A wireless airspace intrusion prevention system, method and device
By integrating monitoring, analysis, identification and response subsystems into the wireless airspace intrusion prevention system, the problem of lack of automated defense after intrusion identification in the prior art is solved, real-time security defense against proprietary networks is achieved, and network security and defense efficiency are improved.
Patent Information
- Application Number
- CN202411008939.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-07-26
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2044-07-26
AI Technical Summary
After identifying wireless network intrusion, the prior art lacks an automated security defense mechanism, resulting in untimely defense, low network security, and easy to cause losses.
A wireless airspace intrusion prevention system is designed, including a monitoring subsystem, a data analysis subsystem, a threat identification subsystem and a defense response subsystem. Through wireless environment monitoring, key feature extraction, intrusion behavior identification and automatic defense strategy adjustment, real-time defense against proprietary networks can be achieved.
Improve the network security of proprietary networks, reduce losses caused by untimely defense, and achieve rapid response and effective defense against wireless airspace intrusion behavior.
Smart Images

Figure CN119012196B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and particularly relates to a wireless airspace intrusion prevention system, method and device. Background Art
[0002] Due to its open transmission medium, wireless networks are vulnerable to various attacks (such as spoofing attacks, encryption cracking attacks, man-in-the-middle attacks, denial-of-service attacks, wireless interference attacks, wireless search attacks, and battleship-style attacks, etc.). And the private networks applying wireless networks are relatively closed usage environments. Most systems focus on the real-time performance and reliable implementation of functions during design and R & D, and relatively lack attention to security, resulting in the current situation of private network security being in a state of "inadequate at birth, neglected in the future, and worrying about the future". There is a lack of pre-design and effective resistance methods for security attacks. These defects make the private network information system relatively vulnerable to network security attacks.
[0003] The invention patent with the application number: 202010558116.2 discloses a WiFi-based environmental intrusion detection method and system. The above invention first collects signals in different intrusion environments and performs preprocessing, then uses a self-organizing neural network algorithm to extract features from the preprocessed data, uses a Softmax classifier to classify the feature values, establishes an intrusion fingerprint database, and finally online matches the data collected in the environment to be detected with the data in the fingerprint database to judge whether there is an intrusion. The above invention uses the existing WiFi network to realize the security monitoring function, has a wide coverage range and does not expose privacy, and the recognition rate is greatly improved, having a good development prospect.
[0004] However, after the above-mentioned prior art identifies whether there is an intrusion, it does not perform automated security defense. It waits for the intrusion recognition information to be received manually and then sets the defense strategy, resulting in untimely defense, low network security, and easy to cause related losses.
[0005] In view of this, there is an urgent need for a wireless airspace intrusion prevention system, method and device to at least solve the above deficiencies. Summary of the Invention
[0006] One of the purposes of the present invention is to provide a wireless airspace intrusion prevention system, method and device, which performs wireless environment monitoring in the wireless airspace of the target private network host to obtain wireless monitoring data, extracts key features from the wireless monitoring data, identifies intrusion behaviors based on the key features, and adaptively adjusts the defense strategy according to the changes in the identified intrusion behaviors, improving the network security of the private network and reducing losses.
[0007] A wireless airspace intrusion prevention system provided by an embodiment of the present invention includes:
[0008] The monitoring subsystem is used to perform wireless environment monitoring on the wireless airspace of the target private network host and obtain wireless monitoring data; the wireless airspace is the space where WI-FI radio waves propagate;
[0009] The data analysis subsystem is used to analyze the key features in the wireless monitoring data;
[0010] The threat identification subsystem is used to attempt to identify intrusion behaviors based on the key features;
[0011] The defense response subsystem is used to automatically adjust the defense strategy according to the behavior changes of the intrusion behavior if the attempt to identify the intrusion behavior is successful.
[0012] Preferably, the monitoring subsystem includes:
[0013] The first wireless monitoring data acquisition module is used to capture the encrypted data packets in the wireless airspace of the target private network host based on a preset WI-FI scanning tool, decrypt the encrypted data packets according to the obtained encryption standard, and obtain the wireless monitoring data;
[0014] and / or,
[0015] The second wireless monitoring data acquisition module is used to identify the allowed access users and obtain the wireless monitoring data through a preset API interface according to the allowed access behaviors of the allowed access users.
[0016] Preferably, the first wireless monitoring data acquisition module includes:
[0017] The AP distribution point set acquisition sub-module is used to acquire the AP distribution point set of the wireless airspace;
[0018] The mapping image display sub-module is used to map the AP distribution point set in the target space where the target private network host is located to obtain a mapping image and display the mapping image to the user of the WI-FI scanning tool for viewing;
[0019] The scanning point acquisition sub-module is used to determine the scanning points set after the user views the mapping image;
[0020] The listening list acquisition sub-module is used to acquire the listening list of the scanning tool when the viewer reaches the scanning point and starts the scanning process;
[0021] The client information acquisition sub-module is used to parse the listening list and acquire the client information of the target private network host connected to the target AP;
[0022] The wireless monitoring data acquisition sub-module is used to determine the client encryption standard according to the client information and decrypt it to obtain the wireless monitoring data.
[0023] A wireless airspace intrusion prevention system provided by an embodiment of the present invention further includes:
[0024] A scanning point recommendation sub-module, configured to obtain the tool usage experience information of the user before the user sets the scanning points, determine whether it is necessary to recommend scanning points to the user according to the tool usage experience information, and make corresponding recommendations if necessary.
[0025] Preferably, the scanning point recommendation sub-module includes:
[0026] A tool usage experience value determination unit, configured to determine the tool usage experience value according to the tool usage experience information; the tool usage experience value is the result obtained by normalizing and summing the number of times the user uses the scanning tool and the user's working years based on a preset normalization rule;
[0027] A distribution feature acquisition unit, configured to, if the tool usage experience value is less than or equal to a preset tool usage experience value threshold, obtain the distribution feature of the projection points of the API interface according to the mapping image;
[0028] A candidate position determination unit, configured to determine the candidate positions in the mapping image according to the distribution feature and a preset scanning position determination library;
[0029] An obstacle feature acquisition unit, configured to obtain the obstacle features between the candidate positions and the projection points of the API interface in the mapping image;
[0030] An obstacle interference value determination unit, configured to determine the obstacle interference value according to the obstacle features and associate it with the corresponding candidate position;
[0031] A target value calculation unit, configured to accumulate and calculate the obstacle interference values associated with the candidate positions to determine the target value;
[0032] A recommended scanning position determination unit, configured to use the actual position in the target space corresponding to the candidate position with the smallest target value as the recommended scanning position.
[0033] Preferably, the threat recognition subsystem includes:
[0034] A threat behavior feature library update module, configured to update the threat behavior feature library;
[0035] An intrusion behavior determination module, configured to, if the result of the consistency judgment of the feature data of the threat behavior features and the key features in the threat behavior feature library is consistent, determine the target threat behavior as an intrusion behavior according to the corresponding consistent threat behavior features.
[0036] Preferably, the defense response subsystem includes:
[0037] A host service acquisition module, configured to acquire the host service of a target dedicated network host;
[0038] A simulation service determination module, configured to determine a simulation service according to the honeypot technology and the host service;
[0039] A defense strategy library construction module, configured to construct a defense strategy library based on machine learning technology according to the simulation service;
[0040] A change feature acquisition module, configured to acquire the change features of the behavior changes of intrusion behaviors; the change features include: changes in attack targets, changes in attack tools, and changes in attack speeds;
[0041] A strategy adjustment module, configured to automatically adjust the defense strategy according to the change features and the defense strategy library.
[0042] Preferably, the defense strategy library construction module includes:
[0043] Acquire a target attack behavior according to the simulation service;
[0044] Extract the attack features of the target attack behavior, where the attack features include: attack targets and attack means;
[0045] Establish defense record indexing conditions according to the attack features;
[0046] Index the target defense records according to the defense record indexing conditions;
[0047] Determine whether the target defense record meets the defense strategy extraction conditions. If it meets, extract the defense strategy according to the corresponding target defense record and store it in the library;
[0048] Among them, the defense strategy extraction conditions include:
[0049] The defense result of the target defense record conforms to the standard defense result;
[0050] And / or,
[0051] The authentication number of the target defense record is greater than or equal to the preset authentication number threshold;
[0052] And / or,
[0053] The condition feature similarity between the condition feature of the defense subject corresponding to the target defense record and the condition feature of the target dedicated network host condition feature is greater than or equal to the preset condition feature similarity threshold.
[0054] Preferably, the strategy adjustment module includes:
[0055] A strategy adjustment determination sub-module, configured to determine whether a strategy adjustment is required according to the change features and a preset strategy adjustment behavior change determination template;
[0056] The first target policy determination sub-module is used to determine the first target policy before adjustment if it is determined that policy adjustment is required;
[0057] The second target policy determination sub-module is used to determine the second target policy as a candidate in the defense policy library in real time according to the change characteristics; wherein, the number of policies of the candidate second target policy is less than the preset policy number threshold;
[0058] The policy transition operation acquisition sub-module is used to acquire the policy transition operation for the first target policy to be converted into the second target policy;
[0059] The waiting instruction description vector construction sub-module is used to construct a waiting instruction description vector according to the operation characteristics of the policy transition operation;
[0060] The vector number real-time acquisition sub-module is used to acquire the vector number of the waiting instruction description vector in real time;
[0061] The automatic adjustment sub-module is used to, when the vector number is 1, use the corresponding waiting instruction description vector as the target instruction description vector, and automatically adjust the defense policy according to the preset operation instruction library and the target instruction description vector.
[0062] A wireless airspace intrusion defense method provided by an embodiment of the present invention includes:
[0063] Perform wireless environment monitoring on the wireless airspace of the target private network host to obtain wireless monitoring data;
[0064] Analyze the key features in the wireless monitoring data;
[0065] Attempt to identify intrusion behaviors according to the key features;
[0066] If the attempt to identify intrusion behaviors is successful, automatically adjust the defense policy according to the behavior changes of the intrusion behaviors.
[0067] An embodiment of the present invention provides a wireless airspace intrusion defense device, which uses the above method for defense.
[0068] The beneficial effects of the present invention are:
[0069] The present invention performs wireless environment monitoring on the wireless airspace of the target private network host to obtain wireless monitoring data, extracts the key features in the wireless monitoring data, identifies intrusion behaviors based on the key features, and adaptively adjusts the defense policy according to the changes of the identified intrusion behaviors, improving the network security of the private network and reducing losses.
[0070] Other features and advantages of the present invention will be set forth in the following description, and in part will be obvious from the description, or may be learned by practice of the present invention. The objectives and other advantages of the present invention may be realized and attained by the structure particularly pointed out in this application document.
[0071] The technical solution of the present invention will be further described in detail below with reference to the drawings and embodiments. Description of the Drawings
[0072] The drawings are used to provide a further understanding of the present invention, and constitute a part of the specification. Together with the embodiments of the present invention, they are used to explain the present invention, and do not constitute a limitation to the present invention. In the drawings:
[0073] Figure 1 is a schematic diagram of a wireless airspace intrusion prevention system in an embodiment of the present invention;
[0074] Figure 2 is a schematic diagram of a wireless airspace intrusion prevention method in an embodiment of the present invention. Detailed Embodiments
[0075] The following describes the preferred embodiments of the present invention with reference to the drawings. It should be understood that the preferred embodiments described herein are only used to illustrate and explain the present invention, and are not used to limit the present invention.
[0076] An embodiment of the present invention provides a wireless airspace intrusion prevention system, as Figure 1 shown, including:
[0077] A monitoring subsystem 1 for performing wireless environment monitoring on the wireless airspace of a target proprietary network host to obtain wireless monitoring data; the wireless airspace is: the space where WI F I radio waves propagate; wherein, the target proprietary network host is: the server of a dedicated network that needs to perform wireless airspace intrusion prevention; wireless environment monitoring is: the process of detecting and analyzing the wireless signal environment; wireless monitoring data is: the data collected during wireless environment monitoring, including information such as the strength, frequency, modulation method, and signal quality of the signal;
[0078] A data analysis subsystem 2 for analyzing the key features in the wireless monitoring data; wherein, the key features are: in the wireless monitoring data, parameters that are significantly different from the behavior patterns of normal operations or known devices, and the key features can be used to identify abnormal or intrusion behaviors;
[0079] A threat identification subsystem 3 for attempting to identify intrusion behaviors based on the key features; wherein, the intrusion behaviors are specifically: unauthorized access or attack behaviors, such as: data theft, denial of service attack (DoS), and malicious software implantation, etc.;
[0080] The defense response subsystem 4 is used to automatically adjust the defense strategy according to the behavior changes of the intrusion behavior if the intrusion behavior attempt is successfully identified. Among them, automatically adjusting the defense strategy according to the behavior changes of the intrusion behavior is: determining the latest adjusted defense strategy according to the identified intrusion behavior changes and applying it.
[0081] The working principle and beneficial effects of the above technical solution are as follows:
[0082] The present invention performs wireless environment monitoring in the wireless airspace of the target private network host to obtain wireless monitoring data, extracts key features from the wireless monitoring data, identifies intrusion behaviors based on the key features, and adaptively adjusts the defense strategy according to the identified changes in the intrusion behaviors, improving the network security of the private network and reducing losses.
[0083] In one embodiment, the monitoring subsystem includes:
[0084] The first wireless monitoring data acquisition module is used to capture encrypted data packets in the wireless airspace of the target private network host based on a preset WI-FI scanning tool, and decrypt the encrypted data packets according to the obtained encryption standard to obtain wireless monitoring data; among them, the WI-FI scanning tool is: a software and hardware tool for scanning WI-FI networks and capturing wireless signals, such as: Wi reshark software and a mobile computer; the encrypted data packet is: a data packet that uses an encryption algorithm to encrypt data during wireless transmission to protect the security of the data; the encryption standard is: pre-set rules and algorithms for encrypting the wireless transmission data of the target private network host, such as: WEP, WPA, and WPA2, etc.;
[0085] And / or,
[0086] The second wireless monitoring data acquisition module is used to identify allowed access users and obtain wireless monitoring data through a preset API interface according to the allowed access behaviors of the allowed access users. Among them, the allowed access users are: legally acquired users of the preset wireless monitoring data. When identifying, it is determined whether the logged-in user is an allowed access user according to the login information of the logged-in user (such as: login ID, login IP, etc.) and the preset allowed login information library; the allowed access behavior specifically is: the behavior of the allowed access user to access the wireless monitoring system by accessing the API interface.
[0087] The working principle and beneficial effects of the above technical solution are as follows:
[0088] The present invention introduces two methods of obtaining wireless monitoring data, namely WI-FI scanning and API interface acquisition, improving the comprehensiveness and suitability of obtaining wireless monitoring data.
[0089] In one embodiment, the first wireless monitoring data acquisition module includes:
[0090] The AP distribution point set acquisition sub-module is used to acquire the AP distribution point set of the wireless airspace; wherein, the AP distribution point set is: the set of physical positions of all access points in the wireless airspace;
[0091] The mapped image display sub-module is used to map the AP distribution point set in the target space where the target dedicated network host is located to obtain a mapped image, and display the mapped image to the user of the WI-FI scanning tool for viewing; wherein, the target space where the target dedicated network host is located is the spatial area where the target dedicated network host is located, such as: Machine Room A; when constructing the mapped image, a three-dimensional space of the target space is constructed, and mapping is correspondingly performed in the three-dimensional space according to the actual position of the AP distribution point relative to the target space;
[0092] The scanning point acquisition sub-module is used to determine the scanning points set after the user views the mapped image;
[0093] The monitoring list acquisition sub-module is used to acquire the monitoring list of the scanning tool after the viewer arrives at the scanning point and starts the scanning process; wherein, it is determined whether the viewer arrives at the scanning point according to the indoor positioning information of the viewer; the monitoring list is a list displayed by the scanning tool, including information such as the SSID (network name), BSSID (MAC address of the access point), signal strength, and channel of all detected wireless networks;
[0094] The client information acquisition sub-module is used to parse the monitoring list and acquire the client information of the target dedicated network host connected to the target AP; wherein, the client information is: the MAC address, used channel, and signal strength of the target dedicated network host;
[0095] The wireless monitoring data acquisition sub-module is used to determine the client encryption standard and decrypt it according to the client information to acquire the wireless monitoring data.
[0096] The working principle and beneficial effects of the above technical solution are:
[0097] The present invention obtains a set of AP distribution points in the wireless airspace, maps the AP distribution points in the corresponding three-dimensional space of the target space to obtain a mapped image, and presents the mapped image to the scanning personnel. After the scanning personnel view the mapped image and learn about the AP distribution, they then determine the corresponding scanning positions, avoiding deviations in the scanning results caused by the setting of inappropriate scanning positions. When the scanning personnel reach the scanning positions to perform scanning of the corresponding wireless network, the monitoring list presented by their scanning tools is obtained. According to the information in the monitoring list, the client information of the target private network host connected to the AP can be determined. Due to the particularity of the private network, the directly obtained data packets are encrypted data packets. However, legal users can learn about the encryption standard of the corresponding encrypted data packets through the client information, decrypt the encrypted data packets according to the encryption standard, and obtain wireless monitoring data, improving the acquisition accuracy of the wireless monitoring data.
[0098] An embodiment of the present invention provides a wireless airspace intrusion prevention system, further including:
[0099] A scanning point recommendation sub-module, configured to, before a user sets scanning points, obtain the tool usage experience information of the user, determine whether to recommend scanning points to the user according to the tool usage experience information, and perform corresponding recommendations if necessary. Among them, the tool usage experience information is information about the user's familiarity with the wireless scanning tool, usage history, and operation skills.
[0100] The working principle and beneficial effects of the above technical solution are as follows:
[0101] After mapping the AP distribution points to the mapped image, experienced users can determine suitable scanning points in the target space by themselves. However, there are situations where users are not proficient in using the scanning tools, and the setting of scanning points greatly affects the scanning quality. Therefore, before the user sets the scanning points, the present invention determines whether to recommend scanning points to the user according to the tool usage experience information, improving the suitability of the scanning point setting.
[0102] In one embodiment, the scanning point recommendation sub-module includes:
[0103] A tool usage experience value determination unit, configured to determine a tool usage experience value according to the tool usage experience information; the tool usage experience value is the result obtained by normalizing and then summing the number of times the user uses the scanning tool and the user's working years based on a preset normalization rule; among them, the preset normalization rule is: maximum-minimum normalization;
[0104] A distribution feature acquisition unit, configured to, if the tool usage experience value is less than or equal to a preset tool usage experience value threshold, acquire the distribution feature of the API interface projection point according to the mapping image; wherein, the preset tool usage experience value threshold is pre-set manually;
[0105] A candidate position determination unit, configured to determine the candidate position in the mapping image according to the distribution feature and a preset scanning position determination library; wherein, the preset scanning position determination library stores the one-to-one historical AP position distribution feature and the historical determined scanning position extracted from the historical scanning position determination record; when determining the candidate position, perform distribution feature matching on the distribution feature and the historical AP position distribution feature, and use the position in the target space corresponding to the historical determined scanning position that matches as the candidate position. Distribution feature matching compliance means that the feature similarity is the largest. Since there may be multiple feature similarities with the same maximum value, therefore, there may be more than one candidate position;
[0106] An obstacle feature acquisition unit, configured to acquire the obstacle feature between the candidate position and the API interface projection point in the mapping image; wherein, the obstacle feature is: the three-dimensional data of the obstacle, the distance between the obstacle and the corresponding candidate position of the obstacle between the candidate position and the API interface projection point, and the distance between the obstacle and the corresponding API distribution point of the obstacle between the candidate position and the API interface projection point;
[0107] An obstacle interference value determination unit, configured to determine the obstacle interference value according to the obstacle feature and associate it with the corresponding candidate position; wherein, the obstacle interference value is determined by comparing the obstacle feature with a manually preset interference value determination template;
[0108] A target value calculation unit, configured to accumulate and calculate the obstacle interference values associated with the candidate positions to determine the target value;
[0109] A recommended scanning position determination unit, configured to use the actual point position in the target space corresponding to the candidate position with the smallest target value as the recommended scanning position.
[0110] The working principle and beneficial effects of the above technical solution are as follows:
[0111] The present invention normalizes the number of times a scanning tool is used by a user and the user's years of work experience based on a preset normalization rule and then sums them to obtain a tool usage experience value. When the tool usage experience value of the user is less than or equal to a preset tool usage experience value threshold, the distribution characteristics of the API interface projection points are extracted. A scanning position determination library is introduced, database matching is performed according to the distribution characteristics, and the candidate scanning positions, i.e., candidate positions, are determined. The occlusion of obstacles between the scanning position and the AP distribution points may also affect the signal scanning. Therefore, the obstacle characteristics are extracted, the obstacle interference value is quantified and associated with the candidate positions, and the obstacle interference values associated with the candidate positions are accumulated to obtain a target value. The target value represents the overall interference degree of the obstacle distribution on the scanning. The candidate position corresponding to the smallest target value is selected as the actual position of the target space as the recommended scanning position, and the determination process of the scanning position is more reasonable.
[0112] In one embodiment, the threat recognition subsystem includes:
[0113] A threat behavior feature library update module for updating the threat behavior feature library; wherein, the threat behavior feature library is a database containing known attack methods, malware behaviors, and abnormal network traffic patterns, and is updated based on big data during the update.
[0114] An intrusion behavior determination module for determining a target threat behavior as an intrusion behavior according to the corresponding consistent threat behavior features if the determination result of the feature data consistency between the threat behavior features and the key features in the threat behavior feature library is consistent.
[0115] The working principle and beneficial effects of the above technical solution are as follows:
[0116] The present invention updates the threat behavior feature library based on big data and performs feature matching with key features to identify intrusion behaviors, and the identification efficiency of intrusion behaviors is higher.
[0117] In one embodiment, the defense response subsystem includes:
[0118] A host service acquisition module for acquiring the host services of the target dedicated network host; wherein, the host services are: the services provided by the target dedicated network host based on a wireless network.
[0119] A simulated service determination module for determining a simulated service according to the honeypot technology and the host services; wherein, the simulated service is: a service that is easily attacked by the target dedicated network host simulated based on the honeypot technology.
[0120] A defense strategy library construction module, which is used to construct a defense strategy library based on machine learning technology according to simulated services. The specific process of constructing the defense strategy library based on machine learning technology according to simulated services is as follows: After learning the defense strategies when other networks are attacked based on machine learning technology, determine the defense strategies according to the attacks suffered by the simulated services and summarize and enter them into an empty database.
[0121] A change feature acquisition module, which is used to acquire the change features of the behavior changes of intrusion behaviors. The change features include: changes in the attack target, changes in the attack tool, and changes in the attack speed.
[0122] A strategy adjustment module, which is used to automatically adjust the defense strategy according to the change features and the defense strategy library.
[0123] The working principle and beneficial effects of the above technical solution are as follows:
[0124] The present invention introduces the honeypot technology, simulates the services that the target dedicated network host is likely to be attacked according to the host services of the target dedicated network host, and improves the comprehensiveness of obtaining attack types. Automatically adjust the defense strategy according to the change features of the behavior changes of the intrusion behavior and the constructed defense strategy library, which is more intelligent.
[0125] In one embodiment, the defense strategy library construction module includes:
[0126] Obtain target attack behaviors according to the simulated services. Among them, the target attack behaviors are specifically: the network attacks suffered by the simulated services during the preset simulation duration.
[0127] Extract the attack features of the target attack behaviors. The attack features include: the attack target and the attack means. Among them, the attack target is: the specific part of the system or service targeted by the attack behavior, such as a specific server, application program, or network device; the attack means is: the method or technology used by the attacker to implement the attack, such as: exploiting software vulnerabilities, social engineering techniques, or automated attack scripts.
[0128] Establish defense record indexing conditions according to the attack features. Among them, the defense record indexing conditions are: the conditions for indexing the records of attacks similar to the attack features.
[0129] Index the target defense records according to the defense record indexing conditions. Among them, the target defense records are: the records of defending against attacks similar to the attack features.
[0130] Judge whether the target defense records meet the defense strategy extraction conditions. If they meet, extract the defense strategies according to the corresponding target defense records and store them in the database.
[0131] Among them, the defense strategy extraction conditions include:
[0132] The defense result of the target defense record meets the standard defense result; among them, the standard defense result is: defense successful;
[0133] and / or,
[0134] The authentication number of the target defense record is greater than or equal to the preset authentication number threshold; among them, the preset authentication number threshold is, for example: 20;
[0135] and / or,
[0136] The condition feature similarity between the condition features of the defense entity corresponding to the target defense record and the condition features of the target dedicated network host is greater than or equal to the preset condition feature similarity threshold. Among them, the defense entity is: the entity that executes the defense behavior corresponding to the target defense record; the condition features of the entity are: the features possessed by the defense entity, such as: firewall, intrusion detection system, etc.; the condition features of the target dedicated network host are: the features possessed by the target dedicated network host; the preset condition feature similarity threshold is, for example: 0.92.
[0137] The working principle and beneficial effects of the above technical solution are:
[0138] The present invention obtains the target attack behaviors collected by the simulation service during the simulation duration, extracts the attack features of the attack behaviors, and indexes the target defense records based on the attack features. In addition, three conditions are introduced to determine whether the target defense record is available for defense strategy extraction; the first condition is whether the defense result of the target defense record is successful in defense; the second condition is whether the authenticator using the target defense record is greater than or equal to the authentication number threshold; the third condition is whether the own conditions of the entity that executes the defense behavior corresponding to the target defense record (such as: the configuration of the software and hardware defense system) match the conditions of the target dedicated network host. The defense strategy is extracted from the target defense records that meet the defense strategy extraction conditions and stored in the database, improving the suitability of the construction of the defense strategy library.
[0139] In one embodiment, the policy adjustment module includes:
[0140] The policy adjustment determination sub-module is used to determine whether policy adjustment is needed according to the change features and the preset policy adjustment behavior change determination template; among them, the preset policy adjustment behavior change determination template is used for the change features to determine whether the defense policy needs to be adjusted, and the policy adjustment behavior change determination template is constructed based on the records during manual deployment of defense policy adjustment;
[0141] The first target policy determination sub-module is used to determine the first target policy before adjustment if it is determined that policy adjustment is needed; among them, the first target policy is: the current defense policy;
[0142] The second target policy determination sub-module is used to determine in real time the second target policies on the waiting list in the defense policy library according to the change characteristics; wherein, the number of the second target policies on the waiting list is less than the preset policy number threshold; the second target policies determine the intrusion behavior characteristics at the trend end point according to the characteristic trend of the change characteristics, and then obtain them by matching with the defense policy library; the preset policy number threshold is set manually in advance, for example: 5;
[0143] The policy transition operation acquisition sub-module is used to acquire the policy transition operation for the first target policy to be converted into the second target policy; wherein, the policy transition operation is: the server operation instruction for the first target policy to be converted into the second target policy;
[0144] The waiting instruction description vector construction sub-module is used to construct a waiting instruction description vector according to the operation characteristics of the policy transition operation; wherein, the operation characteristics are: the operation commands obtained by decomposing the policy transition operation and the corresponding execution order of the operation commands; the rule for constructing the waiting instruction description vector is the same as the rule for the trigger vector that triggers the server to automatically execute the server operation;
[0145] The vector number real-time acquisition sub-module is used to acquire in real time the number of vectors of the waiting instruction description vector;
[0146] The automatic adjustment sub-module is used to, when the number of vectors is 1, use the corresponding waiting instruction description vector as the target instruction description vector, and automatically adjust the defense policy according to the preset operation instruction library and the target instruction description vector. The preset operation instruction library includes multiple trigger vectors for triggering the server to execute the server operation.
[0147] The working principle and beneficial effects of the above technical solution are as follows:
[0148] The present invention introduces a policy adjustment behavior change determination template, determines policy adjustment according to change characteristics. When it is determined that policy adjustment is required, the second target policies on the waiting list in the defense policy library are determined according to the change characteristics; the policy transition operation for the current first target policy to be converted into the second target policy is acquired, and a waiting instruction description vector corresponding to the operation characteristics of the policy transition operation is constructed; when the number of vectors is 1, the target instruction description vector is triggered in a timely manner according to the operation instruction library, improving the timeliness of defense policy adjustment and further improving the suitability of defense.
[0149] An embodiment of the present invention provides a wireless airspace intrusion defense method, as Figure 2 shown, including:
[0150] Step 1: Perform wireless environment monitoring on the wireless airspace of the target private network host to obtain wireless monitoring data;
[0151] Step 2: Analyze the key characteristics in the wireless monitoring data;
[0152] Step 3: Try to identify intrusion behavior based on key features;
[0153] Step 4: If the attempt to identify intrusion behavior is successful, automatically adjust the defense strategy according to the behavior changes of the intrusion behavior.
[0154] An embodiment of the present invention provides a wireless airspace intrusion prevention device, which applies the wireless airspace intrusion prevention method of the above embodiment.
[0155] Obviously, those skilled in the art can make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations of the present invention fall within the scope of the claims of the present invention and their equivalent technologies, the present invention also intends to include these changes and modifications.
Claims
1. A wireless airspace intrusion prevention system, characterized in that: include: The monitoring subsystem is used to monitor the wireless environment of the wireless airspace of the target proprietary network host and obtain wireless monitoring data; the wireless airspace is: the space where WIFI radio waves propagate; A data analysis subsystem for analyzing key features in wireless monitoring data; The threat identification subsystem is used to try to identify intrusion behavior based on key features; The defense response subsystem is used to automatically adjust the defense strategy according to the behavior changes of the intrusion behavior if the intrusion behavior attempt is successfully identified; The monitoring subsystem comprises: The first wireless monitoring data acquisition module is used to capture the encrypted data packets of the wireless airspace of the target proprietary network host based on the preset WIFI scanning tool, and decrypt the encrypted data packets according to the obtained encryption standard to obtain the wireless monitoring data; and / or, The second wireless monitoring data acquisition module is used to identify the allowed access users and acquire the wireless monitoring data through a preset API interface according to the allowed access behavior of the allowed access users; The first wireless monitoring data acquisition module includes: The AP distribution point set acquisition submodule is used to acquire the AP distribution point set of the wireless airspace; The mapping image display submodule is used to map the AP distribution point set to the target space where the target private network host is located to obtain the mapping image, and display the mapping image to the user of the WIFI scanning tool for viewing; The scanning point acquisition submodule is used to determine the scanning points set by the user after viewing the mapping image; The monitoring list acquisition submodule is used to obtain the monitoring list of the scanning tool when the viewing personnel arrives at the scanning point and starts the scanning process; The client information acquisition submodule is used to parse the monitoring list and obtain the client information of the target proprietary network host connected to the target AP; The wireless monitoring data acquisition submodule is used to determine the client encryption standard and decrypt it according to the client information to obtain the wireless monitoring data; The scanning point recommendation submodule is used to obtain the tool usage experience information of the user before the user sets the scanning point, and determine whether it is necessary to recommend the scanning point to the user based on the tool usage experience information, and make corresponding recommendations if necessary; The scanning point recommendation submodule includes: A tool usage experience value determination unit is used to determine a tool usage experience value according to the tool usage experience information; the tool usage experience value is a result obtained by normalizing the number of times the user uses the scanning tool and the user's years of service based on a preset normalization rule and then summing them; A distribution feature acquisition unit, configured to acquire distribution features of the API interface projection points according to the mapping image if the tool usage experience value is less than or equal to a preset tool usage experience value threshold; A candidate position determination unit, used to determine the candidate position in the mapping image according to the distribution characteristics and a preset scanning position determination library; The obstacle feature acquisition unit is used to acquire the obstacle features between the selected position in the mapping image and the API interface projection point; An obstacle interference value determination unit, used to determine the obstacle interference value according to the obstacle characteristics and associate it with the corresponding candidate position; A target value calculation unit, used for accumulating and calculating obstacle interference values associated with the selected position to determine a target value; A recommended scanning position determination unit, used for taking the actual point position of the target space corresponding to the candidate position with the smallest target value as the recommended scanning position; The defense response subsystem comprises: A host service acquisition module, used to acquire the host service of a target dedicated network host; A simulation service determination module, used to determine the simulation service according to the honeypot technology and the host service; A defense strategy library building module is used to build a defense strategy library based on simulation services based on machine learning technology; A change feature acquisition module is used to acquire change features of the behavior changes of the intrusion behavior; the change features include: changes in the attack object, changes in the attack tool, and changes in the attack speed; A strategy adjustment module is used to automatically adjust the defense strategy according to the change characteristics and the defense strategy library; Based on machine learning technology and simulation services, a defense strategy library is built, including: According to the simulation service, the target attack behavior is obtained; Extract attack features of target attack behaviors, including attack targets and attack methods; Establish defense record index conditions based on attack characteristics; According to the defense record indexing condition, index the target defense record; Determine whether the target defense record meets the defense strategy extraction conditions. If so, extract the defense strategy according to the corresponding target defense record and store it in the database; Among them, the defense strategy extraction conditions include: The defense results of the target defense record meet the standard defense results; and / or, The number of authentications of the target defense record is greater than or equal to the preset authentication number threshold; and / or, The conditional feature similarity between the subject conditional feature of the defense subject recorded in the target defense record and the conditional feature of the target dedicated network host is greater than or equal to a preset conditional feature similarity threshold; The policy adjustment module includes: The strategy adjustment determination submodule is used to determine whether strategy adjustment is required based on the change characteristics and the preset strategy adjustment behavior change determination template; A first target strategy determination submodule, for determining the first target strategy before adjustment if it is determined that strategy adjustment is required; The second target strategy determination submodule is used to determine the candidate second target strategy in the defense strategy library in real time according to the change characteristics; wherein the number of the candidate second target strategies is less than a preset strategy number threshold; A policy transition operation acquisition submodule, used to acquire a policy transition operation of converting a first target policy to a second target policy; A waiting instruction description vector construction submodule is used to construct a waiting instruction description vector according to the operation characteristics of the strategy transition operation; A vector number real-time acquisition submodule is used to obtain the vector number of the waiting instruction description vector in real time; The automatic adjustment submodule is used to use the corresponding waiting instruction description vector as the target instruction description vector when the number of vectors is 1, and automatically adjust the defense strategy according to the preset operation instruction library and the target instruction description vector.
2. A wireless airspace intrusion prevention system as claimed in claim 1, characterized in that: Threat identification subsystem, including: A threat behavior signature library update module, used to update the threat behavior signature library; The intrusion behavior determination module is used to determine the target threat behavior as an intrusion behavior according to the corresponding consistent threat behavior characteristics if the threat behavior characteristics of the threat behavior characteristic library and the characteristic data consistency judgment result of the key characteristics are consistent.
3. A wireless airspace intrusion defense method, characterized in that: include: Conduct wireless environment monitoring on the wireless airspace of the target private network host and obtain wireless monitoring data; Analyze key features in wireless monitoring data; Based on key features, try to identify intrusion behavior; If the intrusion attempt is successfully identified, the defense strategy is automatically adjusted based on the behavioral changes of the intrusion behavior; The wireless environment monitoring of the wireless airspace of the target private network host and obtaining wireless monitoring data includes: Based on the preset WIFI scanning tool, the encrypted data packets of the wireless airspace of the target proprietary network host are captured, and the encrypted data packets are decrypted according to the obtained encryption standard to obtain the wireless monitoring data; and / or, Identify the users allowed to access, and obtain wireless monitoring data through the preset API interface according to the access behavior of the users allowed to access; The preset WIFI scanning tool captures the encrypted data packets of the wireless airspace of the target proprietary network host, and decrypts the encrypted data packets according to the obtained encryption standard to obtain wireless monitoring data, including: Obtain the AP distribution point set of the wireless airspace; Map the AP distribution point set to the target space where the target private network host is located to obtain a mapping image, and display the mapping image to the user of the WIFI scanning tool for viewing; Determine the scanning points set by the user after viewing the mapping image; When the viewer arrives at the scanning point and starts the scanning process, the monitoring list of the scanning tool is obtained; Parse the monitoring list to obtain the client information of the target private network host connected to the target AP; According to the client information, determine the client encryption standard and decrypt it to obtain wireless monitoring data; Before the user sets the scanning point, the tool usage experience information of the user is obtained, and whether it is necessary to recommend the scanning point to the user is determined according to the tool usage experience information, and if necessary, the corresponding recommendation is made; Before the user sets the scanning point, the user's tool usage experience information is obtained, and it is determined whether it is necessary to recommend the scanning point to the user according to the tool usage experience information, and if necessary, a corresponding recommendation is made, including: Determine the tool usage experience value according to the tool usage experience information; the tool usage experience value is a result obtained by normalizing the number of times the user uses the scanning tool and the user's years of service based on a preset normalization rule and then summing them; If the tool usage experience value is less than or equal to the preset tool usage experience value threshold, the distribution characteristics of the API interface projection points are obtained according to the mapping image; Determine the library according to the distribution characteristics and the preset scanning position, and determine the candidate position in the mapping image; Obtain obstacle features between the candidate location in the mapping image and the API interface projection point; According to the obstacle characteristics, the obstacle interference value is determined and associated with the corresponding candidate position; Accumulate and calculate the obstacle interference value associated with the selected position to determine the target value; The candidate position with the smallest target value corresponding to the actual point position in the target space is taken as the recommended scanning position; If the intrusion behavior attempt is successfully identified, the defense strategy is automatically adjusted according to the behavior changes of the intrusion behavior, including: Obtain hosting services from the target dedicated network host; Determine the simulated services based on honeypot technology and host services; Based on machine learning technology and simulation services, a defense strategy library is built; Obtaining the characteristics of the behavior changes of the intrusion behavior; the characteristics of the changes include: changes in the attack target, changes in the attack tool, and changes in the attack speed; Automatically adjust defense strategies based on change characteristics and defense strategy library; Based on the machine learning technology, a defense strategy library is constructed according to the simulation service, including: According to the simulation service, the target attack behavior is obtained; Extract attack features of target attack behaviors, including attack targets and attack methods; Establish defense record index conditions based on attack characteristics; According to the defense record indexing condition, index the target defense record; Determine whether the target defense record meets the defense strategy extraction conditions. If so, extract the defense strategy according to the corresponding target defense record and store it in the database; Among them, the defense strategy extraction conditions include: The defense results of the target defense record meet the standard defense results; and / or, The number of authentications of the target defense record is greater than or equal to the preset authentication number threshold; and / or, The conditional feature similarity between the subject conditional feature of the defense subject recorded in the target defense record and the conditional feature of the target dedicated network host is greater than or equal to a preset conditional feature similarity threshold; The automatic adjustment of the defense strategy according to the change characteristics and the defense strategy library includes: Adjust the behavior change judgment template based on the change characteristics and preset strategies to determine whether strategy adjustment is needed; If it is determined that a strategy adjustment is necessary, the first target strategy before the adjustment is determined; According to the change characteristics, the candidate second target strategies in the defense strategy library are determined in real time; wherein the number of the candidate second target strategies is less than a preset strategy number threshold; Obtain a policy transition operation for converting a first target policy to a second target policy; According to the operation characteristics of the strategy transition operation, a waiting instruction description vector is constructed; Get the number of vectors waiting for instruction description vectors in real time; When the number of vectors is 1, the corresponding waiting instruction description vector is used as the target instruction description vector, and the defense strategy is automatically adjusted according to the preset operation instruction library and the target instruction description vector.
4. A wireless airspace intrusion prevention device, characterized in that: Used for defending according to the defense method as claimed in claim 3.
Citation Information
Patent Citations
A WiFi-based environmental intrusion detection method and system
CN111698258B
Network data security protection method and system based on collaborative intrusion detection
CN117879945A
Notification and early warning method capable of classifying and identifying various network behaviors
CN118214590A