A State Policy Matching Method and Device for Network Encryption Devices
By adopting the state policy matching method in network encryption devices, combining the five-tuple matching policy and the state matching policy, the problem that network encryption devices in the prior art cannot effectively prevent illegal access from TCP is solved, and the security and anti-attackability of network encryption machines are improved.
Patent Information
- Application Number
- CN202411653465.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-18
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2044-11-18
AI Technical Summary
There are limitations in policy matching of existing network encryption devices, which cannot effectively prevent hackers from illegal access to the master station devices through TCP.
A state policy matching method is adopted to combine the five-tuple matching policy and the state matching policy to match network packets. Specific steps include: five-tuple matching processing, status policy matching processing and message status judgment processing.
Improves the security and anti-attackability of network encryption machines in complex network environments, and prevents hackers from causing damage to the main site devices through illegal access.
Smart Images

Figure CN119276613B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network encryption machine IPsec VPN, and specifically relates to a method and device for state policy matching of network encryption devices. Background Art
[0002] In a complex network environment, hackers may use a network terminal with relatively weak security as a springboard to initiate illegal TCP access to the central master station device, causing damage and impact to the master station device.
[0003] Currently, the policy matching of network encryption devices has limitations. If TCP data needs to be encrypted, according to the current IPsec VPN technology, the policy needs to be configured bidirectionally to ensure the normal operation of TCP services (because TCP services are two-way interactions). After configuring the bidirectional policy, the terminal side can initiate a TCP connection to the master station, and using this feature, hackers can scan ports and initiate attacks on the master station.
[0004] Therefore, how to invent a policy matching method to improve the security and anti-attack ability of network encryption machines in a complex network environment has become an urgent problem to be solved. Summary of the Invention
[0005] For this purpose, the present invention provides a method and device for state policy matching of network encryption devices, which can improve the security and anti-attack ability of network encryption machines in a complex network environment.
[0006] To achieve the above object, the present invention provides the following technical solution: A method for state policy matching of network encryption devices, including:
[0007] After the network packet enters the Ipsec processing unit, perform five-tuple matching processing on the network packet through the five-tuple matching policy; if the network packet meets the five-tuple matching policy, perform subsequent state policy matching processing; if the network packet does not meet the five-tuple matching policy, discard the network packet.
[0008] For the network packet that has passed the five-tuple matching processing, perform the state policy matching processing through the state matching policy; if the network packet does not meet the state matching policy, add the node to the state hash fast table and perform subsequent packet state judgment processing.
[0009] Perform the packet state judgment processing on the state of the network packet. If the state of the network packet is incorrect, discard the network packet; if the state of the network packet is correct, perform subsequent operation processing.
[0010] As a preferred solution of a state policy matching method for a network encryption device, during the process of performing five-tuple matching processing on the network packet through the five-tuple matching policy, the steps of the five-tuple matching processing are as follows:
[0011] Perform five-tuple matching on the network packet;
[0012] Compare the direction of the network packet with the direction of the five-tuple matching policy. If the directions are the same, perform subsequent state policy matching processing; if the directions are different, discard the network packet.
[0013] As a preferred solution of a state policy matching method for a network encryption device, during the process of performing state policy matching processing on the network packet through the state matching policy, the steps of the state policy matching processing are as follows:
[0014] Hash the five-tuple of the sent packet; after swapping the five-tuple of the received packet, perform hashing to make the hash values the same;
[0015] Perform the state policy matching processing on the network packet;
[0016] Compare the direction of the network packet with the direction of the state matching policy. If the directions are the same, perform subsequent operation processing; if the directions are different, add the state hash fast table at the node and perform comparison on the packet direction.
[0017] As a preferred solution of a state policy matching method for a network encryption device, during the process of maintaining the state hash fast table, hash the five-tuple of the sent packet; after swapping the five-tuple of the received packet, perform hashing to make the hash values the same; when the total number of hash nodes reaches the upper limit, replace the newly established hash; when a hash node times out, establish a connection cleaning thread to clean the timeout nodes regularly.
[0018] As a preferred solution of a state policy matching method for a network encryption device, the hash node includes source IP, destination IP, source port, destination port, protocol number, timeout time, time, and connection status information.
[0019] The present invention also provides a state policy matching device for a network encryption device. Based on the above state policy matching method for a network encryption device, it includes:
[0020] A five-tuple matching processing module, which is used to perform five-tuple matching processing on the network packet through a five-tuple matching policy after the network packet enters the Ipsec processing unit; if the network packet meets the five-tuple matching policy, subsequent status policy matching processing is performed; if the network packet does not meet the five-tuple matching policy, the network packet is discarded.
[0021] A status policy matching processing module, which is used to perform the status policy matching processing on the network packet that has passed through the five-tuple matching processing through a status matching policy; if the network packet does not meet the status matching policy, it joins the status hash fast table at the node for subsequent packet status judgment processing.
[0022] A packet status judgment processing module, which is used to perform the packet status judgment processing on the status of the network packet. If the status of the network packet is incorrect, the network packet is discarded; if the status of the network packet is correct, subsequent operation processing is performed.
[0023] As a preferred solution for a status policy matching device for a network encryption device, in the five-tuple matching processing module, the five-tuple matching processing sub-module includes:
[0024] A five-tuple matching sub-module, which is used to perform five-tuple matching on the network packet.
[0025] A first sub-module for comparing the direction of the network packet, which is used to compare the direction of the network packet with the direction of the five-tuple matching policy. If the directions are the same, subsequent status policy matching processing is performed; if the directions are different, the network packet is discarded.
[0026] As a preferred solution for a status policy matching device for a network encryption device, in the status policy matching processing module, the status policy matching processing sub-module includes:
[0027] A status hash fast table maintenance sub-module, which is used to perform hashing on the five-tuples of the sent packets; perform hashing on the five-tuples of the received packets after swapping them to make the hash values the same.
[0028] A status policy matching processing sub-module, which is used to perform the status policy matching processing on the network packet.
[0029] A second sub-module for comparing the direction of the network packet, which is used to compare the direction of the network packet with the direction of the status matching policy. If the directions are the same, subsequent operation processing is performed; if the directions are different, it joins the status hash fast table at the node for comparing the packet direction.
[0030] As a preferred solution for a status policy matching device of a network encryption device, in the status policy matching processing module, during the process of maintaining the status hash fast table, the five-tuple of the sent packet is hashed; the five-tuple of the received packet is swapped and then hashed to make the hash values the same; when the total number of hash nodes reaches the upper limit, the newly established hash is replaced; when a hash node times out, a connection cleanup thread is established to periodically clean up the timed-out nodes.
[0031] As a preferred solution for a status policy matching device of a network encryption device, in the status hash fast table maintenance sub-module of the status policy matching processing module, the hash node includes source IP, destination IP, source port, destination port, protocol number, timeout time, time, and connection status information.
[0032] The present invention has the following advantages: After a network packet enters the Ipsec processing unit, the five-tuple matching strategy is used to perform five-tuple matching processing on the network packet; if the network packet meets the five-tuple matching strategy, subsequent status policy matching processing is performed; if the network packet does not meet the five-tuple matching strategy, the network packet is discarded; the steps of the five-tuple matching processing are: performing five-tuple matching on the network packet; comparing the direction of the network packet with the direction of the five-tuple matching strategy, if the directions are the same, subsequent status policy matching processing is performed; if the directions are different, the network packet is discarded. For the network packet that passes through the five-tuple matching processing, the status policy matching processing is performed through the status matching strategy; if the network packet does not meet the status matching strategy, it is added to the status hash fast table at the node for subsequent packet status judgment processing; the steps of the status policy matching processing are: hashing the five-tuple of the sent packet; swapping the five-tuple of the received packet and then hashing to make the hash values the same; performing the status policy matching processing on the network packet; comparing the direction of the network packet with the direction of the status matching strategy, if the directions are the same, subsequent operation processing is performed; if the directions are different, it is added to the status hash fast table at the node for comparing the packet direction. The packet status judgment processing is performed on the status of the network packet, if the status of the network packet is incorrect, the network packet is discarded; if the status of the network packet is correct, subsequent operation processing is performed. The present invention can improve the security and anti-attack ability of the network encryption machine in a complex network environment. Description of the Drawings
[0033] To more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following will briefly introduce the accompanying drawings required for the description of the embodiments or the prior art. Obviously, the accompanying drawings in the following description are only exemplary. For those of ordinary skill in the art, without creative efforts, other implementation drawings can also be obtained based on the provided drawings.
[0034] The structures, ratios, sizes, etc. shown in this specification are only used to cooperate with the content disclosed in the specification for those familiar with this technology to understand and read, and are not used to limit the limiting conditions for the implementation of the present invention. Therefore, they do not have substantial technical significance. Any modification of the structure, change in the proportional relationship, or adjustment of the size, without affecting the effects that the present invention can produce and the purposes that can be achieved, should still fall within the scope covered by the technical content disclosed in the present invention.
[0035] Figure 1 It is a schematic flow chart of a method for state policy matching of a network encryption device provided in Embodiment 1 of the present invention;
[0036] Figure 2 It is a schematic processing flow chart of the IPsec function module in a method for state policy matching of a network encryption device provided in Embodiment 1 of the present invention;
[0037] Figure 3 It is a schematic diagram of the state hash table in a method for state policy matching of a network encryption device provided in Embodiment 1 of the present invention;
[0038] Figure 4 It is a schematic processing flow chart when the total number of hash nodes reaches the upper limit in a method for state policy matching of a network encryption device provided in Embodiment 1 of the present invention;
[0039] Figure 5 It is a schematic processing flow chart for hash node timeout in a method for state policy matching of a network encryption device provided in Embodiment 1 of the present invention;
[0040] Figure 6 It is a schematic diagram of the jump between TCP packet states in a possible embodiment provided in Embodiment 1 of the present invention;
[0041] Figure 7 It is a schematic diagram of the jump between simplified TCP packet states in a possible embodiment provided in Embodiment 1 of the present invention;
[0042] Figure 8 It is a schematic processing flow chart of TCP packets in a possible embodiment provided in Embodiment 1 of the present invention;
[0043] Figure 9Schematic diagram of the UDP packet connection status conversion process in a possible embodiment provided in Embodiment 1 of the present invention;
[0044] Figure 10 Schematic diagram of the ICMP packet connection status conversion process in a possible embodiment provided in Embodiment 1 of the present invention;
[0045] Figure 11 Schematic diagram of the architecture of a status policy matching device for a network encryption device provided in Embodiment 2 of the present invention. Detailed implementation manners
[0046] The following specific embodiments illustrate the implementation manners of the present invention. Those skilled in the art can easily understand other advantages and effects of the present invention from the content disclosed in this specification. Obviously, the described embodiments are part of the embodiments of the present invention, rather than all of them. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0047] Embodiment 1
[0048] See Figure 1 and Figure 2 Embodiment 1 of the present invention provides a full - disk encryption storage method that is transparent to the upper layer, including the following steps:
[0049] S1. After the network packet enters the Ipsec processing unit, perform five - tuple matching processing on the network packet through the five - tuple matching policy; if the network packet meets the five - tuple matching policy, perform subsequent status policy matching processing; if the network packet does not meet the five - tuple matching policy, discard the network packet;
[0050] S2. For the network packet that has passed the five - tuple matching processing, perform the status policy matching processing through the status matching policy; if the network packet does not meet the status matching policy, add the node to the status hash fast table and perform subsequent packet status judgment processing;
[0051] S3. Perform the packet status judgment processing on the status of the network packet. If the status of the network packet is incorrect, discard the network packet; if the status of the network packet is correct, perform subsequent operation processing.
[0052] In this embodiment, the network packets are of three types: TCP, ICMP, and UDP. The detailed design and processing flow of the three - type packet protocols are as follows:
[0053] I. TCP
[0054] a1) Control the direction of actively initiating a connection, and only allow TCP connections specified in the policy;
[0055] b1) Track the link state. The link establishment message should conform to the three-way handshake process, and the link release message should conform to the four-way handshake process. Only TCP data messages that conform to the policy after the three-way handshake and before the four-way handshake are allowed to pass;
[0056] c1) The link release timeout can be configured, and the minimum value should be ≥ 300 seconds;
[0057] d1) Intercept the message and generate an alarm after receiving a data packet that does not conform to the link connection state.
[0058] When situations such as connection not established, connection timed out and disconnected, four-way handshake connection disconnected, RST disconnected occur, when TCP receives a data packet (PUSH packet), the state is abnormal. For the first three abnormal data packets, the device replies with RST to the source address of the abnormal data packet, and no more RST is replied to subsequent abnormal data packets; the connection release session time can be configured, and the default value is 30 min.
[0059] II. UDP
[0060] a2) Control the connection direction according to the first message and confirm the tracking of the link state;
[0061] b2) The link release timeout can be configured, and the minimum value should be ≥ 180 seconds;
[0062] c2) Disconnect the connection and generate an alarm after detecting an abnormal link state.
[0063] III. ICMP
[0064] a3) The policy only allows message types of Echo request and Echo Reply to pass;
[0065] b3) Control the connection direction according to the direction of the request message;
[0066] c3) ICMP error message: Discard and alarm, and the alarm log should include the type, code of the error message and the source and destination IPs, source and destination ports, and protocol type of the faulty IP datagram;
[0067] d3) The link release timeout can be configured, and the minimum value should be ≥ 30 seconds;
[0068] e3) Disconnect the connection and generate an alarm after detecting an abnormal link state.
[0069] Therefore, the core of the state-based policy matching function can be divided into two parts: one is the state transition and maintenance of TCP, UDP, and ICMP message types; the other is the timeout processing mechanism for each connection.
[0070] In this embodiment, in step S1, after the network packet enters the Ipsec processing unit, the five-tuple matching strategy is used to perform five-tuple matching processing on the network packet; if the network packet meets the five-tuple matching strategy, subsequent state strategy matching processing is performed; if the network packet does not meet the five-tuple matching strategy, the network packet is discarded.
[0071] Specifically, during the processing in the IPsec unit, the state strategy matching is placed after the five-tuple strategy matching. When the packet meets the five-tuple strategy, the state strategy matching is performed.
[0072] Among them, the steps of the five-tuple matching processing are as follows:
[0073] S11. Perform five-tuple matching on the network packet;
[0074] S12. Compare the direction of the network packet with the direction of the five-tuple matching strategy. If the directions are the same, subsequent state strategy matching processing is performed; if the directions are different, the network packet is discarded.
[0075] In this embodiment, in step S2, for the network packet that has passed the five-tuple matching processing, the state strategy matching processing is performed through the state matching strategy; if the network packet does not meet the state matching strategy, it is added to the state hash fast table at the node for subsequent packet state judgment processing.
[0076] Specifically, ICMP and TCP services are strongly related to the direction during the state matching process. In the process of processing the state function, the relationship between the packet direction and the five-tuple strategy direction is required: after the five-tuple strategy function module completes the strategy matching function, it returns the comparison value of the packet direction and the strategy direction. All processing related to the connection state is completed by the state strategy matching function module, and there is coupling in their calls.
[0077] To ensure that the same connection is maintained on one node, the five-tuples of the sent packets are hashed, and the five-tuples of the received packets are hashed after being swapped to make the hash values the same.
[0078] Among them, the steps of the state strategy matching processing are as follows:
[0079] S21. Hash the five-tuples of the sent packets; hash the five-tuples of the received packets after being swapped to make the hash values the same;
[0080] S22. Perform the state strategy matching processing on the network packet;
[0081] S23. Compare the direction of the network packet with the direction of the status matching policy. If the directions are the same, perform subsequent operation processing; if the directions are different, add the node to the status hash fast table and compare the packet directions.
[0082] In this embodiment, the status hash fast table is composed of a linked list array designed according to the support of 2048 tunnels by IPsecVPN. The array has a total of 2048 elements, that is, 0 - 2047 are hash values. When there are hash value conflicts for different connections, a linked list operation is performed at the node. The structure is as Figure 3 shown. To ensure that the same connection is maintained on one node, hash the five-tuple of the sent packet and hash the five-tuple of the received packet after swapping, so that the hash values are the same.
[0083] Among them, a connection node includes information such as source IP, destination IP, source port, destination port, protocol number, timeout time, time, and connection status.
[0084] To ensure the controllability of the hash nodes and avoid memory leaks, control the total number of hash nodes. When the total number of hash nodes reaches the upper limit, replace the newly established hash. The specific process is as Figure 4 shown.
[0085] When a hash node times out, establish a connection cleanup thread to periodically clean up the timed-out nodes. The specific process is as Figure 5 shown.
[0086] In this embodiment, in step S3, perform the packet status judgment process on the status of the network packet. If the status of the network packet is incorrect, discard the network packet; if the status of the network packet is correct, perform subsequent operation processing.
[0087] In a possible embodiment, the TCP packet status matching mechanism is as follows:
[0088] There are 6 TCP packet flags, namely: URG, PSH, ACK, RST, SYN, FIN. Among them, URG (urgent pointer field is valid) and PSH (Push operation) have no impact on the TCP connection status. Therefore, during the state transition process, only the four types of packets ACK, RST, SYN, and FIN need to be subjected to state transition.
[0089] In a TCP connection, the port numbers are different between different services. Therefore, there is only one connection on each node.
[0090] There are 11 state transitions involved in a TCP connection. Specifically, as Figure 6 shown.
[0091] Among them, there are 11 TCP states in total. The explanations of the various states, events, and transition processes for Figure 6 are as shown in
[0092] Table 1:
[0093]
[0094] Table 1 State Explanation
[0095] During the implementation process, the TCP state machine can be simplified, and only the TCP connection establishment and TCP disconnection processes are strictly judged. According to the TCP state machine, it is simplified, and the simplification rules are as follows:
[0096] a4) The CLOSED and LISTEN states are simplified to the disconnected state;
[0097] b4) SYN-SENT is the first state during connection, and SYN-RECEIVED is the second state during connection;
[0098] c4) ESTABLISHED is the connected state;
[0099] d4) Since two FINs and two ACKs are required in the TCP disconnection phase, the disconnection processes of CLOSE-WAIT, LAST-ACK, FIN-WAIT-1, FIN-WAIT-2, CLOSING, and TIME-WAIT can be simplified to the first state during disconnection and the second state during disconnection;
[0100] After simplification, the TCP transition states are 6 states, as shown in Figure 7 shown.
[0101] As shown in Figure 8 shown, the processing flow of TCP packets is as follows:
[0102] M1. Perform a state hash fast table match. If the match is successful, perform node state judgment; if the match fails, add the node to the state hash fast table;
[0103] M2. Judge the node state. If the node is in the disconnected state, perform SYN packet and direction judgment processing; if the node is in the connected state, the state machine jumps, and then subsequent processing is performed;
[0104] M3. Perform SYN packet and direction judgment processing. If the direction is correct, jump to the first state during connection; if the direction is incorrect, maintain the disconnected state and discard the packet;
[0105] M4. After completing the jump to the first state during connection, after forwarding the packet, update the timeout time and perform subsequent processing;
[0106] M5. After remaining in the disconnected state and discarding the message, the node determines the number of times it sends an RST message. If the number of transmissions ≤ 3, it sends an RST message and proceeds with subsequent processing; if the number of transmissions > 3, it directly proceeds with subsequent processing.
[0107] In a possible embodiment, the UDP message status matching mechanism is as follows:
[0108] The connection status of UDP messages does not distinguish between directions and can be divided into two states, DISCONNECT and CONNECTED, for conversion. The UDP messages in the outgoing and incoming directions record their status in a hash node.
[0109] Status rule: When the device receives the first UDP message that conforms to the five-tuple policy and has the correct direction, the UDP connection corresponding to this five-tuple becomes the connected state until it times out and the node is deleted after disconnection.
[0110] As Figure 9 shown, the connection status conversion process of TCP messages is as follows:
[0111] N1. Perform a status hash fast table match. If the match is successful, perform a node status judgment; if the match fails, add the node to the status hash fast table.
[0112] N2. Judge the node status. If the node is in the connected state, update the timeout time and proceed with subsequent processing; if the node is in the disconnected state, perform a message direction judgment process.
[0113] N3. Perform a message direction judgment process. If the direction is correct, set it to the connected state, update the timeout time, and proceed with subsequent processing; if the direction is incorrect, set it to the disconnected state and discard the message.
[0114] In a possible embodiment, the ICMP message status matching mechanism is as follows:
[0115] The ICMP message only processes the status of two types of messages, REQUEST messages and REPLY messages, and discards the rest of the message types. Because the ping service has directionality, the ICMP message is divided into two connections, the outgoing direction (OUT) and the incoming direction (IN), with the REQUEST message as the standard. Since the ICMP message has no port, the two connections are maintained using two status bits in one hash node of the status hash table.
[0116] Status Rule: REQUEST Message Processing: The received REQUEST messages are matched for status according to the direction. If the direction is correct, it changes to the connected state; if the direction is incorrect, it changes to the disconnected state. REPLY Message Processing: In the connected state, when a REPLY message with the correct receiving direction is received, it is considered that the service process has ended, and the connected state is set to the disconnected state. In the disconnected state, all REPLY messages are discarded. The REQUEST messages and REPLY messages correspond one by one. As Figure 10 shown, the connection state transition process of the ICMP message is as follows:
[0117] T1. Perform status hash fast table matching. If the matching is successful, perform message classification; if the matching fails, add the node to the status hash fast table and then perform message classification;
[0118] T2. Perform message classification processing to classify the messages into REQUEST messages and REPLY messages;
[0119] T31. Judge and process the direction of the REQUEST message. If the direction is correct, set it to the connected state, update the timeout time, and perform subsequent processing; if the direction is incorrect, set it to the disconnected state and discard the message;
[0120] T32. Judge the connection state of the REPLY message node. If it is in the connected state, set it to the disconnected state, update the timeout time, and perform subsequent processing; if it is in the disconnected state, update the timeout time and discard the message.
[0121] In summary, after the network packet of the present invention enters the Ipsec processing unit, the five-tuple matching strategy is used to perform five-tuple matching processing on the network packet; if the network packet meets the five-tuple matching strategy, subsequent state strategy matching processing is performed; if the network packet does not meet the five-tuple matching strategy, the network packet is discarded; the steps of the five-tuple matching processing are: performing five-tuple matching on the network packet; comparing the direction of the network packet with the direction of the five-tuple matching strategy, if the directions are the same, subsequent state strategy matching processing is performed; if the directions are different, the network packet is discarded. For the network packet that passes through the five-tuple matching processing, the state strategy matching processing is performed through the state matching strategy; if the network packet does not meet the state matching strategy, it is added to the state hash fast table at the node for subsequent packet state judgment processing; the steps of the state strategy matching processing are: hashing the five-tuple of the sent packet; hashing the five-tuple of the received packet after swapping to make the hash values the same; performing the state strategy matching processing on the network packet; comparing the direction of the network packet with the direction of the state matching strategy, if the directions are the same, subsequent operation processing is performed; if the directions are different, it is added to the state hash fast table at the node for comparing the packet directions. The packet state judgment processing is performed on the state of the network packet, if the state of the network packet is incorrect, the network packet is discarded; if the state of the network packet is correct, subsequent operation processing is performed. The present invention can improve the security and anti-attack ability of the network encryption machine in a complex network environment.
[0122] It should be noted that the method of the embodiments of the present disclosure can be executed by a single device, such as a computer or a server. The method of this embodiment can also be applied to a distributed scenario, and multiple devices cooperate with each other to complete it. In this case of a distributed scenario, one of the multiple devices can only execute one or more steps of the method of the embodiments of the present disclosure, and these multiple devices will interact with each other to complete the described method.
[0123] It should be noted that some embodiments of the present disclosure have been described above. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims can be executed in a different order than in the above embodiments and still achieve the desired results. Additionally, the processes depicted in the figures do not necessarily require the specific order or sequential order shown to achieve the desired results. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0124] Embodiment 2
[0125] See Figure 11, Embodiment 2 of the present invention further provides a status policy matching device for a network encryption device, including:
[0126] A five-tuple matching processing module 001, configured to perform five-tuple matching processing on the network packet through a five-tuple matching policy after the network packet enters the Ipsec processing unit; if the network packet meets the five-tuple matching policy, subsequent status policy matching processing is performed; if the network packet does not meet the five-tuple matching policy, the network packet is discarded;
[0127] A status policy matching processing module 002, configured to perform the status policy matching processing on the network packet that has passed through the five-tuple matching processing through a status matching policy; if the network packet does not meet the status matching policy, it joins the status hash fast table at the node for subsequent packet status judgment processing;
[0128] A packet status judgment processing module 003, configured to perform the packet status judgment processing on the status of the network packet. If the status of the network packet is incorrect, the network packet is discarded; if the status of the network packet is correct, subsequent operation processing is performed.
[0129] In this embodiment, in the five-tuple matching processing module 001, the five-tuple matching processing sub-module includes:
[0130] A five-tuple matching sub-module 011, configured to perform five-tuple matching on the network packet;
[0131] A first sub-module 012 for comparing the direction of the network packet with the direction of the five-tuple matching policy. If the directions are the same, subsequent status policy matching processing is performed; if the directions are different, the network packet is discarded.
[0132] In this embodiment, in the status policy matching processing module 002, the status policy matching processing sub-module includes:
[0133] A status hash fast table maintenance sub-module 021, configured to hash the five-tuple of the sent packet; hash the five-tuple of the received packet after swapping to make the hash values the same;
[0134] A status policy matching processing sub-module 022, configured to perform the status policy matching processing on the network packet;
[0135] A second sub-module 023 for comparing the direction of the network packet with the direction of the status matching policy. If the directions are the same, subsequent operation processing is performed; if the directions are different, it joins the status hash fast table at the node for comparing the packet direction.
[0136] In this embodiment, in the status policy matching processing module 002, during the process of maintaining the status hash fast table, the five-tuple of the sent packet is hashed; the five-tuple of the received packet is swapped and then hashed to make the hash values the same; when the total number of hash nodes reaches the upper limit, the newly established hash is replaced; when a hash node times out, a connection cleaning thread is established to clean the timeout nodes regularly.
[0137] In this embodiment, in the status hash fast table maintenance sub-module 021 of the status policy matching processing module 002, the hash node includes source IP, destination IP, source port, destination port, protocol number, timeout time, time, and connection status information.
[0138] It should be noted that for the information interaction, execution process, etc. between the above system modules, since they are based on the same concept as the method embodiment in Embodiment 1 of this application, the technical effects brought by them are the same as those of the method embodiment of this application. For specific content, reference can be made to the description in the method embodiment shown above in this application, and details will not be repeated here.
[0139] Embodiment 3
[0140] Embodiment 3 of the present invention provides a non-transitory computer-readable storage medium, in which a program code for a status policy matching method for a network encryption device is stored, and the program code includes instructions for executing a status policy matching method for a network encryption device in Embodiment 1 or any possible implementation manner thereof.
[0141] The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or a data center integrating one or more available media. The available medium can be a magnetic medium (for example, a floppy disk, a hard disk, a magnetic tape), an optical medium (for example, a DVD), or a semiconductor medium (for example, a solid-state drive (SSD)).
[0142] Embodiment 4
[0143] Embodiment 4 of the present invention provides an electronic device, including: a memory and a processor;
[0144] The processor and the memory communicate with each other through a bus; the memory stores program instructions executable by the processor, and the processor can execute a status policy matching method for a network encryption device in Embodiment 1 or any possible implementation manner thereof by calling the program instructions.
[0145] Specifically, the processor can be implemented by hardware or software. When implemented by hardware, the processor can be a logic circuit, an integrated circuit, etc.; when implemented by software, the processor can be a general-purpose processor that is realized by reading software code stored in a memory. The memory can be integrated in the processor or can exist independently outside the processor.
[0146] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions described in the embodiments of the present invention are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable systems. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center by wire (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (such as infrared, wireless, microwave, etc.).
[0147] Obviously, those skilled in the art should understand that the above-mentioned modules or steps of the present invention can be implemented by a general computing system. They can be concentrated on a single computing system or distributed on a network composed of multiple computing systems. Optionally, they can be implemented by program code executable by the computing system. Thus, they can be stored in a storage system and executed by the computing system. And in some cases, the steps shown or described can be executed in a different order than here, or they can be made into individual integrated circuit modules respectively, or multiple modules or steps among them can be made into a single integrated circuit module to be realized. In this way, the present invention is not limited to any specific combination of hardware and software.
[0148] Although the present invention has been described in detail above with general descriptions and specific embodiments, based on the present invention, some modifications or improvements can be made, which are obvious to those skilled in the art. Therefore, these modifications or improvements made without departing from the spirit of the present invention all fall within the scope of protection required by the present invention.
Claims
1. A state policy matching method for a network encryption device, characterized in that: include: After the network message enters the IPsec processing unit, the network message is subjected to five-tuple matching processing through the five-tuple matching strategy; If the network message satisfies the five-tuple matching strategy, subsequent state strategy matching processing is performed; if the network message does not satisfy the five-tuple matching strategy, the network message is discarded; The network message processed by the five-tuple matching is subjected to the state policy matching process by the state matching policy, and the state policy matching process step includes: Hash the five-tuple of the outgoing message and swap the five-tuple of the received message and hash them so that the hash values are the same; Perform the state policy matching process on the network message; compare the direction of the network message with the state matching policy direction, if the directions are consistent, perform subsequent message state judgment process; if the directions are inconsistent, add the state hash table to the hash node, and perform subsequent message state judgment process; The state hash table is composed of a linked list array; The hash node includes source IP, destination IP, source port, destination port, protocol number, timeout, time, and connection status; The network message status is judged and processed. If the network message status is incorrect, the network message is discarded; if the network message status is correct, subsequent operation processing is performed.
2. A state policy matching method for a network encryption device according to claim 1, characterized in that: In the process of maintaining the status hash table, the five-tuple of the sent message is hashed; the five-tuple of the received message is swapped and hashed to make the hash value the same; when the total number of hash nodes reaches the upper limit, the newly established hash is replaced; when the hash node times out, a connection cleanup thread is established to regularly clean up the timed out hash nodes.
3. A state policy matching device for a network encryption device, using a state policy matching method for a network encryption device according to any one of claims 1 to 2, characterized in that: include: A five-tuple matching processing module, used for performing five-tuple matching processing on the network message through the five-tuple matching strategy after the network message enters the IPsec processing unit; If the network message satisfies the five-tuple matching strategy, subsequent state strategy matching processing is performed; if the network message does not satisfy the five-tuple matching strategy, the network message is discarded; The state policy matching processing module is used to perform the state policy matching processing on the network message processed by the five-tuple matching through the state matching strategy, and the state policy matching processing steps include: hashing the five-tuple of the sent message, swapping the five-tuple of the received message and hashing them so that the hash values are the same; performing the state policy matching processing on the network message; comparing the direction of the network message with the direction of the state matching strategy, and if the directions are consistent, performing subsequent message state judgment processing; if the directions are inconsistent, adding a state hash table to the hash node, and performing subsequent message state judgment processing; the state hash table is composed of a linked list array, and the hash node includes the source IP, destination IP, source port, destination port, protocol number, timeout, time and connection status; The message status judgment processing module is used to perform the message status judgment processing on the status of the network message. If the status of the network message is incorrect, the network message is discarded; if the status of the network message is correct, subsequent operation processing is performed.
4. A state strategy matching device for a network encryption device according to claim 3, characterized in that: The five-tuple matching processing module includes: A five-tuple matching submodule, used for performing five-tuple matching on the network message; The first submodule of message direction comparison processing is used to compare the network message direction with the five-tuple matching strategy direction. If the directions are consistent, subsequent state strategy matching processing is performed; if the directions are inconsistent, the network message is discarded.
5. A state strategy matching device for a network encryption device according to claim 4, characterized in that: The state strategy matching processing module includes: The state hash table maintenance submodule is used to hash the five-tuple of the sent message; the five-tuple of the received message is swapped and hashed to make the hash values the same; A state policy matching processing submodule, used for performing the state policy matching processing on the network message; The second submodule of message direction comparison processing is used to compare the network message direction with the state matching strategy direction. If the directions are consistent, subsequent message state judgment processing is performed; if the directions are inconsistent, the state hash table is added to the node for subsequent message state judgment processing.
6. A state strategy matching device for a network encryption device according to claim 5, characterized in that: In the state strategy matching processing module, in the process of maintaining the state hash table, the five-tuple of the sent message is hashed; the five-tuple of the received message is swapped and hashed to make the hash value the same; when the total number of hash nodes reaches the upper limit, the newly established hash is replaced; when the hash node times out, a connection cleanup thread is established to regularly clean up the timed out hash nodes.
7. A state strategy matching device for a network encryption device according to claim 6, characterized in that: In the state hash table maintenance submodule of the state policy matching processing module, the hash node includes source IP, destination IP, source port, destination port, protocol number, timeout, time and connection status information.
Citation Information
Patent Citations
Method and device for filtering IP (Internet Protocol) message
CN102932377A
Systems and methods for detection for prioritizing and scheduling packets in a communication network
CN103650440A