Access control method and apparatus, storage medium, program product
Patent Information
- Application Number
- CN202210515906.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-05-12
- Publication Date
- 2026-09-29
- Estimated Expiration
- 2042-05-12
AI Technical Summary
[0003]目前常用的访问控制方法主要是通过对访问发起者进行授信实现对访问发起者的访问控制,但是,这种访问控制方法仅对访问发起者起作用,无法识别被访问的资源是否存在异常开放的问题,一旦被访问的资源异常开放,就容易导致资源被非法获取,从而导致出现信息泄露的安全风险
[0057]本发明实施例至少包括以下有益效果:在获取到针对目标资源对象的访问请求信息,并确定访问请求信息不符合预设的访问策略的情况下,先对访问请求信息进行是否符合受限访问规则的判断,当访问请求信息符合受限访问规则,说明访问请求信息所对应的目标资源对象是不应该开放通信接口的受限访问对象,因此可以根据目标资源对象是否会针对访问请求信息作出相应的响应来判断目标资源对象的通信接口是否异常开放,所以,可以向目标资源对象发送访问请求信息,当接收到目标资源对象根据访问请求信息发送的目标访问响应,可以确定目标资源对象的通信接口异常开放,此时,可以阻断针对目标资源对象的访问请求,降低目标资源对象出现信息泄露的安全风险,并且,还可以告警目标资源对象的通信接口异常开放,使得管理员可以关闭目标资源对象的通信接口,避免信息泄露,从而提高目标资源对象的安全性。也就是说,本发明实施例能够快速有效识别资源是否异常开放,有利于及时关闭异常开放的资源的通信接口,降低漏洞被利用的时间,避免信息泄露,从而能够提高资源的安全性。
Smart Images

Figure CN117097491B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of cloud technology, and in particular to an access control method and apparatus, storage medium, and program product. Background Technology
[0002] With the rapid development of Internet technology, access control technology, as one of the core means to ensure network information security, has been widely used in various application scenarios, such as cloud computing and cloud security.
[0003] Currently, the most common access control method is to grant trust to the initiator of the access to control access. However, this access control method only works on the initiator and cannot identify whether the accessed resource is abnormally open. Once the accessed resource is abnormally open, it is easy for the resource to be illegally obtained, which will lead to the security risk of information leakage. Summary of the Invention
[0004] The following is an overview of the subject matter described in detail herein. This overview is not intended to limit the scope of the claims.
[0005] This invention provides an access control method, apparatus, storage medium, and program product that can quickly identify whether a resource is abnormally open, facilitate the execution of corrective measures for abnormally open resources, reduce the time for vulnerabilities to be exploited, and thus improve resource security.
[0006] On one hand, embodiments of the present invention provide an access control method, comprising the following steps:
[0007] Obtain access request information for the target resource object;
[0008] If the access request information does not conform to the preset access policy, the access request information is judged to determine whether it conforms to the restricted access rules;
[0009] When the access request information matches the restricted access rule, the access request information is sent to the target resource object;
[0010] When a target access response is received from the target resource object based on the access request information, it is determined that the communication interface of the target resource object is abnormally open.
[0011] Block access requests to the target resource object and issue a warning that the target resource object's communication interface is abnormally open.
[0012] On the other hand, embodiments of the present invention also provide an access control device, including:
[0013] The request retrieval unit is used to retrieve access request information for the target resource object.
[0014] The rule acquisition unit is used to determine whether the access request information conforms to the restricted access rule when the access request information does not conform to the preset access policy.
[0015] A request sending unit is configured to send the access request information to the target resource object when the access request information conforms to the restricted access rule.
[0016] An anomaly determination unit is used to determine that the communication interface of the target resource object is abnormally open when it receives a target access response sent by the target resource object according to the access request information.
[0017] An anomaly handling unit is used to block access requests to the target resource object and to alert that the communication interface of the target resource object is abnormally open.
[0018] Optionally, the anomaly determination unit is further configured to:
[0019] When a target access response is received from the target resource object based on the access request information, it is determined whether the target access response is associated with the access request information;
[0020] When the target access response is associated with the access request information, it is determined that the communication interface of the target resource object is abnormally open.
[0021] Optionally, the exception handling unit is further configured to:
[0022] Discard the target access response;
[0023] Send an access blocking response to the initiator of the access request information to block the access request initiated by the initiator to the target resource object.
[0024] Optionally, the access control device further includes:
[0025] The blocking record generation unit is used to generate access blocking records;
[0026] The blocking record reporting unit is used to report the access blocking record to the server, so that the server determines whether to update at least one of the access policy and the restricted access rule based on the access blocking record.
[0027] Optionally, the access control device further includes:
[0028] The first record generation unit is used to generate a first access record based on the access request information when no target access response is received from the target resource object based on the access request information.
[0029] The first record reporting unit is used to report the first access record to the server, so that the server determines whether to update at least one of the access policy and the restricted access rule based on the first access record.
[0030] Optionally, the access control device further includes:
[0031] The second record generation unit is used to generate a second access record based on the access request information when the access request information does not conform to the restricted access rule.
[0032] The second record reporting unit is used to report the second access record to the server, so that the server determines whether to update at least one of the access policy and the restricted access rule based on the second access record.
[0033] Optionally, the access control device further includes:
[0034] The access record acquisition unit is used to acquire the target access records for the target resource object set;
[0035] An access record reporting unit is used to report the target access record to the server, so that the server generates the restricted access rule based on the target access record;
[0036] An access rule receiving unit is used to receive the restricted access rules issued by the server.
[0037] Optionally, the access control device further includes:
[0038] The third record generation unit is used to generate a third access record based on the access request information when the access request information conforms to the access policy.
[0039] The third record reporting unit is used to report the third access record to the server, so that the server determines whether to update at least one of the access policy and the restricted access rule based on the third access record.
[0040] Optionally, the access control device further includes:
[0041] The information sending unit is used to send the access request information to the target resource object through the gateway when the access request information conforms to the access policy;
[0042] A response acquisition unit is configured to acquire a first access response sent by the gateway, wherein the first access response is sent by the target resource object to the gateway according to the access request information;
[0043] A response sending unit is used to send the first access response to the access initiator.
[0044] Optionally, the information sending unit is further configured to:
[0045] Obtain the characteristic information of the access initiator;
[0046] Obtain access credentials based on the aforementioned feature information;
[0047] The access credential and the access request information are sent to the gateway, so that the gateway, after verifying the access credential, sends the access request information to the target resource object.
[0048] Optionally, the information sending unit is further configured to:
[0049] The feature information is sent to the server, enabling the server to perform permission verification on the access initiator based on the feature information;
[0050] Obtain the access credentials sent by the server, wherein the access credentials are generated by the server after passing the permission verification of the access initiator.
[0051] On the other hand, embodiments of the present invention also provide an access control device, including:
[0052] At least one processor;
[0053] At least one memory for storing at least one program;
[0054] The access control method described above is implemented when at least one of the programs is executed by at least one of the processors.
[0055] On the other hand, embodiments of the present invention also provide a computer-readable storage medium storing a processor-executable program, which, when executed by a processor, is used to implement the access control method as described above.
[0056] On the other hand, embodiments of the present invention also provide a computer program product, including a computer program or computer instructions, the computer program or computer instructions being stored in a computer-readable storage medium, a processor of a computer device reading the computer program or computer instructions from the computer-readable storage medium, and the processor executing the computer program or computer instructions to cause the computer device to perform the access control method as described above.
[0057] The embodiments of the present invention include at least the following beneficial effects: Upon obtaining access request information for a target resource object and determining that the access request information does not conform to a preset access policy, the access request information is first judged to determine whether it conforms to restricted access rules. If the access request information conforms to the restricted access rules, it indicates that the target resource object corresponding to the access request information is a restricted access object whose communication interface should not be open. Therefore, it can be determined whether the target resource object's communication interface is abnormally open based on whether the target resource object responds to the access request information. Thus, an access request information can be sent to the target resource object. When a target access response is received from the target resource object based on the access request information, it can be determined that the target resource object's communication interface is abnormally open. At this time, access requests to the target resource object can be blocked, reducing the security risk of information leakage from the target resource object. Furthermore, an alert can be issued regarding the abnormally open communication interface of the target resource object, allowing the administrator to close the target resource object's communication interface to prevent information leakage, thereby improving the security of the target resource object. In other words, the embodiments of the present invention can quickly and effectively identify whether a resource is abnormally open, which is beneficial for timely closing the communication interfaces of abnormally open resources, reducing the time for vulnerabilities to be exploited, preventing information leakage, and thus improving resource security.
[0058] Other features and advantages of the invention will be set forth in the description which follows, and will be apparent in part from the description, or may be learned by practicing the invention. The objects and other advantages of the invention may be realized and obtained by means of the structures particularly pointed out in the description, claims, and drawings. Attached Figure Description
[0059] The accompanying drawings are provided to further understand the technical solutions of the present invention and constitute a part of the specification. They are used together with the embodiments of the present invention to explain the technical solutions of the present invention, and do not constitute a limitation on the technical solutions of the present invention.
[0060] Figure 1 This is a schematic diagram of an implementation environment provided by an embodiment of the present invention;
[0061] Figure 2 This is a schematic diagram of the configuration interface for the zero-trust access control policy configured for authorized accounts provided in an embodiment of the present invention;
[0062] Figure 3 This is a schematic diagram of the configuration interface for configuring gateway resources provided in an embodiment of the present invention;
[0063] Figure 4 Is Figure 3 The following is a schematic diagram of the configuration interface for further configuring gateway resources based on this;
[0064] Figure 5 This is a schematic diagram of an alarm interface that notifies users of abnormal access requests via a pop-up window, provided in an embodiment of the present invention.
[0065] Figure 6 This is a schematic diagram of the interception interface for the intercepted access request provided in an embodiment of the present invention;
[0066] Figure 7 This is a flowchart of an access control method provided in an embodiment of the present invention;
[0067] Figure 8 This is a complete flowchart of the access control method provided in the embodiments of the present invention;
[0068] Figure 9 This is a schematic diagram of an access control device provided in an embodiment of the present invention;
[0069] Figure 10 This is a schematic diagram of another access control device provided in an embodiment of the present invention. Detailed Implementation
[0070] The present invention will be further described below with reference to the accompanying drawings and specific embodiments. The described embodiments should not be considered as limitations on the present invention, and all other embodiments obtained by those skilled in the art without inventive effort are within the scope of protection of the present invention.
[0071] In the following description, references are made to “some embodiments,” which describe a subset of all possible embodiments. However, it is understood that “some embodiments” may be the same subset or different subsets of all possible embodiments and may be combined with each other without conflict.
[0072] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this invention pertains. The terminology used herein is for the purpose of describing embodiments of the invention only and is not intended to limit the invention.
[0073] Before providing a further detailed description of the embodiments of the present invention, the nouns and terms involved in the embodiments of the present invention will be explained, and the nouns and terms involved in the embodiments of the present invention shall be interpreted as follows.
[0074] 1) Cloud technology refers to a hosting technology that unifies hardware, software, and network resources within a wide area network (WAN) or local area network (LAN) to achieve data computation, storage, processing, and sharing. Cloud technology is a general term encompassing network technology, information technology, integration technology, management platform technology, and application technology based on the cloud computing business model. It can form resource pools, providing flexible and convenient on-demand access. Cloud computing technology will become a crucial support. Backend services of technical network systems require substantial computing and storage resources, such as video websites, image websites, e-commerce platforms, and many portal websites. With the rapid development and application of the internet industry, every item may have its own identification mark in the future, requiring transmission to backend systems for logical processing. Data at different levels will be processed separately, and various industry data will require robust system support, which can only be achieved through cloud computing.
[0075] 2) Cloud security refers to the collective term for security software, hardware, users, organizations, and security cloud platforms based on cloud computing business models. Cloud security integrates emerging technologies and concepts such as parallel processing, grid computing, and unknown virus behavior detection. It uses a large network of clients to monitor abnormal software behavior, obtain the latest information on Trojans and malware on the internet, and send it to the server for automatic analysis and processing. Solutions for viruses and Trojans are then distributed to each client. The main research directions of cloud security include: 1. Cloud computing security: This mainly studies how to ensure the security of the cloud itself and various applications on the cloud, including cloud computer system security, secure storage and isolation of target data, user access authentication, information transmission security, network attack protection, and compliance auditing; 2. Cloudification of security infrastructure: This mainly studies how to use cloud computing to build and integrate security infrastructure resources and optimize security protection mechanisms, including building a large-scale security event and information collection and processing platform through cloud computing technology to achieve the collection and correlation analysis of massive amounts of information, and improve the ability to control and manage network-wide security events; 3. Cloud security services: This mainly studies various security services provided to users based on cloud computing platforms, such as antivirus services.
[0076] 3) Private cloud refers to creating cloud infrastructure and hardware / software resources within a firewall, allowing various departments within an organization or enterprise to share resources within a data center. Creating a private cloud typically involves cloud equipment (IaaS, Infrastructure as a Service) software, in addition to hardware resources. Private cloud computing also comprises three layers: cloud hardware, cloud platform, and cloud services. The difference is that cloud hardware consists of the user's own personal computer or server, rather than the cloud computing vendor's data center. Cloud computing vendors build data centers to provide public cloud services to millions of users, thus requiring hundreds of thousands or even millions of servers. For individuals, private cloud computing serves only family and friends; for enterprises, it serves only their own employees, customers, and suppliers. Therefore, the personal computers or servers of individuals or enterprises are sufficient to provide cloud services.
[0077] 4) Blockchain is a new application model of computer technologies such as distributed data storage, peer-to-peer transmission, consensus mechanisms, and cryptographic algorithms. Essentially, a blockchain is a decentralized database, a chain of data blocks linked using cryptographic methods. Each data block contains information about a batch of network transactions, used to verify the validity of the information (anti-counterfeiting) and generate the next block. A blockchain can include an underlying platform, a platform product service layer, and an application service layer. Blockchains can include public blockchains, consortium blockchains, and private blockchains. A public blockchain is one where anyone can access the blockchain network at any time to read data, send data, or compete for ledger entries; a consortium blockchain is one jointly managed by several organizations or institutions; a private blockchain is one with a degree of centralized control, where the right to write to the ledger is controlled by a specific organization or institution, and data access and use are subject to strict permission management.
[0078] 5) Intelligent Traffic System (ITS), also known as Intelligent Transportation System, effectively integrates advanced science and technology (information technology, computer technology, data communication technology, sensor technology, electronic control technology, automatic control theory, operations research, artificial intelligence, etc.) into transportation, service control, and vehicle manufacturing, strengthening the connection between vehicles, roads, and users, thereby forming a comprehensive transportation system that ensures safety, improves efficiency, improves the environment, and saves energy.
[0079] 6) Intelligent Vehicle Infrastructure Cooperative Systems (IVICS), or vehicle-road cooperative systems for short, represent a development direction for Intelligent Transportation Systems (ITS). IVICS utilizes advanced wireless communication and next-generation Internet technologies to implement comprehensive, real-time dynamic information exchange between vehicles and infrastructure. Based on the collection and fusion of dynamic traffic information across all times and spaces, it conducts active vehicle safety control and cooperative road management, fully realizing effective collaboration between people, vehicles, and roads. This ensures traffic safety, improves traffic efficiency, and ultimately forms a safe, efficient, and environmentally friendly road traffic system.
[0080] Currently, common access control methods primarily rely on granting trust to the initiator of access. However, this approach only affects the initiator and cannot identify whether the accessed resource is abnormally open. If the resource is abnormally open, it can easily be illegally acquired, leading to information leakage and security risks. To address this issue, related technologies have proposed using network scanning combined with sniffing toolkits to proactively scan for open network services and ports. This allows for the discovery of abnormally open restricted access ports, components, and services, which can then be shut down by the operations and maintenance team to prevent unauthorized access. However, this method of proactively scanning for abnormally open resources suffers from drawbacks: scans are easily blocked, and the scanning cycle is insufficient to quickly cover all resources. Furthermore, the time required from detecting abnormally open resources to shutting them down by the operations and maintenance team is relatively long, making it difficult to effectively and promptly address security risks such as the successful detection and rapid exploitation of abnormally open resources.
[0081] To quickly identify whether resources are abnormally open and implement corresponding remedial measures, thereby reducing the time for vulnerability exploitation and improving resource security, this invention provides an access control method, access control device, computer-readable storage medium, and computer program product. Upon receiving access request information for a target resource object and determining that the access request information does not conform to a preset access policy, the method first judges whether the access request information complies with restricted access rules. If the access request information complies with restricted access rules, it indicates that the target resource object corresponding to the access request information is a restricted access object whose communication interface should not be open. Therefore, the method can determine whether the target resource object's communication interface is abnormally open based on whether the target resource object responds to the access request information. Thus, an access request can be sent to the target resource object. When a target access response is received from the target resource object based on the access request information, it can be determined that the target resource object's communication interface is abnormally open. At this point, access requests to the target resource object can be blocked, reducing the security risk of information leakage. Furthermore, an alert can be issued regarding the abnormally open communication interface of the target resource object, allowing the administrator to close the target resource object's communication interface to prevent information leakage and thereby improve the security of the target resource object. In other words, the embodiments of the present invention can quickly and effectively identify whether resources are abnormally open, which is conducive to timely closing the communication interfaces of abnormally open resources, reducing the time for vulnerabilities to be exploited, avoiding information leakage, and thus improving the security of resources.
[0082] The solutions provided in the embodiments of the present invention involve technologies such as cloud security, data security, and blockchain, and are specifically described through the following embodiments.
[0083] Figure 1 This is a schematic diagram of an implementation environment provided by an embodiment of the present invention. (Refer to...) Figure 1 The implementation environment includes a terminal 101, a gateway 102, a data server 103, and a management server 104. The terminal 101 can be directly or indirectly connected to the gateway 102, the data server 103, and the management server 104 via wired or wireless communication. Similarly, the gateway 102 can be directly or indirectly connected to the data server 103 and the management server 104 via wired or wireless communication. The terminal 101, gateway 102, data server 103, and management server 104 can be nodes of a private blockchain; however, this embodiment does not impose specific limitations on this.
[0084] Terminal 101 may include, but is not limited to, mobile phones, computers, smart voice interaction devices, smart home appliances, vehicle terminals, aircraft, etc. Optionally, terminal 101 may have a security management client 1011 and a business application client 1012 for accessing business data installed. When terminal 101 runs the security management client 1011, terminal 101 can interact with gateway 102, data server 103, or management server 104 through the security management client 1011. The security management client 1011 may include a proxy component, which can be used to initiate a verification request for the trusted identity of terminal 101 to management server 104. When the identity is verified as trusted, the proxy component can establish an encrypted access connection with gateway 102. Furthermore, the proxy component can also be a policy enforcement point for access control.
[0085] In some possible implementations, the business application client 1012 may include social clients, office clients, browser clients, multimedia clients (such as video clients), entertainment clients (such as game clients), education clients, live streaming clients, news clients, shopping clients, and other application clients, without specific limitations here. The business application client 1012 is a trusted application authorized by the management server 104, and the terminal 101 can access the internal business systems in the data server 103 through the business application client 1012.
[0086] The proxy component in terminal 101 has at least the following functions: acquiring access requests, determining whether access requests comply with access policies, determining whether access requests comply with restricted access rules, and determining whether the communication interface of the target resource object is abnormally open. For example, it can acquire access request information for a target resource object initiated by the business application client 1012, and then determine whether the access request information complies with the preset access policy. When the access request information does not comply with the preset access policy, it further determines whether the access request information complies with the restricted access rules. When the access request information complies with the restricted access rules, it sends the access request information to the target resource object. When it receives the target access response sent by the target resource object according to the access request information, it can determine that the communication interface of the target resource object is abnormally open. At this time, it can block access requests to the target resource object and issue an alarm for the abnormally open communication interface of the target resource object.
[0087] It should be noted that preset access policies can include zero-trust access control policies. Zero-trust access control policies include information on processes (such as trusted applications) that authorized accounts can use and accessible business sites. An authorized account can access any accessible business site through any trusted application. When an access request conforms to a zero-trust access control policy, it means that the access request complies with the access control rules, and therefore the initiator of the access request is allowed to interact with the target resource object through the access request. When an access request does not conform to a zero-trust access control policy, it means that the access request does not comply with the access control rules, and therefore the initiator of the access request is not allowed to interact with the target resource object through the access request. Additionally, restricted access rules include ports and services that are easily exploited, such as ports or services corresponding to high-critical services like file transfer, network access, device management, and system configuration management. Ports or services listed in the restricted access rules should not be open to the initiator of the current access request.
[0088] Gateway 102 can be a smart gateway, deployed between terminal 101 and data server 103. It can verify and forward every access request initiated by terminal 101. For example, when terminal 101 accesses data server 103 through a trusted application, gateway 102 will first obtain the access request sent by terminal 101 and perform authorization authentication on the access request. When the authentication is successful, gateway 102 will then send the access request to data server 103. When data server 103 issues an access response to the access request, gateway 102 will first obtain the access response and then forward the access response to terminal 101, completing the information exchange between terminal 101 and data server 103.
[0089] Data server 103 can be a standalone physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, CDN (Content Delivery Network), and big data and artificial intelligence platforms. Data server 103 stores various data resources or business resources. Terminals 101 with different access permissions can access different data resources or business resources in data server 103. For access requests initiated by terminals 101 that do not have the corresponding access permissions, data server 103 can return response information such as access denied or access error. For example, assuming terminal A only has access permission to access resource A, if terminal A initiates an access request to data server 103 to access resource A, data server 103 will return the corresponding resource A to terminal A. If terminal A initiates an access request to data server 103 to access resource B, data server 103 will return response information such as access denied or access error.
[0090] The management server 104 can be a standalone physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms. Optionally, the management server 104 can be equipped with a security management server 1041, through which accounts for logging into the security management client 1011 can be created, and zero-trust access control policies can be configured based on the account information corresponding to the account.
[0091] Different zero-trust access control policies can be configured for different authorized accounts. For example, a zero-trust access control policy can be configured for a specific authorized account through the configuration interface in the security management server 1041. Figure 2 As shown, Figure 2This is a schematic diagram of the configuration interface for zero-trust access control policies configured for authorized accounts. After configuring the zero-trust access control policies for authorized accounts, the configuration interface in the security management server 1041 allows viewing information on all authorized and accessible business sites for the specified authorized account. Furthermore, this interface also allows adding, deleting, or modifying the configured zero-trust access control policies. Additionally, the security management server 1041 can be used to configure gateway resources, enabling access requests conforming to the access control policies to access the data server 103 through gateway 102, while blocking access requests that do not conform to the access control policies, thus preventing information leakage. Figure 3 and Figure 4 As shown, Figure 3 This is a schematic diagram of the configuration interface for configuring gateway resources. Figure 4 This is a schematic diagram of the configuration interface for further configuring gateway resources. Figure 3 In this configuration, you can configure aspects such as resource name, resource category, domain name information, port information, resource group information, resource access method, and protocol type for network resources. This ensures that gateway 102 only forwards configured network resources, preventing unauthorized access to network resources that do not conform to access control policies, thereby improving network resource security. Once completed... Figure 3 After the configuration operation shown, click Figure 3 The "Next" button 1042 in the middle can... Figure 3 The configuration interface in the middle jumps to, as follows Figure 4 The configuration interface shown is in Figure 4 In the configuration interface, a corresponding accessible gateway can be configured for terminal 101, enabling terminal 101 to access data server 103 only through the corresponding accessible gateway, thereby improving the security of network resources. After completing the configuration of the zero-trust access control policy, when an access request initiated by terminal 101 does not conform to the zero-trust access control policy, the access request will be blocked, and terminal 101 will not obtain the corresponding access result. At this time, the security management client 1011 in terminal 101 can inform the user that the access request initiated is an abnormal access request through pop-up windows or direct page display. In this case, the user can view the list of blocked access requests and the corresponding blocking reasons through the security management client 1011 in terminal 101. Figure 5 and Figure 6 As shown, Figure 5 This is a diagram illustrating an alert interface that displays a pop-up window indicating an abnormal access request. Figure 6 This is a schematic diagram of the intercepted access request interface. When an access request initiated by terminal 101 does not conform to the zero-trust access control policy, the screen of terminal 101 will display something like this. Figure 5The alarm interface shown displays the severity of the access request's anomaly. When an access request initiated by terminal 101 is blocked, the user can view the following information through the security management client 1011: Figure 6 The interception interface shown allows users to view information such as the resource object corresponding to the intercepted access request, the time of the interception, and the reason for the interception.
[0092] Reference Figure 1 As shown, in one application scenario, it is assumed that terminal 101 is an office computer, data server 103 is an internal data resource server of an enterprise, and terminal 101 is equipped with a security management client 1011 and a business application client 1012 for accessing business data. In response to an office worker accessing a target resource object in data server 103 via business application client 1012 in terminal 101, the proxy component in security management client 1011 obtains access request information for the target resource object and determines whether the access request information conforms to a preset access policy. If the access request information does not conform to the preset access policy, the proxy component determines whether the access request information conforms to restricted access rules. If the access request information conforms to restricted access rules, the proxy component sends the access request information to the target resource object. In response to receiving the access request information, the target resource object returns an access response to the proxy component. In response to receiving the access response returned by the target resource object, the proxy component determines whether the access response is the target access response. If the access response is the target access response, the proxy component determines that the communication interface of the target resource object is abnormally open. At this time, the proxy component blocks the access request for the target resource object and alerts the target resource object that the communication interface is abnormally open. Furthermore, when the access request information conforms to the preset access policy, the proxy component sends the access request information to the data server 103 through the gateway 102. After the data server 103 returns the first access response to the gateway 102 based on the access request information, the gateway 102 sends the first access response to the security management client 1011. The security management client 1011 returns the first access response to the business application client 1012, thus completing the data interaction between the business application client 1012 and the data server 103.
[0093] It should be noted that in various specific embodiments of the present invention, when processing is required based on data related to the characteristics of the target object, such as target object attribute information or a set of attribute information, the permission or consent of the target object will be obtained first. Furthermore, the collection, use, and processing of this data will comply with the relevant laws, regulations, and standards of the relevant countries and regions. In addition, when embodiments of the present invention need to obtain target object attribute information, separate permission or consent from the target object will be obtained through pop-up windows or redirection to a confirmation page. Only after obtaining the separate permission or consent of the target object will the necessary target object-related data for the normal operation of the embodiments of the present invention be obtained.
[0094] Figure 7 This is a flowchart of an access control method provided in an embodiment of the present invention. In this embodiment, a proxy component in a terminal is used as the execution subject for illustration. (Refer to...) Figure 7 The access control method includes, but is not limited to, steps 110 to 150.
[0095] Step 110: Obtain access request information for the target resource object.
[0096] It should be noted that the target resource object is the party being accessed on the network. For example, it can be the enterprise's internal network business resources or the enterprise's external website. When the target resource object is the enterprise's internal network business resources, it can include applications, systems (such as development and testing environments, operation and maintenance environments, production environments, etc.), data, interfaces, and functions, etc., without specific limitations here.
[0097] In some possible implementations, assuming the target resource is an enterprise's intranet business resource, when a user initiates an access request through a business application client on their terminal, the proxy component in the terminal can obtain this access request information. This allows subsequent steps to determine whether the access request conforms to a preset access policy, thereby determining whether the user's access to the enterprise's intranet business resource is for normal work needs. For example, if the access request conforms to the preset access policy, it indicates that the user is accessing the enterprise's intranet business resource for normal work needs, and therefore, the user should be allowed to access the target resource. Conversely, if the access request does not conform to the preset access policy, it indicates that the user initiated access to the enterprise's intranet business resource due to a mistake or that the user is illegally accessing the enterprise's intranet business resource. Regardless of the reason, the user should not be allowed to access the target resource.
[0098] In other possible implementations, assuming the target resource is an external website of an enterprise, when a user initiates an access request through a business application client on their terminal, the proxy component in the terminal can obtain this access request information. This allows subsequent steps to determine whether the access request conforms to a preset access policy, thereby determining whether the user has performed an abnormal access operation. For example, if the enterprise does not allow access to the external network, it can be determined that the access request does not conform to the preset access policy, thus confirming that the user has performed an abnormal access operation. Conversely, even if the enterprise does not allow access to the external network, but the user has permission to access the external network due to the nature of their work, it can be determined that the access request conforms to the preset access policy, thus confirming that the user has not performed an abnormal access operation.
[0099] Step 120: When the access request information does not conform to the preset access policy, determine whether the access request information conforms to the restricted access rules.
[0100] In this step, since the access request information for the target resource object was obtained in step 110, it can be first determined whether the access request information conforms to the preset access policy. If the access request information does not conform to the preset access policy, it means that the access request information does not meet the prescribed access requirements, and the transmission of the access request information should be blocked. However, for the current user, although the target resource object is not a resource object that they can access, it may be a resource object that other users can access. After other users access the target resource object normally, the target resource object may be abnormally open. In this case, the target resource object can be easily obtained illegally, which will lead to the security risk of information leakage. Therefore, when the access request information does not conform to the preset access policy, the access request information can be further used to determine whether the target resource object is abnormally open. Therefore, when it is determined that the access request information does not conform to the preset access policy, the access request information can be judged to see if it conforms to the restricted access rules, so that subsequent steps can determine whether the target resource object is abnormally open based on the judgment result.
[0101] It should be noted that preset access policies can include zero-trust access control policies. Zero-trust access control policies include information on processes (such as trusted applications) that authorized accounts can use and the business sites that can be accessed. An authorized account can access any accessible business site through any trusted application. When an access request conforms to a zero-trust access control policy, it means that the access request complies with the access control rules, and therefore the initiator of the access request is allowed to interact with the target resource object through the access request. When an access request does not conform to a zero-trust access control policy, it means that the access request does not comply with the access control rules, and therefore the initiator of the access request is not allowed to interact with the target resource object through the access request. When configuring access policies, for different authenticated users, administrators can configure the allowed resource objects in the corresponding access policies and issue different access policies for different authenticated users. Access policies can include multiple authorization information items, each corresponding to a resource object that an authenticated user is allowed to access. Each authorization information item can include resource category (such as domain name category, IP category, or IP range category), the domain name or IP address corresponding to the resource object, protocol type (such as TCP protocol or UDP protocol), access port, and gateway access information, etc.
[0102] It should be noted that restricted access rules include ports and services that are easily exploited, such as ports or services related to high-critical services like file transfer, network access, device management, and system configuration management. Ports or services listed in the restricted access rules should not be open to the initiator of the current access request. Administrators can determine the corresponding business resources, services, and ports based on their importance and ease of exploitation, and then create restricted access rules accordingly.
[0103] In some possible implementations, restricted access rules can be obtained according to the following steps: First, obtain target access records for the target resource object set; then, report the target access records to a server (such as a management server), so that the server generates restricted access rules based on the target access records; finally, receive the restricted access rules issued by the server. Here, the target resource object set refers to the set of resource objects corresponding to the access policy and restricted access rules, such as a set of internal data resources or a set of business resources within an enterprise. Target access records for the target resource object set refer to all user-initiated access records for resource objects within the target resource object set. Because different users have different access permissions, the target access records for each user are different. For some users, certain ports or services may belong to the restricted access rules, while for other users, these ports or services may not belong to the restricted access rules. In other words, the restricted access rules corresponding to each user are different, so there are many types of ports or services in the restricted access rules. In order to set restricted access rules more accurately and comprehensively, the obtained target access records can be reported to the management server, so that the management server can generate restricted access rules based on these target access records. After the management server generates the restricted access rules, it will send the restricted access rules to the terminal. When the terminal receives the restricted access rules, the proxy component in the terminal can use the restricted access rules to judge the access request information for the target resource object, so that subsequent steps can determine whether the target resource object has an abnormal openness problem based on the judgment result.
[0104] Here are some specific examples to illustrate restricted access rules:
[0105] Assuming the restricted access rule includes port 3389 used by Remote Desktop and port 21 used by the File Transfer Protocol (FTP) service, a user's access request that logs into the Remote Desktop via port 3389 or requests the FTP service via port 21 will be considered to comply with the restricted access rule. Similarly, assuming server IP address A has port N used by a console service, if the restricted access rule includes the combination of IP address A and destination port N, a user's access request targeting a resource with IP address A and destination port N will be considered to comply with the restricted access rule.
[0106] In some possible implementations, before determining whether the access request information conforms to the preset access policy, it can be first determined whether the target resource object corresponding to the access request information belongs to the resource object in the target resource set. For example, assuming the target resource set is an internal data resource set or business resource set of an enterprise, and the preset access policy is an access policy adapted to the internal data resource set or business resource set of the enterprise, after obtaining the access request information for the target resource object, it can first determine whether the target resource object belongs to the resource object in the target resource set. If the target resource object belongs to the resource object in the target resource set, it means that the access request information is an access request information initiated for the internal data resource set or business resource set of the enterprise. In order to prevent the internal resources of the enterprise from being illegally obtained, it is then determined whether the access request information conforms to the preset access policy. If the target resource object does not belong to the resource object in the target resource set, it means that the access request information is an access request information initiated for an external network site of the enterprise. Therefore, default traffic access control can be performed. For example, the access request information can be blocked according to the traffic access rules specified by the enterprise, or the terminal can be allowed to directly access the target resource object (i.e., without going through the proxy forwarding of the gateway). It should be noted that the default traffic access control is also configured by the administrator in the security management server of the management server and then distributed to each terminal for execution.
[0107] It should be noted that the following are some situations where the access request information does not conform to the preset access policy:
[0108] (1) The target resource object corresponding to the access request information does not belong to the resource objects in the target resource set;
[0109] (2) The target resource object corresponding to the access request information belongs to the resource object in the target resource set, but the current user does not have permission to access the target resource object, and the access request information complies with the restricted access rules.
[0110] (3) The target resource object corresponding to the access request information belongs to the resource object in the target resource set, and the access request information does not meet the restricted access rules, but the current user does not have the permission to access the target resource object.
[0111] In case (1), the target resource object corresponding to the access request information is generally a public website. Therefore, the access request information for the public website does not conform to the preset access policy. In this case, default traffic access control can be implemented, such as blocking the access request information or allowing the terminal to directly access the target resource object.
[0112] In case (2), the current user does not have permission to access resource objects belonging to the target resource set. Therefore, the access request information does not conform to the preset access policy. Moreover, the access request information conforms to the restricted access rule. Therefore, the access request information may be an illegal access request. So, when such access request information is obtained, it is necessary to report such access request information to the management server for further analysis to determine whether such access request information is an illegal access request.
[0113] In case (3), although the access request information does not conform to the restricted access rules, the current user does not have the permission to access resource objects belonging to the target resource set, so the access request information does not conform to the preset access policy.
[0114] Step 130: When the access request information meets the restricted access rules, send the access request information to the target resource object.
[0115] In this step, since the access request information was judged to comply with the restricted access rules in step 120, if the access request information complies with the restricted access rules, it means that the target resource object corresponding to the access request information is a resource object that is easy to be illegally used. The target resource object should not be open to the current user. However, the target resource object may be abnormally open. In this case, the target resource object can be easily obtained illegally, which will lead to the security risk of information leakage. In order to identify whether the target resource object is abnormally open, the access request information that should not be sent can be sent to the target resource object. This will allow subsequent steps to determine whether the target resource object is abnormally open based on whether the target resource object returns a target access response in response to the access request information.
[0116] In some possible implementations, when it is determined that the access request information conforms to the restricted access rules, the proxy component in the terminal can directly send the access request information to the target resource object. If the target resource object responds to the access request information, it will directly send the response to the proxy component in the terminal. Therefore, the proxy component in the terminal can accurately determine whether the target resource object has responded to the access request information, thereby determining whether the target resource object has an abnormally open problem.
[0117] Step 140: When a target access response is received from the target resource object based on the access request information, it is determined that the communication interface of the target resource object is abnormally open.
[0118] It should be noted that after sending the access request information to the target resource object in step 130, the target resource object will respond differently based on the preset access policy and its operating status. For example, assuming the target resource object is not abnormally open, it will return an access denied or failed response upon receiving the access request. Conversely, assuming the target resource object is abnormally open, it will return a target access response that allows access (e.g., a response message or information about data or business resources corresponding to the access request). Therefore, upon receiving the target access response from the target resource object based on the access request, it can be determined that the target resource object's communication interface is abnormally open, meaning that the target resource object has an abnormally open problem.
[0119] In some possible implementations, based on preset access policies and the operational status of the target resource object, the target resource object may issue different access responses, such as denying or allowing access. Only when the target resource object issues an access-allowing response based on the access request information can it be determined that the target resource object's communication interface is abnormally open. Therefore, when a target access response sent by the target resource object based on the access request information is received, it can be first determined whether the target access response is associated with the access request information. That is, it can be first determined whether the target access response sent by the target resource object is an access-allowing response. If the target access response is associated with the access request information, i.e., the target access response is an access-allowing response, then it can be determined that the target resource object's communication interface is abnormally open. By determining whether the target resource object's communication interface is abnormally open based on the correlation between the target access response and the access request information, the false alarm rate of related technologies that rely on extensive active scanning and probing to detect abnormally open resources can be effectively reduced.
[0120] Step 150: Block access requests to the target resource object and issue an alert that the target resource object's communication interface is abnormally open.
[0121] In this step, since the communication interface of the target resource object was found to be abnormally open in step 140, access requests to the target resource object can be blocked, reducing the security risk of information leakage of the target resource object. In addition, in order to reduce the time for the vulnerability to be exploited, the administrator can be alerted that the communication interface of the target resource object is abnormally open, so that the administrator can close the abnormally open communication interface of the target resource object in time to avoid information leakage.
[0122] In some possible implementations, when blocking access requests to a target resource object, the target access response sent by the target resource object can be discarded first. Then, a custom access blocking response (e.g., an access denial message) can be constructed and sent to the initiator of the access request (e.g., a business application client in the terminal), thus blocking the access request initiated by the initiator to the target resource object. Because the target access response sent by the target resource object is discarded and a custom access blocking response is sent to the initiator of the access request, effective data interaction cannot occur between the initiator of the access request and the target resource object. Therefore, the purpose of blocking access requests to the target resource object can be effectively achieved, preventing information leakage from the target resource object.
[0123] In some possible implementations, when an operation is performed that abnormally opens the communication interface of the target resource object, the administrator can be notified in a timely manner through different means such as alarm email, telephone, SMS or multimedia message to analyze such abnormal communication behavior that is outside the scope of permission settings. This can not only achieve the purpose of risk mitigation, but also reduce the time for the vulnerability to be exploited.
[0124] In this embodiment, the access control method, including steps 110 to 150 above, first determines whether the access request information for the target resource object conforms to the restricted access rules when it is obtained and the access request information does not conform to the preset access policy. If the access request information conforms to the restricted access rules, it means that the target resource object corresponding to the access request information is a restricted access object whose communication interface should not be open. Therefore, it can be determined whether the communication interface of the target resource object is abnormally open based on whether the target resource object responds to the access request information. Thus, an access request information can be sent to the target resource object. When the target access response sent by the target resource object according to the access request information is received, it can be determined that the communication interface of the target resource object is abnormally open. At this time, the access request for the target resource object can be blocked, reducing the security risk of information leakage of the target resource object. In addition, an alarm can be set for the abnormally open communication interface of the target resource object, so that the administrator can close the communication interface of the target resource object to avoid information leakage, thereby improving the security of the target resource object. In other words, the embodiment of the present invention can quickly and effectively identify whether a resource is abnormally open, which is conducive to closing the communication interface of abnormally open resources in a timely manner, reducing the time for vulnerabilities to be exploited, avoiding information leakage, and thus improving the security of the resource.
[0125] It should be noted that in this embodiment, if the obtained access request information is Transmission Control Protocol (TCP) type traffic information, the proxy component can obtain the target access address, target access port, protocol type, and application information during the TCP connection stage with the business application client. Then, based on this information, it determines whether the access request information conforms to the preset access policy and whether it conforms to the restricted access rules. It is important to note that if the access request information does not conform to the preset access policy but conforms to the restricted access rules, blocking the access request information during the TCP connection stage will prevent the detection of whether the target resource object is abnormally open. To detect whether the target resource object is abnormally open, the proxy component will not block the access request information during the TCP connection stage. Instead, it will first establish a TCP connection with the business application client, and then attempt to establish a TCP connection with the target resource object to check whether a valid response is received from the target resource object. If a valid response is successfully received, it can be determined that the target resource object has an abnormal openness issue, which facilitates subsequent steps in implementing corresponding remedial measures for the target resource object, reducing the time for vulnerability exploitation, and improving the security of the target resource object. In addition, if the access request information obtained is User Datagram Protocol (UDP) type traffic information, although there is no connection process between the proxy component and the business application client, the proxy component can still determine whether the target resource object has an abnormal openness problem through connection interaction with the target resource object. This is beneficial for subsequent steps to perform corresponding remedial measures for the abnormally open target resource object, reduce the time for the vulnerability to be exploited, and improve the security of the target resource object.
[0126] In some possible implementations, after determining that the communication interface of the target resource object is abnormally open, a corresponding access blocking record can be generated and reported to the server. This allows the server to determine whether to update at least one of the access policy and restricted access rules based on the access blocking record. Although access request information targeting the target resource object can determine whether its communication interface is abnormally open, such requests may be initiated due to user error or unfamiliarity with access policies and restricted access rules. Therefore, it cannot be determined whether the access request is an illegal access request. To effectively analyze this access request information, a corresponding access blocking record can be generated based on the blocking process, and then reported to the server. This allows the server to analyze the access request information based on the access blocking record to determine whether it is an illegal access request. Furthermore, the analysis can determine the rationality and comprehensiveness of the current access policy and restricted access rules, thereby determining whether at least one of the access policy and restricted access rules needs to be updated. For example, suppose user B, in position A, has an access policy that allows access to resource object C, which includes ports C1 and C2. The restricted access rule includes port C2, meaning port C2 is easily exploited. User B is only allowed to access resource object C through port C1. When user B moves from position A to a different position D, both the access policy and the restricted access rule change. The new access policy no longer allows user B to access resource object C, and the new restricted access rule includes port C1. However, due to work requirements, user B needs to access resource object C through port C1. But according to the new access policy and the new restricted access rule, user B's access request will be considered to violate the new access policy and the new restricted access rule. Therefore, user B's access request will be blocked. However, user B's access request is not an illegal access request. To determine when... The rationality and comprehensiveness of the previous access policy and restricted access rules can be assessed by generating corresponding access blocking records based on the access request information and then reporting these records to the server. When the server determines that the current access policy and restricted access rules are unreasonable based on these records, it can update them accordingly. For example, a new access policy can be added to allow access to resource object C, and port C1 can be removed from the new restricted access rules. This makes the new access policy and new restricted access rules for user B more rational and comprehensive, allowing user B to access resource object C normally through port C1 without being blocked.
[0127] In some possible implementations, after sending an access request to the target resource object, if no target access response is received from the target resource object based on the access request, a first access record can be generated based on the access request, and then reported to the server. This allows the server to determine whether to update at least one of the access policy and restricted access rules based on the first access record. Since the target resource object may respond differently, such as denying or allowing access, depending on the preset access policy and the target resource object's operating state, the absence of a target access response from the target resource object indicates that the target resource object has denied or failed access according to the preset access policy. Therefore, it can be concluded that the target resource object is not abnormally open. Although it has been determined that the target resource object is not abnormally open, it cannot be determined whether the access request is an illegal access request. In order to effectively analyze the access request information, a corresponding first access record can be generated based on the access request information, and then the first access record can be reported to the server. The server can then analyze the access request information based on the first access record to determine whether the access request is illegal. At the same time, the analysis of the access request information can also determine the rationality and comprehensiveness of the current access policy and restricted access rules, thereby determining whether at least one of the access policy and restricted access rules needs to be updated. It should be noted that when no target access response is received from the target resource object based on the access request information, it means that the target resource object has rejected the access request information. In this case, the access response sent by the target resource object (such as an access denial or access failure response) can be returned to the access initiator of the access request information (such as the business application client in the terminal) to inform the access initiator that the access request information it initiated has been rejected or failed. Alternatively, a custom access blocking response (such as an access denial message) can be constructed and then sent to the access initiator to inform the access initiator that the access request information it initiated has been rejected or failed.
[0128] In some possible implementations, when determining whether an access request conforms to restricted access rules, if the access request does not conform, a second access record can be generated based on the access request, and then reported to the server. This allows the server to determine whether to update at least one of the access policy and restricted access rules based on the second access record. Although the access request does not conform to the restricted access rules—meaning the target resource object corresponding to the access request is not easily obtained illegally—the access request still falls under the category of an access request that does not conform to the preset access policy. Therefore, the current access request should be blocked. While it can be determined that the access request needs to be blocked, it may be due to a user's erroneous operation or a user's unfamiliarity with the access policy and restricted access rules. Therefore, it cannot be determined whether the access request is an illegal access request. To effectively analyze the access request information, a corresponding second access record can be generated based on the request information. This second access record is then reported to the server, allowing the server to analyze the access request information to determine whether it constitutes an illegal access request. Furthermore, the analysis can determine the rationality and comprehensiveness of the current access policy and restricted access rules, thereby determining whether at least one of the access policy and restricted access rules needs to be updated. For example, suppose user B, who holds a position A, has an access policy that allows access to resource object C, which includes ports C1 and C2. The restricted access rule includes port C2, meaning that port C2 is easily exploited, and user B is only allowed to access resource object C through port C1.When User B moves from position A to a different position D, and due to work requirements, the resource object that User B frequently accesses changes from C to E, the access policy and restricted access rules for User B have not been updated in time. Therefore, when User B accesses resource object E, the access request initiated by User B will be considered to be inconsistent with the access policy. Although the access request does not conform to the restricted access rules, it will still be blocked. However, the access request initiated by User B is not an illegal access request. In order to determine the rationality and comprehensiveness of the current access policy and restricted access rules, a corresponding second access record can be generated based on the access request information, and then the second access record can be reported to the server. When the server determines that the current access policy and restricted access rules are unreasonable based on the second access record, the server can update the current access policy and restricted access rules based on the second access record. For example, the access policy can be modified to allow access to resource object E, and the restricted access rules can be updated accordingly, making the new access policy and new restricted access rules for User B more rational and comprehensive. In this way, User B can access resource object E normally without being blocked.
[0129] In some possible implementations, when determining whether access request information conforms to a preset access policy, if the access request information conforms to the access policy, a third access record can be generated based on the access request information, and then the third access record is reported to the server. This allows the server to determine whether to update at least one of the access policy and restricted access rules based on the third access record. Because the access request information conforms to the access policy, data interaction between the initiator of the access request and the target resource object is allowed. In this case, to effectively utilize these access behaviors to optimize and adjust the access policy, a corresponding third access record can be generated based on the access request information, and then the third access record is reported to the server. This allows the server to analyze the current access policy and restricted access rules based on the received third access record, determine the rationality and comprehensiveness of the current access policy and restricted access rules, and thus determine whether to update at least one of the access policy and restricted access rules. For example, suppose the access policy includes 10 resource objects, but after analyzing all the third access records, it is found that only 4 of the resource objects are frequently accessed. Therefore, it can be determined that the existing access policy including 10 resource objects is unreasonable, and thus it can be determined that the existing access policy needs to be updated. For example, suppose the access strategy includes 10 resource objects, and based on the analysis of all third-party access records, it is found that 9 resource objects are frequently accessed. Then it can be determined that the existing access strategy is relatively reasonable and comprehensive, and therefore it can be determined that there is no need to update the existing access strategy.
[0130] In some possible implementations, when judging whether the access request information conforms to the preset access policy, if the access request information conforms to the access policy, it means that the access behavior corresponding to the access request information is a normal access behavior. At this time, the proxy component in the terminal can send the access request information to the target resource object through the gateway. When the target resource object receives the access request information, the target resource object will return the corresponding first access response (such as response information or data resource or business resource information corresponding to the access request information) to the gateway according to the access request information. After the gateway receives the first access response returned by the target resource object, the gateway will send the first access response to the access initiator of the access request information (such as the business application client), thereby realizing the data interaction between the access initiator and the target resource object. When the proxy component sends the access request information to the target resource object through the gateway, it can first obtain the access initiator's characteristic information (such as application characteristic information of the business application client, terminal device information, current authenticated user information, and environment status information). Then, based on this characteristic information, it obtains access credentials. After obtaining the access credentials, it sends the access credentials and the access request information to the gateway. When the gateway receives the access credentials and the access request information, it first verifies the access credentials. If the gateway passes the verification, it then sends the access request information to the target resource object. During the process of the proxy component obtaining access credentials based on the access initiator's characteristic information, the proxy component can first send this characteristic information to the server (such as a management server), allowing the server to first verify the access initiator's permissions based on this characteristic information. If the server passes the permission verification, it sends the corresponding access credentials to the proxy component.
[0131] While related technologies have proposed using periodic proactive scanning to detect whether resource objects are abnormally open, in practical applications, the time interval between a resource object becoming abnormally open and being illegally probed and exploited is very short. Periodic proactive scanning is insufficient to scan all services and ports within a short period, resulting in untimely protection responses. To address this issue, some possible implementations can use a proxy component in the terminal to converge access traffic. This traffic is compared with the response traffic returned by the target resource object. If the comparison determines that the target resource object corresponding to the access traffic is abnormally open, the access traffic is directly blocked. Simultaneously, the corresponding blocking record is reported to the server, and administrators are notified via alert emails, phone calls, SMS messages, or multimedia messages to promptly analyze such abnormal communication behavior outside the authorized scope. This not only achieves risk mitigation but also reduces the time before vulnerabilities are exploited.
[0132] The principle of the access control method provided in this embodiment of the invention will be fully explained below with a specific example.
[0133] Reference Figure 8 , Figure 8 The complete flowchart of the access control method provided in the embodiment of the present invention specifically includes the following steps 801 to 814.
[0134] Step 801: Obtain access request information.
[0135] Step 802: Parse the access request information to determine the resource object to be accessed corresponding to the access request information.
[0136] Step 803: Determine whether the resource object to be accessed is the target resource object. If yes, proceed to step 804; otherwise, proceed to step 810.
[0137] Step 804: Determine whether the access request information conforms to the preset access policy. If yes, proceed to step 811; otherwise, proceed to step 805.
[0138] Step 805: Determine whether the access request information complies with the restricted access rules. If yes, proceed to step 806; otherwise, proceed to step 810.
[0139] Step 806: Send an access request to the target resource object.
[0140] Step 807: Determine whether an access response has been received from the target resource object based on the access request information. If yes, proceed to step 808; otherwise, proceed to step 812.
[0141] Step 808: Determine whether the access response sent by the target resource object is a valid target access response. If yes, proceed to step 809; otherwise, proceed to step 812.
[0142] Step 809: Determine that the communication interface of the target resource object is abnormally open, discard the target access response, construct a custom access blocking response, send the access blocking response to the access initiator of the access request information, block the access request initiated by the access initiator to the target resource object, and alert that the communication interface of the target resource object is abnormally open, then jump to step 813.
[0143] Step 810: Block the access request information or allow the initiator of the access request information to directly access the resource object to be accessed, and jump to step 812.
[0144] Step 811: Implement data interaction with the target resource object through the gateway, and then proceed to step 812.
[0145] In this step, during the data interaction with the target resource object through the gateway, the proxy component in the terminal can first obtain the characteristic information of the access initiator (such as the application characteristic information of the business application client, the terminal's device information, the current authenticated user information, and the environment status information, etc.), and then obtain access credentials based on these characteristic information. After obtaining the access credentials, the access credential and the access request information are sent to the gateway. When the gateway receives the access credential and the access request information, it will first verify the access credential. If the gateway passes the verification of the access credential, it will then send the access request information to the target resource object. When the target resource object receives the access request information, it will return the corresponding first access response (such as response information or data resource or business resource information corresponding to the access request information) to the gateway based on the access request information. After the gateway receives the first access response returned by the target resource object, it will send the first access response to the access initiator of the access request information (such as the business application client), thereby realizing the data interaction between the access initiator and the target resource object. In the process of the proxy component obtaining access credentials based on the access initiator's characteristic information, the proxy component can first send this characteristic information to the server (such as the management server), so that the server can first verify the access initiator's permissions based on this characteristic information. When the server passes the access initiator's permission verification, the server will send the corresponding access credentials to the proxy component.
[0146] Step 812: Generate the corresponding access record based on the access request information, report the access record to the server for analysis, so that the server can determine whether to update at least one of the access policy and restricted access rules, and then jump to step 814.
[0147] Step 813: Generate an access blocking record and report the access blocking record to the server, so that the server can determine whether to update at least one of the access policy and restricted access rules based on the access blocking record, and then proceed to step 814.
[0148] Step 814: Processing complete.
[0149] The following examples illustrate the application scenarios of the embodiments of the present invention.
[0150] Scene 1
[0151] The access control method provided in this invention can be applied to scenarios where resource objects are passively detected as abnormally open. Specifically, when a user accesses a target resource object through a business application client on a terminal according to business needs, the proxy component in the terminal first obtains the access request information for the target resource object, and then determines whether the access request information conforms to a preset access policy. If the access request information does not conform to the preset access policy, it determines whether the access request information conforms to restricted access rules. If the access request information conforms to restricted access rules, the proxy component directly sends the access request information to the target resource object. In response to receiving the access request information, the target resource object returns a corresponding access response to the proxy component. Upon receiving an access response from the target resource object, the proxy component determines whether the response is associated with the access request information. If the response is associated, it confirms that the target resource object has sent a target access response based on the access request information. At this point, the proxy component determines that the target resource object's communication interface is abnormally open. Therefore, the proxy component discards the target access response, constructs a custom access blocking response, and sends it to the business application client, blocking the client's access request to the target resource object. It also alerts the administrator that the target resource object's communication interface is abnormally open, enabling the administrator to promptly close the abnormally open interface and prevent information leakage. Furthermore, the proxy component generates an access blocking record for this action and reports it to the server. This record allows the server to determine whether to update at least one of the access policy and restricted access rules.
[0152] Scene 2
[0153] The access control method provided in this embodiment of the invention can be applied to detection scenarios where resource objects are actively detected as abnormally open. Specifically, the detection personnel send an access request to the target resource object through a business application client in the terminal. This access request is configured to not conform to a preset access policy but conform to restricted access rules. After the business application client sends the access request, the proxy component in the terminal obtains the access request and then determines whether the access request conforms to the preset access policy. Since the access request is configured to not conform to the preset access policy, the result is that the access request does not conform to the preset access policy. At this time, the proxy component determines whether the access request conforms to the restricted access rules. Since the access request is configured to conform to the restricted access rules, the result is that the access request conforms to the restricted access rules. Then, the proxy component directly sends the access request to the target resource object. In response to receiving the access request, The target resource object returns a corresponding access response to the proxy component. Upon receiving the access response, the proxy component determines whether the response is associated with the access request information. If the response is associated, it confirms that the target resource object has sent a target access response based on the access request information. At this point, the proxy component determines that the target resource object's communication interface is abnormally open. Therefore, the proxy component discards the target access response, constructs a custom access blocking response, and sends it to the business application client, blocking the client's access request to the target resource object. It also alerts the testing personnel that the target resource object's communication interface is abnormally open. Thus, when the testing personnel receive this alert, they can confirm that the target resource object has an abnormally open issue, achieving the goal of proactively detecting abnormally open resource objects. The testing personnel can then promptly close the abnormally open target resource object's communication interface to prevent information leakage. Furthermore, the proxy component generates an access blocking record for this blocking action and reports it to the server. This allows the server to determine whether to update at least one of the access policy and restricted access rules based on the access blocking record.
[0154] Reference Figure 9 The present invention also discloses an access control device 900, which is capable of implementing the access control method as described in the preceding embodiments. The access control device 900 includes:
[0155] The request acquisition unit 910 is used to acquire access request information for the target resource object;
[0156] The rule acquisition unit 920 is used to determine whether the access request information conforms to the restricted access rules when the access request information does not conform to the preset access policy.
[0157] The request sending unit 930 is used to send access request information to the target resource object when the access request information conforms to the restricted access rules.
[0158] The anomaly determination unit 940 is used to determine that the communication interface of the target resource object is abnormally open when it receives a target access response sent by the target resource object according to the access request information.
[0159] The exception handling unit 950 is used to block access requests to the target resource object and to alert that the communication interface of the target resource object is abnormally open.
[0160] In one embodiment, the anomaly determination unit 940 is further configured to:
[0161] When a target access response is received from the target resource object based on the access request information, it is determined whether the target access response is associated with the access request information.
[0162] When the target access response is associated with the access request information, it is determined that the communication interface of the target resource object is abnormally open.
[0163] In one embodiment, the exception handling unit 950 is further configured to:
[0164] Discard the target access response;
[0165] Send an access blocking response to the initiator of the access request information, blocking the access request initiated by the initiator to the target resource object.
[0166] In one embodiment, the access control device 900 further includes:
[0167] The blocking record generation unit is used to generate access blocking records;
[0168] The blocking record reporting unit is used to report access blocking records to the server, so that the server can determine whether to update at least one of the access policy and restricted access rules based on the access blocking records.
[0169] In one embodiment, the access control device 900 further includes:
[0170] The first record generation unit is used to generate a first access record based on the access request information when no target access response is received from the target resource object based on the access request information.
[0171] The first record reporting unit is used to report the first access record to the server, so that the server can determine whether to update at least one of the access policy and restricted access rules based on the first access record.
[0172] In one embodiment, the access control device 900 further includes:
[0173] The second record generation unit is used to generate a second access record based on the access request information when the access request information does not conform to the restricted access rules.
[0174] The second record reporting unit is used to report the second access record to the server, so that the server can determine whether to update at least one of the access policy and restricted access rules based on the second access record.
[0175] In one embodiment, the access control device 900 further includes:
[0176] The access record acquisition unit is used to acquire the target access records for the target resource object set;
[0177] The access record reporting unit is used to report the target access record to the server, so that the server can generate restricted access rules based on the target access record;
[0178] The access rule receiving unit is used to receive restricted access rules issued by the server.
[0179] In one embodiment, the access control device 900 further includes:
[0180] The third record generation unit is used to generate a third access record based on the access request information when the access request information conforms to the access policy.
[0181] The third record reporting unit is used to report a third access record to the server, so that the server can determine whether to update at least one of the access policy and restricted access rules based on the third access record.
[0182] In one embodiment, the access control device 900 further includes:
[0183] The information sending unit is used to send access request information to the target resource object through the gateway when the access request information conforms to the access policy.
[0184] The response acquisition unit is used to acquire the first access response sent by the gateway, wherein the first access response is sent to the gateway by the target resource object according to the access request information;
[0185] The response sending unit is used to send the first access response to the access initiator.
[0186] In one embodiment, the information sending unit is further configured to:
[0187] Obtain the characteristic information of the access initiator;
[0188] Obtain access credentials based on feature information;
[0189] Send access credentials and access request information to the gateway, so that the gateway, after verifying the access credentials, sends access request information to the target resource object.
[0190] In one embodiment, the information sending unit is further configured to:
[0191] Send characteristic information to the server so that the server can verify the access initiator's permissions based on the characteristic information;
[0192] Obtain the access credentials sent by the server, which are generated by the server after the access initiator's permissions have been verified.
[0193] It should be noted that since the access control device 900 of this embodiment can implement the access control method as described in the previous embodiment, the access control device 900 of this embodiment has the same technical principle and the same beneficial effect as the access control method described in the previous embodiment. To avoid repetition, it will not be described again here.
[0194] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs.
[0195] Reference Figure 10 The present invention also discloses an access control device, the access control device 1000 comprising:
[0196] At least one processor 1001;
[0197] At least one memory 1002 is used to store at least one program;
[0198] When at least one program is executed by at least one processor 1001, the access control method as described in any of the preceding embodiments is implemented.
[0199] This invention also discloses a computer-readable storage medium storing a processor-executable program, which, when executed by a processor, is used to implement the access control method as described in any of the preceding embodiments.
[0200] This invention also discloses a computer program product, including a computer program or computer instructions, which are stored in a computer-readable storage medium. A processor of a computer device reads the computer program or computer instructions from the computer-readable storage medium and executes the computer program or computer instructions, causing the computer device to perform the access control method as described in any of the preceding embodiments.
[0201] The terms “first,” “second,” “third,” “fourth,” etc. (if present) in the specification and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that embodiments of the invention described herein can be implemented, for example, in orders other than those illustrated or described herein. Furthermore, the terms “comprising” and “having,” and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatuses.
[0202] It should be understood that in this invention, "at least one (item)" refers to one or more, and "more than one" refers to two or more. "And / or" describes the relationship between related objects, indicating that three relationships can exist. For example, "A and / or B" can represent three cases: only A exists, only B exists, and both A and B exist simultaneously, where A and B can be singular or plural. The character " / " generally indicates that the preceding and following related objects are in an "or" relationship. "At least one (item) of the following" or similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one (item) of a, b, or c can represent: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, and c can be single or multiple.
[0203] In the several embodiments provided by this invention, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the couplings or direct couplings or communication connections shown or discussed may be indirect couplings or communication connections through some interfaces, apparatuses, or units, and may be electrical, mechanical, or other forms.
[0204] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0205] Furthermore, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0206] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0207] The step numbers in the above method embodiments are set only for ease of explanation and do not limit the order of the steps. The execution order of each step in the embodiments can be adaptively adjusted according to the understanding of those skilled in the art.
Claims
1. An access control method, characterized in that, Includes the following steps: Obtain access request information for the target resource object; If the access request information does not conform to the preset access policy, the access request information is judged to determine whether it conforms to the restricted access rules; When the access request information matches the restricted access rule, the access request information is sent to the target resource object; When a target access response is received from the target resource object based on the access request information, it is determined that the communication interface of the target resource object is abnormally open. Block access requests to the target resource object and issue a warning that the target resource object's communication interface is abnormally open.
2. The access control method according to claim 1, characterized in that, The step of determining that the communication interface of the target resource object is abnormally open upon receiving a target access response sent by the target resource object according to the access request information includes: When a target access response is received from the target resource object based on the access request information, it is determined whether the target access response is associated with the access request information; When the target access response is associated with the access request information, it is determined that the communication interface of the target resource object is abnormally open.
3. The access control method according to claim 1, characterized in that, The blocking of access requests to the target resource object includes: Discard the target access response; Send an access blocking response to the initiator of the access request information to block the access request initiated by the initiator to the target resource object.
4. The access control method according to claim 1, characterized in that, After determining that the communication interface of the target resource object is abnormally open, the access control method further includes: Generate access blocking record; The access blocking record is reported to the server, so that the server determines whether to update at least one of the access policy and the restricted access rule based on the access blocking record.
5. The access control method according to claim 1, characterized in that, After sending the access request information to the target resource object, the access control method further includes: If no target access response is received from the target resource object based on the access request information, a first access record is generated based on the access request information. The first access record is reported to the server, so that the server determines whether to update at least one of the access policy and the restricted access rule based on the first access record.
6. The access control method according to claim 1, characterized in that, The access control method further includes: If the access request information does not conform to the restricted access rule, a second access record is generated based on the access request information; The second access record is reported to the server, so that the server determines whether to update at least one of the access policy and the restricted access rule based on the second access record.
7. The access control method according to claim 1, characterized in that, The restricted access rules are obtained according to the following steps: Retrieve the target access records for the target set of resource objects; The target access record is reported to the server, so that the server generates the restricted access rule based on the target access record; Receive the restricted access rules issued by the server.
8. The access control method according to claim 1, characterized in that, The access control method further includes: When the access request information matches the access policy, a third access record is generated based on the access request information; The third access record is reported to the server, so that the server determines whether to update at least one of the access policy and the restricted access rule based on the third access record.
9. The access control method according to claim 1, characterized in that, The access control method further includes: When the access request information matches the access policy, the access request information is sent to the target resource object through the gateway; Obtain the first access response sent by the gateway, wherein the first access response is sent by the target resource object to the gateway according to the access request information; Send the first access response to the access initiator.
10. The access control method according to claim 9, characterized in that, Sending the access request information to the target resource object through the gateway includes: Obtain the characteristic information of the access initiator; Obtain access credentials based on the aforementioned feature information; The access credential and the access request information are sent to the gateway, so that the gateway, after verifying the access credential, sends the access request information to the target resource object.
11. The access control method according to claim 10, characterized in that, The step of obtaining access credentials based on the feature information includes: The feature information is sent to the server, enabling the server to perform permission verification on the access initiator based on the feature information; Obtain the access credentials sent by the server, wherein the access credentials are generated by the server after passing the permission verification of the access initiator.
12. An access control device, characterized in that, include: The request retrieval unit is used to retrieve access request information for the target resource object. The rule acquisition unit is used to determine whether the access request information conforms to the restricted access rule when the access request information does not conform to the preset access policy. A request sending unit is configured to send the access request information to the target resource object when the access request information conforms to the restricted access rule. An anomaly determination unit is used to determine that the communication interface of the target resource object is abnormally open when it receives a target access response sent by the target resource object according to the access request information. An anomaly handling unit is used to block access requests to the target resource object and to alert that the communication interface of the target resource object is abnormally open.
13. An access control device, characterized in that, include: At least one processor; At least one memory for storing at least one program; The access control method as described in any one of claims 1 to 11 is implemented when at least one of the programs is executed by at least one of the processors.
14. A computer-readable storage medium, characterized in that, It stores a processor-executable program, which, when executed by a processor, is used to implement the access control method as described in any one of claims 1 to 11.
15. A computer program product, comprising a computer program or computer instructions, characterized in that, The computer program or the computer instructions are stored in a computer-readable storage medium, the processor of the computer device reads the computer program or the computer instructions from the computer-readable storage medium, and the processor executes the computer program or the computer instructions, causing the computer device to perform the access control method as described in any one of claims 1 to 11.
Citation Information
Patent Citations
Systems, methods, and media for authorizing external network access requests
EP3890271A1
Cloud-based web application and API protection
US20210336934A1