Method and device for detecting port bounce, storage medium and electronic equipment

By using a time window mechanism to analyze the destination port and source IP address on the traffic side, the detection difficulties caused by changes in the name of the port bounce tool are resolved, achieving more efficient and accurate intranet security protection.

CN118694546BActive Publication Date: 2025-12-16BEIJING HONGTENG INTELLIGENT TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310298400.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-03-24
Publication Date
2025-12-16
Estimated Expiration
2043-03-24

AI Technical Summary

Technical Problem

In existing technologies, the names of port reverse shell tools can be changed at will, which makes EDR process detection ineffective in detecting malicious behavior, leading to hacker intrusion into the company's intranet.

Method used

By filtering and analyzing the destination port and source IP address in the traffic, a time window mechanism is used to detect port bounce attacks. The attack behavior is determined based on the access records and quantity of the source IP address of the target traffic in the second window.

Benefits of technology

It improves the efficiency of intranet security protection, avoids detection errors caused by changes in the name of the reverse port tool, and enhances the accuracy and efficiency of detecting reverse port attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118694546B_ABST
    Figure CN118694546B_ABST
Patent Text Reader

Abstract

The application discloses a port bounce detection method and device, a storage medium and an electronic device. The method comprises the following steps: filtering out traffic whose destination port is an intranet port and whose destination IP address is an intranet IP address in a first time window, and marking the traffic as a first target traffic set; extracting the source IP address of the first target traffic set to obtain a first target IP address set; if an IP address in the first target IP address set accesses an intranet port of an intranet IP address in a second time window and is accessed by an extranet IP address, the second time window is determined as a first target time window; and if the number of the first target time window contained in the first time window reaches a preset threshold, it is determined that there is an intranet port bounce attack, and the security protection efficiency of the intranet is improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of Internet security protection, and in particular to a port bounce detection method and device, a storage medium and an electronic device. BACKGROUND

[0002] With the evolution of hacking technology, enterprises pay more and more attention to the security of the intranet. Hackers will use port bounce tools to access the intranet of the attacked company, and in related technologies, the Endpoint Detection and Response (EDR) process detection method will be used to track and handle malicious behavior activities. However, due to the large number of bounce port tools used by hackers, the names of the tools can be changed at will, and the EDR process detection cannot detect malicious activities, so the intranet of the company is vulnerable to hacking and intrusion. SUMMARY

[0003] The embodiments of the present application provide a port bounce detection method, device, storage medium and electronic device. When the attack behavior of port bounce occurs in the intranet of the company, the name change of the bounce port tool can be ignored, the attack behavior of port bounce is detected from the traffic side, and the security of the intranet of the company is ensured.

[0004] In a first aspect, the embodiments of the present application provide a port bounce detection method, which includes:

[0005] Filtering out traffic in a first time window whose destination port is an intranet port and whose destination Internet Protocol (IP) address is an intranet IP address, and marking the traffic as a first target traffic set;

[0006] Extracting the source IP addresses of the first target traffic set to obtain a first target IP address set;

[0007] If an IP address in the first target IP address set accesses an intranet port of an intranet IP address in a second time window and is accessed by an extranet IP address, it is determined that the second time window is a first target time window; the first time window contains multiple second time windows;

[0008] If the number of second time windows contained in the first time window reaches a preset threshold, it is determined that there is an intranet port bounce attack.

[0009] The embodiments of the present application select a time window on the traffic side to detect traffic behavior, and then determine the existence of a port bounce attack according to the access record of the source IP address of the target traffic in the second window and the number of target second windows, thereby effectively avoiding the problem that the attack behavior cannot be detected due to the name change of the bounce port tool, and improving the security protection efficiency of the intranet.

[0010] In a possible implementation, if an IP address in the first target IP address set accesses an intranet port of an intranet IP address in a second time window and is accessed by an extranet IP address, it is determined that the second time window is after the first target time window, and the method further includes:

[0011] If the number of the first time windows containing the first target time window does not reach the preset threshold, it is determined that there is no intranet port bounce attack.

[0012] Embodiments of the present application determine whether there is a port bounce attack according to the number of the first target window in the first time window that meets the condition, avoid false information due to detection errors, and improve the detection efficiency and accuracy of the port bounce attack.

[0013] In a possible implementation, the intranet port is configured on a host in an intranet area, the intranet area includes hosts of at least one security level, each security level of host corresponds to at least one host, and the intranet port that exists intranet port bounce attack is configured on any one of the hosts.

[0014] Embodiments of the present application determine the existence of port bounce attack through flow side detection, and the port bounce attack on hosts of different security levels can be detected by the method, so that the application scenario of the present application is more extensive.

[0015] In a possible implementation, the intranet area includes hosts of a first security level and hosts of a second security level, the first security level is higher than the second security level, the intranet port that exists intranet port bounce attack is configured on the host of the first security level, and the intranet port bounce attack is a first-level intranet port bounce attack.

[0016] In the embodiments of the present application, the attack behavior exists through the host of the second security level to attack the host of the first security level, and it is determined that there is a first-level port bounce attack, which can accurately determine the type of intranet host attacked and improve the efficiency and accuracy of port bounce attack detection.

[0017] In a possible implementation, after the first-level intranet port bounce attack is determined, the method further includes:

[0018] Filtering out the flow with the first target port as the destination port and the second target IP address set as the destination IP address in the first time window, and marking it as the second target flow set; the first target port is configured on the host of the second security level, and the second target IP address is the IP address corresponding to the host of the second security level;

[0019] extracting the source IP address of the second target flow set to obtain a third target IP address set;

[0020] If an IP address in the third target IP address set accesses a first target port of the second target IP address in a second time window and is accessed by a fixed port of an external network IP address, it is determined that the second time window is a second target time window.

[0021] If the number of the second target time windows contained in the first time window reaches the preset threshold, it is determined that there is a two-level internal network port bounce attack.

[0022] After detecting the existence of a one-level port bounce attack, the embodiment of the application continues to detect the access behavior from the flow side, determines the existence of a two-level port bounce attack according to the number of time windows in which the target access behavior exists, can detect attack behaviors on hosts in multiple security levels of the internal network, and guarantees the security of the internal network hosts.

[0023] In a possible implementation, after it is determined that an IP address in the third target IP address set accesses a first target port of the second target IP address in a second time window and is accessed by a fixed port of an external network IP address, the method further includes:

[0024] If the number of the second target time windows contained in the first time window does not reach the preset threshold, it is determined that there is no two-level internal network port bounce attack.

[0025] After determining the existence of a one-level port bounce attack, the embodiment of the application continues to detect the flow behavior, determines whether there is a two-level port bounce attack by detecting whether the number of second windows that meet the condition reaches a threshold, avoids false positives, and improves the detection efficiency and accuracy of the port bounce attack.

[0026] In a possible implementation, the internal network region includes at least one of the following: a public region, a confidential region, a secret region, and a top secret region, and each region includes hosts with different security levels.

[0027] The internal network regions involved in the embodiment of the application are various, and the security levels of the hosts included in each internal network region are different, so that security problems of hosts in different internal network regions can be detected by the method, and the detection efficiency is improved.

[0028] In a second aspect, the embodiment of the application provides a port bounce detection device, which includes:

[0029] A filtering module is configured to filter out traffic with an internal network port as a destination port and an internal network IP address as a destination network protocol (IP) address in a first time window, and mark the traffic as a first target traffic set;

[0030] An extraction module is configured to extract source IP addresses of the first target traffic set to obtain a first target IP address set;

[0031] A determination module is configured to determine a second time window as a first target time window if an IP address in the first target IP address set accesses an internal network port of an internal network IP address in the second time window and is accessed by an external network IP address; the first time window contains a plurality of the second time windows; and a number of the first target time windows in the first time window reaches a preset threshold, the existence of an internal network port bounce attack is determined.

[0032] In a third aspect, an embodiment of the present application provides a computer storage medium, including: the computer storage medium stores a plurality of instructions, the instructions are suitable for being loaded by a processor and executing the method provided in the first aspect or any possible implementation manner of the first aspect.

[0033] In a fourth aspect, an embodiment of the present application provides an electronic device, including: a memory and a processor; wherein the memory stores a computer program, the computer program is suitable for being loaded by the processor and executing the method provided in the first aspect or any possible implementation manner of the first aspect of the present application. BRIEF DESCRIPTION OF DRAWINGS

[0034] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings required to be used in the embodiments will be briefly introduced as follows. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor on the basis of these drawings.

[0035] Figure 1 A port bounce detection system provided by an embodiment of the present application is shown in a schematic diagram;

[0036] Figure 2 A flowchart of a port bounce detection method provided by an embodiment of the present application is shown in a schematic diagram;

[0037] Figure 3 A flowchart of a port bounce detection method provided by an embodiment of the present application is shown in a schematic diagram;

[0038] Figure 4 A flowchart of a port bounce detection method provided by an embodiment of the present application is shown in a schematic diagram;

[0039] Figure 5A flowchart of a two-level port bounce detection method provided by an embodiment of the present application is shown in FIG. 1.

[0040] Figure 6 A flowchart of a one-level port bounce detection method provided by an embodiment of the present application is shown in FIG. 2.

[0041] Figure 7 A flowchart of a two-level port bounce detection method provided by an embodiment of the present application is shown in FIG. 1.

[0042] Figure 8 A flowchart of another two-level port bounce detection method provided by an embodiment of the present application is shown in FIG. 3.

[0043] Figure 9 A structural diagram of a port bounce detection device provided by an embodiment of the present application is shown in FIG. 4.

[0044] Figure 10 A structural diagram of an electronic device provided by an embodiment of the present application is shown in FIG. 5. DETAILED DESCRIPTION

[0045] The technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application.

[0046] The terms "first", "second", "third", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish different objects, and are not used to describe a specific order. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device that includes a series of steps or units is not limited to the listed steps or units, but can optionally include steps or units that are not listed, or can optionally include other steps or units inherent to the process, method, product or device.

[0047] Figure 1A port bounce detection system provided by an embodiment of the present application is shown in a schematic diagram. The port bounce detection system 100 includes an intranet host, a public network server, and the Internet. The intranet host in the system can be used to execute the detection method of port bounce provided by the present solution, and the intranet area contains at least one intranet host. This method determines the existence of a port bounce attack by detecting and analyzing the traffic behavior in the intranet. The intranet host is a machine in a special local area network or office network in an enterprise or organization. The intranet host has different security levels and is in different intranet areas. Each intranet area includes at least one intranet host of a security level, for example, the security level of the core host in the confidential area is higher than that of the intranet host in the public area. The intranet host can be a desktop computer, a laptop computer, a server (such as a physical server or a virtual server), or a mobile terminal (such as a mobile phone or a smart wearable device). In the Internet, users in the external network can directly access the public network server in the demilitarized zone (DMZ) to obtain public information in the demilitarized zone. In normal circumstances, the server in the intranet cannot be directly accessed.

[0048] Specifically, the DMZ area is a buffer area between the Internet (external network) and the intranet (enterprise internal network). The public network server is placed in the DMZ area to display the public network service information of the enterprise.

[0049] Specifically, the port bounce detection system can detect the port bounce attack behavior of hackers attacking the intranet host through the public network server in the Internet.

[0050] In related technologies, the EDR process detects intranet port bounce attacks. The EDR monitors running processes, detects suspicious activities, collects information, establishes models, and prevents further attacks. However, there are many types of bounce port tools, and the tool names can be changed at will, which can easily bypass the EDR process detection, so that the customer cannot be notified in time that the intranet is under attack, and the security of the intranet is reduced.

[0051] To solve the above problems, the present solution combines Figure 2 An exemplary flowchart of a detection method of port bounce provided by an embodiment of the present application is shown. As shown in Figure 2 The port bounce detection method specifically includes the following steps:

[0052] S201, filtering out traffic with a destination port as an intranet port and a destination network protocol IP address as an intranet IP address in a first time window, and marking it as a first target traffic set.

[0053] Specifically, the intranet port is configured on a host in an intranet area, the intranet area includes hosts of at least one security level, each security level of the hosts corresponds to at least one host, and the intranet port subject to the intranet port bounce attack is configured on any one of the hosts.

[0054] Specifically, the intranet area includes at least one of the following: a public area, a confidential area, a secret area, and a top secret area, and each area includes hosts of different security levels.

[0055] Specifically, in the intranet area, the security level of a host in the top secret area is higher than that of a host in the secret area, the security level of the host in the secret area is higher than that of a host in the confidential area, and the security level of the host in the confidential area is higher than that of a host in the public area.

[0056] Specifically, the time length of the first time window is a first preset time length. The first preset time length is, for example but not limited to, 5 minutes.

[0057] For example, the embodiment of the present application sets the first preset time length of the first time window to 5 minutes, randomly selects 5 minutes of traffic in the intranet, and filters out traffic with a destination port as an intranet port and a destination IP address as an intranet IP address, and marks the traffic as a first target traffic set.

[0058] S202, extracting the source IP addresses of the first target traffic set to obtain a first target IP address set.

[0059] Specifically, the source IP address of the first target traffic set is the IP address of a host sending a data packet.

[0060] S203, if an IP address in the first target IP address set accesses an intranet port of an intranet IP address in a second time window and is accessed by an extranet IP address, determining that the second time window is a first target time window.

[0061] Specifically, the first time window includes a plurality of second time windows, and the time length of the second time window is a second preset time length. The second preset time length is, for example but not limited to, 3 seconds.

[0062] For example, the embodiment of the present application sets the first preset time length of the first time window to 5 minutes and the second preset time length of the second time window to 3 seconds, screens the first target IP address in the first time window of 5 minutes, and selects a target IP address that accesses an intranet IP address of an intranet port in a second time window of 3 seconds and is accessed by an extranet IP address, and the second time window of 3 seconds in the first time window of 5 minutes containing the target IP address is a first target time window.

[0063] S204. If the number of times the first target time window is included in the first time window reaches a preset threshold, then it is determined that there is an internal network port reverse shell attack.

[0064] Specifically, a preset threshold is set for the number of first target time windows where internal network port bounce attacks exist, for example, but not limited to, 5.

[0065] For example, such as Figure 3 The diagram illustrates a port bounce attack. In this embodiment, a preset threshold of 5 times is set for the first target time window, the internal network port is port 3389, the first time window is 5 minutes, and the second time window is 3 seconds. Within the first time window of 5 minutes, traffic accessing the internal network port 3389 and whose destination IP address is also internal is filtered out and marked as the first traffic set. The source IP addresses in the first traffic set are extracted as the first target IP address set and marked as potential public servers. If an IP address in the first target IP address set accesses the internal network port 3389 within the second time window of 3 seconds and is also accessed by an external IP address on port 7777 (the port specified by the hacker) within the second time window of 3 seconds, and the number of times the second time window of 3 seconds meets the conditions reaches 5 times within the first time window of 5 minutes, then a 3389 internal network port bounce attack is confirmed, data is reported, and a notification of the existence of an internal network port bounce attack is issued.

[0066] This application embodiment selects a time window on the traffic side to detect traffic behavior, and then determines the existence of a port reverse attack based on the source IP address of the target traffic, the access records in the second window, and the number of target second windows. This effectively avoids the problem of being unable to detect attack behavior due to changes in the name of the reverse port tool, and improves the security protection efficiency of the intranet.

[0067] When a port reversal attack exists on the internal network, in order to quickly report data and remind customers to handle it as soon as possible, and to avoid false alarms due to errors in traffic detection, this embodiment of the application determines the existence of an internal network port reversal attack based on the number of first target time windows. For example... Figure 4 As shown in the figure, this application embodiment illustrates a flowchart of another method for detecting port bounce.

[0068] S401. Filter out traffic in the first time window whose destination port is an internal network port and whose destination network protocol IP address is an internal network, and mark it as the first target traffic set.

[0069] Specifically, S401 is the same as S201, and will not be repeated here.

[0070] S402. Extract the source IP addresses of the first target traffic set to obtain the first target IP address set.

[0071] Specifically, S402 is consistent with S202, which will not be repeated here.

[0072] S403, if there is an IP address in the first target IP address set that accesses the intranet port of the intranet IP address in the second time window and is accessed by the extranet IP address, it is determined that the second time window is the first target time window.

[0073] Specifically, S403 is consistent with S203, which will not be repeated here.

[0074] S404, if the number of the first target time window contained in the first time window does not reach the preset threshold, it is determined that there is no intranet port bounce attack.

[0075] Exemplarily, the embodiment of the application sets the preset threshold of the number of the first target time window to 5 times. In the first time window, the first target traffic that satisfies accessing the intranet port and the destination IP address being the intranet is screened out, and the source IP address thereof is extracted and marked as the first target IP address. From the first target IP address, the target IP address that accesses the intranet port in the second time window and is accessed by the extranet IP address is screened out, and such second time window is marked as the first target time window. In the first time window, the number of the first target time window is 1 time, which is less than the preset threshold of 5 times. Therefore, it is determined that there is no intranet port bounce attack, the data at this time is recorded, and no warning is given to the user.

[0076] The embodiment of the application adopts the method of detecting and screening the side information of the traffic to screen out the traffic that accesses the intranet port in the first time window and the destination IP address is the intranet. The source IP address of the traffic accesses the intranet port in the second time window and is accessed by the IP address of the extranet. The second time window is the first target time window. Whether there is a port bounce attack is determined according to the number of the first target window in the first time window that satisfies the condition, which avoids false information caused by detection errors and improves the detection efficiency of the port bounce attack.

[0077] The intranet of a large enterprise is often divided into multiple levels of intranet security areas, and the host security levels corresponding to different security level areas are also different. In order to quickly detect whether there is a port bounce attack in the intranet area, the embodiment of the application detects from the traffic side whether the traffic satisfies the corresponding condition and whether there is a port bounce attack behavior, and timely reports. The security of the multiple-level intranet security area is guaranteed. Figure 5 As shown in the figure, the embodiment of the application shows a flowchart of a two-level port bounce detection method.

[0078] S501, filtering out the traffic whose destination port is the intranet port and whose destination network protocol IP address is the intranet in the first time window, and marking it as the first target traffic set.

[0079] Specifically, S501 is the same as S201, and will not be repeated here.

[0080] S502. Extract the source IP addresses of the first target traffic set to obtain the first target IP address set.

[0081] Specifically, S502 is the same as S202, and will not be repeated here.

[0082] S503. If there is an IP address in the first target IP address set that accesses the internal network port of the internal network IP address in the second time window and is also accessed by the external network IP address, then the second time window is determined to be the first target time window.

[0083] Specifically, S503 is the same as S203, and will not be repeated here.

[0084] S504. If the number of the first target time windows contained in the first time window reaches a preset threshold, then it is determined that there is an internal network port reverse shell attack.

[0085] Specifically, the intranet area includes hosts at a first security level and hosts at a second security level, with the first security level being higher than the second security level; the intranet port where the intranet port reverse bounce attack exists is configured on the host at the first security level, and the intranet port reverse bounce attack is a first-level intranet port reverse bounce attack.

[0086] For example, combined Figure 6 The diagram illustrates a level-one port bounce detection. In this embodiment, internal network port 3389 is configured on a host with the first security level within the internal network. The preset duration of the first time window is 5 minutes, the preset duration of the second time window is 3 seconds, and the preset threshold for the number of first target time windows is 5. Traffic within the first 5-minute time window is selected, and traffic destined for port 3389 and with an internal network IP address is filtered out to obtain the first target traffic set. The source IP addresses of the first target traffic are extracted and deduplicated to obtain the first target IP address set, which is marked as a potential jump server. The IP addresses in the first target IP address set are screened. If, within the second 3-second time window, this IP address accesses port 3389 and is accessed by an external IP address on a fixed port 6666, then this IP address is marked as a first target IP address. If the number of 3-second time windows meeting this condition within 5 minutes reaches the preset threshold of 5, a level-one port bounce attack is confirmed.

[0087] S505. Filter out traffic in the first time window whose destination port is the first target port and whose destination IP address is the second target IP address set, and mark it as the second target traffic set.

[0088] Specifically, the first target port is configured in the host of the second security level, and the second target IP address is an IP address corresponding to the host of the second security level.

[0089] Specifically, the first time window is a time window in which a one-level port bounce attack exists.

[0090] S506, extracting a source IP address of the second target traffic set to obtain a third target IP address set.

[0091] Specifically, S506 is consistent with S202, which will not be described here.

[0092] S507, if an IP address in the third target IP address set accesses the first target port of the second target IP address in the second time window and is accessed by a fixed port of the external network IP address, it is determined that the second time window is a second target time window.

[0093] Specifically, the fixed port accessed by the external network IP address is a fixed port randomly configured by a hacker to implement an attack behavior.

[0094] S508, the number of the second target time window contained in the first time window reaches the preset threshold value, and it is determined that a two-level internal network port bounce attack exists.

[0095] Optionally, the preset threshold value of the number of the second target time window is the same as the preset threshold value of the number of the first target time window.

[0096] Exemplarily, the preset threshold values of the number of the first target time window and the number of the second target time window in the embodiment of the application are both 5 times. After the number of the first target time window meeting the condition in the first time window reaches the preset threshold value of 5 times, it is determined that a one-level port bounce attack exists. In the first time window, continue to screen, and when the number of the second target time window meeting the condition reaches the preset threshold value of 5 times, it is determined that a two-level port bounce attack exists.

[0097] Optionally, the preset threshold value of the number of the second target time window is not the same as the preset threshold value of the number of the first target time window.

[0098] Exemplarily, the preset threshold value of the number of the first target time window in the embodiment of the application is 5 times, and the preset threshold value of the number of the second time window is 10 times. After the number of the first target time window meeting the condition in the first time window reaches the preset threshold value of 5 times, it is determined that a one-level port bounce attack exists. In the first time window, continue to screen, and when the number of the second target time window meeting the condition reaches the preset threshold value of 10 times, it is determined that a two-level port bounce attack exists.

[0099] Exemplarily, in combinationFigure 7 As shown in another secondary port bounceback detection schematic diagram, in the embodiment of the present application, the first time window length is 5 minutes, the second time window length is 3 seconds, the preset threshold of the number of the first target time window and the second target time window is 5 times, the core host is a host of the first security level, and the internal network host is a host of the second security level. The traffic of the 5-minute time window is taken, the traffic whose destination port is 3389 port and whose destination IP address is the core host is filtered out, and the first target traffic set is obtained. The source IP address is extracted, and the first target IP address set is obtained, which is marked as a potential jumpboard machine. In the above-mentioned 5-minute time window, there is a 3-second time window, which satisfies that the IP address accesses the 3389 port of the internal network IP address, and is accessed by the external network IP address to a certain fixed port (6666 port in the figure), and the IP address is marked as the second target IP address set (internal network host in the figure), and the fixed port is marked as the first target port. If the number of such 3-second time windows reaches the preset threshold of 5 times, it is determined that there is a primary internal network port bounceback attack. In the traffic of the above-mentioned 5-minute time window, the traffic whose destination port is the first target port (6666 port) and whose destination IP address is the second target IP address set (internal network host) is filtered out, and the second target traffic set is obtained. The source IP address is extracted, and the third target IP address set is obtained. In the third target IP address set, the IP address accesses the first target port (6666 port) of the second target IP address (internal network host) in the above-mentioned 5-minute time window with a 3-second time window, and is accessed by the external network IP address to a certain fixed port (7777 port). In the 5-minute time window, the number of such 3-second time windows reaches the preset threshold of 5 times, and it is determined that there is a secondary port bounceback attack.

[0100] In a possible embodiment, the present scheme can detect multi-level port bounceback attacks in internal network regions of multiple security levels according to the above-mentioned steps, wherein the internal network regions of multiple security levels contain internal network hosts of multiple security levels, and when at least one internal network host of a security level in the internal network region is subjected to a port bounceback attack, the present scheme can quickly detect and report.

[0101] After detecting the existence of a primary port bounceback attack, the embodiment of the present application continues to detect the access behavior from the traffic side, determines the existence of a secondary port bounceback attack according to the number of time windows of the target access behavior, can detect attack behaviors on internal network hosts of multiple security levels, and protects the security of the internal network hosts.

[0102] To adapt to complex network region environments and make internal network security detection more accurate, the embodiment of the present application determines the existence of a secondary internal network port bounceback attack according to the number of the first target time window and the second target time window. For example, Figure 8As shown, the embodiment of the present application shows a flow diagram of another port bounce detection method.

[0103] S801, filtering out traffic in the first time window whose destination port is an intranet port and whose destination IP address is an intranet IP address, and marking the traffic as a first target traffic set.

[0104] Specifically, S801 is consistent with S201, which will not be repeated here.

[0105] S802, extracting the source IP addresses of the first target traffic set to obtain a first target IP address set.

[0106] Specifically, S802 is consistent with S202, which will not be repeated here.

[0107] S803, if an IP address in the first target IP address set accesses an intranet port of an intranet IP address in a second time window and is accessed by an extranet IP address, determining that the second time window is a first target time window.

[0108] Specifically, S803 is consistent with S203, which will not be repeated here.

[0109] S804, if the number of first target time windows contained in the first time window reaches a preset threshold, determining that there is an intranet port bounce attack.

[0110] Specifically, S804 is consistent with S504, which will not be repeated here.

[0111] S805, filtering out traffic in the first time window whose destination port is a first target port and whose destination IP address is a second target IP address set, and marking the traffic as a second target traffic set.

[0112] Specifically, S805 is consistent with S505, which will not be repeated here.

[0113] S806, extracting the source IP addresses of the second target traffic set to obtain a third target IP address set.

[0114] Specifically, S806 is consistent with S506, which will not be repeated here.

[0115] S807, if an IP address in the third target IP address set accesses a first target port of a second target IP address in a second time window and is accessed by an extranet IP address fixed port, determining that the second time window is a second target time window.

[0116] Specifically, S807 is consistent with S507, which will not be repeated here.

[0117] S808, if the number of the second target time windows included in the first time window does not reach the preset threshold, it is determined that there is no secondary inner network port bounce attack.

[0118] Exemplarily, the embodiment of the present application sets the preset threshold of the number of the second target time windows as 10 times, and the preset threshold of the number of the first target time windows as 5 times. After the number of the first target time windows meeting the condition in the first time window reaches the preset threshold of 5 times, it is determined that there is a primary port bounce attack. In the first time window, the second target time window is continuously screened, and the number of the second target time windows meeting the condition is less than the preset threshold of 10 times, and it is determined that there is no secondary port bounce attack.

[0119] The embodiment of the present application continues to detect the traffic behavior after determining that there is a primary port bounce attack, determines whether there is a secondary port bounce attack by detecting whether the number of the second window meeting the condition reaches the threshold, and improves the detection efficiency of the port bounce attack.

[0120] Figure 9 An exemplary structure diagram of a port bounce detection device provided by the embodiment of the present application is shown. As shown in Figure 9 The port bounce detection device 900 can include:

[0121] The filtering module 901 is configured to filter out traffic whose destination port is an inner network port and whose destination IP address is an inner network IP address in a first time window, and mark the traffic as a first target traffic set.

[0122] The extraction module 902 is configured to extract the source IP address of the first target traffic set to obtain a first target IP address set.

[0123] The determination module 903 is configured to determine that, if an IP address in the first target IP address set accesses an inner network port of an inner network IP address in a second time window and is accessed by an outer network IP address, the second time window is a first target time window; the first time window includes a plurality of second time windows; and if the number of the first target time windows included in the first time window reaches a preset threshold, it is determined that there is an inner network port bounce attack.

[0124] In some possible embodiments, the determination module 903 is further configured to determine that, if the number of the first target time windows included in the first time window does not reach the preset threshold, there is no inner network port bounce attack.

[0125] In some possible embodiments, the intranet port is configured on a host in an intranet area, the intranet area includes hosts of at least one security level, each security level of the hosts corresponds to at least one host, and the intranet port subject to the intranet port bounce attack is configured on any one of the hosts.

[0126] In some possible embodiments, the intranet area includes hosts of a first security level and hosts of a second security level, the first security level is higher than the second security level, the intranet port subject to the intranet port bounce attack is configured on the host of the first security level, and the intranet port bounce attack is a first-level intranet port bounce attack.

[0127] In some possible embodiments,

[0128] The filtering module 901 is further configured to filter out traffic with a destination port being a first target port and a destination IP address being a second target IP address set in a first time window, and mark the traffic as a second target traffic set; the first target port is configured on the host of the second security level, and the second target IP address is an IP address corresponding to the host of the second security level;

[0129] The extraction module 902 is further configured to extract a source IP address of the second target traffic set to obtain a third target IP address set.

[0130] The determination module 903 is further configured to determine, if an IP address in the third target IP address set accesses the first target port of the second target IP address in a second time window and is accessed by an external network IP address to a fixed port, that the second time window is a second target time window; and determine, if a number of the second target time windows in the first time window reaches the preset threshold, that a second-level intranet port bounce attack exists.

[0131] In some possible embodiments, the determination module 903 is further configured to determine, if the number of the second target time windows in the first time window does not reach the preset threshold, that the second-level intranet port bounce attack does not exist.

[0132] In some possible embodiments, the intranet area includes at least one of the following: a public area, a confidential area, a secret area, and a top secret area, and each area includes hosts of different security levels.

[0133] The division of the modules in the port bounce detection apparatus is only for example, and in other embodiments, the port bounce detection apparatus can be divided into different modules as needed to complete all or part of the functions of the port bounce detection apparatus. The implementation of each module in the port bounce detection apparatus provided in the embodiments of the present application can be in the form of a computer program. The computer program can run on a terminal or a server. The program modules formed by the computer program can be stored in the memory of the terminal or the server. When the computer program is executed by the processor, all or part of the steps of the port bounce detection method described in the embodiments of the present application are implemented.

[0134] Please refer to Figure 10 , Figure 10 A structural schematic diagram of an electronic device provided in an embodiment of the present application is shown.

[0135] As Figure 10 shown, the electronic device 1000 can include at least one processor 1001, at least one network interface 1004, a user interface 1003, a memory 1005, a touch screen 1006, and at least one communication bus 1002.

[0136] The communication bus 1002 can be used to realize the connection and communication of the above-mentioned components.

[0137] The user interface 1003 can include a key, and the optional user interface can also include a standard wired interface, a wireless interface.

[0138] The network interface 1004 can optionally include a Bluetooth module, an NFC module, a Wi-Fi module, etc.

[0139] The processor 1001 can include one or more processing cores. The processor 1001 connects various parts in the entire electronic device 1000 through various interfaces and lines, executes various functions of the routing device 1000 and processes data by running or executing instructions, programs, code sets or instruction sets stored in the memory 1005, and calling data stored in the memory 1005. Optionally, the processor 1001 can be implemented in at least one hardware form of DSP, FPGA, PLA. The processor 1001 can integrate CPU, GPU, and modem, etc. in a combination of one or several. Among them, the CPU mainly processes the operating system, user interface and application programs, etc.; the GPU is responsible for rendering and drawing the content to be displayed on the display screen; the modem is used to process wireless communication. It can be understood that the above-mentioned modem can also not be integrated into the processor 1001, but be realized by a separate chip.

[0140] The memory 1005 may include RAM or ROM. Optionally, the memory 1005 may include a non-transitory computer-readable medium. The memory 1005 may be used to store instructions, programs, code, code sets, or instruction sets. The memory 1005 may include a program storage area and a data storage area, wherein the program storage area may store instructions for implementing an operating system, instructions for at least one function (such as touch function, sound playback function, image playback function, etc.), instructions for implementing the above-described method embodiments, etc.; the data storage area may store data involved in the above-described method embodiments, etc. Optionally, the memory 1005 may also be at least one storage device located remotely from the aforementioned processor 1001. Figure 10 As shown, the memory 1005, which serves as a computer storage medium, may include an operating system, a network communication module, a user interface module, and application programs.

[0141] Specifically, the processor 1001 can be used to call the application stored in the memory 1005 and perform the following operations:

[0142] Filter out traffic in the first time window whose destination port is an internal network port and whose destination network protocol IP address is an internal network, and mark it as the first target traffic set;

[0143] Extract the source IP addresses from the first target traffic set to obtain the first target IP address set;

[0144] If an IP address in the first set of target IP addresses accesses the internal network port of an internal network IP address in the second time window and is also accessed by an external network IP address, then the second time window is determined to be the first target time window; the first time window contains multiple second time windows;

[0145] If the number of times the first target time window is included in the first time window reaches a preset threshold, then an internal network port reverse shell attack is determined to exist.

[0146] In some possible embodiments, after processor 1001 determines that the second time window is the first target time window, if an IP address in the first target IP address set accesses the internal network port of the internal network IP address in the second time window and is also accessed by an external network IP address, it further executes:

[0147] If the number of times the first target time window is included in the first time window does not reach the preset threshold, then it is determined that there is no internal network port bounce attack.

[0148] In some possible embodiments, the intranet port is configured on a host in an intranet area, the intranet area includes hosts of at least one security level, each security level of the hosts corresponds to at least one host, and the intranet port subject to the intranet port bounce attack is configured on any one of the hosts.

[0149] In some possible embodiments, the intranet area includes hosts of a first security level and hosts of a second security level, the first security level is higher than the second security level, the intranet port subject to the intranet port bounce attack is configured on the host of the first security level, and the intranet port bounce attack is a first-level intranet port bounce attack.

[0150] In some possible embodiments, after the processor 1001 determines that the intranet port bounce attack exists, the processor 1001 is further configured to perform the following operations:

[0151] filtering out traffic with a first target port and a second target IP address set as destination ports and IP addresses in a first time window, and marking the traffic as a second target traffic set; the first target port is configured on the host of the second security level, and the second target IP address is an IP address corresponding to the host of the second security level;

[0152] extracting a source IP address of the second target traffic set to obtain a third target IP address set;

[0153] if an IP address in the third target IP address set accesses the first target port of the second target IP address in a second time window and is accessed by an external network IP address to a fixed port, determining that the second time window is a second target time window;

[0154] if a number of the second target time windows in the first time window reaches a preset threshold, determining that a second-level intranet port bounce attack exists.

[0155] In some possible embodiments, after the processor 1001 determines that, if an IP address in the third target IP address set accesses the first target port of the second target IP address in a second time window and is accessed by an external network IP address to a fixed port, the second time window is a second target time window, the processor 1001 is further configured to perform the following operations:

[0156] if a number of the second target time windows in the first time window does not reach the preset threshold, determining that the second-level intranet port bounce attack does not exist.

[0157] In some possible embodiments, the intranet area includes at least one of the following: a public area, a confidential area, a secret area, and a top secret area, and each area includes hosts of different security levels.

[0158] The embodiments of the present application further provide a computer readable storage medium, which stores instructions. When the instructions are executed on a computer or a processor, the computer or the processor performs one or more steps in the embodiments shown above. When each component module of the above-mentioned electronic device is implemented in the form of a software function unit and sold or used as an independent product, the computer readable storage medium can store the software function unit. Figures 2 to 8 The component modules of the above-mentioned electronic device, if implemented in the form of a software function unit and sold or used as an independent product, can be stored in the computer readable storage medium.

[0159] In the above embodiments, all or some of the steps can be implemented by software, hardware, firmware or any combination thereof. When implemented by software, all or some of the steps can be implemented in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded on a computer and executed, all or some of the steps described in the embodiments of the present application are performed. The computer can be a general purpose computer, a special purpose computer, a computer network, or other programmable apparatus. The computer instructions can be stored in a computer readable storage medium or transmitted by the computer readable storage medium. The computer instructions can be transmitted from one website, computer, server or data center to another website, computer, server or data center through a wired (such as coaxial cable, optical fiber, digital subscriber line (Digital Subscriber Line, DSL)) or wireless (such as infrared, wireless, microwave, etc.) manner. The computer readable storage medium can be any available medium accessible by a computer or a data storage device such as a server, data center, etc. integrated with one or more available media. The available media can be a magnetic medium (for example, a floppy disk, a hard disk, a magnetic tape), an optical medium (for example, a digital versatile disc (Digital Versatile Disc, DVD)), or a semiconductor medium (for example, a solid state disk (Solid State Disk, SSD)) and the like.

[0160] A person of ordinary skill in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be implemented by a computer program to instruct the relevant hardware, and the program can be stored in a computer readable storage medium. When the program is executed, it can include the processes of the above-mentioned embodiments of each method. The aforementioned storage medium includes ROM, RAM, magnetic or optical disks and various program code storage media. In the case of no conflict, the technical features in the embodiments and the embodiments can be combined arbitrarily.

[0161] The above-described embodiments are merely exemplary and are not intended to limit the scope of the present application. Various modifications and improvements can be made to the embodiments of the present application by those skilled in the art without departing from the design spirit of the present application, and such modifications and improvements shall fall within the scope of the claims of the present application.

Claims

1. A method for detecting port bounce, characterized in that, The method includes: Filter out traffic in the first time window whose destination port is an internal network port and whose destination network protocol IP address is an internal network, and mark it as the first target traffic set; Extract the source IP addresses from the first target traffic set to obtain the first target IP address set; If an IP address in the first set of target IP addresses accesses the internal network port of an internal network IP address in the second time window and is also accessed by an external network IP address, then the second time window is determined to be the first target time window; the first time window contains multiple second time windows; If the number of times the first target time window is included in the first time window reaches a preset threshold, then an internal network port reverse shell attack is determined to exist.

2. The method according to claim 1, characterized in that, If, within the first set of target IP addresses, there exists an IP address that accesses the internal network port of an internal network IP address within the second time window and is also accessed by an external network IP address, then after determining the second time window as the first target time window, the method further includes: If the number of times the first target time window is included in the first time window does not reach the preset threshold, then it is determined that there is no internal network port bounce attack.

3. The method according to claim 1, characterized in that, The internal network port is configured on a host in the internal network area, which includes hosts of at least one security level. Each security level of host corresponds to at least one host. The internal network port that is vulnerable to internal network port reverse shell attacks is configured on any one of the hosts.

4. The method according to claim 3, characterized in that, The intranet area includes hosts at a first security level and hosts at a second security level, with the first security level being higher than the second security level; the intranet port where the intranet port reverse bounce attack exists is configured on the host at the first security level, and the intranet port reverse bounce attack is a level one intranet port reverse bounce attack.

5. The method according to claim 4, characterized in that, After determining that an internal network port reverse shell attack exists, the method further includes: Filter out traffic in the first time window whose destination port is the first target port and whose destination IP address is the second target IP address set, and mark it as the second target traffic set; the first target port is configured on the host of the second security level, and the second target IP address is the IP address corresponding to the host of the second security level; The source IP addresses of the second target traffic set are extracted to obtain the third target IP address set; If an IP address in the third target IP address set accesses the first target port of the second target IP address in the second time window, and is accessed by an external IP address on a fixed port, then the second time window is determined to be the second target time window. If the number of second target time windows included in the first time window reaches the preset threshold, it is determined that a secondary intranet port reverse shell attack exists.

6. The method according to claim 5, characterized in that, If any IP address in the third set of target IP addresses accesses the first target port of the second target IP address within the second time window, and is accessed by an external IP address on a fixed port, then after determining the second time window as the second target time window, the method further includes: If the number of second target time windows included in the first time window does not reach the preset threshold, it is determined that there is no secondary intranet port reverse shell attack.

7. The method according to any one of claims 3-6, characterized in that, The internal network area includes at least one of the following: public area, confidential area, secret area, and top secret area, with each area including hosts with different security levels.

8. A detection device for port bounce, characterized in that, include: The filtering module is used to filter out traffic in the first time window whose destination port is an internal network port and whose destination network protocol IP address is an internal network, and mark it as the first target traffic set; The extraction module is used to extract the source IP addresses of the first target traffic set to obtain the first target IP address set; The determination module is used to determine the second time window as the first target time window if an IP address in the first target IP address set accesses the internal network port of the internal network IP address in the second time window and is also accessed by an external network IP address; the first time window contains multiple second time windows; if the number of first target time windows contained in the first time window reaches a preset threshold, it is determined that there is an internal network port reverse shell attack.

9. A computer storage medium, characterized in that, The computer storage medium stores a plurality of instructions, which are adapted to be loaded by a processor and executed as method steps as claimed in any one of claims 1 to 7.

10. An electronic device, characterized in that, include: A memory and a processor; wherein the memory stores a computer program adapted to be loaded by the processor and executed the method steps as claimed in any one of claims 1 to 7.

Citation Information

Patent Citations

  • Reflection attack protection and flow cleaning method and device, equipment and medium

    CN110365658A

  • Automated Prediction Of Cybersecurity Vulnerabilities

    US20230019180A1