Network device end hop variation access system and method based on situation awareness
By using situational awareness and chaotic sequence encryption to dynamically change network parameters at the network device end of the access system, the problem of easy interception of mid-terminal information jumps and man-in-the-middle attacks in existing technologies is solved, thereby improving network security and defense capabilities.
Patent Information
- Application Number
- CN202411208787.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-08-30
- Publication Date
- 2025-11-25
- Estimated Expiration
- 2044-08-30
AI Technical Summary
In existing technologies, end-to-end information switching methods are easily intercepted, have poor security, and fail to effectively prevent man-in-the-middle attacks. Traditional encryption algorithms are also insufficient in their defense capabilities against new types of network attacks.
A situational awareness-based network device end-to-end access system is adopted. The system generates port knocking information through the service gateway, and determines whether to execute the end-to-end information hopping strategy by combining the comprehensive situational awareness score. It also uses chaotic sequences for key exchange and encrypted transmission to realize dynamic changes in end-to-end information.
It improves network security, reduces the impact of frequent hopping on network services, balances the risks of system security and business interruption, and enhances the ability to resist man-in-the-middle attacks.
Smart Images

Figure CN119182568B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of network security access, and more particularly to a network device end hopping access system and method based on situation awareness. BACKGROUND
[0002] Network security is a very important branch in the field of information technology, aiming to protect the confidentiality, integrity and availability of data transmission. With the rapid development and wide application of the Internet, the challenges faced by network security are increasing. Traditional encryption algorithms, such as symmetric encryption (such as AES) and asymmetric encryption (such as RSA), have played an important role in protecting data. However, with the improvement of computing power and the emergence of new attack methods, traditional encryption algorithms also face new threats.
[0003] End information hopping is a network security technology that aims to prevent attackers from tracking and invading by dynamically changing endpoint information. This method is similar to the application of frequency hopping in wireless communication, by constantly changing the communication port, IP address or other key network parameters, increasing the difficulty of attackers locating and attacking targets, thereby enhancing the security of the system.
[0004] In today's complex and changing network environment, situation awareness technology has become a core means to ensure network security. With the rapid development of the Internet and information technology, the network size and complexity of enterprises and organizations are increasing, while the security threats they face are becoming increasingly severe. Advanced persistent threats (APT), zero-day attacks, distributed denial of service (DDoS) attacks and other new network attack methods are emerging, and traditional static defense measures have been difficult to cope with. Situation awareness technology can effectively improve the overall defense capability of the network through real-time monitoring, dynamic analysis and intelligent early warning.
[0005] Some methods related to end information hopping and situation awareness are provided in the prior art, but there are still some problems, for example: the hopping port needs to be pre-set and has poor security, and is easy to be intercepted and penetrated; although the spatial uniqueness and time variability of wireless random channels are used to improve the randomness of the key, no defense measures are considered when a man-in-the-middle attack occurs, thus unable to prevent penetration. SUMMARY
[0006] Based on the problems existing in the prior art, the present application provides a network device end hopping access system and method based on situation awareness.
[0007] According to an embodiment of the present application, a network device end hopping access system based on situation awareness is disclosed, which can include a service gateway, the service gateway can be configured to generate port knocking information for a client to communicate with the service gateway based on the port knocking information, the service gateway can be further configured to monitor comprehensive situation awareness and determine whether to execute an end information hopping strategy based on a score of the comprehensive situation awareness, wherein the port knocking information at least includes a service IP address, a port knocking sequence and a service port, the end information at least includes the service IP address, the port knocking sequence and the service port, the execution of the end information hopping strategy includes changing the end information and sending the changed end information to the client for the client to switch communication with the service gateway using the changed end information.
[0008] Further, the comprehensive situation awareness can include one or more of user behavior detection, network topology change, time period security analysis and abnormal interaction determination.
[0009] Further, sending the changed end information to the client for the client to switch communication with the service gateway using the changed end information can include: sending the changed end information to the client for the client to switch communication with the service gateway using the changed end information using a key, wherein the key is obtained by the client and the service gateway based on a chaotic sequence for key exchange when communicating with the service gateway.
[0010] Further, determining whether to execute the end information hopping strategy based on the score of the comprehensive situation awareness can include: not executing the end information hopping strategy when the score of the comprehensive situation awareness is higher than a first threshold value; executing the end information hopping strategy when the score of the comprehensive situation awareness is lower than the first threshold value but higher than a second threshold value and the level of the service communication is lower than a predetermined level; executing the end information hopping strategy when the score of the comprehensive situation awareness is lower than the second threshold value.
[0011] According to an embodiment of the present application, a network device end hopping access system based on situation awareness is disclosed, which can include a client, the client can be configured to communicate with a service gateway using port knocking information generated by the service gateway, the client is further configured to execute end hopping when receiving changed end information from the service gateway, wherein the port knocking information at least includes a service IP address, a port knocking sequence and a service port, the end information at least includes the service IP address, the port knocking sequence and the service port, the changed end information is generated by the service gateway based on a score of comprehensive situation awareness meeting a predetermined condition, and the execution of the end information hopping includes switching communication with the service gateway using the changed end information.
[0012] Further, the comprehensive situation awareness can include one or more of user behavior detection, network topology change, time period security analysis, and abnormal interaction determination.
[0013] Further, performing the endpoint hopping when receiving the changed endpoint information from the service gateway can include performing the endpoint hopping when receiving the changed endpoint information encrypted by a key from the service gateway, wherein the key is obtained based on a key exchange using a chaotic sequence when the client communicates with the service gateway.
[0014] Further, the predetermined condition can include that the score of the comprehensive situation awareness is lower than a first threshold but higher than a second threshold, and the level of the service communication is lower than a predetermined level, or the score of the comprehensive situation awareness is lower than the second threshold.
[0015] According to an embodiment of the present application, a network device endpoint hopping access method based on situation awareness is disclosed, which is applied to a service gateway, and can include: generating a port knocking information for a client to communicate with the service gateway based on the port knocking information; and monitoring a comprehensive situation awareness, and determining whether to perform an endpoint information hopping strategy based on a score of the comprehensive situation awareness, wherein the port knocking information at least includes a service IP address, a port knocking sequence, and a service port, the endpoint information at least includes the service IP address, the port knocking sequence, and the service port, and performing the endpoint information hopping strategy includes changing the endpoint information, and sending the changed endpoint information to the client to switch the communication with the service gateway using the changed endpoint information.
[0016] According to an embodiment of the present application, a network device endpoint hopping access method based on situation awareness is disclosed, which is applied to a client, and can include: communicating with a service gateway using a port knocking information generated by the service gateway; and performing endpoint hopping when receiving changed endpoint information from the service gateway, wherein the port knocking information at least includes a service IP address, a port knocking sequence, and a service port, the endpoint information at least includes the service IP address, the port knocking sequence, and the service port, the changed endpoint information is generated by the service gateway based on a score of a comprehensive situation awareness satisfying a predetermined condition, and performing the endpoint information hopping includes switching the communication with the service gateway using the changed endpoint information.
[0017] According to the present application, specific flow, topology, module, and other information of network knocking are provided, and secure network knocking from a network client to a service gateway is realized.
[0018] According to the present application, a method of performing key exchange using a chaotic sequence method, and encrypting and transmitting hopping information based on the exchanged key is provided, and the problem of hopping information leakage is solved.
[0019] According to the application, a multi-dimensional situation awareness mechanism is provided, based on situation awareness situation initiation end hopping, reducing the impact of frequent hopping on network services. The specific calculation method of multi-dimensional situation awareness is given. At the same time, by using the double threshold mechanism, unnecessary hopping is realized, and the influence of balancing system security and service interruption is further reduced to reduce the influence on network services. BRIEF DESCRIPTION OF DRAWINGS
[0020] Figure 1 is a structural schematic diagram of a network device end hopping access system based on situation awareness according to an embodiment of the application;
[0021] Figure 2 is a flowchart of a network device end hopping access method based on situation awareness according to an embodiment of the application;
[0022] Figure 3 is a structural schematic diagram of a network device end hopping access system based on situation awareness according to an embodiment of the application;
[0023] Figure 4 is a structural schematic diagram of a network device end hopping access system based on situation awareness according to another embodiment of the application;
[0024] Figure 5 is a flowchart of a network device end hopping access method based on situation awareness according to another embodiment of the application;
[0025] Figure 6 is a flowchart of a network device end hopping access method based on situation awareness according to another embodiment of the application. DETAILED DESCRIPTION
[0026] Examples or embodiments of the present application will be described below with reference to the accompanying drawings, in which specific examples or embodiments that can be implemented are shown by way of illustration, and in which the same or similar reference signs and symbols are used to denote the same or similar components even if they are shown in different drawings. Further, in the following description of examples or embodiments of the present application, when it is determined that a detailed description of well-known functions and components incorporated herein can obscure the subject matter of some embodiments of the present application, such detailed descriptions will be omitted. The terms such as "include", "have", "contain", "consist of", "comprise", "form" and the like used herein are generally intended to allow the addition of other components unless the term "only" is used together with the term. As used herein, unless the context clearly indicates otherwise, the singular form is intended to include the plural form.
[0027] Terms such as "first", "second", "A", "B", "(A)", or "(B)" can be used herein to describe elements of the present application. Each of these terms is not used to define an element, order, sequence, or number, etc., but is only used to distinguish the corresponding element from other elements.
[0028] When referring to a first element and a second element being "connected or coupled", "contacted or overlapped", it should be understood that not only can the first element be "directly connected or coupled" or "directly contacted or overlapped" with the second element, but also a third element can be "interposed" between the first element and the second element, or the first element and the second element can be "connected or coupled", "contacted or overlapped" with each other through a fourth element, etc. Here, the second element can be included in at least one of two or more elements that are "connected or coupled", "contacted or overlapped", etc. with each other.
[0029] When temporal relative terms such as "after", "subsequent to", "then", "before", etc. are used to describe the process or operation of an element or configuration or the flow or step in an operation, process, manufacturing method, unless these terms are used together with the term "directly" or "immediately", these terms can be used to describe non-continuous or non-sequential processes or operations.
[0030] In addition, when referring to any dimension, relative dimension, etc., even if the relevant description is not specified, the numerical value or the corresponding information of the element or feature (e.g., level, range, etc.) should be considered to include a tolerance or error range that can be caused by various factors (e.g., process factors, internal or external influences, noise, etc.). Further, the term "may" fully encompasses all meanings of the term "can".
[0031] Herein, the NTP protocol can refer to the Network Time Protocol.
[0032] Herein, the chaotic sequence can refer to a highly complex, seemingly random but actually deterministic and intrinsically structured sequence generated by a chaotic system.
[0033] Herein, the end hopping, which can also be referred to as end information hopping, refers to the simultaneous and synchronized change of network parameters used in communication by both parties in the process of computer network communication, which mainly includes IP address, port, protocol, etc.
[0034] Herein, situation awareness can refer to a capability of comprehensively and dynamically understanding security risks based on the environment, which is a way to improve the discovery, identification, understanding, analysis, and response and disposal capabilities of security threats from a global perspective based on security big data, and ultimately for decision-making and action, which is the landing of security capabilities.
[0035] Herein, port knocking can refer to a method of opening a port of a firewall from the outside by generating connection attempts on a set of pre-designated closed ports. Once the correct sequence of connection attempts is received, the firewall rules are dynamically modified to allow the host that sent the connection to attempt to connect through a specific port. Before the connection, the firewall closes all ports by default.
[0036] Figure 1 is a structural schematic diagram of a situation-aware network device end hopping access system according to an embodiment of the present application.
[0037] With reference to Figure 1 , the situation-aware network device end hopping access system of the present application comprises three entities: a controller, a plurality of clients, and one or more service gateways.
[0038] (1.1) Scheme topology
[0039] Controller: deployed in the external network environment, and a secure encrypted channel is pre-established with the service gateway. The controller can perform secure authentication on the client. The controller can obtain the end hopping information of the gateway and send it to the client.
[0040] Client: deployed in the external network environment, pre-configured with the network address information of the controller, capable of identity authentication and information interaction with the controller using a general network protocol, and the authentication and interaction method is not particularly limited herein.
[0041] Service gateway: deployed at the network boundary between the internal and external networks. The client can connect to the service gateway according to the network knocking information provided by the controller, and then access the service in the internal network. The relevant information of the service gateway (such as service name, hopping information, effective time, etc.) will be transmitted and stored to the controller through the pre-established persistent encrypted channel (the specific implementation of the encrypted channel is not particularly limited). The client and the service gateway can perform a key exchange based on a chaotic sequence according to the information in steps 4-6 herein, and use the exchanged key for encrypted transmission.
[0042] In this scheme, there is only one controller globally, supporting a number of service gateways and multiple clients.
[0043] Gateway connection information storage module: this module is used to receive the end information and necessary accessory information sent by the service gateway, and to store and manage them. Specifically, it includes:
[0044] (1) The information format is referred to in the initialization phase of the gateway and step 4.3.
[0045] (2) Support for storing the end information sent by multiple gateways.
[0046] (2.1) The module maintains 1-2 pieces of end information for each gateway.
[0047] At least the currently effective end hopping strategy, called running information.
[0048] There may also be end hopping information that will be effective at some future time, which is delivered to the controller by step 4.3, called candidate information, whether or not it exists, is determined by step 3 (situation detection) and step 4 (situation transmission).
[0049] The module can maintain running and candidate information according to the description method of step 4.3, etc., and switch states.
[0050] User authentication module: This module is used for the client to initiate a connection to the service gateway, and performs security authentication on the client. The authentication includes the identity information of the client and the security certificate authentication information.
[0051] (1.3) Main modules in the service gateway
[0052] Situation awareness module: used to monitor network topology situation values and judge risks, details see section 1.6.
[0053] Key exchange module: This module acts between the gateway and the client, and generates encryption keys according to the process described later. A random sequence is generated by using the high randomness and unpredictability of a nonlinear dynamic system through a chaotic sequence generator, which is used to process encryption keys.
[0054] Hopping module: generates end hopping strategy and implements hopping.
[0055] Port knocking connection module: This module is used when the client connects to the service gateway using the port knocking method. The service gateway identifies the knocking strategy and opens the corresponding port to the client.
[0056] (1.4) Main modules in the client
[0057] Key exchange module: same function as the module with the same name in 1.3.
[0058] Hopping module: implements hopping according to the end hopping strategy transmitted by the server.
[0059] (1.5) Situation awareness module and situation value calculation method
[0060] The situation awareness module is a situation calculation module that collects (perceives) multi-dimensional security indicators. Through multi-dimensional data collection and analysis, it provides accurate security situation values to provide strong support for security decision-making and risk management. The situation awareness module includes the following sub-modules.
[0061] (1.5.1.1) User behavior detection submodule
[0062] The user behavior detection submodule identifies abnormal behavior by monitoring, analyzing, and evaluating user operational behavior in the network and system. This module sets a short detection period manually, and the submodule performs periodic detection according to this period. When the situation calculation submodule initiates a calculation request, this module has already performed N detections, obtaining N sets of detection results. The specific output results are as follows:
[0063] is the total number of detections within the detection period. (i ∈ N in subsequent symbols).
[0064] : The number of abnormal behaviors detected in the ith detection.
[0065] : The number of failed attempts detected in the ith detection.
[0066] : The number of time anomalies in the ith detection.
[0067] (1.5.1.2) Abnormal interaction detection submodule
[0068] The abnormal interaction detection submodule identifies and evaluates abnormal interaction situations by monitoring and analyzing interaction behavior in the network and system, thereby discovering and responding to potential security threats in a timely manner.
[0069] This module sets a short detection period manually, and the submodule performs periodic detection according to this period. When the situation calculation submodule initiates a calculation request, this module has already performed N detections, obtaining N sets of detection results. The specific output results are as follows:
[0070] : The total number of detections within the detection period, and the start and end times of the detection period are given when the situation calculation module initiates a request. (i ∈ N in subsequent symbols).
[0071] : Abnormal traffic detected in the ith detection, and j represents the type of abnormal traffic, i.e., the data volume of abnormal traffic is counted by type.
[0072] : The number of time anomalies in the ith detection (such as abnormal interactions during non-working hours), network topology change module. (1.5.1.3) Network topology change detection submodule
[0073]
[0074] The network topology change detection submodule detects the dynamic changes of client connections in the network in real time, identifies and evaluates the changes in the network structure, and thus prevents potential security risks.
[0075] This module sets a short detection period manually, and the submodule performs periodic detection according to the period. When the situation calculation submodule initiates a calculation request, the module has performed N detections and obtained N sets of detection results. The specific output results are as follows:
[0076] is the total number of detections in the detection period (i∈N in the following).
[0077] is the number of newly added nodes detected in the i-th detection.
[0078] is the number of lost nodes detected in the i-th detection.
[0079] is the number of connection changes detected in the i-th detection. (1.5.1.4) Timer Submodule
[0080] When the situation calculation module initiates a request, the following results are output:
[0081]
[0082] : The length of time since the last step 6 (section 1.6.7) was performed. (1.5.1.5) Situation Calculation Submodule
[0083] (1) According to the preset timer, initiate situation collection and calculation, and after the predetermined time, send situation collection requests to each submodule, as well as the start time and end time (reference time and current time). Each submodule determines the parameter N according to the start time and end time, and aggregates and sends the detection information in the specified time period.
[0084] The workflow is as follows: 1. Manually set a timing period N2, which is much larger than N, and perform cyclic timing according to N2. 2. When the N2 period is reached, the desktop calculator module sends the time range of the current N2 (the last calculation time to the current time) to each submodule. Each submodule sends the output data to this module for subsequent calculation. 3. First, calculate each item situation value, such as the following "(1)-(4)" method. 4. Then calculate the overall situation value according to step "(5)".
[0085]
[0086] (1) User behavior status calculation
[0087] Considering different types of abnormal behavior, the following formula can be used for calculation:
[0088]
[0089] S U It is the status score output by the user behavior detection module.
[0090] N、 , , Input from the user behavior detection submodule.
[0091] , , These are weight values, which are empirical values determined manually.
[0092] (2) Calculation of abnormal interaction situation
[0093] Based on different types of network anomaly interactions, the following formula is used for calculation:
[0094]
[0095] The output status score of the abnormal interaction judgment module.
[0096] , and : Input from the abnormal interaction detection submodule.
[0097] The following are empirical parameters determined manually during the calculation:
[0098] : The severity of the detected abnormal interaction type.
[0099] These are the weights for traffic volume, time factor, and severity, respectively.
[0100] : An exponential factor for flow volume, used to amplify or reduce the effect of flow volume.
[0101] : No. The special case correction factor in the sub-detection is used to adjust the weight of abnormal cases.
[0102] (3) Calculation of network topology change status
[0103]
[0104] : Output of the network topology change detection module.
[0105] , , , : Output of the network topology change detection sub-module.
[0106] The following are manually determined empirical value parameters during calculation:
[0107] : The weights of the added nodes, lost nodes, and connection changes, respectively.
[0108] : Topology change impact factor.
[0109] : Total amount of topology changes in the current detection period.
[0110] : Maximum expected amount of topology changes.
[0111] (4) Time period trend calculation
[0112]
[0113] : Time period trend score.
[0114] : Output of the timer sub-module.
[0115] The following are manually determined empirical value parameters during calculation:
[0116] : Maximum risk value, indicating that the risk gradually approaches this value over time.
[0117] : Time impact factor, indicating the rate at which time increases risk.
[0118] (5) Comprehensive trend change degree score calculation
[0119] By combining the scores of each sub-module, the comprehensive trend change degree score is obtained:
[0120]
[0121] : Comprehensive trend score.
[0122] : Score of the user behavior detection module.
[0123] : Score of abnormal interaction determination module.
[0124] : Score of network topology change detection module.
[0125] : Score of time period trend detection module.
[0126] : Weight of each frequency division trend score.
[0127] (6) After the calculation is completed
[0128] Send the current comprehensive situation change degree to the situation judgment module.
[0129] Reset the timing period N2.
[0130] (1.5.1.6) Situation maintenance sub-module
[0131] This module is responsible for maintaining the overall situation value, and completing the threshold trigger notification operation according to subsequent step 3 (1.6.4), and completing the situation value reset according to step 6 (1.6.8).
[0132] The situation module periodically perceives the situation value, and calculates the situation difference value: current situation value-comprehensive situation change degree.
[0133] The situation awareness module indicates the current network security risk form through the score, and sends a jump request to the jump controller when the situation value decreases to threshold_1, threshold_2, respectively. See steps 3-5.
[0134] Figure 2 is a flowchart showing a network device end jump access method based on situation awareness according to an embodiment of the present application.
[0135] Referring to Figure 2 , the network device end jump access method based on situation awareness can be described as follows:
[0136] (1.6.1) Initialization stage
[0137] First, the controller, service gateway and client use NTP and the like to keep time synchronization.
[0138] Service gateway:
[0139] (1) Generate initial parameters:
[0140] Pre-assign a globally unique service name GN.
[0141] Generate the initial situation value State_0.
[0142] Set two state threshold: threshold_1, threshold_2.
[0143] Set a chaotic initial value chaos_0 (each gateway is unique, not changing over time).
[0144] Generate an initial jump strategy, step 4.1.
[0145] Determine the initial end information: Gate_Info, information format: (service IP address, port knocking sequence, service port, effective time t), effective time t is the current time.
[0146] (2) and the controller to maintain a secure encrypted channel, which will not be port hopping. Business gateway after starting, and the controller to establish contact, will send the initial Gate_Info to the controller. The format of sending is: (GN, Gate_Info, chaos_0). The controller stores and manages the information received by the jump information storage module. And set it as running information. Support according to GN search different gateway sent corresponding information.
[0147] (3) business gateway according to the initial end information to provide port knocking access service.
[0148] Business gateway in no client connection to keep the port hidden state, will not respond to any connection request, unless the client connection to the gateway service IP address, and in accordance with the preset port knocking sequence, and connect the service port, at this time the business gateway will provide access services through the service port.
[0149] (4) business gateway in accordance with step 5 way to monitor the state value after starting.
[0150] Client: 1, pre store the network address of the controller, support using public network channel for communication and contact. 2, get the gateway service name GN need to connect in advance. 3, determine the client name CN. Controller: 1, to establish a secure encrypted channel with the business gateway, which will not be port hopping, support using secure encrypted channel exchange gateway port hopping information, and store it, see the gateway initialization process and step 4.3. 2, pre store client authentication information, support client access from public network and authentication.
[0151] (1.6.2) step 1: client and controller communication
[0152] When the client first connects to the service gateway, it needs to access the controller for identity authentication and establish an encrypted channel first. (The specific authentication process of the client sending an identity authentication request to the controller is not within the scope of this description) After authentication, the client sends the service name GN to the controller. The controller will send the client the corresponding end information of GN: if there are both running and candidate information, they will be sent at the same time. If there is only running information, the running information will be sent.
[0153] The running and candidate information formats are consistent, and the contents are the same as described in the initialization phase (GN, Gate_Info, chaos_0). The Gate_Info format is: (service IP address, port knocking sequence, service port, effective time t). The difference is that the effective time in running must be before the current time, and the effective time in candidate is after the current time. This consistency is maintained by the controller, see step 4.
[0154] (1.6.3) Step 2: The client connects to the service gateway through network knocking and performs key exchange.
[0155] (1) The client initiates a connection to the "service IP address" of the service gateway through network knocking, and uses the "port knocking sequence" to connect to the knocking port of the service gateway in turn, performs network knocking, and finally contacts the service port for business communication.
[0156] (2) If the service IP address is correct and the port knocking sequence is correct, the service gateway will open the "service port" for communication preparation after identifying the knocking strategy.
[0157] (3) The service gateway initiates a key exchange process: (a) The service gateway sends two random numbers, r1 and r2.
[0158] (4) The client uses the previously received chaos_0 to calculate r1 using the same chaotic calculation formula (the calculation method is a general method), and the result is the encryption and decryption key key1 for secure communication.
[0159] (5) The client uses key1 to encrypt the following data: (r2, current timestamp, GN, client name CN), and sends it back to the service gateway.
[0160] (6) The service end also uses chaos_0 to calculate r1 using the same chaotic calculation formula to obtain key1', and uses key1' to decrypt the data sent by the client, and verifies: (a) whether r2 is correct; (b) whether the timestamp is fresh (whether it is too far from the current time); (c) whether the GN name is the name of the current service; (d) get the client name CN.
[0161] (7) The server encrypts the following data (CN, GN, current timestamp) using key1 and sends it back to the client.
[0162] (8) The client uses key1 to decrypt and verify whether the CN is correct and whether the timestamp is fresh.
[0163] (9) If successful, use key0+n1 key to encrypt a message (key1 (one for each connection pair), timestamp, service name, client name).
[0164] (10) The client decrypts key1 and saves it.
[0165] After authentication, the client is allowed to conduct normal business communication through the service port. Subsequent client authentication with the gateway can be performed in other ways, such as username / password or digital certificate authentication, which has no impact on this document.
[0166] (1.6.4) Step 3: Situation Detection
[0167] (1) Based on the preset timer, initiate situation collection and calculation. After the predetermined time, send situation collection requests to each sub-module, and send the start time and end time (base time and current time). Each sub-module determines the parameter N based on the start time and end time, and summarizes and sends the detection information within the specified time period.
[0168] The workflow is as follows: 1. A timing period N2 is manually set, where N2 is much larger than N, and the timing is repeated based on N2. 2. After the N2 period is reached, the desktop computer's calculation submodule sends the current time range of N2 (from the last time the calculation was initiated to the current time), and each submodule sends its output data to this module for subsequent calculations. 3. First, calculate the status values of each sub-item, as shown in "(1)-(4)" below. 4. Then, calculate the overall status value according to step "(5)".
[0169] (1) User behavior status calculation
[0170] Considering different types of abnormal behavior, the following formula can be used for calculation:
[0171]
[0172] S U It is the status score output by the user behavior detection module.
[0173] N、 , , Input from the user behavior detection submodule.
[0174] is a weight value, which is an empirical value determined manually.
[0175] (2) Abnormal interaction situation calculation
[0176] In combination with different types of network abnormal interaction, the following formula is used for calculation:
[0177]
[0178] : Output situation score of abnormal interaction determination module.
[0179] , and : Output results of abnormal interaction detection sub-module.
[0180] The following are empirical value parameters determined manually during calculation:
[0181] : Severity of detected abnormal interaction type.
[0182] : Weights of flow volume, time factor and severity, respectively.
[0183] : Exponential factor of flow volume, used to amplify or reduce the influence of flow volume.
[0184] : Special case correction factor in the nth detection, used to adjust the weight of abnormal situation.
[0185] (3) Network topology change situation calculation
[0186]
[0187] : Output situation score of network topology change detection module.
[0188] , , , : Output results of network topology change detection sub-module.
[0189] The following are empirical value parameters determined manually during calculation:
[0190] : Weights of added node, lost node and connection change, respectively.
[0191] : Topology change influence factor.
[0192] : Total amount of topology changes in the current detection period.
[0193] : Maximum expected amount of topology changes.
[0194] (4) Time period trend calculation
[0195]
[0196] : Time period trend score.
[0197] : Timer sub-module output.
[0198] The following are the experience value parameters determined manually during calculation:
[0199] : Maximum risk value, indicating that the risk gradually approaches this value over time.
[0200] : Time influence factor, indicating the rate of risk increase over time.
[0201] (5) Comprehensive situation change degree score calculation
[0202] By combining the scores of each sub-module, the comprehensive situation change degree score is obtained:
[0203]
[0204] : Comprehensive situation score.
[0205] : Score of user behavior detection module.
[0206] : Score of abnormal interaction determination module.
[0207] : Score of network topology change detection module.
[0208] : Score of time period trend detection module.
[0209] : Weight of each frequency division trend score.
[0210] (6) After calculation
[0211] Send the current comprehensive situation change degree to the situation judgment module.
[0212] Resetting the timing period N2.
[0213] (1.6.5) Step 3: Business gateway (situation awareness module) monitors the jump threshold
[0214] The business gateway monitors the network security situation value according to this step after starting. The process of calculating the situation is shown in section 1.5.
[0215] The situation awareness module judges the current jump situation value by analyzing the network topology changes, time period security analysis, user behavior detection, abnormal interaction judgment, and vulnerability management log analysis. The situation value gradually decreases with the decrease of the network topology security score.
[0216] The situation module records the reference time situation, and different business gateways compare the changes of the current time and the initial situation value within a period T according to the set two thresholds.
[0217] When the situation value decreases to threshold_1 and threshold_2, respectively, send a jump request to the jump controller.
[0218] When the security threshold decreases to the first threshold threshold_1: the business gateway judges the existing connection, and each connection sets the interruption threshold according to the importance of the business. If it cannot be interrupted, it responds to the situation awareness module to continue monitoring. If the business gateway responds that it can jump, it enters the jump process.
[0219] When the security threshold decreases to threshold_2: the business gateway interrupts all information transmission and starts the port jump function. At this time, the controller stops sending corresponding end information to the client until the jump ends.
[0220] Considering normalization, intranet target service, importance index, connection customer number, and maximum value, we can design the following formula:
[0221]
[0222] Where: S is the business importance score. N is the number of intranet target services. is the identification value of the th service (based on IP+port). is the importance index of the th service. is the connection customer number of the th service. is the sum of all intranet target service identification values for normalization. denotes taking the maximum value.
[0223] The calculated business importance score SB and the preset service threshold T B to determine whether to perform port hopping.
[0224] (1.6.6) Step 4: Port hopping process
[0225] (1.6.6.1) Step 4.1 Generate hopping strategy
[0226] The gateway generates the hopping strategy: (GN, Gate_Info, effective time T1, chaos_0), (gateway name N1, port hopping information, effective time T1, key2, key0), where T1 is a future determined time point, i.e. the time point when the strategy takes effect and the old strategy is invalid.
[0227] The gateway uses chaos_0 to calculate r2 times using the same chaotic calculation formula to obtain key2, and stores records corresponding to the client in the gateway, and multiple clients are different.
[0228] (1.6.6.2) Step 4.2: Service gateway securely sends port hopping information to client
[0229] The service gateway sends it to the client by encrypting it with key1.
[0230] It includes a random number and an encrypted hopping strategy.
[0231] Encryption method: calculate the number of times of the random number using the chaotic sequence key1.
[0232] Store the random number, and next time hop, calculate the difference between the new and old random numbers, and get the new key.
[0233] It includes a random number, an encrypted strategy, a timestamp, a service name, and a client name.
[0234] The client decrypts and records it.
[0235] key1 is invalid, and key2 is valid.
[0236] (1.6.6.3) Step 4.3: Service gateway sends hopping information to controller
[0237] The service gateway transmits the hopping information to the controller using a secure channel.
[0238] The service gateway records this information and subsequently sends two port hopping information to the new client: running and candidate.
[0239] The information includes: (gateway name N1, port hopping information, effective time T1, chaos_0).
[0240] Controller stores end information: if the effective time has not arrived, set as candidate, and set the timer. If the candidate time arrives, delete running, set candidate as running, and wait for client authentication (as in step 2).
[0241] (1.6.7) Step 5: Synchronization jump is performed
[0242] After the T1 time point of step 4.1 is reached, the service gateway will switch its own end information, and the client will switch the network connection according to the new end jump information determined in step 4.1. The specific switching manner is not particularly limited herein.
[0243] If a client is disconnected or unable to connect with the gateway for any reason, the connection process of steps 1 to 3 needs to be repeated.
[0244] The controller end processes the synchronization information, and if the time set by candidate arrives, the running information is deleted, the current candidate information is set as running, and candidate is empty.
[0245] (1.6.8) Step 6: Situation value reset
[0246] The client and the service gateway clear kk1 and record kk2.
[0247] The situation module in the service gateway: reset the reference value to the initial value, reset the time node of each module. Update and rebuild the baseline model of the network topology to ensure the accuracy of the topology change detection. Reset the parameters and state of each sub-module, initialize the detection environment. Check the reset system to ensure that it is in a normal working state.
[0248] Figure 3 is a structural schematic diagram of a situation-aware network device end jump access system 100 according to an embodiment of the present application.
[0249] Reference Figure 3The network device end hopping access system 100 based on the situational awareness can include a service gateway 110, the service gateway can be configured to generate port knocking information, so that the client 120 communicates with the service gateway 110 based on the port knocking information, the service gateway 110 can be further configured to monitor the comprehensive situational awareness, and determine whether to execute the end information hopping strategy based on the score of the comprehensive situational awareness, wherein the port knocking information at least includes a service IP address, a port knocking sequence, and a service port, the end information at least includes a service IP address, a port knocking sequence, and a service port, the execution of the end information hopping strategy includes changing the end information, and sending the changed end information to the client 120, so that the client 120 switches the communication with the service gateway 110 by using the changed end information.
[0250] As described above, the comprehensive situational awareness can include one or more of user behavior detection, network topology change, time period security analysis, and abnormal interaction determination.
[0251] As described above, sending the changed end information to the client 120 so that the client 120 switches the communication with the service gateway 110 by using the changed end information can include: sending the changed end information to the client 120 by using a key for encryption so that the client 120 switches the communication with the service gateway 110 by using the changed end information, wherein the key is obtained based on the key exchange of the chaotic sequence when the client 120 communicates with the service gateway 110.
[0252] As described above, determining whether to execute the end information hopping strategy based on the score of the comprehensive situational awareness can include: not executing the end information hopping strategy when the score of the comprehensive situational awareness is higher than a first threshold value; executing the end information hopping strategy when the score of the comprehensive situational awareness is lower than the first threshold value but higher than a second threshold value, and the level of the service communication is lower than a predetermined level; and executing the end information hopping strategy when the score of the comprehensive situational awareness is lower than the second threshold value.
[0253] Figure 4 FIG. 1 is a structural schematic diagram of a network device end hopping access system 100 based on situational awareness according to another embodiment of the present application.
[0254] Referring to Figure 4, the network device end hopping access system 100 based on situation awareness can include a client 120, which can be configured to communicate with the service gateway 110 using the port knocking information generated by the service gateway 110, and the client 120 is further configured to perform end hopping when receiving changed end information from the service gateway 110, wherein the port knocking information at least includes a service IP address, a port knocking sequence, and a service port, the end information at least includes a service IP address, a port knocking sequence, and a service port, the changed end information is generated by the service gateway 110 based on the score of the comprehensive situation awareness meeting a predetermined condition, and performing end information hopping includes switching communication with the service gateway 110 using the changed end information.
[0255] As described above, the comprehensive situation awareness can include one or more of user behavior detection, network topology change, time period security analysis, and abnormal interaction determination.
[0256] As described above, performing end hopping when receiving changed end information from the service gateway 110 can include performing end hopping when receiving changed end information sent by the service gateway 110 using encryption based on a key, wherein the key is obtained by the client 120 based on a key exchange using a chaotic sequence when communicating with the service gateway 110.
[0257] As described above, the predetermined condition can include that the score of the comprehensive situation awareness is lower than a first threshold but higher than a second threshold, and the level of service communication is lower than a predetermined level; or the score of the comprehensive situation awareness is lower than the second threshold.
[0258] Figure 5 is a flow chart showing a network device end hopping access method based on situation awareness according to another embodiment of the application.
[0259] Referring to Figure 5 , a network device end hopping access method based on situation awareness is provided, applied to a service gateway 110, which can include: generating port knocking information for a client 120 to communicate with the service gateway 110 based on the port knocking information (S510); and monitoring comprehensive situation awareness, and determining whether to perform an end information hopping strategy based on the score of the comprehensive situation awareness (S530), wherein the port knocking information at least includes a service IP address, a port knocking sequence, and a service port, the end information at least includes a service IP address, a port knocking sequence, and a service port, and performing the end information hopping strategy includes changing the end information and sending the changed end information to the client 120 for the client 120 to switch communication with the service gateway 110 using the changed end information.
[0260] Figure 6is a flow chart showing a situation-awareness-based network device end hop change access method according to another embodiment of the present application.
[0261] With reference to Figure 6 A situation-awareness-based network device end hop change access method is provided, applied to a client 120, which can include: performing service communication with a service gateway 110 by using port knocking information generated by the service gateway 110 (S610); and performing end hop change when changed end information is received from the service gateway 110 (S630), wherein the port knocking information at least includes a service IP address, a port knocking sequence, and a service port, the end information at least includes the service IP address, the port knocking sequence, and the service port, the changed end information is generated by the service gateway 110 based on a score of comprehensive situation awareness meeting a predetermined condition, and performing end information hop change includes switching communication with the service gateway 110 by using the changed end information.
[0262] According to the present application, the awareness direction of each sub-system of situation awareness is optimized, user behavior detection and network topology detection are innovatively added, the awareness of the characteristics of strong concealment and difficulty to find of intelligent agent attacks is improved, and through a double-threshold situation awareness strategy, the business overhead and the influence of business interruption caused by hop change are reduced.
[0263] According to the present application, an optimized chaotic sequence is used as an information transmission mechanism of the entire hop change process, and the randomness of the key is strengthened through the chaotic sequence, so that it is more difficult for an attacker to crack.
[0264] According to the present application, a situation-based security access strategy is provided, and through a situation awareness module, a cloud security service, and a hop change control module, hop change control is performed on a service gateway and a client, so that the problem that hop change information is intercepted when hop change is performed and defense means are ineffective is solved.
[0265] Although various embodiments of the present application have been described with reference to specific details and particular embodiments for purposes of illustration, it will be understood by one of ordinary skill in the art that various alterations, modifications and / or parametric substitutions can be made to the embodiments disclosed or suggested in the present application without departing from the spirit and scope of the present application as defined in the appended claims. In addition, embodiments can be combined to form additional embodiments.
Claims
1. A situational awareness-based network device-side hopping access system, comprising a service gateway, characterized in that, The service gateway is configured to generate port knocking information, so that clients can communicate with the service gateway based on the port knocking information. The service gateway is further configured to monitor comprehensive situational awareness and determine whether to execute the endpoint information switching strategy based on the score of the comprehensive situational awareness. The port knocking information includes at least a service IP address, a port knocking sequence, and a service port. The endpoint information includes at least a service IP address, a port knocking sequence, and a service port. The endpoint information switching strategy includes changing the endpoint information and sending the changed endpoint information to the client, so that the client can use the changed endpoint information to switch communication with the service gateway. The comprehensive situational awareness includes one or more of the following: user behavior detection, network topology change, time-period security analysis, and abnormal interaction determination. Specifically, determining whether to execute the endpoint information switching strategy based on the comprehensive situational awareness score includes: not executing the endpoint information switching strategy if the comprehensive situational awareness score is higher than a first threshold; executing the endpoint information switching strategy if the comprehensive situational awareness score is lower than the first threshold but higher than a second threshold, and the service communication level is lower than a predetermined level; and executing the endpoint information switching strategy if the comprehensive situational awareness score is lower than the second threshold.
2. The network device-side jump access system based on situational awareness according to claim 1, characterized in that, Sending the modified endpoint information to the client so that the client can use the modified endpoint information to switch communication with the service gateway includes: encrypting the modified endpoint information with a key and sending it to the client so that the client can use the modified endpoint information to switch communication with the service gateway, wherein the key is obtained by the client and the service gateway through key exchange based on a chaotic sequence during service communication.
3. A network device-side hopping access system based on situational awareness, comprising a client, characterized in that, The client is configured to use port knocking information generated by the service gateway to communicate with the service gateway. The client is further configured to perform an endpoint transition when it receives the modified endpoint information from the service gateway. The port knocking information includes at least a service IP address, a port knocking sequence, and a service port. The endpoint information includes at least a service IP address, a port knocking sequence, and a service port. The modified endpoint information is generated by the service gateway based on a comprehensive situational awareness score that meets predetermined conditions. Executing endpoint information switching includes using the modified endpoint information to switch communication with the service gateway. The comprehensive situational awareness includes one or more of the following: user behavior detection, network topology change, time-period security analysis, and abnormal interaction determination. The predetermined conditions include: the integrated situational awareness score is lower than a first threshold but higher than a second threshold, and the service communication level is lower than a predetermined level; or the integrated situational awareness score is lower than the second threshold.
4. The network device-side jump access system based on situational awareness according to claim 3, characterized in that, Executing a terminal transition upon receiving modified terminal information from the service gateway includes: executing a terminal transition upon receiving modified terminal information encrypted using a key from the service gateway, wherein the key is obtained by the client and the service gateway through key exchange based on a chaotic sequence during service communication.
5. A network device-side hopping access method based on situational awareness, applied to a service gateway, characterized in that, The method includes: Generate port knocking information so that the client can communicate with the service gateway based on the port knocking information; and Monitor comprehensive situational awareness and determine whether to execute the endpoint information switching strategy based on the score of the comprehensive situational awareness. The port knocking information includes at least a service IP address, a port knocking sequence, and a service port. The endpoint information includes at least a service IP address, a port knocking sequence, and a service port. The endpoint information switching strategy includes changing the endpoint information and sending the changed endpoint information to the client, so that the client can use the changed endpoint information to switch communication with the service gateway. The comprehensive situational awareness includes one or more of the following: user behavior detection, network topology change, time-period security analysis, and abnormal interaction determination. Specifically, determining whether to execute the endpoint information switching strategy based on the comprehensive situational awareness score includes: not executing the endpoint information switching strategy if the comprehensive situational awareness score is higher than a first threshold; executing the endpoint information switching strategy if the comprehensive situational awareness score is lower than the first threshold but higher than a second threshold, and the service communication level is lower than a predetermined level; and executing the endpoint information switching strategy if the comprehensive situational awareness score is lower than the second threshold.
6. A network device-side hopping access method based on situational awareness, applied to a client, characterized in that, The method includes: Utilizing port knocking information generated by the service gateway to conduct service communication with the service gateway; and When the modified endpoint information is received from the service gateway, an endpoint transition is performed. The port knocking information includes at least a service IP address, a port knocking sequence, and a service port. The endpoint information includes at least a service IP address, a port knocking sequence, and a service port. The modified endpoint information is generated by the service gateway based on a comprehensive situational awareness score that meets predetermined conditions. Executing endpoint information switching includes using the modified endpoint information to switch communication with the service gateway. The comprehensive situational awareness includes one or more of the following: user behavior detection, network topology change, time-period security analysis, and abnormal interaction determination. The predetermined conditions include: the integrated situational awareness score is lower than a first threshold but higher than a second threshold, and the service communication level is lower than a predetermined level; or the integrated situational awareness score is lower than the second threshold.
Citation Information
Patent Citations
Netfilter-based address and port hopping communication implementation method
CN104853003A
Address port hopping method of source change mode
CN115996210A