A security defense method and device, electronic equipment and storage medium

The AC monitors the number of HTTP/HTTPS packets from STAs, identifies and notifies the AP to discard offensive packets, solving the problem of insufficient AC processing capacity in centralized forwarding mode and improving user experience.

CN119071784BActive Publication Date: 2025-10-10NEW H3C TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411181724.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-08-27
Publication Date
2025-10-10
Estimated Expiration
2044-08-27

AI Technical Summary

Technical Problem

In a centralized forwarding wireless LAN, HTTP/HTTPS packets sent by STAs that have not passed portal authentication may exceed the concurrent processing capacity of the access controller (AC), resulting in redirection failures or service interruptions, affecting user experience.

Method used

The AC counts HTTP/HTTPS packets from the same STA to identify blacklisted users under attack, adds them to the blacklist, and instructs the access point (AP) to discard these packets, reducing the AC load.

Benefits of technology

It improves the processing capability of AC, enhances the user experience, and prevents redirection failure and operation lag.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119071784B_ABST
    Figure CN119071784B_ABST
Patent Text Reader

Abstract

The application provides a security defense method and device, electronic equipment and storage medium. The method is applied to AC, and comprises the following steps: after a current first statistical period arrives, a first total number of HTTP / HTTPS messages received from a same STA in the first statistical period is counted; if all the counted first total numbers contain a first total number not less than a first set number, and the device works in a normal mode, the device is set to work in a blacklist mode, a first STA corresponding to the first total number not less than the first set number is added to a blacklist list, and first blacklist information is sent to a first AP accessed by the first STA; when a second deletion notification message carrying second blacklist information of a second STA is received from a second AP, the second STA is deleted from the current blacklist list; and when the blacklist list is empty after the deletion, the device is set to work in the normal mode. The application can improve user experience.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of communication technology, and in particular to a security defense method, device, electronic device and storage medium. Background Art

[0002] In a wireless local area network (WLAN) with centralized forwarding mode, the AC (Acting Controller) does not allow any station (STA) that has not passed portal authentication to access network resources. That is, the AC discards uplink data packets from the STA. For Hypertext Transfer Protocol (HTTP) / Secure Hypertext Transfer Protocol (HTTPS) packets from the STA, the AC initiates a redirection process. That is, the AC pops up a portal authentication page to the STA. After the STA enters the correct authentication account information (for example, user name and password) on the portal authentication page, the STA is allowed to access network resources.

[0003] When a STA is attacked, the AC may receive a large number of HTTP / HTTPS messages. If the number exceeds the AC's concurrent processing capability, redirection failure or operation lag may occur, affecting the user experience. Summary of the Invention

[0004] To overcome the problems existing in the related art, the present application provides a security defense method, device, electronic device and storage medium.

[0005] According to a first aspect of an embodiment of the present application, a security defense method is provided. The method is applied to an AC and includes:

[0006] After the current first statistical period arrives, count the first total number of Hypertext Transfer Protocol (HTTP) / Secure Hypertext Transfer Protocol (HTTPS) messages received by the device from the same STA in the current first statistical period;

[0007] If there is a first total number that is not less than a first set number among all the counted first total numbers, and the device operates in normal mode, the device is set to operate in blacklist mode, a first STA corresponding to the first total number that is not less than the first set number is added to a blacklist list, and first blacklist information for the first STA is sent to a first access point (AP) to which the first STA accesses, so that the first AP discards HTTP / HTTPS messages received from the first STA corresponding to the first blacklist information after receiving the first blacklist information, and when a second total number of HTTP / HTTPS messages discarded by the first AP counted within a second statistical period set for the first STA is less than a first safe number, the device deletes the first blacklist information and reports a first deletion notification message carrying the first blacklist information to the AC;

[0008] Upon receiving a second deletion notification message carrying second blacklist information of a second STA from a second AP, deleting the second STA from the current blacklist, and setting itself to work in normal mode when the blacklist is empty after deletion;

[0009] If there is a first total number that is not less than the first set number among all the counted first total numbers, and the system works in the blacklist mode, the step of adding the first STA corresponding to the first total number that is not less than the first set number to the blacklist list is started.

[0010] According to a second aspect of an embodiment of the present application, a security defense method is provided. The method is applied to an AP, and the method includes:

[0011] After receiving blacklist information for a first STA sent by an AC to which the AC itself is connected, discarding HTTP / HTTPS messages received from the first STA, wherein the blacklist information is sent after the AC arrives at a current first statistical period, when a first total number of HTTP / HTTPS messages of the first STA received by the AC in the current first statistical period is counted to be not less than a first set number, and the AC operates in normal mode, setting the AC to operate in blacklist mode, adding the first STA to the blacklist list;

[0012] When the second total number of HTTP / HTTPS messages discarded by the first AP counted within the first statistical period set for the first STA is less than the first safety number, the blacklist information is deleted, and a deletion notification message carrying the blacklist information is reported to the AC.

[0013] According to a third aspect of an embodiment of the present application, a security defense device is provided. The device is applied to an AC, and the device includes:

[0014] a statistics module, configured to count, after a current first statistics period arrives, a first total number of HTTP / HTTPS messages received by the module from the same STA within the current first statistics period;

[0015] a first defense module, configured to, if a first total number not less than a first set number exists among all the first total numbers counted by the statistical module and the first defense module operates in normal mode, set the first defense module to operate in blacklist mode, add a first STA corresponding to the first total number not less than the first set number to a blacklist, and send first blacklist information for the first STA to a first AP to which the first STA accesses, so that the first AP discards HTTP / HTTPS messages received from the first STA corresponding to the first blacklist information after receiving the first blacklist information, and delete the first blacklist information when a second total number of HTTP / HTTPS messages discarded by the first AP counted within a second statistical period set for the first STA is less than a first safety number, and report a first deletion notification message carrying the first blacklist information to the AC; and, if a first total number not less than the first set number exists among all the first total numbers counted and the first defense module operates in blacklist mode, start executing the step of adding the first STA corresponding to the first total number not less than the first set number to the blacklist;

[0016] The deletion setting module is used to delete the second STA from the current blacklist when receiving the second deletion notification message carrying the second blacklist information of the second STA sent by the second AP, and set itself to work in normal mode when the blacklist is empty after deletion.

[0017] According to a fourth aspect of an embodiment of the present application, a security defense device is provided. The device is applied to an AP, and the device includes:

[0018] a discarding module, configured to discard HTTP / HTTPS messages received from a first STA after receiving blacklist information for the first STA sent by the AC to which it is connected, wherein the blacklist information is sent after the AC arrives at a current first statistical period, when a first total number of HTTP / HTTPS messages of the first STA received by the AC in the current first statistical period is counted to be not less than a first set number, and the AC operates in normal mode, setting the AC to operate in blacklist mode, adding the first STA to the blacklist list, and then sending the blacklist information;

[0019] A deletion module is used to delete the blacklist information and report a deletion notification message carrying the blacklist information to the AC when the second total number of HTTP / HTTPS messages discarded by the first AP counted within the first statistical period set for the first STA is less than the first safety number.

[0020] According to the fifth aspect of an embodiment of the present application, an electronic device is provided, comprising a processor and a machine-readable storage medium, wherein the machine-readable storage medium stores machine-executable instructions that can be executed by the processor, and the processor is prompted by the machine-executable instructions to implement the method steps of the above-mentioned security defense method.

[0021] According to a sixth aspect of an embodiment of the present application, a computer-readable storage medium is provided, in which a computer program is stored. When the computer program is executed by a processor, the method steps of the above-mentioned security defense method are implemented.

[0022] The technical solutions provided by the embodiments of the present application may have the following beneficial effects:

[0023] In an embodiment of the present application, the AC periodically monitors the number of HTTP / HTTPS messages from the same STA, promptly identifies the attacked blacklisted users, and sets itself to work in blacklist mode, notifying the corresponding AP of the blacklist information of the corresponding STA, so that the corresponding AP discards the HTTP / HTTPS messages from the corresponding STA based on the blacklist information, thereby improving the processing capability of the AC and further improving the user experience.

[0024] It should be understood that the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the present application. BRIEF DESCRIPTION OF THE DRAWINGS

[0025] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.

[0026] Figure 1 One of the flow charts of a security defense method provided in an embodiment of the present application;

[0027] Figure 2 A second flowchart of a security defense method provided in an embodiment of the present application;

[0028] Figure 3 This is one of the structural diagrams of a security defense device provided in an embodiment of the present application;

[0029] Figure 4Figure 2 is a schematic structural diagram of a security defense device according to an embodiment of the present application;

[0030] Figure 5 Figure 4 is a schematic structural diagram of an electronic device according to an embodiment of the present application. DETAILED DESCRIPTION

[0031] The exemplary embodiments will be described in detail herein below with reference to the drawings. The following description is with reference to the drawings, in which like numerals refer to like elements throughout. The embodiments described in the following exemplary embodiments are not representative of all embodiments consistent with the present application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of the present application as detailed in the appended claims.

[0032] The terminology used in the present application is for the purpose of describing particular embodiments only and is not intended to be limiting of the present application. As used in the present application and the appended claims, the singular forms "a," "an" and "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise. It will be further understood that the terms "comprises" and / or "comprising," when used in this specification, specify the presence of stated features, integers, steps, operations, elements, and / or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof.

[0033] It is to be understood that the singular forms "a," "an," and "the" include plural referents unless the context clearly dictates otherwise. It will be further understood that the terms "comprises" and / or "comprising," when used in this specification, specify the presence of stated features, integers, steps, operations, elements, and / or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof.

[0034] Next, the embodiments of the present application will be described in detail.

[0035] The embodiments of the present application provide a security defense method, which is applied to an AC, as shown in the figure, the method can include the following steps: Figure 1

[0036] S11, after the current first statistical period arrives, statistics of the first total number of HTTP / HTTPS messages from the same STA received by itself in the current first statistical period.

[0037] ​S12. If there is a first total number that is not less than the first set number among all the first total numbers counted, and the device itself works in normal mode, it sets itself to work in blacklist mode, adds the first STA corresponding to the first total number that is not less than the first set number to the blacklist list, and sends the first blacklist information for the first STA to the first AP to which the first STA accesses, so that after receiving the first blacklist information, the first AP discards the HTTP / HTTPS message received from the first STA corresponding to the first blacklist information, and when the second total number of HTTP / HTTPS messages discarded by the first AP counted within the second statistical period set for the first STA is less than the first safe number, delete the first blacklist information, and report the first deletion notification message carrying the first blacklist information to the AC.

[0038] In this step, the first blacklist information may be address information of the first STA, for example, the Internet Protocol (IP) address and / or Media Access Control (MAC) address of the first STA.

[0039] S13. Upon receiving a second deletion notification message sent by the second AP and carrying the second blacklist information of the second STA, the second STA is deleted from the current blacklist, and when the blacklist is empty after deletion, the system is set to work in normal mode.

[0040] In this step, the second blacklist information may be the address information of the second STA, for example, the IP address and / or MAC address of the second STA. Here, after the AC sets itself to work in normal mode, it processes the received message according to the existing message processing method.

[0041] S14. If there is a first total number that is not less than the first set number among all the first total numbers counted, and the STA itself works in the blacklist mode, start executing the step of adding the first STA corresponding to the first total number that is not less than the first set number to the blacklist list in step S12.

[0042] It should be noted that, in the embodiment of the present application, when there are multiple first STAs, the second statistical periods set for the first STAs may be the same or different.

[0043] For the first AP, when the second total number of HTTP / HTTPS messages discarded by the first AP counted within the second statistical period set for the first STA is not less than the first safety number, the first AP continues to discard HTTP / HTTPS messages received from the first STA.

[0044] It should be further explained that in an embodiment of the present application, for the AC, when receiving a second deletion notification message sent by a second AP carrying the second blacklist information of the second STA, after deleting the second STA from the current blacklist, if the blacklist after deletion is not empty, then continue to work in the blacklist mode. Once the total number of HTTP / HTTPS messages of a certain STA or certain STAs is counted to be not less than the first set number after a subsequent first statistical period arrives, continue to add this STA or these STAs to the blacklist, and send corresponding blacklist information to the AP to which this STA or these STAs access.

[0045] Furthermore, in the embodiment of the present application, the AC may further perform the following operations:

[0046] After executing the step of counting the first total number of HTTP / HTTPS messages received by the user from the STA of the same station in the current first statistical period, if the user operates in the blacklist mode, continue to count the third total number of all HTTP / HTTPS messages received by the user in the current first statistical period;

[0047] If all the first total numbers counted are less than the first set number, and the third total number is not less than the second set number, then set itself to work in blacklist mode and whitelist mode, and send a defense notification message to the third AP to which all third STAs corresponding to the first total number are connected, so that after receiving the defense notification message, the third AP redirects the HTTP / HTTPS message sent by the fourth STA that is not in the obtained STA list that has passed Portal authentication, and reports to the AC the total number of HTTP / HTTPS messages redirected by the third AP within the third statistical period according to the third statistical period;

[0048] Among them, the first statistical period is greater than the third statistical period.

[0049] It should be noted that by performing this operation process, the AC can offload the redirection operation of HTTP / HTTPS messages to the AP side. This can further reduce the load on the AC side, improve the AC's processing capability, and thus improve the user experience.

[0050] In addition, in this operation process, in one example, the STA list may be obtained by the third AP from a defense notification message.

[0051] In another example, the STA list can be sent by the AC and presented as a STA entry before the third AP receives the defense notification message. In this case, once a STA passes Portal authentication, the AC promptly sends the authenticated STA entry to the AP it connects to.

[0052] In addition, for the third AP, the specific implementation process of redirecting the HTTP / HTTPS message sent by the fourth STA is the same as the specific implementation of redirecting the received HTTP / HTTPS message on the AC side, and is not described in detail here.

[0053] Furthermore, in the embodiment of the present application, the AC may further perform the following operations:

[0054] After executing the step of counting the first total number of HTTP / HTTPS messages received by the device from the STA of the same station in the current first statistical period, if the device operates in the blacklist mode and the whitelist mode, continuing to count the fourth total number of all HTTP / HTTPS messages received by the device in the current first statistical period;

[0055] A summation operation is performed on the fourth total number and a fifth total number of HTTP / HTTPS messages for redirection operations performed by the fourth AP in the third statistical period, which is most recently reported by the fourth AP and received by the user in the current first statistical period, to obtain a calculation result;

[0056] When the calculation result is less than the second safety number, if the current blacklist is not empty, the AP is set to work in blacklist mode and sends a defense cancellation notification message to the fourth AP, so that the fourth AP sends the received HTTP / HTTPS message to the AC after receiving the defense cancellation notification message.

[0057] If the current blacklist is empty, set itself to work in normal mode.

[0058] It should be noted that by performing this operation process, the AC can adjust its own working mode in a timely manner to ensure that the WLAN network where the AC is located can operate smoothly.

[0059] It should be further explained that, in the embodiment of the present application, the first set number, the second set number and the second safety number can be set by the administrator based on the network operation experience of the WLAN network where the AC is located, and pre-configured on the AC.

[0060] Correspondingly, the first safety number can also be set by the administrator based on the network operation experience of the WLAN network where the AC is located, and configured in advance on the first AP.

[0061] The above content describes the implementation process of the security defense method from the perspective of the AC. The following describes the implementation process of the security defense method from the perspective of the AP.

[0062] The embodiment of the present application also provides a security defense method, which is applied to AP, such as Figure 2 As shown, the method may include the following steps:

[0063] S21 . After receiving the blacklist information for the first STA sent by the AC to which the STA is connected, discard the HTTP / HTTPS message received from the first STA.

[0064] In this step, the blacklist information is sent after the AC arrives at the current first statistical period, and when it is found that the first total number of HTTP / HTTPS messages of the first STA received by the AC in the current first statistical period is not less than the first set number, and the AC is working in normal mode, the AC is set to work in blacklist mode, and the first STA is added to the blacklist list.

[0065] Furthermore, the blacklist information may be address information of the first STA, for example, the IP address and / or MAC address of the first STA.

[0066] S22. When the second total number of HTTP / HTTPS messages discarded by the first AP counted within the first statistical period set for the first STA is less than the first safety number, delete the blacklist information and report a first deletion notification message carrying the first blacklist information to the AC.

[0067] It should be noted that in an embodiment of the present application, for the AC, when receiving the first deletion notification message, the first STA is deleted from the current blacklist, and when the blacklist is empty after deletion, the AC is set to work in normal mode; or, when the blacklist is not empty after deletion, the AC continues to work in blacklist mode.

[0068] Furthermore, in the embodiment of the present application, the AP may further perform the following operations:

[0069] After receiving the blacklist information for the first STA sent by the AC to which it is connected, if a defense notification message is received from the AC, the HTTP / HTTPS message sent by the second STA that is not in the obtained list of STAs that have passed the portal authentication portal is redirected;

[0070] After the third statistical period arrives, the device reports to the AC the total number of HTTP / HTTPS packets redirected during the third statistical period, where the second statistical period is greater than the third statistical period.

[0071] After receiving the defense cancellation notification message sent by the AC, the received HTTP / HTTPS message is sent to the AC.

[0072] In this operation process, the defense notification message is sent after the AC counts the first total number of HTTP / HTTPS messages received by the AC from the same STA in the current first statistical period. If the AC itself works in the blacklist mode, it continues to count the third total number of all HTTP / HTTPS messages received by the AC in the current first statistical period, and when all the first total numbers counted are less than the first set number and the third total number is not less than the second set number, it sets itself to work in blacklist mode and whitelist mode.

[0073] It should be noted that, in the embodiment of the present application, the above-mentioned first set number and the above-mentioned second set number can be set by the administrator based on the network operation experience of the WLAN network where the AC is located, and can be pre-configured on the AC.

[0074] Correspondingly, the first safety number can also be set by the administrator based on the network operation experience of the WLAN network where the AC is located, and configured on the AP in advance.

[0075] In addition, other processing flows of the AC have been described from the AC side and will not be described in detail here.

[0076] The above security defense method is described in detail below with reference to specific embodiments.

[0077] In a WLAN network in which the forwarding mode is a centralized forwarding mode, for an AC in the WLAN network, assuming that a first first statistical period has arrived, a first total number of HTTP / HTTPS packets received by the AC from the same STA in the first first statistical period is counted.

[0078] Assume that there is a first total number that is not less than the first set number among all the first total numbers counted, and the AC operates in normal mode. In this case, the AC sets itself to operate in blacklist mode and performs the following operations: add the first STA (for example, STA1) corresponding to the first total number that is not less than the first set number to the blacklist list, and send STA1's blacklist information (recorded as blacklist information 1, for example, including STA1's IP address) to the AP (for example, AP1) to which STA1 accesses.

[0079] After receiving the blacklist information 1, if AP1 receives the HTTP / HTTPS message 1 sent by STA1, then AP1 discards the HTTP / HTTPS message 1 and counts the second total number of HTTP / HTTPS messages from STA1 discarded by AP1 within the second statistical period according to the second statistical period set for STA1.

[0080] Subsequently, it is assumed that the second total number of HTTP / HTTPS messages from STA1 discarded by AP1 counted within a second statistical period is less than the first safety number. In this case, AP1 deletes blacklist information 1 and reports deletion notification message 1 carrying blacklist information 1 to AC.

[0081] When the AC receives the deletion notification message 1 sent by AP1, it deletes STA1 from the current blacklist. Assuming that the blacklist is not empty after the deletion, the AC continues to operate in blacklist mode.

[0082] Next, for the AC, assuming that the fourth first statistical period has arrived and the AC is working in blacklist mode, the first total number of HTTP / HTTPS messages received by the AC from the same STA in the fourth first statistical period is counted, and the third total number of all HTTP / HTTPS messages received by the AC in the fourth first statistical period is counted.

[0083] Assume that a first total number not less than the first set number exists among all the first total numbers counted. In this case, the operation flow executed when the AC works in the blacklist mode is continued to be executed, which is not described in detail here.

[0084] Subsequently, assuming that the fifth first statistical period has arrived and the AC is operating in blacklist mode, the first total number of HTTP / HTTPS packets received by the AC from the same STA in the fifth first statistical period is counted, and the third total number of all HTTP / HTTPS packets received by the AC in the fifth first statistical period is counted.

[0085] Assume that all the first total numbers counted are less than the first set number, and the third total number is not less than the second set number. In this case, the AC sets itself to work in blacklist mode and whitelist mode, and sends defense notification message 1 to the AP (for example, AP2) to which all STAs corresponding to the first total number (for example, STA2, STA3 and STA4) are connected.

[0086] For example, defense notification message 1 carries STA list 1 that has passed Portal authentication.

[0087] After receiving the defense notification message 1, if AP2 receives an HTTP / HTTPS message 2 sent by a STA that is not in the STA list 1 (for example, STA5), AP2 redirects the HTTP / HTTPS message 2, counts the total number of HTTP / HTTPS messages that AP2 redirects within the third statistical period according to the third statistical period, and reports the total number to the AC.

[0088] Assume that the eighth first statistical period has been reached and the AC operates in blacklist mode and whitelist mode. Count the first total number of HTTP / HTTPS messages received by the AC from the same STA in the eighth first statistical period, and count the fourth total number of all HTTP / HTTPS messages received by the AC in the eighth first statistical period.

[0089] The AC calculates a sum of the fourth total number and the fifth total number of HTTP / HTTPS packets in which AP2 performs a redirection operation within the third statistical period, which is the most recently reported number of HTTP / HTTPS packets received by the AC within the eighth first statistical period, to obtain a calculation result.

[0090] Assuming that the calculation result is smaller than the second safety number and that the current blacklist is not empty, the AC sets itself to work in the blacklist mode and sends a defense cancellation notification message 1 to AP2.

[0091] After receiving the defense cancellation notification message 1, AP2 sends the received HTTP / HTTPS message to the AC.

[0092] It should be noted that the above content only describes the implementation process of the security defense method using several first statistical cycles as an example. For the subsequent processing process of the AC, please refer to the implementation process of the security defense method described on the AC side, which will not be described in detail here.

[0093] It can be seen from the above technical solution that in the embodiment of the present application, the AC regularly monitors the number of HTTP / HTTPS messages from the same STA, promptly identifies the attacked blacklisted users, and sets itself to work in blacklist mode, and notifies the corresponding AP of the blacklist information of the corresponding STA, so that the corresponding AP discards the HTTP / HTTPS messages from the corresponding STA based on the blacklist information, thereby improving the processing capability of the AC and further improving the user experience.

[0094] Based on the same inventive concept, the present application also provides a security defense device, which is applied to AC, and its structural diagram is shown as follows: Figure 3 As shown, specifically including:

[0095] A statistics module 31 is configured to count, after a current first statistics period arrives, a first total number of HTTP / HTTPS messages received by the module from STAs of the same station within the current first statistics period;

[0096] The first defense module 32 is configured to, if a first total number not less than a first set number exists among all the first total numbers counted by the statistics module 31 and the first defense module 32 operates in normal mode, set itself to operate in blacklist mode, add a first STA corresponding to the first total number not less than the first set number to a blacklist, and send first blacklist information for the first STA to a first access point AP to which the first STA accesses, so that the first AP discards HTTP / HTTPS messages received from the first STA corresponding to the first blacklist information after receiving the first blacklist information, and delete the first blacklist information when a second total number of HTTP / HTTPS messages discarded by the first AP counted within a second statistics period set for the first STA is less than a first safety number, and report a first deletion notification message carrying the first blacklist information to the AC; and, if a first total number not less than the first set number exists among all the first total numbers counted and the first defense module 32 operates in blacklist mode, start executing the step of adding the first STA corresponding to the first total number not less than the first set number to the blacklist;

[0097] The deletion setting module 33 is used to delete the second STA from the current blacklist when receiving the second deletion notification message sent by the second AP carrying the second blacklist information of the second STA, and set itself to work in normal mode when the blacklist is empty after deletion.

[0098] Preferably, the statistical module 31 is further configured to:

[0099] After executing the step of counting the first total number of HTTP / HTTPS messages received by the user from the STA of the same station in the current first statistical period, if the user operates in the blacklist mode, continue to count the third total number of all HTTP / HTTPS messages received by the user in the current first statistical period;

[0100] The device further comprises:

[0101] Second defense module ( Figure 3(not shown) is used for, if all the first total quantities counted by the statistical module are less than the first set quantity, and the third total quantity is not less than the second set quantity, setting itself to work in blacklist mode and whitelist mode, and sending a defense notification message to the third AP to which the third STA corresponding to the first total quantity accesses, so that after receiving the defense notification message, the third AP redirects the HTTP / HTTPS message sent by the fourth STA that is not in the obtained STA list that has passed the portal authentication, and reports to the AC according to the third statistical period the total number of HTTP / HTTPS messages redirected by the third AP within the third statistical period;

[0102] The first statistical period is greater than the third statistical period.

[0103] Preferably, the statistics module 31 is further used for:

[0104] After executing the step of counting the first total number of HTTP / HTTPS messages received by the device from the STA of the same station in the current first statistical period, if the device operates in the blacklist mode and the whitelist mode, continuing to count the fourth total number of all HTTP / HTTPS messages received by the device in the current first statistical period;

[0105] performing a sum operation on the fourth total number and a fifth total number of HTTP / HTTPS messages for redirection operations performed by the fourth AP within the third statistical period, which is most recently reported by the fourth AP and received by the fourth AP within the current first statistical period, to obtain a calculation result;

[0106] When the calculation result is less than the second safety number, if the current blacklist is not empty, setting itself to work in blacklist mode, and sending a defense cancellation notification message to the fourth AP, so that the fourth AP sends the received HTTP / HTTPS message to the AC after receiving the defense cancellation notification message;

[0107] If the current blacklist is empty, set itself to work in normal mode.

[0108] The present application also provides a security defense device, which is applied to AP, and its structural diagram is shown as follows: Figure 4 As shown, specifically including:

[0109] a discarding module 41 configured to discard HTTP / HTTPS messages received from a first station STA after receiving blacklist information for the first station STA sent by an access controller AC to which the AC is connected, wherein the blacklist information is sent after the AC arrives at a current first statistical period, when a first total number of HTTP / HTTPS messages from the first STA received by the AC in the current first statistical period is counted to be not less than a first set number, and when the AC operates in normal mode, setting the AC to operate in blacklist mode and adding the first STA to the blacklist;

[0110] The deletion module 42 is used to delete the blacklist information and report a deletion notification message carrying the blacklist information to the AC when the second total number of HTTP / HTTPS messages discarded by the first AP counted within the first statistical period set for the first STA is less than the first safety number.

[0111] Preferably, the device further comprises:

[0112] Redirection Module ( Figure 4 (not shown) for, after receiving the blacklist information for the first STA sent by the access controller AC to which it has accessed, if a defense notification message is received from the AC, redirecting the HTTP / HTTPS message sent by the second STA that is not in the obtained STA list that has passed the portal authentication Portal;

[0113] Reporting module ( Figure 4 (not shown) for reporting, after reaching a third statistical period, to the AC the total number of HTTP / HTTPS messages for which the AC performs a redirection operation within the third statistical period, wherein the first statistical period is greater than the third statistical period;

[0114] Transceiver module ( Figure 4 (not shown) is used to send the received HTTP / HTTPS message to the AC after receiving the defense cancellation notification message sent by the AC.

[0115] It can be seen from the above technical solution that in the embodiment of the present application, the AC regularly monitors the number of HTTP / HTTPS messages from the same STA, promptly identifies the attacked blacklisted users, and sets itself to work in blacklist mode, and notifies the corresponding AP of the blacklist information of the corresponding STA, so that the corresponding AP discards the HTTP / HTTPS messages from the corresponding STA based on the blacklist information, thereby improving the processing capability of the AC and further improving the user experience.

[0116] The present application also provides an electronic device, such as Figure 5 As shown, it includes a processor 51 and a machine-readable storage medium 52, wherein the machine-readable storage medium 52 stores machine-executable instructions that can be executed by the processor 51, and the processor 51 is prompted by the machine-executable instructions to implement the steps of any of the above-mentioned security defense methods.

[0117] The machine-readable storage medium may include random access memory (RAM) or non-volatile memory (NVM), such as at least one disk storage device. Alternatively, the machine-readable storage medium may be at least one storage device located remote from the processor.

[0118] The above-mentioned processor can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, and discrete hardware components.

[0119] In another embodiment provided in the present application, a computer-readable storage medium is also provided, in which a computer program is stored. When the computer program is executed by a processor, the steps of any of the above-mentioned security defense methods are implemented.

[0120] The above description is only a preferred embodiment of the present application and is not intended to limit the present application. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present application shall be included in the scope of protection of the present application.

Claims

1. A security defense method, characterized in that: The method is applied to an access controller AC, and includes: After the current first statistical period arrives, count the first total number of HTTP / HTTPS messages received by the user from STAs of the same station during the current first statistical period; If there is a first total number that is not less than the first set number among all the first total numbers counted, and the network itself works in normal mode, it sets itself to work in blacklist mode, adds the first STA corresponding to the first total number that is not less than the first set number to the blacklist list, and sends first blacklist information for the first STA to the first access point AP to which the first STA accesses, so that after receiving the first blacklist information, the first AP discards the HTTP / HTTPS message received from the first STA corresponding to the first blacklist information, and when the second total number of HTTP / HTTPS messages discarded by the first AP counted within the second statistical period set for the first STA is less than the first safe number, delete the first blacklist information, and report a first deletion notification message carrying the first blacklist information to the AC; Upon receiving a second deletion notification message carrying second blacklist information of a second STA from a second AP, deleting the second STA from the current blacklist, and setting itself to work in normal mode when the blacklist is empty after deletion; If there is a first total number that is not less than the first set number among all the counted first total numbers, and the system works in the blacklist mode, the step of adding the first STA corresponding to the first total number that is not less than the first set number to the blacklist list is started.

2. The method according to claim 1, characterized in that The method further comprises: After executing the step of counting the first total number of HTTP / HTTPS messages received by the user from the STA of the same station in the current first statistical period, if the user operates in the blacklist mode, continue to count the third total number of all HTTP / HTTPS messages received by the user in the current first statistical period; If all the first total numbers counted are less than the first set number, and the third total number is not less than the second set number, then set itself to work in blacklist mode and whitelist mode, and send a defense notification message to the third AP to which all third STAs corresponding to the first total number are connected, so that after receiving the defense notification message, the third AP redirects the HTTP / HTTPS message sent by the fourth STA that is not in the obtained STA list that has passed the portal authentication, and reports to the AC according to the third statistical period the total number of HTTP / HTTPS messages redirected by the third AP within the third statistical period; The first statistical period is greater than the third statistical period.

3. The method according to claim 2, characterized in that The method further comprises: After executing the step of counting the first total number of HTTP / HTTPS messages received by the device from the STA of the same station in the current first statistical period, if the device operates in the blacklist mode and the whitelist mode, continuing to count the fourth total number of all HTTP / HTTPS messages received by the device in the current first statistical period; performing a sum operation on the fourth total number and a fifth total number of HTTP / HTTPS messages for redirection operations performed by the fourth AP within the third statistical period, which is most recently reported by the fourth AP and received by the fourth AP within the current first statistical period, to obtain a calculation result; When the calculation result is less than the second safety number, if the current blacklist is not empty, setting itself to work in blacklist mode, and sending a defense cancellation notification message to the fourth AP, so that the fourth AP sends the received HTTP / HTTPS message to the AC after receiving the defense cancellation notification message; If the current blacklist is empty, set itself to work in normal mode.

4. A security defense method, characterized in that: The method is applied to an access point AP, and includes: After receiving blacklist information for a first station STA sent by an access controller AC to which the AC is connected, discarding HTTP / HTTPS messages received from the first STA, wherein the blacklist information is sent after the AC arrives at a current first statistical period, when a first total number of HTTP / HTTPS messages from the first STA received by the AC in the current first statistical period is counted to be not less than a first set number, and the AC operates in normal mode, setting the AC to operate in blacklist mode, and adding the first STA to the blacklist list; When the second total number of HTTP / HTTPS messages discarded by the AP counted within the first statistical period set for the first STA is less than the first safety number, the blacklist information is deleted, and a deletion notification message carrying the blacklist information is reported to the AC.

5. The method according to claim 4, characterized in that The method further comprises: After receiving the blacklist information for the first STA sent by the access controller AC to which it is connected, if a defense notification message is received from the AC, the HTTP / HTTPS message sent by the second STA that is not in the obtained list of STAs that have passed the portal authentication Portal is redirected; After a third statistical period arrives, reporting to the AC the total number of HTTP / HTTPS packets redirected by the user within the third statistical period, where the first statistical period is greater than the third statistical period; After receiving the defense cancellation notification message sent by the AC, the received HTTP / HTTPS message is sent to the AC.

6. A security defense device, characterized in that: The device is applied to an access controller AC, and includes: a statistics module, configured to count, after a current first statistics period arrives, a first total number of HTTP / HTTPS messages received by the module from STAs of the same station within the current first statistics period; a first defense module, configured to, if a first total number not less than a first set number exists among all the first total numbers counted by the statistical module and the first defense module operates in normal mode, set the first defense module to operate in blacklist mode, add a first STA corresponding to the first total number not less than the first set number to a blacklist, and send first blacklist information for the first STA to a first access point AP to which the first STA accesses, so that the first AP discards HTTP / HTTPS messages received from the first STA corresponding to the first blacklist information after receiving the first blacklist information, and delete the first blacklist information when a second total number of HTTP / HTTPS messages discarded by the first AP counted within a second statistical period set for the first STA is less than a first safety number, and report a first deletion notification message carrying the first blacklist information to the AC; and, if a first total number not less than the first set number exists among all the first total numbers counted and the first defense module operates in blacklist mode, start executing the step of adding the first STA corresponding to the first total number not less than the first set number to the blacklist; The deletion setting module is used to delete the second STA from the current blacklist when receiving the second deletion notification message carrying the second blacklist information of the second STA sent by the second AP, and set itself to work in normal mode when the blacklist is empty after deletion.

7. The device according to claim 6, characterized in that The statistics module is further used to: After executing the step of counting the first total number of HTTP / HTTPS messages received by the user from the STA of the same station in the current first statistical period, if the user operates in the blacklist mode, continue to count the third total number of all HTTP / HTTPS messages received by the user in the current first statistical period; The device further comprises: The second defense module is used to set itself to work in blacklist mode and whitelist mode if all the first total quantities counted by the statistical module are less than the first set quantity, and the third total quantity is not less than the second set quantity, and send a defense notification message to the third AP to which all third STAs corresponding to the first total quantity are connected, so that after receiving the defense notification message, the third AP redirects the HTTP / HTTPS message sent by the fourth STA that is not in the obtained STA list that has passed the portal authentication, and reports to the AC according to the third statistical period the total number of HTTP / HTTPS messages redirected by the third AP within the third statistical period; The first statistical period is greater than the third statistical period.

8. The device according to claim 7, characterized in that The statistics module is further used to: After executing the step of counting the first total number of HTTP / HTTPS messages received by the device from the STA of the same station in the current first statistical period, if the device operates in the blacklist mode and the whitelist mode, continuing to count the fourth total number of all HTTP / HTTPS messages received by the device in the current first statistical period; performing a sum operation on the fourth total number and a fifth total number of HTTP / HTTPS messages for redirection operations performed by the fourth AP within the third statistical period, which is most recently reported by the fourth AP and received by the fourth AP within the current first statistical period, to obtain a calculation result; When the calculation result is less than the second safety number, if the current blacklist is not empty, setting itself to work in blacklist mode, and sending a defense cancellation notification message to the fourth AP, so that the fourth AP sends the received HTTP / HTTPS message to the AC after receiving the defense cancellation notification message; If the current blacklist is empty, set itself to work in normal mode.

9. A security defense device, characterized in that: The device is applied to an access point AP, and includes: a discarding module, configured to discard HTTP / HTTPS messages received from a first station STA after receiving blacklist information for the first station STA sent by an access controller AC to which the AC is connected, wherein the blacklist information is sent after the AC arrives at a current first statistical period, when a first total number of HTTP / HTTPS messages of the first STA received by the AC in the current first statistical period is counted to be not less than a first set number, and when the AC operates in normal mode, setting the AC to operate in blacklist mode and adding the first STA to the blacklist list; A deletion module is used to delete the blacklist information and report a deletion notification message carrying the blacklist information to the AC when the second total number of HTTP / HTTPS messages discarded by the AP counted within the first statistical period set for the first STA is less than the first safety number.

10. The device according to claim 9, characterized in that The device further comprises: A redirection module is configured to, after receiving blacklist information for a first STA sent by an access controller AC to which the access controller is connected, redirect an HTTP / HTTPS message sent by a second STA that is not in the obtained list of STAs that have passed the portal authentication Portal if a defense notification message is received from the AC; a reporting module, configured to report, after a third statistical period arrives, to the AC a total number of HTTP / HTTPS messages for which the AC performs a redirection operation within the third statistical period, wherein the first statistical period is greater than the third statistical period; The transceiver module is used to send the received HTTP / HTTPS message to the AC after receiving the defense cancellation notification message sent by the AC.

11. An electronic device, characterized in that: The method comprises a processor and a machine-readable storage medium, wherein the machine-readable storage medium stores machine-executable instructions that can be executed by the processor, and the processor is prompted by the machine-executable instructions to implement the method steps according to any one of claims 1 to 5.

12. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method steps according to any one of claims 1 to 5 are implemented.

Citation Information

Patent Citations

  • Message processing method and device

    CN105939320A

  • Method and equipment for issuing WLAN user access authentication and configuration information

    CN107517189A