent hardware server; or, the second gateway G2 / third gateway G3 can be a virtual machine generated on the hardware device using virtualization technology, without limitation. The accompanying drawings illustrate the second gateway G2 / third gateway G3 as an independent hardware device.

[0139] During specific implementation, in order to further reduce the exposure of information of the resource server to the client, the client may be informed in advance of incorrect address information, port number, etc. of the corresponding resource server. When the second gateway / third gateway forwards the second request information to the resource server to be processed corresponding to the second request information, the second gateway / third gateway may redirect the second request information to the correct address and port based on the identity identification information of the resource server to be processed indicated in the second request information, so as to direct the second request information to the resource server to be processed.

[0140] Next, the functions of the access controller D and the first gateway G1 in the micro-isolation protection system S will be described using a processing flow.

[0141] If the result of step S1080 is no, as an optional implementation, the first gateway executes step S1093 (not shown in the drawings).

[0142] S1093: The first gateway discards the second request information.

[0143] If the result of step S1080 is no, as another optional implementation, the first gateway executes step S1094 (not shown in the drawings).

[0144] S1094: The first gateway returns a response error prompt message to the target client.

[0145] It is understandable that the above two optional implementations can also be implemented in combination, which will not be described in detail here.

[0146] In this way, the first gateway can effectively reduce the subsequent processing pressure of the access controller by directly discarding the second request information that does not comply with the hardware group-level control rules of the client group-resource group correspondence; and the first gateway can facilitate the client to troubleshoot the problem by returning a response error prompt message to the client for the second request information that does not comply with the hardware group-level control rules of the client group-resource group correspondence.

[0147] Optionally, the step S1020, in which the first gateway forwards the first request information to the access controller, includes:

[0148] The first gateway forwards the first request information sent by using the first preset communication method to the access controller.

[0149] Alternatively, as Figure 5 As shown, in step S1080, before the first gateway determines whether the resource server to be processed belongs to the target resource group according to the hardware group correspondence, the method further includes:

[0150] S1070: The first gateway determines whether the second request information is sent using the second preset communication method.

[0151] If the result of step S1070 is yes, the first gateway executes step S1080; if the result of step S1070 is no, the first gateway may directly discard the second request information, or further return a response error prompt information to the target client.

[0152] During the specific implementation process, the first preset communication mode and the second preset communication mode can be the same communication mode or different communication modes. The preset communication mode (the first preset communication mode or the second preset communication mode) can be set as needed. For example, if the first gateway is a zero-trust security gateway, then the preset communication mode can be set as a mode in which the client sends information to the designated port of the first gateway. If the client sends the first request information to the non-designated port of the first gateway, the first gateway rejects or discards the first request information, or further returns a response error prompt message to the client. For another example, the preset communication mode is a mode in which the client sends information using a preset encryption rule. If the client sends the first request information in plain text or encrypted using a non-preset encryption rule, the first gateway discards the first request information, or further returns a response error prompt message to the client. For another example, the preset communication mode is a mode in which the client sends information using a private protocol. If the client does not send the first request information through the private protocol, the first gateway discards the first request information, or further returns a response error prompt message to the client. The preset communication mode can also be other modes, which are not limited here.

[0153] If the client requesting access to the resource server is a malicious "zombie" client, the malicious application running on it will be unable to correctly send the request information to the first gateway, thereby invoking the access controller. The request information will be discarded, ensuring network security at the application layer. In this way, the first gateway can perform preliminary screening of the first request information based on its transmission method, further reducing the pressure on the access controller to perform access control.

[0154] Alternatively, as Figure 5 As shown, in step S1110, before the access controller controls the legitimate second request information to be sent to the to-be-processed resource server corresponding to the second request information, the process further includes:

[0155] S1050: For any resource server to be processed, the access controller notifies the resource server to be processed to allow the corresponding target client to access the server.

[0156] During the specific implementation process, the resource server to be processed can confirm the corresponding client based on the identity information of the client carried in the received second request information (such as the client ID, IP address, etc.), and decide to release and respond to the second request information of the target client that is allowed to access; or discard the second request information of the client that is not allowed to access, and can further return a response error prompt information to the target client through forwarding by a device such as the first gateway.

[0157] Optionally, the access controller may specifically send a first firewall rule to the resource server to be processed, where the first firewall rule is used to control the resource server to be processed to allow the corresponding target client to access the resource.

[0158] For example, for a resource server to be processed that uses the Linux operating system, the access controller can issue the first rule of a firewall such as Iptables, Ipfwadm, or Ipchains to the resource server to allow the corresponding target client to access the resource server to be processed and prevent non-corresponding clients from accessing the resource server to be processed.

[0159] In this way, micro-isolation protection at the network layer can be achieved, further ensuring the security of the network system.

[0160] Further optionally, as Figure 5 As shown, it also includes:

[0161] S1200: For any resource server to be processed, when the access controller determines that the resource server to be processed has ended communication with the target client, it notifies the resource server to be processed that the target client is not allowed to access.

[0162] Optionally, the access controller may issue a second firewall rule to the resource server to be processed, wherein the second firewall rule is used to control the resource server to be processed from accessing the target client. In a specific implementation, if the resource server's firewall controls client access using a whitelist, the second firewall rule may instruct the resource server to remove the target client from the whitelist.

[0163] This approach ensures zero trust in the client by promptly clearing the network-layer release protection rules on the pending resource server after the target client terminates communication, further ensuring network system security and reducing the pressure on the resource server's protection control processing. Furthermore, by promptly clearing the network-layer release protection rules on the pending resource server, the overflow of the pending resource server's firewall release protection rules can be avoided.

[0164] Furthermore, the access controller determines whether the received second request information is legal information by:

[0165] like Figure 5 As shown, before S1110, the access controller controls the legitimate second request information to be sent to the to-be-processed resource server corresponding to the second request information, the method further includes:

[0166] S1100: The access controller determines whether the second request information complies with the preset access rule.

[0167] If the result of step S1100 is yes, the access controller determines that the second request information is legal, and executes step S1110. If the result of step S1100 is no, the access controller determines that the second request information is illegal.

[0168] The preset access rule may be a hardware correspondence between a client and a resource server that the client is allowed to access, or a correspondence between a client application corresponding to the second request information and a port of a resource server that the application is allowed to access. The preset access rule may also be set to other granularity rules as needed.

[0169] For example, when implemented in combination with the S1050 process described above, the access controller can perform micro-isolation protection from the network layer by configuring a list of clients allowed to access the resource server (for example, in the form of the first firewall rule); at the same time, the access controller pre-configures the correspondence between the client application and the port of the resource server allowed to access the application as a preset access rule, and the access controller performs micro-isolation protection on the second request information from the application layer, thereby realizing multi-dimensional fine-grained micro-isolation protection at the hardware group level, network layer level, and application layer level.

[0170] As an optional implementation, if the micro-isolation protection system S includes a second gateway G2 and the result of step S1100 is negative, the access controller may notify the second gateway G2 to discard the illegal second request information. Furthermore, the access controller may notify the second gateway G2 to return a response error prompt to the target client via forwarding by the first gateway G1, or notify the first gateway G1 to return a response error prompt to the target client.

[0171] As another optional implementation, if the micro-isolation protection system S includes a third gateway G3 and the result of step S1100 is negative, the access controller may discard the illegal second request information. Furthermore, the access controller may generate a response error prompt message and return the response error prompt message to the target client via forwarding by the first gateway G1, or the access controller may notify the first gateway G1 to generate a response error prompt message and return it to the target client.

[0172] The following combination Figure 10 , the workflow of the above-mentioned micro-isolation protection system is explained with a specific example.

[0173] (1) During a preset time period, five clients, A, B, C, D, and E, send first request information to a first gateway. A, B, C, and D send the first request information to the first gateway through the first gateway's preset designated port, and E sends the first request information to the first gateway through the first gateway's non-designated port. A's first request information indicates that it is ready to access resource servers A and B, B's first request information indicates that it is ready to access resource server C, C's first request information indicates that it is ready to access resource server D, and D's first request information indicates that it is ready to access resource servers E and F.

[0174] (2) The first gateway forwards the first request information of clients A, B, C, and D to the access controller, and discards the first request information of client E.

[0175] (3) The access controller divides clients A, B, C, and D into client group X based on the first request information of clients A, B, C, and D. Based on the preset access permission relationships between the clients and the resource servers that the clients have permission to access, the access controller determines that client A has permission to access resource servers A and B. Client B has permission to access resource server C, and client C has permission to access resource server D. Client D has permission to access resource server E. Resource servers A, B, C, D, and E are divided into resource group Y, and a hardware group correspondence relationship is established between client group X and resource group Y.

[0176] (4) The access controller sends the hardware group correspondence between the client group X and the resource group Y to the first gateway.

[0177] (5) The access controller sends the first firewall rule that allows client A to access to resource server A, sends the first firewall rule that allows client A to access to resource server B, sends the first firewall rule that allows client B to access to resource server C, sends the first firewall rule that allows client C to access to resource server D, and sends the first firewall rule that allows client D to access to resource server E.

[0178] (6) The first gateway receives second request messages sent by A, B, C, and D through the preset designated port of the first gateway. The three second request messages from A indicate that the resource servers to be processed are A, B, and C, respectively. The second request message from B indicates that the resource server to be processed is C. The second request message from C indicates that the resource server to be processed is D. The second request message from D indicates that the resource server to be processed is F.

[0179] (7) The first gateway determines, based on the hardware group correspondence, that the resource servers A, B, C, and D to be processed indicated by the second request information of clients A, B, and C belong to resource group Y, and forwards the second request information of A, B, and C to the access controller; the resource server F to be processed indicated by the second request information of client D does not belong to resource group Y, and the second request information of client D is discarded.

[0180] (8) The access controller determines, based on the correspondence between the client application corresponding to the second request information and the port of the resource server that the application is allowed to access, that the second request information of client A's application I to the resource server A is legal, that the second request information of client A's application II to the resource server B is legal, and that the second request information of client A's application III to the resource server C is legal. The access controller determines that the second request information of client B's application IV to the resource server C is legal, and sends these second request information to the third gateway; determines that the second request information of client C's application V to the resource server D is illegal, and discards the second request information of client C to the resource server D.

[0181] (9) The third gateway sends the second request information of client A to the resource servers A, B, and C, and the second request information of client B to the resource server C to the corresponding resource servers respectively.

[0182] (10) Resource servers A and B receive the second request information from client A and respond to it. Resource server C receives the second request information from client B and responds to it, but discards the second request information from client A.

[0183] (11) When the access controller determines that resource server A has terminated communication with client A, it sends the second firewall rule that does not allow client A to access to resource server A; when it determines that resource server B has terminated communication with client A, it sends the second firewall rule that does not allow client A to access to resource server B; when it determines that resource server C has terminated communication with client B, it sends the second firewall rule that does not allow client B to access to resource server C; when it determines that resource server D has terminated communication with client C, it sends the second firewall rule that does not allow client C to access to resource server D; when it determines that resource server E has terminated communication with client D, it sends the second firewall rule that does not allow client D to access to resource server E.

[0184] In the second aspect, based on the above invention concept, the embodiment of the present invention also provides a micro-isolation protection method applied to the access controller, such as Figure 8 As shown, including:

[0185] S210: Receive first request information sent by at least one client and forwarded by a first gateway.

[0186] S220: Divide the at least one client into at least one client group. For any client group, group the resource servers corresponding to each client in the client group into the same resource group. Clients that send the first request information within the same preset time period belong to the same client group. For any client, the resource server corresponding to the client is determined based on the first request information of the client.

[0187] S230: Send the hardware group correspondence between the client group and the resource group to the first gateway. This allows the first gateway to forward the second request information from the target client to the resource server to be processed to the resource server. If the first gateway determines, based on the hardware group correspondence, that the resource server to be processed belongs to the target resource group, the second request information will be forwarded to the access controller. The target resource group is the resource group corresponding to the client group to which the target client belongs.

[0188] S250: Receive the second request information, and control the legal second request information to be sent to the to-be-processed resource server corresponding to the second request information.

[0189] As an optional implementation manner, the step S250 of controlling the legitimate second request information to be sent to the to-be-processed resource server corresponding to the second request information includes:

[0190] The second gateway is notified to send the legal second request information to the to-be-processed resource server corresponding to the second request information, wherein the second gateway receives the second request information from the first gateway.

[0191] As another optional implementation, the step S250 of controlling the legitimate second request information to be sent to the to-be-processed resource server corresponding to the second request information includes:

[0192] The legal second request information is sent to the third gateway, so that the third gateway forwards the second request information to the to-be-processed resource server corresponding to the second request information.

[0193] Optionally, before step S250, controlling the sending of the legal second request information to the to-be-processed resource server corresponding to the second request information, the method further includes:

[0194] S240: Notify any pending resource server to allow the corresponding target client to access the server.

[0195] Optionally, the method further includes:

[0196] S260: For any resource server to be processed, when it is determined that the resource server to be processed has ended communication with the target client, notify the resource server to be processed that the target client is not allowed to access.

[0197] Furthermore, in step S240, notifying the to-be-processed resource server to allow the corresponding target client to access the resource includes:

[0198] A first firewall rule is issued to the resource server to be processed, where the first firewall rule is used to control the resource server to be processed to allow a corresponding target client to access the resource.

[0199] Furthermore, in step S260, notifying the server of the resource to be processed that any client is not allowed to access the resource includes:

[0200] A second firewall rule is issued to the resource server to be processed, where the second firewall rule is used to control the resource server to be processed to not allow the target client to access the resource.

[0201] Optionally, in step S250, before controlling the sending of the legal second request information to the to-be-processed resource server corresponding to the second request information, the method further includes:

[0202] When determining that the second request information is information that complies with the preset access rule, determining that the second request information is legal second request information;

[0203] The preset access rules include at least one of the following:

[0204] The hardware correspondence between the client and the resource server that the client is allowed to access;

[0205] The corresponding relationship between the client application corresponding to the second request information and the port of the resource server allowed to be accessed by the application.

[0206] Optionally, for any target client, the first request information and / or the second request information of the target client includes at least one of the following:

[0207] The sending time of the first request information;

[0208] The identification information of the target client;

[0209] Address information of the target client;

[0210] The port number of the target client;

[0211] Access application identification information of the target client;

[0212] The identity identification information of the corresponding resource server to be processed;

[0213] The address information of the corresponding resource server to be processed;

[0214] The port number of the corresponding resource server to be processed.

[0215] In the third aspect, based on the same inventive concept, an embodiment of the present invention further provides a micro-isolation protection method, which is applied to the first gateway, such as Figure 9 Shown, including:

[0216] S310: Receive first request information sent by at least one client.

[0217] S320: Forward the first request information to an access controller. The access controller then divides the at least one client into at least one client group, and for any client group, assigns the resource servers corresponding to the clients in the client group to the same resource group. Clients that send the first request information within the same preset time period belong to the same client group. For any client, the resource server corresponding to the client is determined based on the first request information of the client.

[0218] S330: Receive the hardware group correspondence between the client group and the resource group sent by the access controller.

[0219] S340: Receive second request information from the target client to the resource server to be processed.

[0220] S360: Determine whether the resource server to be processed belongs to a target resource group according to the hardware group correspondence.

[0221] If the result of step S360 is yes, step S370 is executed.

[0222] S370: Forward the second request information to the access controller, so that the access controller controls the second request information to be legally sent to the resource server to be processed corresponding to the second request information; wherein the target resource group is the resource group corresponding to the client group where the target client is located.

[0223] Optionally, if the result of step S360 is no, execute step S380.

[0224] S380: discard the second request information, and / or return a response error prompt information to the target client.

[0225] Optionally, after the step S370 of forwarding the second request information to the access controller, the method further includes:

[0226] The second request information is forwarded to the second gateway, so that the second gateway sends the legal second request information to the to-be-processed resource server corresponding to the second request information under the control of the access controller.

[0227] Optionally, the step S320 of forwarding the first request information to the access controller includes:

[0228] The first request information sent by using the first preset communication method is forwarded to the access controller.

[0229] Optionally, before step S360, determining whether the resource server to be processed belongs to a target resource group according to the hardware group correspondence, the method further includes:

[0230] S350: Determine whether the second request information is sent using a second preset communication method.

[0231] If the result of step S350 is yes, step S360 is executed.

[0232] Optionally, if the result of step S350 is no, step S380 is executed.

[0233] Optionally, for any target client, the first request information and / or the second request information of the target client includes at least one of the following:

[0234] The sending time of the first request information;

[0235] The identification information of the target client;

[0236] Address information of the target client;

[0237] The port number of the target client;

[0238] Access application identification information of the target client;

[0239] The identity identification information of the corresponding resource server to be processed;

[0240] The address information of the corresponding resource server to be processed;

[0241] The port number of the corresponding resource server to be processed.

[0242] Since the micro-isolation protection methods described in the second and third aspects are basically consistent with the working principles of the access controller and the first gateway in the micro-isolation protection system described in the first aspect, the micro-isolation protection methods described in the second and third aspects can be implemented with reference to the corresponding content in the first aspect and will not be repeated here.

[0243] In a fourth aspect, based on the same inventive concept, an embodiment of the present invention further provides an access controller, such as Figure 11 As shown, including:

[0244] The client grouping module M101 is configured to receive a first request message sent by at least one client and forwarded by a first gateway, and to divide the at least one client into at least one client group; wherein the clients that send the first request message within the same preset time period belong to the same client group;

[0245] The resource server grouping module M102 is configured to group the resource servers corresponding to the respective clients in any client group into the same resource group; for any client, the resource server corresponding to the client is determined based on the first request information of the client;

[0246] The hardware group-level protection module M103 is configured to send the hardware group correspondence between the client group and the resource group to the first gateway, so that when the first gateway receives the second request information from the target client for the resource server to be processed and forwards it to the resource server, if it is determined based on the hardware group correspondence that the resource server to be processed belongs to the target resource group, the second request information is forwarded to the access controller; wherein the target resource group is the resource group corresponding to the client group to which the target client belongs;

[0247] The application-level protection module M105 is configured to receive the second request information and control the legal second request information to be sent to a to-be-processed resource server corresponding to the second request information.

[0248] As an optional implementation manner, the controlling the legitimate second request information to be sent to the to-be-processed resource server corresponding to the second request information includes:

[0249] The second gateway is notified to send the legal second request information to the to-be-processed resource server corresponding to the second request information, wherein the second gateway receives the second request information from the first gateway.

[0250] As another optional implementation manner, the controlling the legitimate second request information to be sent to the to-be-processed resource server corresponding to the second request information includes:

[0251] The legal second request information is sent to the third gateway, so that the third gateway forwards the second request information to the to-be-processed resource server corresponding to the second request information.

[0252] Optionally, the access controller further includes:

[0253] The network-level protection module M104 is used to notify any resource server to be processed to allow the corresponding target client to access it.

[0254] Optionally, the network-level protection module M104 is further configured to:

[0255] For any resource server to be processed, when it is determined that the resource server to be processed has ended communication with the target client, the resource server to be processed is notified to not allow the target client to access.

[0256] Optionally, the notifying the to-be-processed resource server to allow the corresponding target client to access the resource includes:

[0257] A first firewall rule is issued to the resource server to be processed, where the first firewall rule is used to control the resource server to be processed to allow a corresponding target client to access the resource.

[0258] Optionally, notifying the to-be-processed resource server that any client is not allowed to access the resource includes:

[0259] A second firewall rule is issued to the resource server to be processed, where the second firewall rule is used to control the resource server to be processed to not allow the target client to access the resource.

[0260] Optionally, before controlling the legitimate second request information to be sent to the to-be-processed resource server corresponding to the second request information, the application-level protection module M105 is further configured to:

[0261] When determining that the second request information is information that complies with the preset access rule, determining that the second request information is legal second request information;

[0262] The preset access rules include at least one of the following:

[0263] The hardware correspondence between the client and the resource server that the client is allowed to access;

[0264] The corresponding relationship between the client application corresponding to the second request information and the port of the resource server allowed to be accessed by the application.

[0265] Optionally, for any target client, the first request information and / or the second request information of the target client includes at least one of the following:

[0266] The sending time of the first request information;

[0267] The identification information of the target client;

[0268] Address information of the target client;

[0269] The port number of the target client;

[0270] Access application identification information of the target client;

[0271] The identity identification information of the corresponding resource server to be processed;

[0272] The address information of the corresponding resource server to be processed;

[0273] The port number of the corresponding resource server to be processed.

[0274] In a fifth aspect, based on the same inventive concept, an embodiment of the present invention further provides a first gateway, such as Figure 12 As shown, including:

[0275] Access module M201 is configured to receive a first request message sent by at least one client and forward it to an access controller. This allows the access controller to divide the at least one client into at least one client group and, for any client group, assign resource servers corresponding to each client in the client group to the same resource group. Clients that send the first request message within the same preset time period belong to the same client group. For any client, the resource server corresponding to the client is determined based on the client's first request message.

[0276] Configuration module M202, configured to receive a hardware group correspondence between a client group and a resource group sent by the access controller;

[0277] The protection module M203 is configured to receive a second request message from a target client to a pending resource server, and if the pending resource server is determined to belong to a target resource group based on the hardware group correspondence, forward the second request message to the access controller, so that the access controller controls the second request message to be legally sent to the pending resource server corresponding to the second request message. The target resource group is the resource group corresponding to the client group to which the target client belongs.

[0278] Optionally, the protection module M203 is further configured to:

[0279] If it is determined according to the hardware group correspondence that the resource server to be processed does not belong to the target resource group, the second request information is discarded, and / or a response error prompt information is returned to the target client.

[0280] Optionally, the first gateway further includes:

[0281] The diversion module M204 is configured to forward the second request information to the second gateway, so that the second gateway sends the legal second request information to the to-be-processed resource server corresponding to the second request information under the control of the access controller.

[0282] Optionally, the access module M201 is specifically configured to:

[0283] receiving a first request message sent by at least one client, and forwarding the first request message sent by using a first preset communication method to the access controller;

[0284] Before determining, according to the hardware group correspondence, that the resource server to be processed belongs to the target resource group, the protection module M203 is further configured to:

[0285] It is determined that the second request information is sent using a second preset communication method.

[0286] Optionally, for any target client, the first request information and / or the second request information of the target client includes at least one of the following:

[0287] The sending time of the first request information;

[0288] The identification information of the target client;

[0289] Address information of the target client;

[0290] The port number of the target client;

[0291] Access application identification information of the target client;

[0292] The identity identification information of the corresponding resource server to be processed;

[0293] The address information of the corresponding resource server to be processed;

[0294] The port number of the corresponding resource server to be processed.

[0295] In the several embodiments provided herein, it should be understood that the device embodiments described above are merely illustrative. For example, the module division is merely a logical functional division, and actual implementations may employ alternative divisions, such as combining or integrating multiple modules or components into another system, or omitting or disabling certain features. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be an indirect coupling or communication connection through some interface, device, or module, and may be electrical, mechanical, or other means.

[0296] The modules described as separate components may or may not be physically separate, and the components shown as modules may or may not be physical modules, that is, they may be located in one place or distributed across multiple network modules. Some or all of the modules may be selected to achieve the purpose of the present embodiment according to actual needs.

[0297] In addition, the functional modules in the various embodiments of the present application may be integrated into a single processing module, or each module may exist physically separately, or two or more modules may be integrated into a single module. The aforementioned integrated modules may be implemented in the form of hardware or in the form of software functional modules. If the integrated modules are implemented in the form of software functional modules and sold or used as independent products, they may be stored in a removable storage medium.

[0298] Since the specific manners in which the access controller described in the fourth aspect and the various modules of the first gateway described in the fifth aspect perform operations have been described in detail in the corresponding contents of the first to third aspects, they will not be repeated here.

[0299] In a sixth aspect, based on the same inventive concept, an embodiment of the present invention further provides an electronic device, such as Figure 13 As shown, it includes: a processor 110 and a memory 120 for storing executable instructions of the processor 110;

[0300] The processor 110 is configured to execute the instructions to implement the micro-isolation protection method described in the first aspect and / or the second aspect.

[0301] In a specific implementation, the device may have relatively large differences due to different configurations or performances, and may include one or more processors 110, a memory 120, and a computer-readable storage medium 130. The memory 120 and / or the computer-readable storage medium 130 may include one or more applications 131 or data 132. The memory 120 and / or the computer-readable storage medium 130 may also include one or more operating systems 133, such as Windows, Mac OS, Linux, IOS, Android, Unix, FreeBSD, etc. The memory 120 and the computer-readable storage medium 130 may be temporary storage or persistent storage. The application 131 may include one or more modules ( Figure 13 (not shown), each module may include a series of instruction operations. Furthermore, the processor 110 may be configured to communicate with the computer-readable storage medium 130 and execute a series of instruction operations in the computer-readable storage medium 130 on the device. The device may also include one or more power supplies ( Figure 13 one or more network interfaces 140, the network interface 140 including a wired network interface 141 and / or a wireless network interface 142; one or more input / output / interfaces 143.

[0302] In the seventh aspect, based on the same inventive concept, an embodiment of the present invention also provides a computer-readable storage medium, which stores a computer program, and the computer program is used to implement the micro-isolation protection method described in the first aspect and / or the second aspect.

[0303] The embodiment of the present invention provides a micro-isolation protection method and related hardware, which groups the clients according to the sending time of the first request information and determines the corresponding resource group for the client group. Then, the first gateway only releases the second access request of the target client to the corresponding target resource group to the access controller, so that the access controller can perform subsequent control operations, thereby reducing the number of request information control operations that the access controller needs to process, reducing the processing pressure of the access controller, and reducing the performance resource requirements for the access controller. In addition, by using the sending time of the first request information as the basis for grouping, there is almost no significant pattern in the members of the client group and resource group obtained in each grouping. It is difficult for malicious clients controlled by criminals to bypass the hardware group level protection of the client group-resource group and invade and destroy the vast majority of other resource servers that do not belong to the resource group corresponding to the malicious client. Therefore, the security protection of the network system is more effectively achieved.

[0304] Those skilled in the art will appreciate that the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.

[0305] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the present application. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0306] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.

[0307] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.

[0308] Obviously, those skilled in the art may make various changes and modifications to this application without departing from the spirit and scope of this application. Thus, if these modifications and variations of this application fall within the scope of the claims of this application and their equivalents, this application is intended to include these modifications and variations.

Claims

1. A micro-isolation protection method, characterized in that: Applies to access controllers, including: receiving a first request message sent by at least one client and forwarded by a first gateway, and dividing the at least one client into at least one client group; wherein the clients sending the first request message within the same preset time period belong to the same client group; For any client group, the resource servers corresponding to the respective clients in the client group are divided into the same resource group; for any client, the resource server corresponding to the client is determined according to the first request information of the client; Sending the hardware group correspondence between the client group and the resource group to the first gateway; so that when the first gateway receives a second request message from the target client to the resource server to be processed and forwards it to the resource server, if it is determined based on the hardware group correspondence that the resource server to be processed belongs to the target resource group, the second request message is forwarded to the access controller; wherein the target resource group is the resource group corresponding to the client group to which the target client belongs; The second request information is received, and the legal second request information is controlled to be sent to a to-be-processed resource server corresponding to the second request information.

2. The method according to claim 1, wherein The controlling the legitimate second request information to be sent to the to-be-processed resource server corresponding to the second request information includes: Notifying the second gateway to send the legitimate second request information to the to-be-processed resource server corresponding to the second request information; wherein the second gateway receives the second request information from the first gateway; Alternatively, the legal second request information is sent to a third gateway, so that the third gateway forwards the second request information to a to-be-processed resource server corresponding to the second request information.

3. The method according to claim 1, wherein Before controlling the legitimate second request information to be sent to the to-be-processed resource server corresponding to the second request information, the method further includes: For any pending resource server, the pending resource server is notified to allow the corresponding target client to access the server.

4. The method according to claim 3, wherein The method further comprises: For any resource server to be processed, when it is determined that the resource server to be processed has ended communication with the target client, the resource server to be processed is notified to not allow the target client to access.

5. The method according to claim 3, wherein The notifying the to-be-processed resource server to allow the corresponding target client to access the resource includes: A first firewall rule is issued to the resource server to be processed, where the first firewall rule is used to control the resource server to be processed to allow a corresponding target client to access the resource.

6. The method according to claim 4, wherein The notifying the server of the resource to be processed that no client is allowed to access the resource includes: A second firewall rule is issued to the resource server to be processed, where the second firewall rule is used to control the resource server to be processed to not allow the target client to access the resource.

7. The method according to claim 1, wherein Before controlling the legitimate second request information to be sent to the to-be-processed resource server corresponding to the second request information, the method further includes: When determining that the second request information is information that complies with the preset access rule, determining that the second request information is legal second request information; The preset access rules include at least one of the following: The hardware correspondence between the client and the resource server that the client is allowed to access; The corresponding relationship between the client application corresponding to the second request information and the port of the resource server allowed to be accessed by the application.

8. The method according to claim 1, wherein For any target client, the first request information and / or the second request information of the target client includes at least one of the following: The sending time of the first request information; The identification information of the target client; Address information of the target client; The port number of the target client; Access application identification information of the target client; The identity identification information of the corresponding resource server to be processed; The address information of the corresponding resource server to be processed; The port number of the corresponding resource server to be processed.

9. A micro-isolation protection method, characterized in that: Applied to the first gateway, including: Receive a first request message sent by at least one client and forward it to an access controller; so that the access controller divides the at least one client into at least one client group, and for any client group, divides the resource servers corresponding to the clients in the client group into the same resource group; wherein the clients that send the first request message within the same preset time period belong to the same client group; and for any client, the resource server corresponding to the client is determined based on the first request message of the client; receiving a hardware group correspondence between a client group and a resource group sent by the access controller; Receive a second request message from the target client to the resource server to be processed. If it is determined that the resource server to be processed belongs to the target resource group based on the hardware group correspondence, forward the second request message to the access controller; so that the second request message, which is legally controlled by the access controller, is sent to the resource server to be processed corresponding to the second request message; wherein the target resource group is the resource group corresponding to the client group to which the target client is located.

10. The method according to claim 9, wherein The method further comprises: If it is determined according to the hardware group correspondence that the resource server to be processed does not belong to the target resource group, the second request information is discarded, and / or a response error prompt information is returned to the target client.

11. The method according to claim 9, wherein After forwarding the second request information to the access controller, the method further includes: Forwarding the second request information to the second gateway; so that the second gateway sends the legal second request information to the to-be-processed resource server corresponding to the second request information under the control of the access controller.

12. The method according to claim 9, wherein The receiving first request information sent by at least one client and forwarding it to the access controller includes: receiving a first request message sent by at least one client, and forwarding the first request message sent by using a first preset communication method to the access controller; Before determining that the resource server to be processed belongs to the target resource group according to the hardware group correspondence, the method further includes: It is determined that the second request information is sent using a second preset communication method.

13. The method according to claim 9, wherein For any target client, the first request information and / or the second request information of the target client includes at least one of the following: The sending time of the first request information; The identification information of the target client; Address information of the target client; The port number of the target client; Access application identification information of the target client; The identity identification information of the corresponding resource server to be processed; The address information of the corresponding resource server to be processed; The port number of the corresponding resource server to be processed.

14. A micro-isolation protection system, characterized in that: include: An access controller used to implement the micro-isolation protection method according to any one of claims 1 to 8; A first gateway used to implement the micro-isolation protection method according to any one of claims 9 to 13; Furthermore, the micro-isolation protection system further includes at least one of the following: The second gateway is configured to receive the second request information sent by the first gateway; receive a notification from the access controller, and send the legitimate second request information to a pending resource server corresponding to the second request information; The third gateway is configured to receive the legitimate second request information sent by the access controller, and forward the second request information to a to-be-processed resource server corresponding to the second request information.

15. An access controller, characterized in that: include: a client grouping module, configured to receive a first request message sent by at least one client and forwarded by the first gateway, and divide the at least one client into at least one client group; wherein the clients sending the first request message within the same preset time period belong to the same client group; A resource server grouping module is configured to group resource servers corresponding to each client in any client group into the same resource group; for any client, the resource server corresponding to the client is determined based on the first request information of the client; a hardware group-level protection module, configured to send a hardware group correspondence between a client group and a resource group to the first gateway, so that when the first gateway receives a second request message from a target client to a resource server to be processed and forwards it to the resource server, if the first gateway determines, based on the hardware group correspondence, that the resource server to be processed belongs to a target resource group, the second request message is forwarded to the access controller; wherein the target resource group is the resource group corresponding to the client group to which the target client belongs; The application-level protection module is used to receive the second request information and control the legal second request information to be sent to the to-be-processed resource server corresponding to the second request information.

16. A first gateway, characterized in that: include: An access module, configured to receive first request information sent by at least one client and forward the information to an access controller; The access controller divides the at least one client into at least one client group, and for any client group, divides the resource servers corresponding to the respective clients in the client group into the same resource group; wherein the clients that send the first request information within the same preset time period belong to the same client group; and for any client, the resource server corresponding to the client is determined based on the first request information of the client; A configuration module, configured to receive a hardware group correspondence between a client group and a resource group sent by the access controller; The protection module is used to receive a second request information from a target client to a resource server to be processed, and if it is determined that the resource server to be processed belongs to a target resource group based on the hardware group correspondence, the protection module forwards the second request information to the access controller so that the second request information, which is legally controlled by the access controller, is sent to the resource server to be processed corresponding to the second request information; wherein the target resource group is a resource group corresponding to the client group to which the target client is located.

17. An electronic device, characterized in that: include: a processor and a memory for storing instructions executable by the processor; The processor is configured to execute the instructions to implement the micro-isolation protection method as described in any one of claims 1-8, and / or to implement the micro-isolation protection method as described in any one of claims 9-13.

18. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, which is used to implement the micro-isolation protection method as described in any one of claims 1-8, and / or to implement the micro-isolation protection method as described in any one of claims 9-13.

Citation Information

Patent Citations

  • Mixed storage system based on data block

    CN103714022A

  • Access authority control method and reverse agent server

    CN105721420A