Network security service method, device and system

By deploying a mapping generator and controller between network security toolsets and target systems, a mapping relationship between fixed and dynamic addresses is established, solving the problem of difficult network security tool invocation and achieving effective service and system decoupling in various network environments.

CN118827087BActive Publication Date: 2025-11-21CHINA MOBILE GRP GUANGDONG CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202311159463.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-09-07
Publication Date
2025-11-21
Estimated Expiration
2043-09-07

AI Technical Summary

Technical Problem

In the process of calling and configuring network security tools, the large number of tools makes the tasks of calling, configuring and using them extremely difficult as network devices and systems increase, and existing technologies are unable to provide effective network security services in various network environments.

Method used

By deploying a mapping generator and a mapping controller, a mapping relationship is established between the fixed and dynamic addresses in the mapping generator and the target system, thereby decoupling the network security toolset from the target system. The mapping proxy enables the sending and receiving of data packets in non-direct address domains.

Benefits of technology

It enables the use of a universal network security toolset to provide effective services to the target system in various network environments, solves the decoupling between the network security toolset and the target system, and has flexible adaptability and connection quality monitoring and optimization.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118827087B_ABST
    Figure CN118827087B_ABST
Patent Text Reader

Abstract

The application provides a network security service method, device and system. The system comprises a mapping generator and a mapping controller, the mapping generator comprises a fixed address set and a dynamic address set; the mapping controller configures the fixed address set to a target service address of a network security tool set; receives a security service request sent by a target system, establishes a mapping relationship between a target address set of the target system and the dynamic address set, establishes a mapping relationship between the fixed address set and the dynamic address set; establishes an association relationship between an address port combination of the target address set and an address port combination of the fixed address set; and notifies the network security tool set to provide a service for the fixed address set. The network address cross-domain mapping technical problem is effectively solved, the network security tool set and the target system are decoupled, and the network security tool set can provide effective services for the target system in various network environments.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of network address mapping, and in particular to a network security service method, device and system. BACKGROUND

[0002] In order to achieve effective protection of network security, network operation personnel need to perform operations such as vulnerability scanning, penetration testing and data checking on the network and target protection system equipment. Due to the high requirements of these operations on technology and business processes, various network security tools are often used to assist in implementation.

[0003] Due to the large number of network security tools involved, with the increase of network equipment and target protection systems, the calling, configuration and use of these tools will become very difficult. SUMMARY

[0004] The present application provides a network security service method, device and system to achieve effective services provided by a universal network security tool set to a target system in various network environments. The technical solution of the present application is as follows:

[0005] In a first aspect, the present application provides a network security service method, which is applied to a mapping controller and includes the following steps:

[0006] Obtaining a fixed address set of a mapping generator and configuring the fixed address set in a target service address of a network security tool set; wherein the mapping generator includes an IP address set, and the IP address set includes a fixed address set and a dynamic address set;

[0007] In response to receiving a security service request sent by a target system, establishing a mapping relationship between a target address set of the target system and an available dynamic address set in the dynamic address set, and establishing a mapping relationship between the fixed address set and the available dynamic address set in the dynamic address set;

[0008] Based on the mapping relationship between the target address set of the target system and the available dynamic address set in the dynamic address set and the mapping relationship between the fixed address set and the available dynamic address set in the dynamic address set, an association relationship is established between an address port combination of the target address set and an address port combination of the fixed address set to achieve transmission of data packets;

[0009] Notifying the network security tool set to provide services for the fixed address set, and sending a service report generated by the network security tool set to the target system.

[0010] In some implementations, the method further includes:

[0011] In response to receiving the registration information submitted by the target system, a target address set of the target system is obtained based on the registration information.

[0012] The establishing of the mapping relationship between the target address set of the target system and the available dynamic address set in the dynamic address set, and the establishing of the mapping relationship between the fixed address set and the available dynamic address set in the dynamic address set, comprises:

[0013] For each target address in the target address set, a first tuple list with address port combination as elements is constructed; and the first tuple lists of the target address set are spliced to obtain a first total tuple list;

[0014] For each dynamic address in the available dynamic address set, a second tuple list with address port combination as elements is constructed; and the second tuple lists of the available dynamic address set are spliced to obtain a second total tuple list;

[0015] For each fixed address in the fixed address set, a third tuple list with address port combination as elements is constructed; and the third tuple lists of the fixed address set are spliced to obtain a third total tuple list;

[0016] The number of elements in the first total tuple list and the second total tuple list is obtained respectively to obtain a first length and a second length;

[0017] Based on the first total tuple list, the second total tuple list, the third total tuple list, the first length and the second length, the mapping relationship between the target address set and the available dynamic address set and the mapping relationship between the fixed address set and the available dynamic address set are obtained.

[0018] In some implementations, the obtaining of the mapping relationship between the target address set and the available dynamic address set and the mapping relationship between the fixed address set and the available dynamic address set based on the first total tuple list, the second total tuple list, the third total tuple list, the first length and the second length comprises:

[0019] The following steps are executed in a loop until all elements in the first total tuple list complete mapping matching with elements in the second total tuple list;

[0020] From the first total tuple list, a second length of first target elements are determined, and the second length of first target elements are associated with a second length of second target elements in the second total tuple list in a one-to-one manner to obtain the mapping relationship between the target address set and the available dynamic address set;

[0021] establishing one-to-one association between the second length of second target elements in the second total list of two-element groups and the determined second length of third target elements in the third total list of two-element groups, to obtain a mapping relationship between the fixed address set and the available dynamic address set;

[0022] After completing packet interaction between the network security tool set and the target system, deleting the determined second length of first target elements from the first total list of two-element groups.

[0023] In some implementations, the method further comprises:

[0024] In a case where the target address set and the available dynamic address set belong to address domains that cannot be directly passed through, establishing, by a mapping agent, an association relationship between address port combinations of the target address set and address port combinations of the fixed address set.

[0025] In some implementations, the method further comprises:

[0026] counting a plurality of index parameters, the plurality of index parameters including a speed of transmitting and receiving data packets of each address port combination in the available dynamic address set, a number of established sessions, and a success rate of established sessions;

[0027] based on the plurality of index parameters and respective threshold values, changing a mapping relationship between the target address set of the target system and the available dynamic address set in the dynamic address set, and changing a mapping relationship between the fixed address set and the available dynamic address set in the dynamic address set.

[0028] In some implementations, after the method of sending the service report generated by the network security tool set to the target system, further comprising:

[0029] releasing the mapping relationship between the target address set of the target system and the available dynamic address set in the dynamic address set, and releasing the mapping relationship between the fixed address set and the available dynamic address set in the dynamic address set.

[0030] In a second aspect, an embodiment of the present application provides a network security service device, which is configured in a mapping controller and comprises:

[0031] a fixed address configuration module configured to obtain a fixed address set of a mapping generator and to configure the fixed address set in a target service address of a network security tool set, wherein the mapping generator comprises an IP address set, and the IP address set comprises a fixed address set and a dynamic address set;

[0032] The mapping relationship configuration module is used to, in response to receiving a security service request sent by the target system, establish a mapping relationship between the target address set of the target system and the available dynamic address set in the dynamic address set, and establish a mapping relationship between the fixed address set and the available dynamic address set in the dynamic address set;

[0033] The port association module is used to establish an association between the address port combination of the target address set and the address port combination of the fixed address set based on the mapping relationship between the target address set of the target system and the available dynamic address set in the dynamic address set and the mapping relationship between the fixed address set and the available dynamic address set in the dynamic address set, so as to realize the transmission of data packets.

[0034] The service control module is used to notify the network security toolset to provide services to the fixed address set and to send the service report generated by the network security toolset to the target system.

[0035] In some implementations, the fixed address configuration module is specifically used for:

[0036] Each fixed address in the fixed address set is set to the target service address of each tool in the network security toolset.

[0037] In some implementations, the mapping configuration module is also used for:

[0038] In response to receiving the registration information submitted by the target system, the target address set of the target system is obtained based on the registration information.

[0039] In some implementations, the mapping configuration module is specifically used for:

[0040] For each target address in the target address set, construct a first binary tuple list with address port combinations as elements; and concatenate the first binary tuple list of the target address set to obtain the total first binary tuple list.

[0041] For each dynamic address in the available dynamic address set, construct a second list of tuples with address port combinations as elements; and concatenate the second list of tuples in the available dynamic address set to obtain the total list of second tuples.

[0042] For each fixed address in the fixed address set, construct a list of third tuples with address port combinations as elements; and concatenate the list of third tuples in the fixed address set to obtain a total list of third tuples.

[0043] The number of elements in the first binary tuple list and the second binary tuple list are obtained respectively to obtain the first length and the second length;

[0044] obtain the mapping relationship between the target address set and the available dynamic address set and the mapping relationship between the fixed address set and the available dynamic address set based on the first total list of two-tuples, the second total list of two-tuples, the third total list of two-tuples, the first length, and the second length.

[0045] In some implementations, the mapping relationship configuration module, when obtaining the mapping relationship between the target address set and the available dynamic address set and the mapping relationship between the fixed address set and the available dynamic address set based on the first total list of two-tuples, the second total list of two-tuples, the third total list of two-tuples, the first length, and the second length, is specifically configured to:

[0046] perform the following steps in a loop until all elements in the first total list of two-tuples complete mapping matching with elements in the second total list of two-tuples;

[0047] determine second length first target elements from the first total list of two-tuples, and establish one-to-one association between the second length first target elements and second length second target elements in the second total list of two-tuples, to obtain the mapping relationship between the target address set and the available dynamic address set;

[0048] establish one-to-one association between the second length second target elements in the second total list of two-tuples and second length third target elements determined from the third total list of two-tuples, to obtain the mapping relationship between the fixed address set and the available dynamic address set;

[0049] After completing packet interaction between the network security tool set and the target system, delete the determined second length first target elements from the first total list of two-tuples.

[0050] In some implementations, the port association module is further configured to:

[0051] In the case that the target address set and the available dynamic address set belong to address domains that cannot be directly passed through, establish an association relationship between address port combinations of the target address set and address port combinations of the fixed address set through a mapping agent.

[0052] In some implementations, the mapping relationship configuration module is further configured to:

[0053] count a plurality of index parameters, the plurality of index parameters including a transceiving packet speed, a number of established sessions, and a success rate of establishing sessions of each address port combination in the available dynamic address set;

[0054] based on the plurality of index parameters and the respective corresponding threshold values, changing a mapping relationship between the target address set of the target system and the available dynamic address set in the dynamic address set, and changing a mapping relationship between the fixed address set and the available dynamic address set in the dynamic address set.

[0055] In some implementations, the mapping relationship configuration module is further configured to:

[0056] release the mapping relationship between the target address set of the target system and the available dynamic address set in the dynamic address set, and release the mapping relationship between the fixed address set and the available dynamic address set in the dynamic address set.

[0057] In a third aspect, an embodiment of the present application provides a network security service system, comprising:

[0058] a mapping generator, the mapping generator comprising an IP address set, the IP address set comprising a fixed address set and a dynamic address set;

[0059] a mapping controller configured to perform the network security service method of the first aspect of the present application.

[0060] In a fourth aspect, an embodiment of the present application provides an electronic device, comprising: at least one processor; and a memory communicatively connected with the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the network security service method of the first aspect of the present application.

[0061] In a fifth aspect, an embodiment of the present application provides a non-transitory computer-readable storage medium storing computer instructions, the computer instructions being used to cause a computer to perform the network security service method of the first aspect of the present application.

[0062] In a sixth aspect, an embodiment of the present application provides a computer program product, comprising computer instructions, which, when executed by a processor, implement the steps of the network security service method of the first aspect of the present application.

[0063] The technical solutions provided in the embodiments of the present application at least bring the following beneficial effects:

[0064] The fixed address set of the mapping generator is configured to the target service address of the network security tool set, and the dynamic address set of the mapping generator is dynamically bound to the target address set of the target system, and the mapping relationship between the fixed address set and the bound dynamic address set is established, which effectively solves the cross-domain mapping technical problem of network address, realizes the decoupling of the network security tool set and the target system, has flexible adaptability, and realizes that the general network security tool set can provide effective services for the target system in various network environments.

[0065] It should be understood that the foregoing general description and the following detailed description are only exemplary and explanatory, and are not limiting to the present application. BRIEF DESCRIPTION OF DRAWINGS

[0066] The accompanying drawings incorporated in and forming a part of the specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the application without imposing on the application limitations inconsistent with the patent law.

[0067] Figure 1 is a flow chart of a network security service method according to an exemplary embodiment.

[0068] Figure 2 is a flow chart of a network security service method according to another exemplary embodiment.

[0069] Figure 3 is an example diagram of a network security service method according to an example.

[0070] Figure 4 is an example diagram of a network security service method according to another example.

[0071] Figure 5 is a block diagram of a network security service system according to an exemplary embodiment.

[0072] Figure 6 is a block diagram of a network security service device according to an exemplary embodiment.

[0073] Figure 7 is a block diagram of an electronic device according to an exemplary embodiment. DETAILED DESCRIPTION

[0074] In order for ordinary people in the art to better understand the technical solutions of the present application, the technical solutions in the embodiments of the present application will be described clearly and completely below in conjunction with the drawings.

[0075] It should be noted that the terms "first", "second", etc. in the present application are used to distinguish similar objects, and do not necessarily have to be used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances, so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. The implementation described in the following exemplary embodiments does not represent all implementations consistent with the present application. Instead, they are merely examples of devices and methods consistent with some aspects of the present application as detailed in the appended claims.

[0076] Network security, commonly referred to as computer network security, can actually refer to the security of computer communication networks. A computer communication network is a system that connects several computers with independent functions through communication equipment and transmission media, and realizes information transmission and exchange between computers under the support of communication software. A computer network refers to a system that connects several independent computer systems, terminal equipment and data equipment in different regions for the purpose of sharing resources, using communication means, and exchanging data under the control of protocols.

[0077] In order to effectively protect network security, network operation and maintenance personnel need to perform operations such as vulnerability scanning, penetration testing, and data checking on the network and system equipment. Due to the high requirements of technology and business processes for these operations, various tools are often used to assist in implementation. Taking vulnerability scanning as an example, common vulnerability scanning tools provide automatic scanning capabilities for system vulnerabilities. In order to ensure system security, some organizations often require regular scanning of systems in accordance with security standard requirements. Taking web application vulnerability scanning as an example, the security industry proposes OWASP 10 as a security vulnerability definition and example for web application security. OWASP 10 usually lists ten common vulnerabilities, and the discovery and repair of these vulnerabilities is the most effective first step to achieve software development security and source code security. Common vulnerability types include access control damage, encryption failure, injection, insecure design, security misconfiguration, vulnerable and outdated components, identification and authentication failure, security log recording and monitoring failure, and server-side request forgery.

[0078] Due to the large number of tools involved, with the increase of network equipment and systems, the tasks of calling, configuring and using these tools will become very difficult.

[0079] To solve the problem of the difficulty of calling various tools, the prior art mainly solves the conversion of network addresses, and realizes the availability and reachability of target network addresses through address conversion and address mapping methods. However, in the context of network security, the access demand for target addresses not only includes address reachability, but also needs to solve technical problems including application accessibility, role control of communication parties, and differences in data interaction behaviors. Therefore, it is necessary to provide an effective technical solution for the use of network addresses of communication parties required by network security, so as to realize that the target system can be provided with effective services by a general network security tool set in various network environments.

[0080] To solve the above problems, the embodiments of the present application provide a network security service method, device and system. The core idea of the network security service method is to deploy a mapping generator and a mapping controller between a target system and a network security tool set, the mapping controller fixes a part of fixed addresses in the mapping generator in the network security tool set, and uses another part of dynamic addresses in the mapping generator for dynamic binding with target addresses of the target system. When the address mapping is performed, a one-to-one correspondence between IP addresses and ports in the fixed addresses, the dynamic addresses and the target addresses in the mapping generator is established. The technical problem of network security service is effectively solved, the decoupling of the network security tool set and the target system is realized, and the flexible adaptability is achieved. Meanwhile, the connection quality can be monitored and optimized.

[0081] Figure 1 is a flowchart of a network security service method according to an embodiment of the present application. It should be noted that the network security service method of the embodiments of the present application can be applied to the network security service device of the embodiments of the present application. The network security service device can be configured on the mapping controller. As shown in Figure 1 the network security service method can include the following steps:

[0082] In step S101, a fixed address set of a mapping generator is obtained, and the fixed address set is configured in a target service address of a network security tool set; wherein the mapping generator includes an IP address set, and the IP address set includes a fixed address set and a dynamic address set.

[0083] First of all, it should be noted that the mapping generator is a set of IP addresses, and the addresses in the mapping generator are divided into two parts, one part is a fixed address set for fixed setting in the network security tool set, which is called Afix, and the other part is a dynamic address set for dynamic binding with the target address set of the target system, which is called Adyn.

[0084] As an implementation, the dynamic address set is divided into an available dynamic address set Ause for interfacing with the target system and a free dynamic address set Afree. If an address in the available dynamic address set Ause is shielded or other abnormal conditions occur, an address can be randomly obtained from the free dynamic address set Afree to replace it.

[0085] As a specific implementation, an expansion factor alpha is set, and the addresses in Adyn are divided into two parts: Ause and Afree for interfacing with the target system according to alpha.

[0086] The quantity ratio of the two parts satisfies: size(Ause) / size(Afree)=1 / alpha.

[0087] The mapping controller takes the fixed address set of the mapping generator as the fixed target service addresses of the network security tool set. When the mapping controller initializes the network security tool set, the fixed address set of the mapping generator is configured in the target service addresses of the network security tool set as the fixed target set of the network security tool set. The network security tool set provides corresponding security services according to the target service addresses.

[0088] As an implementation, each fixed address in the fixed address set is respectively set in the target service address of each security tool in the network security tool set.

[0089] In addition, the fixed address needs to be set according to the processing capacity of the network security tool set. For example, the corresponding fixed address can be set as the default target service address of each security tool in the network security tool set according to the processing capacity of each security tool in the network security tool set.

[0090] In step S102, in response to receiving the security service request sent by the target system, a mapping relationship between the target address set of the target system and the available dynamic address set in the dynamic address set is established, and a mapping relationship between the fixed address set and the available dynamic address set in the dynamic address set is established.

[0091] It should be noted that the mapping controller needs to obtain the registration information of the target system before receiving the security service request sent by the target system, so as to obtain the target address set and other information of the target system from the registration information.

[0092] As an implementation, in response to receiving the registration information submitted by the target system, the target address set of the target system is obtained based on the registration information.

[0093] It can be understood that the target system needs to submit a registration request carrying registration information to the mapping controller to register the target address set Aobj requiring services to the mapping controller, so as to send a security service request to the mapping controller. The registration information at least includes the following contents: device name, device type, device IP address information, operating system and version, application name, protocol, port, etc. The device IP address information constitutes the target address set of the target system.

[0094] Optionally, the registration request carries a registration message, and the registration message includes the registration information. The message structure of the registration message includes the device name, device type, device IP address, operating system and version, application 1 name / protocol / port, application 2 name / protocol / port, etc.

[0095] When the target system needs the network security tool set to provide security services, the target system sends a security service request to the mapping controller. After receiving the security service request sent by the target system, the mapping controller establishes the mapping relationship between the target address set of the target system and the available dynamic address set in the dynamic address set according to the network configuration, and establishes the mapping relationship between the fixed address set and the available dynamic address set in the dynamic address set.

[0096] That is, the mapping controller allocates and configures the available dynamic address for the target system, maps the target address set of the target system to the available dynamic address set in the dynamic address set, and constructs the corresponding relationship between the fixed address set and the available dynamic address set, so as to dynamically bind the target address set of the target system and the available dynamic address set in the dynamic address set, and finally associate the target address set of the target system with the fixed address set of the mapping generator.

[0097] As an implementation manner, as shown in Figure 2 The establishment of the mapping relationship includes the following steps:

[0098] Step S201, for each target address in the target address set, a first two-tuple list with address port combination as elements is constructed; and the first two-tuple lists of the target address set are spliced to obtain a first two-tuple total list;

[0099] Step S202, for each dynamic address in the available dynamic address set, a second two-tuple list with address port combination as elements is constructed; and the second two-tuple lists of the available dynamic address set are spliced to obtain a second two-tuple total list;

[0100] Step S203, for each fixed address in the fixed address set, a third two-tuple list with address port combination as elements is constructed; and the third two-tuple lists of the fixed address set are spliced to obtain a third two-tuple total list;

[0101] Step S204, respectively obtaining the number of elements in the first and second total lists of tuples, to obtain the first and second lengths;

[0102] Step S205, performing the following steps in a loop until all elements in the first total list of tuples complete mapping matching with elements in the second total list of tuples;

[0103] Step S206, determining the second length of first target elements from the first total list of tuples, and establishing one-to-one association between the second length of first target elements and the second length of second target elements in the second total list of tuples, to obtain the mapping relationship between the target address set and the available dynamic address set.

[0104] Step S207, establishing one-to-one association between the second length of second target elements in the second total list of tuples and the second length of third target elements determined from the third total list of tuples, to obtain the mapping relationship between the fixed address set and the available dynamic address set.

[0105] Step S208, after completing packet interaction between the network security tool set and the target system, deleting the second length of first target elements determined from the first total list of tuples.

[0106] It should be noted that since the elements in the total list of tuples in Ause are relatively fixed, and the elements in the total list of tuples in Aobj may change, the number of elements in the total list of tuples corresponding to the dynamic address is used to establish one-to-one correspondence between the elements, and after completing packet interaction between the network security tool set and the target system, the second length of first target elements determined from the first total list of tuples is deleted, i.e. the mapping relationship is released, and the elements in the total list of tuples corresponding to the dynamic address set can continue to be used in the next round of mapping relationship establishment, so that the entire mapping operation is completed through multiple rounds of loops.

[0107] For example, the IP address set of the network security tool set is T = {t1, t2, t3, … ti…}, where ti is the IP address of the ith security tool, supporting IPv4 and IPv6.

[0108] The address set {Afix, Adyn} of the mapping generator is M = {m1 / (q11, q12,...), m2 / (q21, q22,...),... mi / (qi1, qi2, … qij…), …}, where mi is the ith address of the mapping generator, and qij is the jth port of the ith address in the mapping generator. mi belongs to IPv4 or IPv6 address space, for example: 192.168.1.1, 100A:90::19F1, etc.

[0109] The target address set Aobj of the target system is set as Aobj = {n1 / (p11, p12,...), n2 / (p21, p22,...),... ni / (pi1, pi2,...pij,...}, where ni is the i-th target address of the target system, and qij is the j-th port of the i-th address in the mapping generator. ni belongs to the IPv4 or IPv6 address space, for example: 10.10.1.1, 1A:9::F1, etc. The following steps are applicable to security tools based on TCP and UDP protocols. For the sake of clarity, the mapping implementation for the TCP protocol is taken as the default in each step, but the mapping implementation for the UDP protocol is also applicable.

[0110] In step S21, each target address in the target system Aobj and the corresponding multiple ports are combined into a two-tuple to construct a two-tuple list.

[0111] It should be noted that a device includes an IP address and multiple ports, and each port corresponds to an application. Therefore, according to an IP address and a port number, a unique application on a device can be determined. If an IP address and multiple ports of a device are combined into a two-tuple including an address and a port (for example, ni / pi1), multiple two-tuples can be obtained, and the multiple two-tuples are combined into a two-tuple list, where each two-tuple composed of an address and a port is an element in the two-tuple list, that is, each element corresponds to an application of a device to which the address belongs.

[0112] For example, for the target address ni, the two-tuple list constructed is:

[0113] Ci = [Ci1 = (ni / pi1), Ci2 = (ni / pi2),...].

[0114] In step S22, all two-tuple lists constructed for the target system Aobj are spliced to obtain a first two-tuple total list: D = [C1, C2,...].

[0115] In step S23, each dynamic address in the Ause part of the mapping generator M and the corresponding multiple ports are combined into a two-tuple to construct a two-tuple list.

[0116] For example, the two-tuple list Ei = [Ei1 = (mi / qi1),... Eix(mi / qix),...], where mi is an address in the Adyn part of M, and qix is a port number, taking a value in the range (1-65535).

[0117] Step S24, the list of the tuples of Adyn in the mapping generator M is spliced to obtain a total list of tuples: F=[E1, E2,...]. In order to randomly allocate the target service address and port to the whole mapping generator, F is randomly sorted;

[0118] Step S25, similarly, the list of the tuples of all addresses and ports of the Afix part in the mapping generator M is constructed and spliced to obtain a total list of tuples: G=[B1, B2,...].

[0119] Step S26, the length of the total list of tuples F of Ause is calculated and denoted as Lf.

[0120] Step S27, the length of the total list of tuples D of the target system Aobj is calculated and denoted as Ld.

[0121] Step S28, Ld elements are taken out from F and one-to-one associated with Ld elements in the total list of tuples D to obtain a one-to-one correspondence; Ld elements are taken out from the list of tuples G in Afix and one-to-one associated with the Ld elements taken out from F to obtain a one-to-one correspondence.

[0122] X=[(Cij, Egh)], that is, a list of one-to-one correspondence between the tuples of Aobj and Ause.

[0123] Y=[(Bkl, Egh)], that is, a list of one-to-one correspondence between the tuples of Afix and Ause.

[0124] Let Cij=(ni / Pni), Egh=(mg / Pmg), Bkl=(tq / Ptq), wherein ni is a target address in the target system Aobj, mg is a dynamic address of Ause in Adyn, tq is a fixed address in Afix, and Pni, Pmg, Ptq are ports on the corresponding addresses.

[0125] Since the one-to-one correspondence of IP and port between Afix and Ause and Aobj has been established in step S28, the data packet sent by the network security tool to the address Bkl=(tq / Ptq) in Afix can be sent to the target address (ni / Pni) in the target system Aobj through Egh=(mg / Pmg).

[0126] As another possible implementation, the establishment of the mapping relationship includes the following steps:

[0127] Step S301, for each target address in the target address set, a first list of tuples with address port combination as elements is constructed; and the first list of tuples of the target address set is spliced to obtain a first total list of tuples;

[0128] In step S302, for each dynamic address in the set of available dynamic addresses, a second list of tuples is constructed with address-port combinations as elements; and the second lists of tuples of the set of available dynamic addresses are concatenated to obtain a second total list of tuples.

[0129] In step S303, for each fixed address in the set of fixed addresses, a third list of tuples is constructed with address-port combinations as elements; and the third lists of tuples of the set of fixed addresses are concatenated to obtain a third total list of tuples.

[0130] In step S304, the number of elements in the first total list of tuples and the second total list of tuples are obtained respectively to obtain a first length and a second length.

[0131] In step S305, the first length of second target elements are determined from the second total list of tuples, and the first length of second target elements are associated with the first length of first target elements in the first total list of tuples in a one-to-one manner to obtain a mapping relationship between the set of target addresses and the set of available dynamic addresses.

[0132] In step S306, the first length of second target elements in the second total list of tuples are associated with the first length of third target elements determined from the third total list of tuples in a one-to-one manner to obtain a mapping relationship between the set of fixed addresses and the set of available dynamic addresses.

[0133] That is, the number of elements in the total list of tuples corresponding to the target address is used as a criterion to take the same number of elements from the total list of tuples corresponding to the dynamic address to establish a one-to-one correspondence between the address-port combinations; similarly, for the set of dynamic addresses that have established a mapping relationship with the target address, a one-to-one correspondence between the address-port combinations in the same number of fixed address sets is established.

[0134] In step S103, based on the mapping relationship between the set of target addresses and the set of available dynamic addresses in the dynamic address set of the target system and the mapping relationship between the set of fixed addresses and the set of available dynamic addresses in the dynamic address set, an association relationship between the address-port combinations of the set of target addresses and the address-port combinations of the set of fixed addresses is established to realize the transmission of data packets.

[0135] This step is to open the port and address mapping, for example, the network security tool set is preset to access the Ptq port of the tq address in Afix, and real access to the Pni port of the ni address in the target system Aobj also needs to be realized according to the following steps.

[0136] It can be understood that the mapping controller needs to open the port and address mapping after mapping the target address set of the target system to the available dynamic address set in the dynamic address set, and establish the association between the port of each target address and the port of the dynamic address with which the mapping relationship has been established, so that when the network security tool accesses the port of a dynamic address, the data packet sent by the network security tool will be forwarded to the port of the target address with which the mapping relationship has been established, and the data packet returned from the port of the target address will be returned to the network security tool through the port of the dynamic address, that is, the real access of the network security tool set to the target system is realized.

[0137] According to different situations of actual scenes, different implementation methods of the network security tool set for sending data packets to the corresponding port of the target address of the target system are as follows:

[0138] 1) If the target address port and the address port of the mapping generator are directly reachable, the mapping generator can directly forward the data packet received at the fixed address port thereof to the corresponding target address port through the corresponding dynamic address port.

[0139] 2) If the target address port and the address port of the mapping generator are not directly reachable, but the firewall therebetween can be configured with NAT, the data packet transmission and reception can be realized by setting NAT / PAT and the like on the firewall.

[0140] 3) If the target address port and the address port of the mapping generator are not directly reachable, but a connection can be established by establishing a VPN or a tunnel, the data packet transmission and reception can be realized by establishing a VPN or a tunnel.

[0141] 4) Otherwise, the target address port and the address port of the mapping generator belong to address domains that cannot be directly passed through, and the data packet transmission and reception needs to be realized by an indirect mapping method.

[0142] As a specific implementation manner, in the case that the target address set and the available dynamic address set belong to address domains that cannot be directly passed through, an association relationship between the address port combination of the target address set and the address port combination of the fixed address set is established by a mapping agent. That is, in the case that the target address port and the address port of the mapping generator belong to address domains that cannot be directly passed through, the indirect mapping method is realized by the mapping agent, so as to realize the data packet transmission and reception.

[0143] For example, it is assumed that the target address n i is inside the firewall of the target system, and the dynamic address m g associated with the target address is outside the firewall. An address n 0 is arbitrarily selected in the target system, and the address n 0 is in the same network as the other target addresses n i, and the networks therebetween are interconnected. A mapping agent mirrorAgent is run on the address n 0, and the address mapping of the port is realized by the following operations:

[0144] S1, suppose there are N target addresses in the target system, then arrange the N target addresses and P open ports into a list K = [(ni, Pni)].

[0145] S2, suppose that one of the target addresses ni needs to obtain network security services, and its order index in the list K is Pn0.

[0146] S3, the mirrorAgent sends a TCP connection request to the port Pmg of the dynamic address mg corresponding to the target address ni, and sets the source port as Jn0, which represents the Pn0th address in the list K, which is ni.

[0147] S4, the dynamic address mg establishes a TCP connection C1 with the mirrorAgent through three-way handshake, and its (source address / port, target address / port) is (n0 / Pn0, mg / Pmg).

[0148] After the establishment of C1 connection, the target system can realize the transmission and reception of data packets.

[0149] For example, when the address Ti of the network security tool performs security services to the port Ptq of the fixed address tq, Ti will send an IP packet Sp0 containing Payload0 to the Ptq port of the fixed address tq. The (source address / port, target address / port) of the IP packet Sp0 are (Ti / Pti, tq / Ptq) respectively, wherein Pti is the port allocated by the network security tool to its own address Ti.

[0150] The format and content of the IP packet Sp0 are as follows:

[0151] Domain Value Source address Ti Source port Pti Destination address Tq Destination port Ptq IP data Payload0

[0152] Since the correspondence between Afix and Ause has been established by the above steps, the network space can perform address conversion on Sp0 to Sp1. However, in order to protect the information of SP0, the entire SP0 can be taken as the payload of SP1. The implementation is: the format of SP1 is the format of IP packet, but the content filled in the data part of the IP packet is SP0. The format of SP1 is as follows:

[0153] Domain Value Source address Ti Source port Pti Destination address mg Destination port Pmg IP data SP0

[0154] After receiving the IP packet Sp1 at the Pmg port of the dynamic address mg, it will modify the corresponding target IP address information based on it and encapsulate it into an IP packet Sp2, which is forwarded to the mirrorAgent through the connection C1;

[0155] The format of the IP packet Sp2 during forwarding is as follows:

[0156]

[0157] After the mirrorAgent receives the IP packet Sp2 through the connection C1, the mirrorAgent queries the corresponding address ni and the port Pni from the list K according to Pn0, and then changes the (source address / port, target address / port) to (n0 / Pn0, ni / Pni), and takes out the Payload0 in Sp0 to obtain the IP packet Sp3, and forwards Sp3 to the Pni port on the address ni in the target network. The following is the format of the IP packet Sp3 during forwarding:

[0158] Domain Value Source address n0 Source port Pn0 Destination address ni Destination port Pni IP data Payload0

[0159] After the Pni port on the address ni processes the Payload0, the response data is sent from the Pni port on the address ni to the Ptq port on the address tq through the mirrorAgent on the address n0 in the opposite direction, and finally reaches the network security tool, thereby completing the data interaction between the target system and the network security tool. That is, by modifying the source address port or the destination address port of the data packet based on the mapping relationship between the fixed address, the dynamic address, and the target address, the transmission of the data packet between the network security tool and the target system is realized.

[0160] It should be further noted that,

[0161] Since the network security tool needs to initiate more connection sessions and data transmission and reception to the target address, the mapping controller periodically changes the mapping relationship to prevent the related sessions from being intercepted by the firewall and the like.

[0162] As an implementation manner, a plurality of index parameters are counted, the plurality of index parameters including a data packet transmission and reception speed of each address port combination in the available dynamic address set, a number of established sessions, and a success rate of established sessions; and based on the plurality of index parameters and respective threshold values, a mapping relationship between the target address set of the target system and the available dynamic address set in the dynamic address set is changed, and a mapping relationship between the fixed address set and the available dynamic address set in the dynamic address set is changed.

[0163] The mapping controller counts and analyzes three indexes in real time when processing the data packet at each dynamic address, and periodically changes the mapping relationship to prevent the related sessions from being intercepted by the firewall and the like. Optionally, the three indexes include a data packet transmission and reception speed pps of each dynamic address port (for example, mg / Pmg) combination, a number of established sessions sessionnumber, and a success rate of established sessions sess_ratio, and threshold values of the three indexes are set.

[0164] For example, when the sending data packet speed pps or the number of sessions session number is greater than the corresponding threshold value, it indicates that the sending data is too fast, and the mapping relationship is replaced. The implementation is to randomly sort and recombine the available dynamic address set and remap it, so that the source address and port of the data packet sent from the network security tool to the target system through the mapping generator are randomly rotated, avoiding being intercepted due to the high speed of the network security tool sending data packets and the number of sessions. When the session establishment success rate sess_ratio is less than the threshold value, it indicates that the dynamic address may have been shielded, so a random address is taken out from the standby address set Afree to replace mg, avoiding the influence on the use of the network security tool due to the shielding of the fast or excessive sending of mg. Put mg into the Afree set for cooling, and wait for a period of time before recycling for use according to the need.

[0165] In step S104, the network security tool set is notified to provide services for the fixed address set, and the service report generated by the network security tool set is sent to the target system.

[0166] It can be understood that the mapping controller notifies the target system that the network security service is ready. The mapping controller notifies the network security tool set to start providing security services. The network security tool set uses the Afix set of the mapping generator as the target service address to carry out network security services. After the network security tool set completes the security services, it submits a service report to the mapping controller. After receiving the service report sent by the network security tool set, the mapping controller notifies the target system that the network security service has been completed, and sends the service report generated by the network security tool set to the target system.

[0167] It should be noted that after the open port and address mapping, the mapping controller starts to notify the corresponding network security tool to provide security services, and the service type is determined by the service request submitted by the target system to the mapping controller.

[0168] As an implementation, after receiving the service report sent by the network security tool set, the mapping controller releases the mapping relationship between the target address set, the available dynamic address set in the dynamic address set, and the fixed address set established in the previous step.

[0169] That is, the address mapping relationship between the network security tool set and the target system will be released after each service is completed, and the mapping relationship will be re-established before the next service to ensure the security of the system.

[0170] By implementing the embodiment, the fixed address set of the mapping generator is configured to the target service address of the network security tool set, and the dynamic address set of the mapping generator is dynamically bound to the target address set of the target system, and the mapping relationship between the fixed address set and the bound dynamic address set is established, effectively solving the cross-domain mapping technical problem of network address, realizing the decoupling of the network security tool set and the target system, and having flexible adaptability. In the network security scene, for the needs of address reachability, application accessibility, role control of communication parties, and control of data interaction behavior of various target systems required for protection, the mapping controller and the mapping generator are used to realize the mapping, conversion and connection of the target system address in various network environments, and the mapping mechanism is controlled according to the characteristics of the network security tool, so that the network security tool set can provide effective services for the target system in various network environments. At the same time, the connection quality of the network security tool set and the target system can be monitored and optimized, the mapping relationship can be updated based on the actual communication situation, the related session can be avoided to be intercepted by the firewall and other devices, and high-quality network security services can be realized.

[0171] As can be seen from the above embodiments, the implementation of the network security service method is specifically divided into two cases, one is the case of needing a mapping agent, and the other is the case of not needing a mapping agent. Next, a specific example is provided for each of the two cases to further illustrate the network security service method of the present application.

[0172] Figure 3 is an example diagram of a network security service method provided by the present application. Referring to Figure 3 , the network security service method can include the following steps:

[0173] S1, preset the address information Afix of the mapping generator to the network security tool set.

[0174] The mapping controller presets the address information Afix of the mapping generator to the network security tool set.

[0175] S2, register the address information Aobj that needs service.

[0176] The target system registers the address information Aobj that needs service to the mapping controller.

[0177] S3, submit a service request.

[0178] The target system submits a service request to the mapping controller.

[0179] S4, allocate an available space address Adyn.

[0180] The mapping controller allocates an available space address Adyn.

[0181] S5, open port and address mapping (for the case of supporting NAT / PAT / tunneling).

[0182] The mapping controller opens port and address mapping to the network security device (firewall) (for the case of supporting NAT / PAT / tunneling).

[0183] S6, notify that the service is ready.

[0184] The mapping controller notifies the target system that the service is ready.

[0185] S7, start the security service.

[0186] The mapping controller notifies the network security toolset to start the security service.

[0187] S8, carry out the network security service.

[0188] The network security toolset carries out the network security service with the address set Afix of the mapping generator as the target service address.

[0189] S9, carry out the network security service (for the case of supporting NAT / PAT / tunneling).

[0190] If NAT / PAT / tunneling is supported, the service data packet of the network security toolset will be sent to the network security device by the mapping generator.

[0191] S10, forward the security service data packet (for the case of supporting NAT / PAT / tunneling).

[0192] The network security device (firewall) forwards the security service data packet to the target system.

[0193] S11, submit the service report.

[0194] The network security toolset submits the service report to the mapping controller after the service is completed.

[0195] S12, release the address space.

[0196] The mapping controller releases the mapping relationship of Ause, Afree, Adyn, etc. used in the above steps.

[0197] S13, notify that the service is completed.

[0198] The mapping controller notifies the target system that the service is completed.

[0199] For the case of needing a mapping agent, Figure 4 is another example diagram of the network security service method provided by the present application. Referring to Figure 4 , the steps of the network security service method are the same asFigure 3 The steps of the method shown include:

[0200] S5, opening the port and address mapping (applicable to the case where a proxy is needed).

[0201] The mapping controller opens the port and address mapping to the mapping proxy.

[0202] S9, launching a network security service (applicable to the case where a proxy is needed).

[0203] If a mapping proxy is needed, the service data packet of the network security tool set will be sent by the mapping generator to the network mapping proxy.

[0204] S10, forwarding the security service data packet (applicable to the case where a proxy is needed).

[0205] The mapping proxy forwards the security service data packet to the target system.

[0206] It should be noted that other steps in addition to the above steps are the same as the method shown in Figure 3 , and will not be repeated.

[0207] On the basis of any of the above embodiments, Figure 5 is a block diagram of a network security service system according to an exemplary embodiment. Referring to Figure 5 , the network security service system can include a mapping generator and a mapping controller.

[0208] The mapping generator includes an IP address set, which includes a fixed address set and a dynamic address set.

[0209] The mapping controller is configured to obtain the fixed address set of the mapping generator and configure the fixed address set in the target service address of the network security tool set.

[0210] The mapping controller is further configured to, in response to receiving a security service request sent by a target system, establish a mapping relationship between a target address set of the target system and an available dynamic address set in the dynamic address set, and establish a mapping relationship between the fixed address set and the available dynamic address set in the dynamic address set;

[0211] The mapping controller is further configured to, based on the mapping relationship between the target address set of the target system and the available dynamic address set in the dynamic address set and the mapping relationship between the fixed address set and the available dynamic address set in the dynamic address set, establish an association relationship between an address port combination of the target address set and an address port combination of the fixed address set, to realize transmission of a data packet.

[0212] The mapping controller is further configured to notify the network security tool set to provide services for the fixed address set, and send a service report generated by the network security tool set to the target system.

[0213] In some implementations, the mapping controller is specifically configured to:

[0214] set each fixed address in the fixed address set as a target service address of each tool in the network security tool set.

[0215] In some implementations, the mapping controller is further configured to:

[0216] In response to receiving the registration information submitted by the target system, obtain a target address set of the target system based on the registration information.

[0217] In some implementations, the mapping controller is specifically configured to:

[0218] For each target address in the target address set, construct a first tuple list with address-port combinations as elements; and splice the first tuple lists of the target address set to obtain a first total tuple list;

[0219] For each dynamic address in the available dynamic address set, construct a second tuple list with address-port combinations as elements; and splice the second tuple lists of the available dynamic address set to obtain a second total tuple list;

[0220] For each fixed address in the fixed address set, construct a third tuple list with address-port combinations as elements; and splice the third tuple lists of the fixed address set to obtain a third total tuple list;

[0221] Obtain the number of elements in the first total tuple list and the second total tuple list respectively to obtain a first length and a second length;

[0222] Based on the first total tuple list, the second total tuple list, the third total tuple list, the first length, and the second length, obtain a mapping relationship between the target address set and the available dynamic address set and a mapping relationship between the fixed address set and the available dynamic address set.

[0223] In some implementations, when obtaining the mapping relationship between the target address set and the available dynamic address set and the mapping relationship between the fixed address set and the available dynamic address set based on the first total tuple list, the second total tuple list, the third total tuple list, the first length, and the second length, the mapping controller is specifically configured to:

[0224] perform the following steps in a loop until all elements in the first total tuple list complete mapping matching with elements in the second total tuple list;

[0225] determine the second length of first target elements from the first total list of two-tuples, establish one-to-one association between the second length of first target elements and the second length of second target elements in the second total list of two-tuples, and obtain a mapping relationship between the target address set and the available dynamic address set;

[0226] establish one-to-one association between the second length of second target elements in the second total list of two-tuples and the second length of third target elements determined from the third total list of two-tuples, and obtain a mapping relationship between the fixed address set and the available dynamic address set;

[0227] after completing packet interaction between the network security tool set and the target system, delete the determined second length of first target elements from the first total list of two-tuples.

[0228] In some implementations, the mapping controller is further configured to:

[0229] in the case that the target address set and the available dynamic address set belong to address domains that cannot be directly passed through, establish an association relationship between the address port combination of the target address set and the address port combination of the fixed address set through the mapping agent.

[0230] In some implementations, the mapping controller is further configured to:

[0231] count a plurality of index parameters, the plurality of index parameters including a data packet transmission and reception speed of each address port combination in the available dynamic address set, a number of established sessions, and a success rate of established sessions;

[0232] based on the plurality of index parameters and respective threshold values, change a mapping relationship between the target address set of the target system and the available dynamic address set in the dynamic address set, and change a mapping relationship between the fixed address set and the available dynamic address set in the dynamic address set.

[0233] In some implementations, the mapping controller is further configured to:

[0234] release the mapping relationship between the target address set of the target system and the available dynamic address set in the dynamic address set, and release the mapping relationship between the fixed address set and the available dynamic address set in the dynamic address set.

[0235] By implementing the embodiment, a network security service system including at least a mapping controller and a mapping generator is constructed, the mapping controller is used to realize address mapping, conversion and connection of a target system in various network environments, the mapping mechanism is controlled according to the characteristics of a network security tool, and effective services of the target system by a general network security tool set in various network environments are realized. Through parameter setting and integration of network devices, address reachability and application accessibility are effectively realized, and network security protection work efficiency is improved.

[0236] It should be further noted that the embodiments of the present application also provide a data access module, which comprises the network security service system described above.

[0237] It should be further noted that the embodiments of the present application also provide a network security robot, which comprises the data access module described above.

[0238] Figure 6 is a block diagram of a network security service device according to an exemplary embodiment. The device is configured in a mapping controller, referring to Figure 6 The network security service device can comprise a fixed address configuration module 601, a mapping relationship configuration module 602, a port association module 603 and a service control module 604.

[0239] Specifically, the fixed address configuration module 601 is configured to obtain a fixed address set of a mapping generator, and configure the fixed address set in a target service address of a network security tool set; wherein the mapping generator comprises an IP address set, and the IP address set comprises the fixed address set and a dynamic address set;

[0240] The mapping relationship configuration module 602 is configured to, in response to receiving a security service request sent by a target system, establish a mapping relationship between a target address set of the target system and an available dynamic address set in the dynamic address set, and establish a mapping relationship between the fixed address set and the available dynamic address set in the dynamic address set;

[0241] The port association module 603 is configured to, based on the mapping relationship between the target address set of the target system and the available dynamic address set in the dynamic address set, and the mapping relationship between the fixed address set and the available dynamic address set in the dynamic address set, establish an association relationship between an address port combination of the target address set and an address port combination of the fixed address set, so as to realize transmission of a data packet;

[0242] The service control module 604 is configured to notify the network security tool set to provide a service for the fixed address set, and send a service report generated by the network security tool set to the target system.

[0243] In some implementations, the fixed address configuration module 601 is specifically configured to:

[0244] Set each fixed address in the fixed address set in a target service address of each tool in the network security tool set respectively.

[0245] In some implementations, the mapping relationship configuration module 602 is further configured to:

[0246] In response to receiving registration information submitted by the target system, obtain the target address set of the target system based on the registration information.

[0247] In some implementations, the mapping relationship configuration module 602 is specifically configured to:

[0248] For each target address in the target address set, a first tuple list with address port combinations as elements is constructed; and the first tuple lists of the target address set are spliced to obtain a first total tuple list;

[0249] For each dynamic address in the available dynamic address set, a second tuple list with address port combinations as elements is constructed; and the second tuple lists of the available dynamic address set are spliced to obtain a second total tuple list;

[0250] For each fixed address in the fixed address set, a third tuple list with address port combinations as elements is constructed; and the third tuple lists of the fixed address set are spliced to obtain a third total tuple list;

[0251] The number of elements in the first total tuple list and the second total tuple list is obtained respectively to obtain a first length and a second length;

[0252] Based on the first total tuple list, the second total tuple list, the third total tuple list, the first length, and the second length, the mapping relationship between the target address set and the available dynamic address set and the mapping relationship between the fixed address set and the available dynamic address set are obtained.

[0253] In some implementations, when the mapping relationship configuration module 602 obtains the mapping relationship between the target address set and the available dynamic address set and the mapping relationship between the fixed address set and the available dynamic address set based on the first total tuple list, the second total tuple list, the third total tuple list, the first length, and the second length, it is specifically configured to:

[0254] The following steps are executed in a loop until all elements in the first total tuple list complete mapping matching with elements in the second total tuple list;

[0255] From the first total tuple list, a second length of first target elements are determined, and the second length of first target elements are associated with a second length of second target elements in the second total tuple list in a one-to-one manner to obtain the mapping relationship between the target address set and the available dynamic address set;

[0256] The second length of second target elements in the second total tuple list are associated with a second length of third target elements determined in the third total tuple list in a one-to-one manner to obtain the mapping relationship between the fixed address set and the available dynamic address set;

[0257] After the network security tool set and the target system complete packet interaction, the determined second length of first target elements in the first total tuple list are deleted.

[0258] In some implementations, the port association module 603 is further configured to:

[0259] In the case that the target address set and the available dynamic address set belong to address domains that cannot be directly passed through, the mapping agent is used to establish an association relationship between the address port combination of the target address set and the address port combination of the fixed address set.

[0260] In some implementations, the mapping relationship configuration module 602 is further configured to:

[0261] The plurality of index parameters include the data packet transmission speed, the number of established sessions, and the success rate of established sessions of each address port combination in the available dynamic address set;

[0262] Based on the plurality of index parameters and the respective threshold values, the mapping relationship between the target address set of the target system and the available dynamic address set in the dynamic address set is changed, and the mapping relationship between the fixed address set and the available dynamic address set in the dynamic address set is changed.

[0263] In some implementations, the mapping relationship configuration module 602 is further configured to:

[0264] The mapping relationship between the target address set of the target system and the available dynamic address set in the dynamic address set is released, and the mapping relationship between the fixed address set and the available dynamic address set in the dynamic address set is released.

[0265] As to the apparatus in the above-mentioned embodiments, the specific manners in which various modules perform operations have been described in detail in the embodiments of the method, and thus will not be described in detail here.

[0266] By implementing the present embodiment, the fixed address set of the mapping generator is configured at the target service address of the network security tool set, the dynamic address set of the mapping generator is dynamically bound with the target address set of the target system, and the mapping relationship between the fixed address set and the bound dynamic address set is established, effectively solving the technical problem of cross-domain mapping of network addresses, realizing decoupling of the network security tool set and the target system, and having flexible adaptability. In the network security scenario, the address reachability of various target systems required for protection, the application accessibility, the role control of the communication parties, and the control of data interaction behaviors are realized, the mapping controller and the mapping generator are used to realize the mapping, conversion, and connection of the target system addresses in various network environments, and the mapping mechanism is controlled according to the characteristics of the network security tool, so that the network security tool set can provide effective services for the target system in various network environments.

[0267] According to the embodiments of the present application, the present application further provides an electronic device and a readable storage medium.

[0268] As shown in Figure 7 is a block diagram of an electronic device for implementing a method of a service for network security according to embodiments of the present application. The electronic device is intended to represent various forms including digital computers, such as laptops, desktops, workstations, personal digital assistants, servers, blade servers, mainframes, and other appropriate computers. The electronic device can also represent various forms of mobile devices, such as personal digital assistants, cellular telephones, smart phones, wearable devices, and other similar computing devices. The components shown here, their connections and relationships, and their functions, are meant to be examples only, and are not meant to limit implementations of the present application described and / or claimed in this document.

[0269] As shown in Figure 7 The electronic device includes one or more processors 701, memory 702, and interfaces for connecting the components, including high-speed interfaces and low-speed interfaces. The components are interconnected using different buses, and can be mounted on a common motherboard or in other manners, as desired. The processor can process instructions for execution within the electronic device, including instructions stored in the memory or on the memory to display graphical information for a GUI on an external input / output device, such as a display device coupled to the interface. In other implementations, multiple processors and / or multiple buses can be employed as desired to improve performance, for example, as in a multi-processor system. Also, various other components of the device can connect the processor to the digital bus, and each of the components can potentially represent a different functionality of the electronic device. Figure 7 The processor 701 is taken as an example in the embodiment.

[0270] The memory 702 is a non-transitory computer readable storage medium provided by the present application. The memory stores instructions executable by at least one processor, so that the at least one processor executes the method of the service for network security provided by the present application. The non-transitory computer readable storage medium of the present application stores computer instructions for causing a computer to execute the method of the service for network security provided by the present application.

[0271] The memory 702 as a non-transitory computer readable storage medium can be used to store non-transitory software programs, non-transitory computer executable programs and modules, such as program instructions / modules corresponding to the method of the service for network security in the embodiments of the present application (for example, the program instructions / modules are stored in the memory 702 in the form of firmware or software). Figure 6The fixed address configuration module 601, the mapping relationship configuration module 602, the port association module 603, and the service control module 604 shown are implemented by the processor 701 running software stored in the memory 702. The software includes program instructions that, when executed by the processor 701, cause the processor 701 to perform various functions described herein, including the method for providing a network security service.

[0272] The memory 702 can include a program storage area and a data storage area. The program storage area can store an operating system, application programs, and modules needed by at least one function. The data storage area can store data created by the network security service electronic device, etc. In addition, the memory 702 can include a high-speed random access memory, and can further include a non-transitory memory, such as at least one disk memory device, a flash memory device, or other non-transitory solid-state memory device. In some embodiments, the memory 702 can optionally include a memory disposed remotely with respect to the processor 701, which can be connected to the network security service electronic device through a network. Examples of the network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0273] The network security service electronic device can further include an input device 703 and an output device 704. The processor 701, the memory 702, the input device 703, and the output device 704 can be connected by a bus or other means, Figure 7 For example, by a bus connection.

[0274] The input device 703 can receive input digital or character information, and generate key signal input related to user settings and function control of the network security service electronic device, such as a touch screen, a keypad, a mouse, a trackpad, a touchpad, a pointing stick, one or more mouse buttons, a trackball, a joystick, etc. The output device 704 can include a display device, an auxiliary lighting device (e.g., an LED), a tactile feedback device (e.g., a vibration motor), etc. The display device can include, but is not limited to, a liquid crystal display (LCD), a light-emitting diode (LED) display, and a plasma display. In some embodiments, the display device can be a touch screen.

[0275] Various implementations of the systems and techniques described here can be realized in digital electronic circuitry, integrated circuitry, specially designed ASICs (application specific integrated circuits), computer hardware, firmware, software, and / or combinations thereof. These various implementations can include implementation in one or more computer programs that are executable and / or interpretable on a programmable system including at least one programmable processor, which can be special or general purpose, coupled to receive data and instructions from, and to transmit data and instructions to, a storage system, at least one input device, and at least one output device.

[0276] These computer programs (also known as programs, software, software applications or code) include machine instructions for the programmable processor, and can be implemented in a high-level procedural and / or object-oriented programming language, and / or in assembly / machine language. As used herein, the terms "machine-readable medium" and "computer-readable medium" refer to any computer program product, apparatus and / or device (e.g., magnetic discs, optical disks, memory, Programmable Logic Devices (PLDs)) used to provide machine instructions and / or data to a programmable processor, including a machine-readable medium that receives machine instructions as a machine-readable signal. The term "machine-readable signal" refers to any signal used to provide machine instructions and / or data to a programmable processor.

[0277] To provide for interaction with a user, the systems and techniques described here can be implemented on a computer having a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the computer. Other kinds of devices can be used to provide for interaction with a user as well; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form, including acoustic, speech, or tactile input.

[0278] The systems and techniques described here can be implemented in a computing system that includes a back end component (e.g., as a data server), or that includes a middleware component (e.g., an application server), or that includes a front end component (e.g., a user computer having a graphical user interface or a Web browser through which a user can interact with an implementation of the systems and techniques described here), or any combination of such back end, middleware, or front end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include a local area network (LAN), a wide area network (WAN), and the Internet.

[0279] The computer system can include clients and servers. A client and server are generally remote from each other and typically interact through a communication network. The relationship of client and server arises by virtue of computer programs running on the respective computers and having a client-server relationship to each other.

[0280] In an example embodiment, also provided is a computer program product, which when the instructions in the computer program product are executed by a processor of an electronic device, enables the electronic device to perform the above method.

[0281] It should also be noted that the example embodiments mentioned in the present application describe some methods or systems based on a series of steps or devices. However, the present application is not limited to the order of the above steps, that is, the steps can be performed in the order mentioned in the embodiments, or different from the order in the embodiments, or several steps are performed simultaneously.

[0282] Other embodiments of the application will be apparent to those skilled in the art from consideration of the specification and practice of the application disclosed herein. It is intended that the application be limited only by the scope of the claims, including any appropriate amendments thereof, and that there be no intention to limit the application to the equivalents of the specifi c embodiments recited herein. The specification and examples given herein are to be considered exemplary of the application, and are presented for the purpose of illustration and description only.

[0283] It is to be understood that the application is not limited to the precise construction described in the specification and shown in the drawings, and that various modifications and changes can be made by those skilled in the art without departing from the scope of the application. The scope of the application is limited only by the claims that follow, and the semantics of the terms used therein.

Claims

1. A network security service method characterized by, The method is applied to a mapping controller, and comprises: obtaining a fixed address set of a mapping generator and configuring the fixed address set in a target service address of a network security tool set; wherein the mapping generator comprises an IP address set, and the IP address set comprises a fixed address set and a dynamic address set; in response to receiving a security service request sent by a target system, establishing a mapping relationship between a target address set of the target system and an available dynamic address set in the dynamic address set, and establishing a mapping relationship between the fixed address set and the available dynamic address set in the dynamic address set; based on the mapping relationship between the target address set of the target system and the available dynamic address set in the dynamic address set and the mapping relationship between the fixed address set and the available dynamic address set in the dynamic address set, establishing an association relationship between an address port combination of the target address set and an address port combination of the fixed address set to realize transmission of a data packet; informing the network security tool set to provide a service for the fixed address set, and sending a service report generated by the network security tool set to the target system.

2. The method of claim 1, wherein, The configuration of the fixed address set in the target service address of the network security tool set comprises: setting each fixed address in the fixed address set in a target service address of each tool in the network security tool set.

3. The method of claim 1, wherein, The method further comprises: in response to receiving registration information submitted by the target system, obtaining a target address set of the target system based on the registration information.

4. The method of claim 1, wherein, The establishment of the mapping relationship between the target address set of the target system and the available dynamic address set in the dynamic address set and the establishment of the mapping relationship between the fixed address set and the available dynamic address set in the dynamic address set comprise: for each target address in the target address set, constructing a first two-tuple list with an address port combination as an element; and splicing the first two-tuple list of the target address set to obtain a first two-tuple total list; for each dynamic address in the available dynamic address set, constructing a second two-tuple list with an address port combination as an element; and splicing the second two-tuple list of the available dynamic address set to obtain a second two-tuple total list; for each fixed address in the fixed address set, constructing a third two-tuple list with an address port combination as an element; and splicing the third two-tuple list of the fixed address set to obtain a third two-tuple total list; obtaining the number of elements in the first two-tuple total list and the second two-tuple total list respectively to obtain a first length and a second length; based on the first two-tuple total list, the second two-tuple total list, the third two-tuple total list, the first length and the second length, obtaining the mapping relationship between the target address set and the available dynamic address set and the mapping relationship between the fixed address set and the available dynamic address set.

5. The method of claim 4, wherein, The mapping relationship between the target address set and the available dynamic address set and the mapping relationship between the fixed address set and the available dynamic address set are obtained based on the first total list of two-tuples, the second total list of two-tuples, the third total list of two-tuples, the first length and the second length, and the method comprises the following steps: The following steps are executed in a loop until all elements in the first total list of two-tuples complete mapping matching with elements in the second total list of two-tuples: Second length first target elements are determined from the first total list of two-tuples, and the second length first target elements are associated with second length second target elements in the second total list of two-tuples in a one-to-one manner to obtain the mapping relationship between the target address set and the available dynamic address set; The second length second target elements in the second total list of two-tuples are associated with second length third target elements determined from the third total list of two-tuples in a one-to-one manner to obtain the mapping relationship between the fixed address set and the available dynamic address set; After the network security tool set and the target system complete packet interaction, the determined second length first target elements are deleted from the first total list of two-tuples.

6. The method of claim 1, wherein, The method further comprises: In the case that the target address set and the available dynamic address set belong to address domains that cannot be directly connected, an association relationship between address port combinations of the target address set and address port combinations of the fixed address set is established through a mapping agent.

7. The method of claim 4, wherein, The method further comprises: A plurality of index parameters are counted, and the plurality of index parameters comprise a data packet transmission speed, a number of established sessions and a success rate of established sessions of each address port combination in the available dynamic address set; Based on the plurality of index parameters and respective threshold values, the mapping relationship between the target address set of the target system and the available dynamic address set in the dynamic address set is changed, and the mapping relationship between the fixed address set and the available dynamic address set in the dynamic address set is changed.

8. The method of claim 1, wherein, After the service report generated by the network security tool set is sent to the target system, the method further comprises: The mapping relationship between the target address set of the target system and the available dynamic address set in the dynamic address set is released, and the mapping relationship between the fixed address set and the available dynamic address set in the dynamic address set is released.

9. A network security service apparatus characterized by comprising: The device is configured in a mapping controller and comprises: A fixed address configuration module is configured to acquire a fixed address set of a mapping generator and configure the fixed address set in a target service address of a network security tool set, wherein the mapping generator comprises an IP address set, and the IP address set comprises a fixed address set and a dynamic address set; A mapping relationship configuration module is configured to, in response to receiving a security service request sent by a target system, establish a mapping relationship between a target address set of the target system and an available dynamic address set in the dynamic address set and establish a mapping relationship between a fixed address set and the available dynamic address set in the dynamic address set. The port association module is configured to establish an association between the address port combination of the target address set and the address port combination of the fixed address set based on the mapping relationship between the target address set of the target system and the available dynamic address set in the dynamic address set and the mapping relationship between the fixed address set and the available dynamic address set in the dynamic address set, so as to realize the transmission of the data packet. The service control module is configured to inform the network security tool set to provide services for the fixed address set, and send a service report generated by the network security tool set to the target system.

10. A network security service system characterized by comprising: The network security service system comprises: a mapping generator, the mapping generator comprising an IP address set, the IP address set comprising a fixed address set and a dynamic address set; a mapping controller configured to perform the network security service method according to any one of claims 1 to 8.

11. A data access module, characterized by The data access module comprises the network security service system according to claim 10.

12. A cyber-security robot, characterized in that, The network security robot comprises the data access module according to claim 11.

13. An electronic device, comprising: The network security robot comprises: at least one processor; and a memory connected in communication with the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the network security service method according to any one of claims 1 to 8.

14. A non-transitory computer-readable storage medium having stored thereon computer instructions, wherein, The computer instructions are used to enable the computer to perform the network security service method according to any one of claims 1 to 8.

Citation Information

Patent Citations

  • Method, system and equipment for accessing terminal

    CN101998684A

  • IP address management method, NEF entity and communication system

    CN113873502A