A network security defense device that proactively responds to hacker intrusions

By using a proactive network security defense device that responds to hacker intrusions and employs simulation probes and automatic blocking technology, the problem of hacker attacks not being detected and blocked in a timely manner in existing technologies has been solved, achieving efficient automatic defense and low-pressure operation and maintenance management.

CN118157987BActive Publication Date: 2026-01-06FUJIAN TORCH ELECTRON TECH CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410503594.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-04-25
Publication Date
2026-01-06
Estimated Expiration
2044-04-25

AI Technical Summary

Technical Problem

In existing network security systems, hacker attacks cannot be detected and blocked in a timely manner, and manual processing is inefficient, prone to false blocking, and puts a lot of pressure on operation and maintenance, especially during non-working hours when attacks occur frequently.

Method used

The network security defense device adopts a proactive response to hacker intrusions. It collects traffic data through multiple simulated probes, analyzes and matches the data, and blocks and alerts the platform automatically, reducing the need for manual intervention.

Benefits of technology

It enables timely detection and automatic blocking of hacker attacks, improving defense effectiveness and operational efficiency while reducing operational burden.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118157987B_ABST
    Figure CN118157987B_ABST
Patent Text Reader

Abstract

The application provides a network security defense device actively responding to hacker intrusion, belonging to the technical field of network security, comprising a collection platform, an analysis platform, a blocking platform and an alarm platform connected in sequence, the collection platform is provided with multiple simulation probes, including multiple first, second and third simulation probes, the analysis platform is connected with each of the first, second and third simulation probes to obtain the traffic data collected by the simulation probes and store the collected data, when the IP address in the traffic data does not match the IP address in the white list, the behavior of the IP address in the traffic data is labeled and then output to the blocking platform, the blocking platform takes different blocking measures according to different objects attacked by the attack IP address, and after the blocking is completed, the alarm platform sends alarm information to the network security administrator. The application can discover the attacker in time, actively block and alarm, does not need manual participation, enhances the defense effect, improves the operation and maintenance efficiency and reduces the operation and maintenance pressure.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of network security technology, specifically relating to a network security defense device that proactively responds to hacker intrusions. Background Technology

[0002] In routine network security defense, if hacker attacks are detected on the network, the IP addresses initiating the attacks must be blocked promptly to prevent hackers from accessing the internal network and thus ensuring system security. More specifically, on the internet side, because users or system administrators may not be able to detect hackers scanning or probing resources exposed to the internet in a timely manner, hackers can launch further attacks on these exposed resources. If a terminal computer or server is infected with a Trojan horse, and the user or system administrator fails to detect and remove the Trojan horse in time, hackers can use that terminal computer or server to attack other terminal computers and servers within the internal network, ultimately leading to system compromise.

[0003] Existing network architectures typically employ next-generation firewalls, intrusion detection systems, and full-traffic security platforms to analyze and monitor network attacks. However, these platforms are often isolated from each other, and some attacking IPs detected by these platforms cannot be automatically blocked by the firewall. This means that overall monitoring still requires manual intervention. Manual processing is highly dependent on the experience and efficiency of the personnel involved, which can lead to difficulties in quickly blocking attacking IPs, ultimately resulting in system intrusion by hackers. Furthermore, manual processing is prone to false blocking, misclassifying non-attacking IPs as attacking ones. In addition, hackers often attack the system outside of working hours, which also puts significant pressure on operations and maintenance. Summary of the Invention

[0004] The purpose of this invention is to propose a network security defense device that proactively responds to hacker intrusions, which can promptly detect attackers and proactively block and alert them without human intervention, thereby enhancing the defense effect, improving operational efficiency, and reducing operational pressure.

[0005] This invention is achieved through the following technical solution:

[0006] A proactive network security defense device for responding to hacker intrusions includes a data collection platform, an analysis platform, a blocking platform, and an alarm platform connected in sequence. The data collection platform includes multiple first emulation probes installed on the internet exposure surface to acquire internet traffic data, multiple second emulation probes installed on each network segment of the server network to acquire server network traffic data, and a third emulation probe installed on each network segment of the office network to acquire office network traffic data. The analysis platform is connected to each of the first, second, and third emulation probes to acquire the traffic data they collect. When an IP address in the traffic data does not match an IP address in the whitelist, the behavior of the IP address in the traffic data is tagged accordingly and output to the blocking platform. When the IP address output by the analysis platform belongs to internet traffic data, the blocking platform adds the IP address to the temporary blocking list on the boundary firewall. When the IP address output by the analysis platform belongs to server network traffic data, the blocking platform takes the corresponding server offline. When the IP address output by the analysis platform belongs to office network traffic data, the blocking platform disconnects the corresponding terminal computer from the network. The alarm platform sends alarm information to the network security administrator after the blocking platform completes its actions.

[0007] Furthermore, the first simulated probe includes a VPN probe, an OA probe, and / or a mail probe.

[0008] Furthermore, the second simulation probe includes various types of databases, operating systems, application layers, file servers, and / or monitoring systems.

[0009] Furthermore, the third simulation probe includes the OA application layer, Windows client, and / or email system.

[0010] Furthermore, for each segment of the server network, each segment is divided into multiple first sub-segments, and at least one second simulation probe is deployed in each first sub-segment. For each segment of the office network, each segment is divided into second sub-segments, and at least one third simulation probe is deployed in each second sub-segment.

[0011] Furthermore, the analysis platform includes a data storage module for storing traffic data collected by the first, second, and third simulation probes, and displaying it according to IP dimension, time dimension, and attack target dimension.

[0012] Furthermore, the analysis platform includes a whitelist module, which stores trusted IP addresses.

[0013] Furthermore, the temporary lockdown list is set to be lifted after 24 hours.

[0014] Furthermore, the alarm information includes the IP address of the attack, the attack time, the target of the attack, and / or the number of attacks.

[0015] Furthermore, the alarm information is sent via email, WeChat Work, and / or DingTalk.

[0016] The present invention has the following beneficial effects:

[0017] 1. This invention utilizes multiple first-stage simulated probes to acquire internet attack traffic data, second-stage simulated probes to acquire server network attack traffic data, and third-stage simulated probes to acquire office network attack traffic data. Each simulated probe is only triggered to collect data during abnormal business operations. The IP addresses in the attack traffic data collected by each simulated probe are primarily attack IP addresses, but there may still be trusted IP addresses that are rarely used in normal business operations. Therefore, the analysis platform first matches the IP addresses in the attack traffic data with IP addresses in the whitelist. IP addresses that do not match are the attack IP addresses. The blocking platform then takes different blocking measures based on the different targets attacked by the attack IP addresses. After the blocking is completed, the alarm platform sends alarm information to the network security administrator so that the network security administrator can promptly handle the compromised servers or infected terminal devices. In this way, attackers can be detected and blocked in a timely manner on the internet. For the office network, defense is initiated when the terminal is attacked but before it attacks the server. For the server network, defense is initiated when the server is attacked but before it attacks the server. This process requires no manual intervention, resulting in better defense, higher operational efficiency, and less operational pressure. Attached Figure Description

[0018] The present invention will now be described in further detail with reference to the accompanying drawings.

[0019] Figure 1 This is a schematic diagram illustrating the principle of the present invention. Detailed Implementation

[0020] like Figure 1 As shown, a network security defense device that proactively responds to hacker intrusions includes a data collection platform, an analysis platform, a blocking platform, and an alarm platform connected in sequence. The data collection platform includes multiple first-level simulated probes positioned on the internet exposure surface to collect internet attack traffic data, multiple second-level simulated probes positioned on each network segment of the server network to collect server network attack traffic data, and a third-level simulated probe positioned on each network segment of the office network to collect office network attack traffic data. The device consists of the first-level, second-level, and third-level simulated probes. Figure 1The internet attack data collection module shown is illustrated. In this embodiment, the first simulated probe includes a VPN probe, an OA probe, and a mail probe. The first simulated probe does not provide real business services, and normal business operations do not require access to these simulated probes. The corresponding first simulated probe is only triggered when the hacker needs to scan the exposed assets of the target or launch an attack using script tools. For each network segment of the server network, each network segment is divided into 5 first sub-segments (for example, taking the server network segment using Class C private addresses as an example, the entire network segment is divided into segments, then IP addresses 1-50 are the first first sub-segment, IP addresses 51-100 are the second first sub-segment, IP addresses 101-150 are the third first sub-segment, and so on). IP addresses 1-200 are designated as the fourth first sub-segment, and IP addresses 201-254 as the fifth first sub-segment. A second emulation probe is deployed in each first sub-segment. These second emulation probes include various types of databases, operating systems, application layers, file servers, and monitoring systems. Routine server operations do not require access to these second emulation probes; scanning is only triggered when the server is compromised and an attack lateral movement or internal network asset scan is needed. Similarly, each segment of the office network is divided into multiple second sub-segments, with a third emulation probe deployed in each. These third emulation probes include OA application layers, Windows clients, and email systems. Terminal computers within the office network also do not need access to these emulation probes; scanning is only triggered when a terminal computer is infected and an attack lateral movement or internal network asset scan is needed.

[0021] The analysis platform connects to each of the first, second, and third emulation probes to obtain the attack traffic data they collect. It includes a data storage module and a whitelist module. The data storage module stores the traffic data collected by the first, second, and third emulation probes and displays it according to IP, time, and attack target dimensions to facilitate later tracing and evidence collection. The whitelist module stores trusted IP addresses. To avoid "false blocking," the IP addresses in the attack traffic data need to be matched with the IP addresses in the whitelist. If they match, it means that the IP addresses in the attack traffic data are not hacker addresses. If they do not match, it means that the addresses in the attack traffic data are hacker addresses. The behavior of the IP addresses in the attack traffic data is then tagged accordingly and output to the blocking platform.

[0022] The blocking platform identifies attack targets based on the results output by the analysis platform and takes different measures depending on the target: When the IP address output by the analysis platform belongs to internet attack traffic data, the blocking platform adds the IP address to a temporary blocking list on the perimeter firewall. The unblocking time for this temporary blocking list is set to 24 hours to avoid the blocking list becoming too large and affecting system performance; when the IP address output by the analysis platform belongs to server network attack traffic data, the blocking platform takes the corresponding server offline. The server can only be brought back online after the virus is removed to prevent large-scale server compromise; when the IP address output by the analysis platform belongs to office network attack traffic data, the blocking platform disconnects the corresponding terminal computer from the network. The terminal computer can only reconnect to the network after the virus is removed. The blocking platform can be implemented by an RPA robot or a corresponding interface.

[0023] After completing the blocking action, the alarm platform sends an alarm message to the network security administrator. The alarm message includes the attacking IP address, attack time, attack target, and number of attacks, and can be sent via email, WeChat Work, or DingTalk.

[0024] The above description is merely a preferred embodiment of the present invention and should not be construed as limiting the scope of the present invention. All equivalent changes and modifications made in accordance with the scope of the patent application and the contents of the specification of the present invention should still fall within the scope of the patent of the present invention.

Claims

1. A network security defense device that actively responds to hacking, characterized by: The system comprises a collection platform, an analysis platform, a blocking platform and an alarm platform connected in sequence. The collection platform comprises a plurality of first simulation probes arranged on an Internet exposure surface to obtain Internet traffic data, a plurality of second simulation probes arranged on each network segment of a server network to obtain server network traffic data, and a third simulation probe arranged on each network segment of an office network to obtain office network traffic data. The analysis platform is connected with each of the first, second and third simulation probes to obtain the traffic data collected thereby. When an IP address in the traffic data does not match an IP address in a white list, the behavior of the IP address in the traffic data is labeled and output to the blocking platform. When the IP address output by the analysis platform belongs to Internet traffic data, the blocking platform writes the IP address into a temporary blocking list on a border firewall. When the IP address output by the analysis platform belongs to server network traffic data, the blocking platform performs offline processing on the corresponding server. When the IP address output by the analysis platform belongs to office network traffic data, the blocking platform performs network disconnection processing on the corresponding terminal computer. The alarm platform sends alarm information to a network security administrator after the blocking platform completes the action.

2. The network security device of claim 1, wherein: The first simulation probes comprise vpn probes, oa probes and / or mail probes.

3. The network security device of claim 1, wherein: The second simulation probes comprise various types of databases, operating systems, application layers, file servers and / or monitoring systems.

4. The network security device of claim 1 or 2 or 3, wherein: The third simulation probes comprise oa application layers, windows clients and / or mailbox systems.

5. The network security device of claim 1 or 2 or 3, wherein: Each network segment of the server network is divided into a plurality of first sub-segments, and at least one second simulation probe is arranged in each first sub-segment. Each network segment of the office network is divided into second sub-segments, and at least one third simulation probe is arranged in each second sub-segment.

6. The network security device that actively responds to hacking according to claim 1 or 2 or 3, characterized in that: The analysis platform comprises a data storage module for storing the traffic data collected by the first, second and third simulation probes and displaying the traffic data according to IP dimensions, time dimensions and attack object dimensions.

7. The network security device of claim 1 or 2 or 3, wherein: The analysis platform comprises a white list module in which trusted IP addresses are stored.

8. The network security device that actively responds to hacking according to claim 1 or 2 or 3, characterized in that: The temporary blocking list is set to be unblocked for 24 hours.

9. The network security device that actively responds to hacking according to claim 1 or 2 or 3, characterized in that: The alarm information comprises an attacking IP address, an attack time, an attack object and / or an attack frequency.

10. The network security device that actively responds to hacking according to claim 1 or 2 or 3, characterized in that: The alarm information is sent through email, enterprise WeChat and / or DingTalk.

Citation Information

Patent Citations

  • Method, system and device for identifying and blocking network attack source, and medium

    CN113726790A

  • Data security transmission control method and system between intranet and extranet

    CN115174242A