A security protection method and system based on protocol controller and security gateway
By working together with the protocol controller and security gateway, deep packet inspection and dynamic policy adjustment of network traffic are achieved, solving the problems of low accuracy and poor adaptability of network security protection, and improving security and resource utilization efficiency.
Patent Information
- Application Number
- CN202310583772.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-05-19
- Publication Date
- 2025-10-31
- Estimated Expiration
- 2043-05-19
AI Technical Summary
Existing network security protection technologies have low precision and poor adaptability, and cannot effectively cope with complex network environments.
By performing deep packet inspection on network traffic through the protocol controller, basic information and communication protocol classification results are obtained. Combined with the failure rate and risk information of deep packet inspection, a policy control mode is selected. The security gateway performs deep inspection and adjusts the inspection granularity to achieve dynamic adjustment of security policies.
It improves the accuracy and adaptability of security protection, saves computing resources, and ensures the reliability of protection.
Smart Images

Figure CN117118652B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network security technology, and more specifically, to a security protection method and system based on a protocol controller and a security gateway. Background Technology
[0002] In today's internet age, cybersecurity threats are becoming increasingly complex and diverse, posing risks to enterprises and organizations from both internal and external sources, including cyberattacks, malware, data breaches, and intrusions. To protect network and system security and improve the confidentiality, integrity, and availability of information assets, protocol controllers and security gateways have become increasingly widely used as important security technologies.
[0003] In existing technologies, due to the complexity of network security environments, fixed security protection strategies can no longer meet the needs of complex network environments, resulting in low protection effectiveness and poor adaptability of network security protection.
[0004] Therefore, how to improve the accuracy and adaptability of network security protection is a technical problem that needs to be solved. Summary of the Invention
[0005] This invention provides a security protection method based on a protocol controller and a security gateway, to solve the technical problems of low accuracy and poor adaptability in existing network security protection technologies. The method includes:
[0006] By performing deep packet inspection on network traffic through a protocol controller, basic network traffic information and communication protocol classification results can be obtained.
[0007] The failure rate of deep packet inspection is determined based on basic network traffic information, security protection targets are obtained, and policy and risk information of communication protocols are collected based on the security protection targets and communication protocol classification results.
[0008] Based on the failure rate and risk information of deep packet inspection, a strategy control mode is selected, and under different strategy control modes, a security policy is determined based on the strategy information.
[0009] The security gateway performs in-depth inspections of traffic for various communication protocols using security policies and takes security protection measures based on the results of the in-depth inspections.
[0010] Obtain logs generated by the deep inspection of the security gateway, and adjust the granularity of the inspection based on the logs generated by the deep inspection of the security gateway.
[0011] In some embodiments of this application, a protocol controller performs deep packet inspection on network traffic to obtain basic network traffic information and communication protocol classification results, including:
[0012] Obtain the message content of network traffic. The message content includes the message header content and the message payload content. Determine the communication protocol type based on the message header content and the message payload content, and record it as the first communication protocol type.
[0013] Obtain the protocol characteristics corresponding to the network traffic, determine the communication protocol type based on the protocol characteristics, and record it as the second communication protocol type;
[0014] Obtain network traffic behavior, determine the communication protocol type based on the network traffic behavior, and record it as the third communication protocol type;
[0015] Obtain the port and protocol number of the network traffic, determine the communication protocol type based on the port and protocol number, and record it as the fourth communication protocol type;
[0016] If the first, second, third, and fourth communication protocol types are all the same, then the communication protocol classification result is determined.
[0017] If the first, second, third, and fourth communication protocol types are different, then the communication protocol types that are the same are selected and used as the communication protocol classification result.
[0018] In some embodiments of this application, the failure rate of deep packet inspection is determined based on basic network traffic information, including:
[0019] Basic network traffic information includes communication protocol MTU, actual packet size, packet fragmentation information, and encryption information;
[0020] If the actual size of the data packet is larger than the communication protocol MTU, the data packet needs to be fragmented, and the failure rate of deep packet inspection is determined based on the data packet fragmentation information.
[0021] If the actual size of the data packet is not greater than the communication protocol MTU, the data packet does not need to be fragmented, and the failure rate of deep packet inspection is determined based on the encryption information.
[0022] In some embodiments of this application, the failure rate of deep packet inspection is determined based on packet fragmentation information, including:
[0023] The data includes fragmentation information, including the number of fragments, fragment offset, and payload content;
[0024] The payload content is analyzed to determine the degree of flow mixing.
[0025] The fragment calibration amount is obtained by considering the number of fragments, fragment offset, and traffic mixing level.
[0026] ;
[0027] Where P is the number of fragments to be checked. The conversion factor corresponds to the number of fragments. Let be the number of fragments, and exp be an exponential function. To determine the degree of traffic mixing, As a preset constant, The conversion factor is the value corresponding to the fragment offset. This is the fragment offset;
[0028] The failure rate of deep packet inspection is determined based on the number of fragments checked, where each fragment check corresponds to a failure rate for deep packet inspection.
[0029] In some embodiments of this application, the failure rate of deep packet inspection is determined based on encrypted information, including:
[0030] Encrypted information includes protocol variants and obfuscation;
[0031] The failure rate of deep packet inspection is determined based on protocol variants and obfuscation.
[0032] In some embodiments of this application, the strategy control mode selected based on the failure rate and risk information of deep packet inspection includes:
[0033] Risk information refers to risk influencing factors, and strategy control models include stationary strategy control models and dynamic strategy control models;
[0034] Risk levels are determined based on risk influencing factors;
[0035] ;
[0036] Where L represents the risk level, and n represents the number of risk influencing factors. Let i be the weight corresponding to the i-th risk factor. Let i be the parameter size corresponding to the i-th influencing factor. for The minimum value in the middle. The integer symbol;
[0037] The failure risk level is determined based on the failure rate and risk level of deep packet inspection;
[0038] ;
[0039] Where K represents the failure risk level, Here, E represents the failure rate of deep packet inspection, and the conversion factor corresponding to the failure rate is denoted as E. To preset the failure rate threshold, A conversion system corresponding to risk levels. The preset risk level threshold is defined by k, which is a preset constant. The integer symbol;
[0040] If the failure risk level does not exceed the failure risk level threshold, then the steady-state strategy control mode is selected;
[0041] If the failure risk level exceeds the failure risk level threshold, then the dynamic strategy control mode is selected.
[0042] In some embodiments of this application, under different policy control modes, a security policy is determined based on policy information, including:
[0043] Strategy information refers to information related to strategy formulation;
[0044] In the stationary policy control mode, security policies are set based on information related to policy formulation;
[0045] In dynamic policy control mode, an initial security policy is set based on information related to policy formulation, and the initial security policy is dynamically adjusted according to the failure risk level.
[0046] In some embodiments of this application, the granularity of the inspection is adjusted based on the logs generated by the deep inspection of the security gateway, including:
[0047] The network security status is determined based on the logs generated by the deep inspection of the security gateway. The actual network security status is obtained, and the security status deviation is determined based on the detected network security status and the actual network security status. The security status deviation is the deviation between the detected network security status and the actual network security status.
[0048] Establish a deviation change curve based on the deviation of the safety status, and refine the granularity of the security gateway depth inspection based on the deviation of the deviation change curve above the first calibration deviation level.
[0049] The granularity of the security gateway depth inspection is coarsened based on the deviation amount of the deviation amount change curve below the second calibration deviation amount level.
[0050] Among them, the first calibration deviation level is higher than the second calibration deviation level.
[0051] Correspondingly, this application also provides a security protection system based on a protocol controller and a security gateway, the system comprising:
[0052] The detection module is used to perform deep packet inspection on network traffic through the protocol controller to obtain basic network traffic information and communication protocol classification results;
[0053] The collection module is used to determine the failure rate of deep packet inspection based on basic network traffic information, obtain security protection targets, and collect policy and risk information of communication protocols based on the security protection targets and communication protocol classification results.
[0054] The control module is used to select the strategy control mode based on the failure rate and risk information of deep packet inspection, and to determine the security policy according to the strategy information under different strategy control modes.
[0055] The deep inspection module is used by the security gateway to perform deep inspections on traffic of various communication protocols through security policies and take security protection measures based on the deep inspection results.
[0056] The adjustment module is used to acquire logs generated by the deep inspection of the security gateway and adjust the granularity of the inspection based on the logs generated by the deep inspection of the security gateway.
[0057] By applying the above technical solutions, a protocol controller performs deep packet inspection on network traffic to obtain basic network traffic information and communication protocol classification results. Based on the basic network traffic information, the failure rate of deep packet inspection is determined, and security protection targets are obtained. Based on the security protection targets and communication protocol classification results, policy information and risk information of communication protocols are collected. Based on the failure rate and risk information of deep packet inspection, a policy control mode is selected. Under different policy control modes, security policies are determined based on the policy information. The security gateway performs deep inspection on the traffic of each communication protocol through the security policy and takes security protection measures based on the deep inspection results. Logs generated by the security gateway's deep inspection are obtained, and the granularity of the inspection is adjusted based on these logs. This application classifies protocols through a protocol controller and obtains corresponding policy and risk information, thereby selecting an appropriate policy control mode. The security gateway performs deep inspection on the traffic of each communication protocol through the security policy. This improves the accuracy and adaptability of security protection, saves computing resources, and ensures the reliability of protection. Attached Figure Description
[0058] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0059] Figure 1 A flowchart illustrating a security protection method based on a protocol controller and a security gateway, as proposed in an embodiment of the present invention, is shown.
[0060] Figure 2 The diagram shows a schematic of a security protection system based on a protocol controller and a security gateway, as proposed in an embodiment of the present invention. Detailed Implementation
[0061] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0062] This application provides a security protection method based on a protocol controller and a security gateway, such as... Figure 1 As shown, the method includes the following steps:
[0063] Step S101: Perform deep packet inspection on network traffic through the protocol controller to obtain basic network traffic information and communication protocol classification results.
[0064] In this embodiment, Deep Packet Inspection (DPI) is a technique for in-depth analysis of network traffic, capable of identifying and classifying different communication protocols. During the inspection process, it acquires basic network traffic information, including packet content, behavior, protocol characteristics, port, and protocol number.
[0065] In some embodiments of this application, a protocol controller performs deep packet inspection on network traffic to obtain basic network traffic information and communication protocol classification results, including:
[0066] Obtain the message content of network traffic. The message content includes the message header content and the message payload content. Determine the communication protocol type based on the message header content and the message payload content, and record it as the first communication protocol type.
[0067] Obtain the protocol characteristics corresponding to the network traffic, determine the communication protocol type based on the protocol characteristics, and record it as the second communication protocol type;
[0068] Obtain network traffic behavior, determine the communication protocol type based on the network traffic behavior, and record it as the third communication protocol type;
[0069] Obtain the port and protocol number of the network traffic, determine the communication protocol type based on the port and protocol number, and record it as the fourth communication protocol type;
[0070] If the first, second, third, and fourth communication protocol types are all the same, then the communication protocol classification result is determined.
[0071] If the first, second, third, and fourth communication protocol types are different, then the communication protocol types that are the same are selected and used as the communication protocol classification result.
[0072] In this embodiment, deep packet inspection typically uses a single method to analyze and determine the protocol type. To improve accuracy, four methods are employed for analysis: packet content of network traffic, network traffic behavior, protocol characteristics corresponding to network traffic, and port and protocol number of network traffic.
[0073] In this embodiment, the four methods are detailed as follows:
[0074] DPI (Device Profiling) technology allows for in-depth analysis of message content, including the message header and payload. The message header contains protocol identifiers, which can be used to quickly determine the protocol type. The payload contains the specific data of the protocol, which can further determine the protocol type.
[0075] Protocol characteristics: Each protocol has its own characteristics, such as protocol header, protocol identifier, data structure, data format, etc. DPI technology can quickly and accurately identify the protocol type by recognizing these characteristics.
[0076] Traffic behavior varies depending on the protocol, including connection establishment, data transmission, and connection termination. DPI technology can determine the protocol type by analyzing traffic behavior.
[0077] Port and protocol number: Some protocols have specific ports and protocol numbers. For example, port 80 of the TCP protocol is used for HTTP communication, and port 53 of the UDP protocol is used for DNS communication. DPI technology can identify the protocol type by recognizing the port and protocol number.
[0078] In this embodiment, the communication protocol types that are the same among the first, second, third, and fourth communication protocol types are used as the communication protocol classification results. For example, if the first, second, and third communication protocol types are all the same, and only the fourth communication protocol type is different from the first three, then the first, second, and third communication protocol types are used as the communication protocol classification results.
[0079] Step S102: Determine the failure rate of deep packet inspection based on basic network traffic information, obtain security protection targets, and collect policy information and risk information of communication protocols based on security protection targets and communication protocol classification results.
[0080] In this embodiment, deep packet inspection has a certain number of false positives and false negatives, which need to be taken into account in order to select the subsequent strategy control mode.
[0081] In this embodiment, the security protection objectives include preventing unauthorized access, detecting and blocking threats, and network traffic management. Collecting policy and risk information for communication protocols based on security protection objectives and communication protocol classification results refers to the policy and risk information related to different security protection objectives of the mobile phone and different communication protocols.
[0082] In some embodiments of this application, the failure rate of deep packet inspection is determined based on basic network traffic information, including:
[0083] Basic network traffic information includes communication protocol MTU, actual packet size, packet fragmentation information, and encryption information;
[0084] If the actual size of the data packet is larger than the communication protocol MTU, the data packet needs to be fragmented, and the failure rate of deep packet inspection is determined based on the data packet fragmentation information.
[0085] If the actual size of the data packet is not greater than the communication protocol MTU, the data packet does not need to be fragmented, and the failure rate of deep packet inspection is determined based on the encryption information.
[0086] In this embodiment, packet fragmentation and promiscuous traffic are the main factors affecting deep packet false positives. Before judging packet fragmentation and promiscuous traffic, it is first determined whether the packet needs to be fragmented. Under normal circumstances, IP packets are not fragmented. The IP protocol specifies the Maximum Transmission Unit (MTU), which is the maximum size of a packet allowed during transmission. If the size of the packet exceeds the MTU limit of a link or device on the network path, the packet will be fragmented so that it can be transmitted in the network.
[0087] In some embodiments of this application, the failure rate of deep packet inspection is determined based on packet fragmentation information, including:
[0088] The data includes fragmentation information, including the number of fragments, fragment offset, and payload content;
[0089] The payload content is analyzed to determine the degree of flow mixing.
[0090] The fragment calibration amount is obtained by considering the number of fragments, fragment offset, and traffic mixing level.
[0091] ;
[0092] Where P is the number of fragments to be checked. The conversion factor corresponds to the number of fragments. Let be the number of fragments, and exp be an exponential function. To determine the degree of traffic mixing, As a preset constant, The conversion factor is the value corresponding to the fragment offset. This is the fragment offset;
[0093] The failure rate of deep packet inspection is determined based on the number of fragments checked, where each fragment check corresponds to a failure rate for deep packet inspection.
[0094] In this embodiment, IP packets may be fragmented during transmission. The fragment number and fragment offset fields can be used to determine whether the packet is fragmented. If a protocol's packet is heavily fragmented, i.e., the number of fragments is large or the fragment offset is small, then the packet fragmentation level is considered high. The payload is the actual data portion carried in the packet; analyzing the payload content can determine whether promiscuous traffic exists.
[0095] In this embodiment, Adjustments to the number of fragments based on the degree of traffic mixing. This is a correction for the fragment offset based on the degree of traffic mixing. The value ranges from 0.1 to 0.16. The value ranges from 0.1 to 0.23.
[0096] In some embodiments of this application, the failure rate of deep packet inspection is determined based on encrypted information, including:
[0097] Encrypted information includes protocol variants and obfuscation;
[0098] The failure rate of deep packet inspection is determined based on protocol variants and obfuscation.
[0099] In this embodiment, malware and attackers may use protocol variants or obfuscation techniques to evade DPI detection. The presence of protocol variants and obfuscation is detected to determine a failure rate.
[0100] Step S103: Select a strategy control mode based on the failure rate and risk information of deep packet inspection, and determine the security strategy according to the strategy information under different strategy control modes.
[0101] In this embodiment, policy information refers to information related to policy formulation, which includes the current network environment, security threat situation, and existing security control measures. Risk information refers to risk influencing factors, which can be determined through methods such as security risk assessment, vulnerability scanning, and security incident analysis.
[0102] In this embodiment, the security strategy is to formulate specific strategies, which should include specific control measures, implementation methods, and operating procedures.
[0103] In some embodiments of this application, the strategy control mode selected based on the failure rate and risk information of deep packet inspection includes:
[0104] Risk information refers to risk influencing factors, and strategy control models include stationary strategy control models and dynamic strategy control models;
[0105] Risk levels are determined based on risk influencing factors;
[0106] ;
[0107] Where L represents the risk level, and n represents the number of risk influencing factors. Let i be the weight corresponding to the i-th risk factor. Let i be the parameter size corresponding to the i-th influencing factor. for The minimum value in the middle. The integer symbol;
[0108] The failure risk level is determined based on the failure rate and risk level of deep packet inspection;
[0109] ;
[0110] Where K represents the failure risk level, Here, E represents the failure rate of deep packet inspection, and the conversion factor corresponding to the failure rate is denoted as E. To preset the failure rate threshold, A conversion system corresponding to risk levels. The preset risk level threshold is defined by k, which is a preset constant. The integer symbol;
[0111] If the failure risk level does not exceed the failure risk level threshold, then the steady-state strategy control mode is selected;
[0112] If the failure risk level exceeds the failure risk level threshold, then the dynamic strategy control mode is selected.
[0113] In this embodiment, the policy control modes include a stationary policy control mode and a dynamic policy control mode. The stationary policy control mode is a security protection mode with fixed policies, suitable for situations with low failure risk and beneficial for resource conservation. The dynamic policy control mode is a security protection mode that dynamically adjusts policies, suitable for situations with high failure risk and capable of maintaining network security stability.
[0114] In this embodiment, the risk level indicates the degree of network risk; the higher the level, the greater the security risk. The failure risk level is a network security stability level that comprehensively considers the failure rate of deep packet inspection and the risk level; the lower the level, the more stable the network and the lower the security risk. Conversely, the same applies.
[0115] In some embodiments of this application, under different policy control modes, a security policy is determined based on policy information, including:
[0116] Strategy information refers to information related to strategy formulation;
[0117] In the stationary policy control mode, security policies are set based on information related to policy formulation;
[0118] In dynamic policy control mode, an initial security policy is set based on information related to policy formulation, and the initial security policy is dynamically adjusted according to the failure risk level.
[0119] In this embodiment, the initial security policy is dynamically adjusted according to the failure risk level. This can be adjusted based on the actual situation. For example, a failure risk level threshold can be set, and if the threshold is exceeded, the initial security policy can be adjusted.
[0120] In step S104, the security gateway performs a deep inspection of the traffic of each communication protocol through security policies and takes security protection measures based on the results of the deep inspection.
[0121] In this embodiment, the protocol controller can perform a preliminary security check on the network, while the security gateway can perform a more in-depth check with the help of the protocol controller, such as access control, vulnerability protection, and anti-virus measures.
[0122] Step S105: Obtain the logs generated by the deep inspection of the security gateway, and adjust the granularity of the inspection based on the logs generated by the deep inspection of the security gateway.
[0123] In this embodiment, the security gateway can also generate real-time logs and reports, facilitating subsequent adjustments to the inspection granularity. While excessively fine inspection granularity ensures high security accuracy, it consumes excessive resources. Conversely, excessively coarse inspection granularity, while consuming fewer resources, compromises security. Therefore, it is necessary to control the granularity within an appropriate range.
[0124] In some embodiments of this application, the granularity of the inspection is adjusted based on the logs generated by the deep inspection of the security gateway, including:
[0125] The network security status is determined based on the logs generated by the deep inspection of the security gateway. The actual network security status is obtained, and the security status deviation is determined based on the detected network security status and the actual network security status. The security status deviation is the deviation between the detected network security status and the actual network security status.
[0126] Establish a deviation change curve based on the deviation of the safety status, and refine the granularity of the security gateway depth inspection based on the deviation of the deviation change curve above the first calibration deviation level.
[0127] The granularity of the security gateway depth inspection is coarsened based on the deviation amount of the deviation amount change curve below the second calibration deviation amount level.
[0128] Among them, the first calibration deviation level is higher than the second calibration deviation level.
[0129] In this embodiment, the security status deviation is the accuracy of the network security status of the deep inspection. The smaller the deviation, the higher the accuracy, but the higher the resource consumption.
[0130] In this embodiment, the deviation change curve is a curve with the deviation amount on the vertical axis and time on the horizontal axis. The first and second calibration deviation horizontal lines are adjusted or set according to the actual situation.
[0131] In this embodiment, the portion of the deviation variation curve above the first calibration deviation level is used to finer the granularity of the security gateway deep inspection, indicating that the accuracy of the network security status obtained through deep inspection is low, which is detrimental to security protection. The portion below the second calibration deviation level is used to coarse the granularity of the security gateway deep inspection, indicating that the accuracy of the network security status obtained through deep inspection is too high, wasting a lot of resources. The portion between the first and second calibration deviation levels meets the requirements, causing the higher and lower portions to converge towards the first calibration deviation level.
[0132] By applying the above technical solutions, a protocol controller performs deep packet inspection on network traffic to obtain basic network traffic information and communication protocol classification results. Based on the basic network traffic information, the failure rate of deep packet inspection is determined, and security protection targets are obtained. Based on the security protection targets and communication protocol classification results, policy information and risk information of communication protocols are collected. Based on the failure rate and risk information of deep packet inspection, a policy control mode is selected. Under different policy control modes, security policies are determined based on the policy information. The security gateway performs deep inspection on the traffic of each communication protocol through the security policy and takes security protection measures based on the deep inspection results. Logs generated by the security gateway's deep inspection are obtained, and the granularity of the inspection is adjusted based on these logs. This application classifies protocols through a protocol controller and obtains corresponding policy and risk information, thereby selecting an appropriate policy control mode. The security gateway performs deep inspection on the traffic of each communication protocol through the security policy. This improves the accuracy and adaptability of security protection, saves computing resources, and ensures the reliability of protection.
[0133] Through the above description of the embodiments, those skilled in the art can clearly understand that the present invention can be implemented in hardware or by means of software plus necessary general-purpose hardware platforms. Based on this understanding, the technical solution of the present invention can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (such as a CD-ROM, USB flash drive, external hard drive, etc.) and includes several instructions to cause a computer device (such as a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments of the present invention.
[0134] To further illustrate the technical concept of this invention, the technical solution of this invention will now be described in conjunction with specific application scenarios.
[0135] Correspondingly, this application also provides a security protection system based on a protocol controller and a security gateway, such as... Figure 2 As shown, the system includes:
[0136] The detection module 201 is used to perform deep packet inspection on network traffic through the protocol controller to obtain basic network traffic information and communication protocol classification results;
[0137] The collection module 202 is used to determine the failure rate of deep packet inspection based on basic network traffic information, obtain security protection targets, and collect policy information and risk information of communication protocols based on security protection targets and communication protocol classification results;
[0138] Control module 203 is used to select a strategy control mode based on the failure rate and risk information of deep packet inspection, and to determine the security policy according to the strategy information under different strategy control modes.
[0139] The deep inspection module 204 is used by the security gateway to perform deep inspections on the traffic of various communication protocols through security policies and take security protection measures based on the deep inspection results.
[0140] The adjustment module 205 is used to acquire the logs generated by the deep inspection of the security gateway and adjust the granularity of the inspection based on the logs generated by the deep inspection of the security gateway.
[0141] In some embodiments of this application, the detection module 201 is used for:
[0142] Obtain the message content of network traffic. The message content includes the message header content and the message payload content. Determine the communication protocol type based on the message header content and the message payload content, and record it as the first communication protocol type.
[0143] Obtain the protocol characteristics corresponding to the network traffic, determine the communication protocol type based on the protocol characteristics, and record it as the second communication protocol type;
[0144] Obtain network traffic behavior, determine the communication protocol type based on the network traffic behavior, and record it as the third communication protocol type;
[0145] Obtain the port and protocol number of the network traffic, determine the communication protocol type based on the port and protocol number, and record it as the fourth communication protocol type;
[0146] If the first, second, third, and fourth communication protocol types are all the same, then the communication protocol classification result is determined.
[0147] If the first, second, third, and fourth communication protocol types are different, then the communication protocol types that are the same are selected and used as the communication protocol classification result.
[0148] In some embodiments of this application, the collection module 202 is used for:
[0149] Basic network traffic information includes communication protocol MTU, actual packet size, packet fragmentation information, and encryption information;
[0150] If the actual size of the data packet is larger than the communication protocol MTU, the data packet needs to be fragmented, and the failure rate of deep packet inspection is determined based on the data packet fragmentation information.
[0151] If the actual size of the data packet is not greater than the communication protocol MTU, the data packet does not need to be fragmented, and the failure rate of deep packet inspection is determined based on the encryption information.
[0152] In some embodiments of this application, the collection module 202 is used for:
[0153] The data includes fragmentation information, including the number of fragments, fragment offset, and payload content;
[0154] The payload content is analyzed to determine the degree of flow mixing.
[0155] The fragment calibration amount is obtained by considering the number of fragments, fragment offset, and traffic mixing level.
[0156] ;
[0157] Where P is the number of fragments to be checked. The conversion factor corresponds to the number of fragments. Let be the number of fragments, and exp be an exponential function. To determine the degree of traffic mixing, As a preset constant, The conversion factor is the value corresponding to the fragment offset. This is the fragment offset;
[0158] The failure rate of deep packet inspection is determined based on the number of fragments checked, where each fragment check corresponds to a failure rate for deep packet inspection.
[0159] In some embodiments of this application, the collection module 202 is used for:
[0160] Encrypted information includes protocol variants and obfuscation;
[0161] The failure rate of deep packet inspection is determined based on protocol variants and obfuscation.
[0162] In some embodiments of this application, the control module 203 is used for:
[0163] Risk information refers to risk influencing factors, and strategy control models include stationary strategy control models and dynamic strategy control models;
[0164] Risk levels are determined based on risk influencing factors;
[0165] ;
[0166] Where L represents the risk level, and n represents the number of risk influencing factors. Let i be the weight corresponding to the i-th risk factor. Let i be the parameter size corresponding to the i-th influencing factor. for The minimum value in the middle. The integer symbol;
[0167] The failure risk level is determined based on the failure rate and risk level of deep packet inspection;
[0168] ;
[0169] Where K represents the failure risk level, Here, E represents the failure rate of deep packet inspection, and the conversion factor corresponding to the failure rate is denoted as E. To preset the failure rate threshold, A conversion system corresponding to risk levels. The preset risk level threshold is defined by k, which is a preset constant. The integer symbol;
[0170] If the failure risk level does not exceed the failure risk level threshold, then the steady-state strategy control mode is selected;
[0171] If the failure risk level exceeds the failure risk level threshold, then the dynamic strategy control mode is selected.
[0172] In some embodiments of this application, the control module 203 is used for:
[0173] Strategy information refers to information related to strategy formulation;
[0174] In the stationary policy control mode, security policies are set based on information related to policy formulation;
[0175] In dynamic policy control mode, an initial security policy is set based on information related to policy formulation, and the initial security policy is dynamically adjusted according to the failure risk level.
[0176] In some embodiments of this application, the adjustment module 205 is used for:
[0177] The network security status is determined based on the logs generated by the deep inspection of the security gateway. The actual network security status is obtained, and the security status deviation is determined based on the detected network security status and the actual network security status. The security status deviation is the deviation between the detected network security status and the actual network security status.
[0178] Establish a deviation change curve based on the deviation of the safety status, and refine the granularity of the security gateway depth inspection based on the deviation of the deviation change curve above the first calibration deviation level.
[0179] The granularity of the security gateway depth inspection is coarsened based on the deviation amount of the deviation amount change curve below the second calibration deviation amount level.
[0180] Among them, the first calibration deviation level is higher than the second calibration deviation level.
[0181] Those skilled in the art will understand that the modules in the system of the implementation scenario can be distributed throughout the system of the implementation scenario as described, or they can be modified to reside in one or more systems different from this implementation scenario. The modules of the above-mentioned implementation scenario can be merged into one module, or they can be further divided into multiple sub-modules.
[0182] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application.
Claims
1. A security protection method based on a protocol controller and a security gateway, characterized in that, The method includes: By performing deep packet inspection on network traffic through a protocol controller, basic network traffic information and communication protocol classification results can be obtained. The failure rate of deep packet inspection is determined based on basic network traffic information, security protection targets are obtained, and policy and risk information of communication protocols are collected based on the security protection targets and communication protocol classification results. Based on the failure rate and risk information of deep packet inspection, a strategy control mode is selected, and under different strategy control modes, a security policy is determined based on the strategy information. The security gateway performs in-depth inspections of traffic for various communication protocols using security policies and takes security protection measures based on the results of the in-depth inspections. Obtain logs generated by the deep inspection of the security gateway, and adjust the granularity of the inspection based on the logs generated by the deep inspection of the security gateway.
2. The security protection method based on protocol controller and security gateway as described in claim 1, characterized in that, By performing deep packet inspection on network traffic through a protocol controller, basic network traffic information and communication protocol classification results are obtained, including: Obtain the message content of network traffic. The message content includes the message header content and the message payload content. Determine the communication protocol type based on the message header content and the message payload content, and record it as the first communication protocol type. Obtain the protocol characteristics corresponding to the network traffic, determine the communication protocol type based on the protocol characteristics, and record it as the second communication protocol type; Obtain network traffic behavior, determine the communication protocol type based on the network traffic behavior, and record it as the third communication protocol type; Obtain the port and protocol number of the network traffic, determine the communication protocol type based on the port and protocol number, and record it as the fourth communication protocol type; If the first, second, third, and fourth communication protocol types are all the same, then the communication protocol classification result is determined. If the first, second, third, and fourth communication protocol types are different, then the communication protocol types that are the same are selected and used as the communication protocol classification result.
3. The security protection method based on protocol controller and security gateway as described in claim 1, characterized in that, The failure rate of deep packet inspection is determined based on basic network traffic information, including: Basic network traffic information includes the communication protocol MTU, actual packet size, packet fragmentation information, and encryption information; If the actual size of the data packet is larger than the communication protocol MTU, the data packet needs to be fragmented, and the failure rate of deep packet inspection is determined based on the data packet fragmentation information. If the actual size of the data packet is not greater than the communication protocol MTU, the data packet does not need to be fragmented, and the failure rate of deep packet inspection is determined based on the encryption information.
4. The security protection method based on protocol controller and security gateway as described in claim 3, characterized in that, The failure rate of deep packet inspection is determined based on packet fragmentation information, including: The data includes fragmentation information, including the number of fragments, fragment offset, and payload content; The payload content is analyzed to determine the degree of flow mixing. The fragment calibration amount is obtained by considering the number of fragments, fragment offset, and traffic mixing level. ; Where P is the number of fragments to be checked. The conversion factor corresponds to the number of fragments. Let be the number of fragments, and exp be an exponential function. Due to the degree of traffic mixing, As a preset constant, The conversion factor is the value corresponding to the fragment offset. This is the fragment offset; The failure rate of deep packet inspection is determined based on the number of fragments checked, where each fragment check corresponds to a failure rate for deep packet inspection.
5. The security protection method based on protocol controller and security gateway as described in claim 3, characterized in that, Determining the failure rate of deep packet inspection based on encrypted information includes: Encrypted information includes protocol variants and obfuscation; The failure rate of deep packet inspection is determined based on protocol variants and obfuscation.
6. The security protection method based on protocol controller and security gateway as described in claim 1, characterized in that, Based on the failure rate and risk information of deep packet inspection, a strategy control mode is selected, including: Risk information refers to risk influencing factors, and strategy control models include stationary strategy control models and dynamic strategy control models; The risk level is determined based on the risk influencing factors; ; Where L represents the risk level, and n represents the number of risk influencing factors. Let i be the weight corresponding to the i-th risk factor. Let i be the parameter size corresponding to the i-th influencing factor. for The minimum value in the middle. The integer symbol; The failure risk level is determined based on the failure rate and risk level of deep packet inspection; ; Where K represents the failure risk level, Here, E represents the conversion coefficient corresponding to the failure rate, and E is the failure rate of deep packet inspection. To preset the failure rate threshold, A conversion system corresponding to risk levels. The preset risk level threshold is defined by k, which is a preset constant. The integer symbol; If the failure risk level does not exceed the failure risk level threshold, then the steady-state strategy control mode is selected; If the failure risk level exceeds the failure risk level threshold, then the dynamic strategy control mode is selected.
7. The security protection method based on protocol controller and security gateway as described in claim 6, characterized in that, Under different policy control modes, security policies are determined based on policy information, including: Strategy information refers to information related to strategy formulation; In the stationary policy control mode, security policies are set based on information related to policy formulation; In dynamic policy control mode, an initial security policy is set based on information related to policy formulation, and the initial security policy is dynamically adjusted according to the failure risk level.
8. The security protection method based on protocol controller and security gateway as described in claim 1, characterized in that, The granularity of the inspection is adjusted based on the logs generated by the deep inspection of the security gateway, including: The network security status is determined based on the logs generated by the deep inspection of the security gateway. The actual network security status is obtained, and the security status deviation is determined based on the detected network security status and the actual network security status. The security status deviation is the deviation between the detected network security status and the actual network security status. Establish a deviation change curve based on the deviation of the safety status, and refine the granularity of the security gateway depth inspection based on the deviation of the deviation change curve above the first calibration deviation level. The granularity of the security gateway depth inspection is coarsened based on the deviation amount of the deviation amount change curve below the second calibration deviation amount level. Among them, the first calibration deviation level is higher than the second calibration deviation level.
9. A security protection system based on a protocol controller and a security gateway, characterized in that, The system includes: The detection module is used to perform deep packet inspection on network traffic through the protocol controller to obtain basic network traffic information and communication protocol classification results; The collection module is used to determine the failure rate of deep packet inspection based on basic network traffic information, obtain security protection targets, and collect policy and risk information of communication protocols based on the security protection targets and communication protocol classification results. The control module is used to select the strategy control mode based on the failure rate and risk information of deep packet inspection, and to determine the security policy according to the strategy information under different strategy control modes. The deep inspection module is used by the security gateway to perform deep inspections on traffic of various communication protocols through security policies and take security protection measures based on the deep inspection results. The adjustment module is used to acquire logs generated by the deep inspection of the security gateway and adjust the granularity of the inspection based on the logs generated by the deep inspection of the security gateway.
Citation Information
Patent Citations
Depth package detection implementation method and device
CN105406977A
Dynamic deep packet inspection for anomaly detection
US20170099310A1