Terminal active external connection protection method, device, equipment, medium and program product

By obtaining malicious link information and modifying the host table or routing table of internal network terminals, compromised terminals can be located and isolated. This solves the problem of insufficient traceability and blocking capabilities when enterprise internal network terminals actively go out of the network, and achieves rapid response and protection against malicious addresses.

CN119316168BActive Publication Date: 2025-12-16INDUSTRIAL AND COMMERCIAL BANK OF CHINA
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202311100343.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-08-29
Publication Date
2025-12-16
Estimated Expiration
2043-08-29

Smart Images

  • Figure CN119316168B_ABST
    Figure CN119316168B_ABST
Patent Text Reader

Abstract

The present disclosure provides a protection method for terminal active external connection, relates to the technical field of network security and the field of information security, and can be applied to the field of financial technology. The method comprises the following steps: in response to alarm information of a terminal active external connection behavior, obtaining malicious link information; setting up an internal network server start request monitoring according to the malicious link information; modifying a host table or a routing table of all terminals in batches according to the malicious link information and internal network monitoring address information; positioning a compromised terminal according to monitored request information; and isolating and protecting the compromised terminal based on a stage of the compromised terminal active external connection behavior. The present disclosure also provides a protection device, equipment, storage medium and program product for terminal active external connection.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present disclosure relates to the technical field of information security, in particular to the technical field of network security, and more particularly to a terminal active external connection protection method, device, equipment, medium and program product. BACKGROUND

[0002] Due to the demand for interconnection and data exchange with third-party payment platforms, suppliers and the like, the enterprise's own Internet security policy usually only restricts access to the network but does not restrict access to the network, and does not restrict the active external connection of intranet terminal devices. When the terminal and server are attacked (e.g., phishing) by a Trojan horse, the related art lacks the ability to trace and block the compromised terminal in a timely manner. Therefore, how to improve the ability of enterprises to prevent malicious addresses from actively connecting to the intranet terminal has become a technical problem to be solved.

[0003] It should be noted that the information disclosed in the above background section is only used to strengthen the understanding of the background of the present disclosure, and therefore can include information that does not constitute prior art known to those of ordinary skill in the art. SUMMARY

[0004] In view of the above problems, the present disclosure provides a terminal active external connection protection method, device, equipment, medium and program product.

[0005] According to a first aspect of the present disclosure, a terminal active external connection protection method is provided, the method comprising:

[0006] in response to the alarm information of the terminal active external connection behavior, obtaining malicious link information;

[0007] setting up an intranet server start request monitoring according to the malicious link information;

[0008] batch modifying the host table or routing table of all terminals according to the malicious link information and intranet monitoring address information;

[0009] locating the compromised terminal according to the monitored request information; and

[0010] isolating and protecting the compromised terminal based on the active external connection behavior stage of the compromised terminal.

[0011] According to an embodiment of the present disclosure, the batch modification of the host table or routing table of the terminal according to the malicious link information and the intranet monitoring address information comprises:

[0012] if it is determined that the malicious link is a domain name, then batch modifying the local host table of the terminal according to the intranet monitoring address information;

[0013] If the malicious link is determined to be an Internet Protocol address, the local routing table of the terminal is modified in batches according to the internal network monitoring address information.

[0014] According to an embodiment of the present disclosure, the request information includes request initiation time, source IP address and port information, and the positioning of the compromised terminal according to the monitored request information includes:

[0015] The physical address of the compromised host is queried from a terminal management platform according to the source IP address.

[0016] According to an embodiment of the present disclosure, the positioning of the compromised terminal according to the monitored request information further includes:

[0017] The physical address corresponding to the source IP address is found by calling a Dynamic Host Configuration Protocol table.

[0018] According to an embodiment of the present disclosure, the isolation and protection of the compromised terminal based on the active external connection behavior stage of the compromised terminal includes:

[0019] The active external connection behavior stage of the compromised terminal is determined according to the alarm information of the terminal active external connection behavior.

[0020] If the active external connection behavior of the compromised terminal is determined to be in the domain name resolution recursion stage, the host table or the routing table of all terminals is modified in batches according to the malicious link type; and

[0021] If the active external connection behavior of the compromised terminal is determined to be in the connection establishment stage with the malicious link, the host table and / or the routing table of the compromised terminal is modified and the connection of the source port is reset.

[0022] According to an embodiment of the present disclosure, the determination of the active external connection behavior stage of the compromised terminal according to the alarm information of the terminal active external connection behavior includes:

[0023] If the compromised terminal IP port information is not contained in the alarm information, it is determined that the active external connection behavior of the compromised terminal is in the domain name resolution recursion stage; and

[0024] If the compromised terminal IP port information is contained in the alarm information, it is determined that the active external connection behavior of the compromised terminal is in the connection establishment stage with the malicious link.

[0025] According to an embodiment of the present disclosure, the method further includes:

[0026] When the requests from the same host exceed a preset threshold, the host is isolated from the network.

[0027] A second aspect of the present disclosure provides a terminal active external connection protection device, the device includes:

[0028] The acquisition module is configured to acquire malicious link information in response to the alarm information of the terminal active external connection behavior.

[0029] The monitoring module is configured to set up an internal network server start request monitoring according to the malicious link information.

[0030] The modification module is configured to modify a host table or a routing table of all terminals in batches according to the malicious link information and the internal network monitoring address information.

[0031] The compromised terminal positioning module is configured to position the compromised terminal according to the monitored request information.

[0032] The protection module is configured to isolate and protect the compromised terminal based on a stage of the compromised terminal active external connection behavior.

[0033] According to an embodiment of the present disclosure, the modification module comprises a first modification submodule and a second modification submodule.

[0034] The first modification submodule is configured to modify a terminal local host table in batches according to the internal network monitoring address information if it is determined that the malicious link is a domain name.

[0035] The second modification submodule is configured to modify a terminal local routing table in batches according to the internal network monitoring address information if it is determined that the malicious link is an Internet Protocol address.

[0036] According to an embodiment of the present disclosure, the compromised terminal positioning module comprises a first positioning submodule and a second positioning submodule.

[0037] The first positioning submodule is configured to query a physical address of a compromised host to a terminal management platform according to a source IP address.

[0038] The second positioning submodule is configured to find a physical address corresponding to the source IP address by calling a dynamic host configuration protocol table.

[0039] According to an embodiment of the present disclosure, the protection module comprises a first isolation and protection submodule and a second isolation and protection submodule.

[0040] The first isolation and protection submodule is configured to modify a host table or a routing table of all terminals in batches according to a malicious link type if it is determined that the compromised terminal active external connection behavior is in a domain name resolution recursion stage.

[0041] The second isolation and protection submodule is configured to modify a host table and / or a routing table of a compromised terminal and reset a source port connection if it is determined that the compromised terminal active external connection behavior is in a stage of establishing a connection with a malicious link.

[0042] According to an embodiment of the present disclosure, further comprising a network disconnecting and isolating module.

[0043] The network isolation module is configured to isolate a host from a network when a request from the host exceeds a preset threshold.

[0044] A third aspect of the present disclosure provides an electronic device, comprising: one or more processors; a memory for storing one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors execute the above-mentioned terminal active external connection protection method.

[0045] A fourth aspect of the present disclosure further provides a computer-readable storage medium having stored executable instructions, which, when executed by a processor, cause the processor to execute the above-mentioned terminal active external connection protection method.

[0046] A fifth aspect of the present disclosure further provides a computer program product comprising a computer program, which, when executed by a processor, implements the above-mentioned terminal active external connection protection method.

[0047] The terminal active external connection protection method provided by the embodiments of the present disclosure comprises the following steps: when receiving alarm information of a terminal active external connection behavior, obtaining malicious link information, starting request monitoring and returning an internal network monitoring address, and batch modifying a host table or a routing table of all terminals according to the malicious link type and the internal network monitoring address information, so as to realize monitoring of the terminal active external connection malicious link; positioning a compromised terminal according to the request information of the compromised terminal, and isolating and protecting the compromised terminal based on a stage of the compromised terminal active external connection behavior. Compared with the related art, the terminal active external connection protection method provided by the embodiments of the present disclosure can make the terminal active external connection IP behavior directly jump to an internal monitoring device address, form effective blocking, and quickly locate the detailed information of the compromised host. BRIEF DESCRIPTION OF DRAWINGS

[0048] The above and other objects, features and advantages of the present disclosure will become more apparent from the following description of embodiments of the present disclosure, taken in conjunction with the accompanying drawings, in which:

[0049] Figure 1 A system architecture diagram of a terminal active external connection protection device according to an embodiment of the present disclosure is schematically shown;

[0050] Figure 2 An application scenario diagram of a terminal active external connection protection method, device, equipment, medium and program product according to an embodiment of the present disclosure is schematically shown;

[0051] Figure 3 A flowchart of a terminal active external connection protection method according to an embodiment of the present disclosure is schematically shown;

[0052] Figure 4A flowchart of a method for protecting a terminal from active external connection according to another embodiment of the present disclosure is schematically shown;

[0053] Figure 5 A flowchart of a method for positioning a compromised terminal according to yet another embodiment of the present disclosure is schematically shown;

[0054] Figure 6 A flowchart of a method for isolating a compromised terminal according to yet another embodiment of the present disclosure is schematically shown;

[0055] Figure 7 A block diagram of a device for protecting a terminal from active external connection according to an embodiment of the present disclosure is schematically shown; and

[0056] Figure 8 A block diagram of an electronic device suitable for implementing a method for protecting a terminal from active external connection according to an embodiment of the present disclosure is schematically shown. DETAILED DESCRIPTION

[0057] Hereinafter, embodiments of the present disclosure will be described with reference to the accompanying drawings. It should be understood, however, that the description which follows is merely illustrative and is not intended to limit the scope of the present disclosure. In the following detailed description of embodiments of the present disclosure, numerous specific details are set forth in order to provide a thorough understanding of the embodiments of the present disclosure. However, it would be apparent to one skilled in the art that the embodiments of the present disclosure can be practiced without these specific details. In other instances, well-known structures and functions have not been described in detail in order to avoid obscuring aspects of the present disclosure.

[0058] The terms used herein are merely used to describe specific embodiments and are not intended to limit the present disclosure. The terms "include" and "have" and the like used herein indicate the presence of the described features, steps, operations, and / or components but do not preclude the presence or addition of one or more other features, steps, operations, or components.

[0059] All terms used herein, including technical and scientific terms, have the same meanings as those generally understood by those skilled in the art unless otherwise defined. It should be noted that the terms used herein should be interpreted as having meanings that are consistent with the context of the present description, and should not be interpreted in an idealized or excessively formal manner.

[0060] In the case of using expressions similar to "at least one of A, B, and C, etc.", it should generally be interpreted to include at least one of each item enumerated, unless otherwise defined. For example, "a system having at least one of A, B, and C" should be interpreted to include a system having at least one of A, a system having at least one of B, a system having at least one of C, a system having at least one of A and B, a system having at least one of A and C, a system having at least one of B and C, and / or a system having at least one of A, B, and C, etc.

[0061] In the related art, for the behavior of terminal and server being attacked (for example, phishing) by a Trojan and actively external connection, the following two steps are usually divided: the terminal in the internal network returns the IP address of the malicious address through the iteration query process of the local host table, the internal domain name resolution (DNS, Domain Name System) server, and the internal DNS request to the external DNS. The Trojan file in the internal terminal and the malicious IP address communicate to establish a connection. Since the Trojan file is usually immune to killing, it cannot be investigated by local killing, and enterprises usually set up an intrusion detection protection device (IDS, Intrusion detection system) in the Internet access area to monitor the active external connection traffic and identify the behavior of actively connecting to the malicious address. However, the following problems still exist, which leads to the lack of prevention of most enterprises for the active external connection situation:

[0062] 1. In the DNS recursive query phase communication phase, the traffic is sent from the internal DNS to the external DNS in the view of the IDS, and in this phase, it is impossible to effectively identify which terminal performs the active external connection behavior, resulting in lack of tracing ability and timely blocking ability, and waiting for the Trojan to establish a connection for tracing and disposal has a high security risk, and important data may have been leaked.

[0063] 2. When the threat intelligence of the malicious address is obtained or the terminal actively connects to the malicious address, since the Trojan file is usually immune to killing, there is no effective means to find out which terminals in the internal network are infected with the Trojan under the premise that the external connection behavior does not go out of the network (the terminal and the malicious address have not established a connection), lacking the overall investigation ability and blocking ability.

[0064] Based on the above technical problems, the embodiments of the present disclosure provide a terminal active external connection protection method, which comprises: in response to the alarm information of the terminal active external connection behavior, obtaining malicious link information; setting the internal server to start request monitoring according to the malicious link information; batch modifying the host table or the routing table of all terminals according to the malicious link information and the internal monitoring address information; positioning the compromised terminal according to the monitored request information; and isolating and protecting the compromised terminal based on the active external connection behavior stage of the compromised terminal.

[0065] Figure 1 The system architecture diagram of the terminal active external connection protection device according to the embodiments of the present disclosure is schematically shown. As Figure 1As shown, the apparatus provided by the embodiment of the present disclosure is deployed in the enterprise intranet. First, the process of the enterprise intranet terminal requesting a domain name outside is introduced. Before the terminal (office computer, server, etc.) of the enterprise intranet requests a domain name outside, after the local DNS has no resolution record, the terminal will query the DNS server of the Internet through the recursive DNS server of the enterprise intranet. The enterprise intrusion detection device is deployed at the boundary of the enterprise Internet. The enterprise has a terminal management system (for example, domain control, client software, agent, etc.), which is controlled by a unified management platform. The apparatus provided by the embodiment of the present disclosure specifically comprises: an intelligence access and command control module A1 and a monitoring and discovery module A2, wherein the intelligence access and command control module A1 is responsible for receiving malicious link intelligence and issuing commands to the terminal management platform or the monitoring and discovery module A2 according to the intelligence, and the terminal management platform is responsible for batch modifying the local hosts file or the routing table of all terminals. The monitoring and discovery module A2 is responsible for starting monitoring according to the command information, discovering and positioning the compromised host. The intelligence access and command control module A1 comprises an intelligence access unit A11 and a terminal command unit A12. The intelligence access unit A11 is mainly responsible for receiving the malicious link information of external threat intelligence input by the user or the malicious link information pushed by the intrusion monitoring system as the information source, so that the monitoring and discovery module A2 starts monitoring. And the terminal command unit A12 issues a command task for terminal protection. The monitoring and discovery module A2 comprises a monitoring unit A21 and a terminal positioning unit A22. The monitoring unit 21 is mainly responsible for setting the server to start requesting monitoring after receiving the command (malicious link information and starting monitoring) sent by the intelligence access unit A11, and the terminal positioning unit A22 is responsible for analyzing the requested information and positioning the compromised host, and setting protection if necessary.

[0066] Figure 2 An application scenario diagram of the terminal active external connection protection method, apparatus, device, medium and program product according to the embodiment of the present disclosure is schematically shown.

[0067] As Figure 2 shown, the application scenario 200 according to the embodiment can include a terminal active external connection protection scenario. The network 204 is used to provide a communication link medium between the terminal devices 201, 202, 203 and the server 205. The network 204 can include various connection types, such as wired, wireless communication links or optical fiber cables, etc.

[0068] The user can use the terminal devices 201, 202, 203 to interact with the server 205 through the network 204 to receive or send messages, etc. Various communication client applications can be installed on the terminal devices 201, 202, 203, such as shopping applications, web browser applications, search applications, instant messaging tools, email clients, social platform software, etc. (only as examples).

[0069] The terminal devices 201, 202, and 203 can be various electronic devices with display screens and supporting web browsing, including but not limited to smart phones, tablet computers, laptop computers, desktop computers, and the like.

[0070] The server 205 can be a protection server to which the terminal actively connects, which can execute the terminal active connection protection method provided by the embodiments of the present disclosure. After receiving the alarm information of the terminal active connection behavior, the server 205 can obtain malicious link information, which can be input by a user through the terminal device 201, 202, or 203, or be found by an intrusion detection system (IDS). The server 205 can set an internal network server to start request monitoring according to the malicious link information. The server 205 can batch modify the host table or the routing table of all terminals according to the malicious link information and the internal network monitoring address information. The server 205 can locate the compromised terminal according to the monitored request information. The server 205 can isolate and protect the compromised terminal based on the stage of the compromised terminal active connection behavior.

[0071] It should be noted that the terminal active connection protection method provided by the embodiments of the present disclosure can generally be executed by the server 205. Accordingly, the terminal active connection protection apparatus provided by the embodiments of the present disclosure can generally be arranged in the server 205. The terminal active connection protection method provided by the embodiments of the present disclosure can also be executed by a server or a server cluster different from the server 205 and capable of communicating with the terminal device 201, 202, 203, and / or the server 205. Accordingly, the terminal active connection protection apparatus provided by the embodiments of the present disclosure can also be arranged in a server or a server cluster different from the server 205 and capable of communicating with the terminal device 201, 202, 203, and / or the server 205.

[0072] It should be understood that Figure 2 The number of terminal devices, networks, and servers in the system architecture is only illustrative. Any number of terminal devices, networks, and servers can be provided according to implementation needs.

[0073] It should be noted that the terminal active connection protection method and apparatus determined by the embodiments of the present disclosure can be used in the field of network security technology, and can also be used in the field of financial technology, and can also be used in any field other than the field of finance. The application field of the terminal active connection protection method and apparatus determined by the embodiments of the present disclosure is not limited.

[0074] The terminal active connection protection method of the embodiments of the present disclosure will be described in detail below based on Figure 1 the system architecture described above and Figure 2 the application scenarios described above, by Figures 3-6 detailed description.

[0075] Figure 3A flowchart of a terminal active external connection protection method according to an embodiment of the present disclosure is shown schematically. As shown in Figure 1 and Figure 3 The terminal active external connection protection method of this embodiment includes operation S210 to operation S250, which can be performed by the device shown in Figure 1 or by a server or other computing device.

[0076] In operation S210, malicious link information is obtained in response to alarm information of terminal active external connection behavior.

[0077] In one example, when the intrusion detection system detects that the internal network has terminal active external connection behavior, it sends out alarm information, and the malicious link information is obtained in response to the alarm information of terminal active external connection behavior. The malicious link information can be manually input by the user, or can be found and pushed by the intrusion monitoring system.

[0078] In operation S220, the internal network server is set to start request monitoring according to the malicious link information.

[0079] In one example, when the intelligence access unit A11 receives the malicious link information, it sends the malicious link domain name information or IP information and the start monitoring command to the monitoring discovery module A2, which starts the internal network server device to monitor the malicious link request, and returns the internal network monitoring address information corresponding to the malicious link to the terminal command unit A12.

[0080] In operation S230, the host table or routing table of all terminals is modified in batches according to the malicious link information and the internal network monitoring address information.

[0081] In one example, in order to effectively block all similar requests in the internal network, the host table or routing table of all terminals is modified in batches according to the malicious link information and the internal network monitoring address information. Specifically, an instruction is sent to the terminal management system to modify the local file hosts or routing table of all terminals in the internal network, so that the dns of the malicious domain name is resolved to the continuously monitored internal network device, i.e. the device that starts request monitoring in step S220, so that the active external connection behavior skips the DNS recursion query phase, avoids the DNS protocol external information threat and subsequent connection establishment, and forms an effective block to all similar requests in the internal network.

[0082] In operation S240, the compromised terminal is located according to the monitored request information.

[0083] According to an embodiment of the present disclosure, when the requests from the same host exceed a preset threshold, the host is disconnected and isolated.

[0084] In one example, after the listening unit A21 sets the server to start the request listening, the internal network device such as the server, host and the like is set to start the listening. If there is a compromised host requesting a malicious link address, the request record is saved, the request information is recorded, and the compromised terminal is located according to the request information. In addition, the terminal positioning unit A22 can set a threshold. When the requests from the same host exceed the preset threshold, the terminal management software on the host is enabled by the terminal command unit A12 to perform the network isolation operation on the compromised host, thereby reducing the risk of horizontal spread.

[0085] In operation S250, the compromised terminal is isolated and protected based on the active external connection behavior stage of the compromised terminal.

[0086] In one example, when the terminal active external connection behavior receives the alarm information, the terminal active external connection behavior can be in different stages, for example, can be in the DNS recursion stage or in the connection establishment stage. According to the alarm information, the stage of the terminal active external connection behavior is determined, and then the compromised terminal is isolated and protected according to the active external connection behavior stage of the compromised terminal.

[0087] The terminal active external connection protection method provided by the embodiment of the present disclosure includes the following steps. When the terminal active external connection behavior alarm information is received, the malicious link information is obtained, the request listening is started, and the internal network listening address is returned. According to the malicious link type and the internal network listening address information, the host table or the routing table of all terminals is modified in batches to realize the listening of the terminal active external connection malicious link. According to the request information of the compromised terminal, the compromised terminal is located, and the compromised terminal is isolated and protected based on the active external connection behavior stage of the compromised terminal. Compared with the related art, the terminal active external connection protection method provided by the embodiment of the present disclosure can make the terminal active external connection IP behavior directly jump to the internal listening device address, form effective blocking, and quickly locate the detailed information of the compromised host.

[0088] Figure 4 A flowchart of a terminal active external connection protection method according to another embodiment of the present disclosure is schematically shown.

[0089] As shown in Figure 4 Operation S230 includes operation S231 and operation S232.

[0090] In operation S231, if it is determined that the malicious link is a domain name, the terminal local host table is modified in batches according to the internal network listening address information.

[0091] In operation S232, if it is determined that the malicious link is an Internet protocol address, the terminal local routing table is modified in batches according to the internal network listening address information.

[0092] In one example, after receiving the alarm information, the device initiates a request to listen, and according to the malicious link information type and the internal network listening address information, all devices in the internal network are modified in batches. Specifically, if it is determined that the malicious link is a domain name, the terminal local host table is modified in batches according to the internal network listening address information, and the local host table is changed so that the DNS resolution address of the malicious link is the corresponding internal network listening address in the listening unit A21.

[0093] In one example, if it is determined that the malicious link is an IP address, the terminal local routing table is modified in batches according to the internal network listening address information, so that the routing finally points to the listening unit A21. Through the above-mentioned operation of modifying the host table or the routing table, the active external connection behavior skips the DNS recursive external query stage, avoids the threat of DNS protocol external information and the subsequent connection establishment, and forms an effective block to all similar requests in the internal network.

[0094] Figure 5 A flowchart of a method for positioning a compromised terminal according to another embodiment of the present disclosure is schematically shown.

[0095] As shown in Figure 5 Operation S240 includes operation S241 and operation S242.

[0096] In operation S241, the physical address of the compromised host is queried from the terminal management platform according to the source IP address.

[0097] According to an embodiment of the present disclosure, the request information includes request initiation time, source IP address, and port information.

[0098] In operation S242, the physical address corresponding to the source IP address is found by calling the dynamic host configuration protocol table.

[0099] In one example, if a compromised host requests a malicious link address, the request record will be seen on the listening unit A21, and the request related information is recorded, including request initiation time, source IP address, port information, etc. Under normal circumstances, since it is not known what port the compromised host will request the malicious address, the internal network device will make a full-port forwarding listening. One implementation is to configure the local firewall (for example, iptables) to forward all non-private (ftp / ssh / mysqk) port requests to a specific port.

[0100] In one example, the compromised device is located according to the request information monitored by the monitoring unit A21. In one possible implementation, the terminal command unit A12 sends a command to the terminal unified management platform, finds the compromised host through the enterprise terminal management system according to the source IP address, and thus determines the mac address of the compromised host. In another possible implementation, if the corresponding compromised host is not found in the enterprise terminal management system, the IP corresponding MAC address can be found by calling the current DHCP table in the enterprise, and the compromised host is located according to the enterprise internal account. After the compromised host is located, the user is presented with the situation of the compromised host.

[0101] The method provided by the embodiments of the present disclosure can quickly lock the mac of the compromised host by querying the DHCP table or the terminal management system, and continuously monitor the compromised terminal that discovers other malicious addresses to achieve rapid positioning and avoid the situation that the compromised host cannot be uniformly investigated due to the Trojan horse immune killing.

[0102] Figure 6 A flowchart of a compromised terminal isolation protection method according to another embodiment of the present disclosure is schematically shown. As shown in Figure 6 The operation S250 includes the operation S251 to the operation S253.

[0103] In the operation S251, the active external connection behavior stage of the compromised terminal is determined according to the alarm information of the terminal active external connection behavior.

[0104] According to the embodiments of the present disclosure, if it is determined that the alarm information does not contain the IP port information of the compromised terminal, it is determined that the active external connection behavior of the compromised terminal is in the domain name resolution recursion stage. If it is determined that the alarm information contains the IP port information of the compromised terminal, it is determined that the active external connection behavior of the compromised terminal is in the connection establishment stage with the malicious link.

[0105] In the operation S252, if it is determined that the active external connection behavior of the compromised terminal is in the domain name resolution recursion stage, the host table or the routing table of all terminals is modified in batches according to the malicious link type.

[0106] In the operation S253, if it is determined that the active external connection behavior of the compromised terminal is in the connection establishment stage with the malicious link, the host table and / or the routing table of the compromised terminal is modified and the connection of the source port is reset.

[0107] In one example, when the intelligence access unit A11 receives the active external connection malicious warning information pushed by the intrusion monitoring system, the stage of the active external connection behavior of the compromised terminal is determined through the warning information. When the active external connection behavior of the compromised terminal is in the connection establishment stage with the malicious link, it is indicated that the compromised terminal has established a connection with the malicious link at this time, and the warning information contains the IP address and port number information of the compromised terminal. Therefore, whether the warning information contains the IP address and port number information of the compromised terminal can be used to determine the current stage of the active external connection behavior of the compromised terminal.

[0108] In one example, if it is determined that the active external connection behavior of the compromised terminal is in the domain name resolution recursion stage, the compromised terminal has not established a connection with the malicious link at this time, and only the operations S231 and S232 shown in the following need to be performed. Figure 4 If it is determined that the active external connection behavior of the compromised terminal is in the connection establishment stage with the malicious link, the IP address and source port information of the compromised terminal will be displayed in the warning information at this time. In order to block the connection in time, the host table and / or the routing table of the compromised terminal are modified through the terminal management platform and the connection of the source port is reset.

[0109] Based on the terminal active external connection protection method described above, the disclosure further provides a terminal active external connection protection device. The device will be described in detail below in combination with Figure 7 the terminal active external connection protection method.

[0110] Figure 7 The structure block diagram of a terminal active external connection protection device according to an embodiment of the disclosure is schematically shown. As Figure 7 shown, the terminal active external connection protection device 800 of this embodiment includes an acquisition module 810, a listening module 820, a modification module 830, a compromised terminal positioning module 840, and a protection module 850.

[0111] The acquisition module 810 is configured to acquire malicious link information in response to the warning information of the terminal active external connection behavior. In one embodiment, the acquisition module 810 can be configured to perform the operation S210 described above, and details are not repeated here.

[0112] The listening module 820 is configured to set up an internal network server start request listening according to the malicious link information. In one embodiment, the listening module 820 can be configured to perform the operation S220 described above, and details are not repeated here.

[0113] The modification module 830 is configured to batch modify the host table or the routing table of all terminals according to the malicious link information and the internal network listening address information. In one embodiment, the modification module 830 can be configured to perform the operation S230 described above, and details are not repeated here.

[0114] The compromised terminal positioning module 840 is configured to position the compromised terminal according to the monitored request information. In an embodiment, the compromised terminal positioning module 840 can be configured to perform operation S240 described above, which will not be repeated here.

[0115] The protection module 850 is configured to isolate and protect the compromised terminal based on the active external connection behavior stage of the compromised terminal. In an embodiment, the protection module 850 can be configured to perform operation S250 described above, which will not be repeated here.

[0116] According to an embodiment of the present disclosure, the modification module comprises a first modification submodule and a second modification submodule.

[0117] The first modification submodule is configured to modify the terminal local host table in batches according to the internal network monitoring address information if it is determined that the malicious link is a domain name. In an embodiment, the first modification submodule can be configured to perform operation S231 described above, which will not be repeated here.

[0118] The second modification submodule is configured to modify the terminal local routing table in batches according to the internal network monitoring address information if it is determined that the malicious link is an Internet Protocol address. In an embodiment, the second modification submodule can be configured to perform operation S232 described above, which will not be repeated here.

[0119] According to an embodiment of the present disclosure, the compromised terminal positioning module comprises a first positioning submodule and a second positioning submodule. In an embodiment, the protection module 850 can be configured to perform operation S250 described above, which will not be repeated here.

[0120] The first positioning submodule is configured to query the physical address of the compromised host from the terminal management platform according to the source IP address. In an embodiment, the first positioning submodule can be configured to perform operation S241 described above, which will not be repeated here.

[0121] The second positioning submodule is configured to find the physical address corresponding to the source IP address by calling the dynamic host configuration protocol table. In an embodiment, the second positioning submodule can be configured to perform operation S242 described above, which will not be repeated here.

[0122] According to an embodiment of the present disclosure, the protection module comprises a first isolation and protection submodule and a second isolation and protection submodule,

[0123] The first isolation and protection submodule is configured to modify the host table or the routing table of all terminals in batches according to the type of malicious link if it is determined that the active external connection behavior of the compromised terminal is in the domain name resolution recursion stage. In an embodiment, the first isolation and protection submodule can be configured to perform operation S251 described above, which will not be repeated here.

[0124] The second isolation protection submodule is configured to modify a host table and / or a routing table of the compromised terminal and reset a source port connection if it is determined that the compromised terminal initiatively connects to a malicious link.

[0125] According to an embodiment of the present disclosure, the network isolation module further comprises:

[0126] The network isolation module is configured to isolate a host from a network if a request from the host exceeds a preset threshold.

[0127] According to an embodiment of the present disclosure, any of the acquisition module 810, the monitoring module 820, the modification module 830, the compromised terminal positioning module 840 and the protection module 850 can be combined in one module, or any of the modules can be split into multiple modules. Alternatively, at least part of the function of one or more of the modules can be combined with at least part of the function of other modules, and implemented in one module. According to an embodiment of the present disclosure, at least one of the acquisition module 810, the monitoring module 820, the modification module 830, the compromised terminal positioning module 840 and the protection module 850 can be at least partially implemented as a hardware circuit, such as a field programmable gate array (FPGA), a programmable logic array (PLA), a system on chip, a system on board, a system on package, an application specific integrated circuit (ASIC), or any other reasonable way of integrating or packaging a circuit, etc. hardware or firmware, or any one of software, hardware and firmware or any appropriate combination of any of them. Alternatively, at least one of the acquisition module 810, the monitoring module 820, the modification module 830, the compromised terminal positioning module 840 and the protection module 850 can be at least partially implemented as a computer program module which can perform corresponding functions when running.

[0128] Figure 8 The block diagram schematically shows an electronic device suitable for implementing the terminal initiatively connecting protection method according to an embodiment of the present disclosure.

[0129] As Figure 8As shown, the electronic device 900 according to embodiments of the present disclosure includes a processor 901 that can perform various appropriate actions and processes according to programs stored in a read only memory (ROM) 902 or loaded into a random access memory (RAM) 903 from a storage section 908. The processor 901 can include, for example, a general purpose microprocessor (e.g., a CPU), an instruction set processor, and / or a related chipset, and / or a special purpose microprocessor (e.g., an application specific integrated circuit (ASIC)), and so on. The processor 901 can also include on-board memory for cache purposes. The processor 901 can include a single processing unit or multiple processing units for executing different actions of the method processes according to embodiments of the present disclosure.

[0130] In the RAM 903, various programs and data required for the operation of the electronic device 900 are stored. The processor 901, the ROM 902, and the RAM 903 are connected to each other via a bus 904. The processor 901 performs various operations of the method processes according to embodiments of the present disclosure by executing the programs in the ROM 902 and / or the RAM 903. Note that the programs can also be stored in one or more memories other than the ROM 902 and the RAM 903. The processor 901 can also perform various operations of the method processes according to embodiments of the present disclosure by executing the programs stored in the one or more memories.

[0131] According to embodiments of the present disclosure, the electronic device 900 can also include an input / output (I / O) interface 905 that is also connected to the bus 904. The electronic device 900 can also include one or more of the following components connected to the I / O interface 905: an input section 906 including a keyboard, a mouse, etc.; an output section 907 including a display such as a cathode ray tube (CRT), a liquid crystal display (LCD), etc., and a speaker, etc.; a storage section 908 including a hard disk, etc.; and a communication section 909 including a network interface card such as a LAN card, a modem, etc. The communication section 909 performs communication processing via a network such as the Internet. The drive 909 is also connected to the I / O interface 905 as necessary. A removable medium 911 such as a magnetic disk, a magneto-optical disk, a semiconductor memory, etc. is attached to the drive 909 as necessary, so that a computer program read out from it is installed into the storage section 908 as necessary.

[0132] The present disclosure also provides a computer readable storage medium, which can be included in the device / apparatus / system described in the above embodiments, or can exist independently without being assembled into the device / apparatus / system. The above computer readable storage medium carries one or more programs, which, when executed, implement the terminal active connection protection method according to the embodiments of the present disclosure.

[0133] According to embodiments of the present disclosure, the computer readable storage medium can be a non-volatile computer readable storage medium, which can include, but is not limited to, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any appropriate combination thereof. In the present disclosure, the computer readable storage medium can be any tangible medium that contains or stores a program, which can be used by or in connection with an instruction execution system, apparatus, or device. For example, according to embodiments of the present disclosure, the computer readable storage medium can include one or more memories, such as the ROM 902 and / or the RAM 903 described above, and / or one or more memories other than the ROM 902 and the RAM 903.

[0134] Embodiments of the present disclosure also include a computer program product, which includes a computer program containing program codes for executing the methods shown in the flowcharts. When the computer program product is run in a computer system, the program codes are used to make the computer system implement the terminal active connection protection method provided by the embodiments of the present disclosure.

[0135] The above functions defined in the system / apparatus of the embodiments of the present disclosure are performed when the computer program is executed by the processor 901. According to embodiments of the present disclosure, the system, apparatus, module, unit, etc. described above can be implemented by computer program modules.

[0136] In one embodiment, the computer program can rely on a tangible storage medium such as an optical storage device, a magnetic storage device, etc. In another embodiment, the computer program can also be transmitted, distributed, and downloaded in the form of a signal via a network medium, and be downloaded and installed via the communication part 909 and / or installed from the detachable medium 911. The program codes contained in the computer program can be transmitted via any appropriate network medium, including but not limited to wireless, wired, etc., or any appropriate combination thereof.

[0137] In such embodiments, the computer program can be downloaded and installed from the network through the communication part 909, and / or installed from the detachable medium 911. When the computer program is executed by the processor 901, the above-described functions defined in the system of the embodiments of the present disclosure are executed. According to the embodiments of the present disclosure, the system, device, apparatus, module, unit, and the like described above can be implemented by computer program modules.

[0138] According to the embodiments of the present disclosure, the program code for executing the computer program provided by the embodiments of the present disclosure can be written in any combination of one or more programming languages, and specifically, these computer programs can be implemented using high-level procedural and / or object-oriented programming language, and / or assembly / machine language. The programming language includes, but is not limited to, such as Java, C++, python, "C" language or similar programming language. The program code can be executed entirely on the user computing device, partially on the user device, partially on a remote computing device, or entirely on a remote computing device or server. In the case involving a remote computing device, the remote computing device can be connected to the user computing device through any kind of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computing device (for example, connected through the Internet by using an Internet service provider).

[0139] The flowcharts and block diagrams in the drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods and computer program products according to various embodiments of the present disclosure. In this regard, each block in the flowcharts or block diagrams can represent a module, a segment, or a portion of code, which comprises one or more executable instructions for implementing the specified logical functions. It should also be noted that in some alternative implementations, the functions noted in the blocks can occur in a different order than that shown in the figures. For example, two blocks noted in succession can actually be executed substantially concurrently, or they can sometimes be executed in reverse order, depending on the functionality involved. It should also be noted that each block in the flowcharts or block diagrams, and combinations of blocks in the flowcharts or block diagrams, can be implemented by dedicated hardware-based systems that perform the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.

[0140] Those skilled in the art can understand that the features described in various embodiments of the present disclosure and / or claims can be combined or / and integrated, even if such combinations or integrations are not explicitly described in the present disclosure. In particular, the features described in various embodiments of the present disclosure and / or claims can be combined and / or integrated in various combinations, without departing from the spirit and teachings of the present disclosure. All these combinations and / or integrations fall within the scope of the present disclosure.

[0141] The above described embodiments of the present disclosure. However, these embodiments are merely for illustrative purposes, and are not intended to limit the scope of the present disclosure. Although each embodiment is described above separately, this does not mean that the measures in each embodiment cannot be advantageously used in combination. The scope of the present disclosure is defined by the appended claims and their equivalents. Those skilled in the art can make various substitutions and modifications without departing from the scope of the present disclosure, and all such substitutions and modifications shall fall within the scope of the present disclosure.

Claims

1. A protection method for terminal active external connection, characterized in that, The method comprises: in response to the alarm information of the terminal active external connection behavior, obtaining malicious link information; setting up internal network server opening request monitoring according to the malicious link information; batch modifying host table or routing table of all terminals according to the malicious link information and internal network monitoring address information; locating the compromised terminal according to the monitored request information; and isolating and protecting the compromised terminal based on the compromised terminal active external connection behavior stage; the batch modifying host table or routing table of the terminal according to the malicious link information and internal network monitoring address information comprises: if it is determined that the malicious link is a domain name, then batch modifying local host table of the terminal according to the internal network monitoring address information; if it is determined that the malicious link is an Internet Protocol address, then batch modifying local routing table of the terminal according to the internal network monitoring address information; the isolating and protecting the compromised terminal based on the compromised terminal active external connection behavior stage comprises: determining the compromised terminal active external connection behavior stage according to the alarm information of the terminal active external connection behavior; if it is determined that the compromised terminal active external connection behavior is in the domain name resolution recursion stage, then batch modifying host table or routing table of all terminals according to the malicious link type; and if it is determined that the compromised terminal active external connection behavior is in the connection establishment stage with the malicious link, then modifying host table and / or routing table of the compromised terminal and resetting the connection of the source port.

2. The method of claim 1, wherein, The request information comprises request initiation time, source IP address and port information, and the locating the compromised terminal according to the monitored request information comprises: inquiring the physical address of the compromised host from the terminal management platform according to the source IP address.

3. The method of claim 2, wherein, The locating the compromised terminal according to the monitored request information further comprises: looking up the physical address corresponding to the source IP address through the dynamic host configuration protocol table.

4. The method of claim 3, wherein, The determining the compromised terminal active external connection behavior stage according to the alarm information of the terminal active external connection behavior comprises: if it is determined that the compromised terminal IP port information is not contained in the alarm information, then determining that the compromised terminal active external connection behavior is in the domain name resolution recursion stage; and if it is determined that the compromised terminal IP port information is contained in the alarm information, then determining that the compromised terminal active external connection behavior is in the connection establishment stage with the malicious link.

5. The method according to one of claims 1 to 4, characterized in that, The method further comprises: when the requests from the same host exceed a preset threshold, disconnecting the network of the host and isolating it.

6. A protection device for a terminal active external connection, characterized in that, The device comprises: an acquisition module, configured to acquire malicious link information in response to alarm information of terminal active external connection behavior; a monitoring module, configured to set up internal network server opening request monitoring according to the malicious link information; a modification module, configured to batch modify host table or routing table of all terminals according to the malicious link information and internal network monitoring address information; a compromised terminal locating module, configured to locate the compromised terminal according to the monitored request information; and a protection module, configured to isolate and protect the compromised terminal based on the compromised terminal active external connection behavior stage; the modification module is further configured to batch modify local host table of the terminal according to the internal network monitoring address information if it is determined that the malicious link is a domain name, and batch modify local routing table of the terminal according to the internal network monitoring address information if it is determined that the malicious link is an Internet Protocol address. The protection module is further configured to determine a stage of the active external connection behavior of the compromised terminal according to the alarm information of the active external connection behavior of the terminal; if it is determined that the active external connection behavior of the compromised terminal is in a domain name resolution recursion stage, to modify a host table or a routing table of all terminals in batches according to a malicious link type; and if it is determined that the active external connection behavior of the compromised terminal is in a connection establishment stage with a malicious link, to modify the host table and / or the routing table of the compromised terminal and reset a connection of a source port. 7.An electronic device, comprising: one or more processors; a storage device for storing one or more programs, wherein the one or more programs, when executed by the one or more processors, enable the one or more processors to perform the method for protecting active external connection of a terminal according to any one of claims 1-5. 8.A computer-readable storage medium having stored thereon executable instructions that, when executed by a processor, cause the processor to perform the method for protecting active external connection of a terminal according to any one of claims 1-5.

Citation Information

Patent Citations

  • WiFi module blocking method and device

    CN107094295A

  • Method for positioning lost host, protection device, network security equipment and medium

    CN111683068A

  • Botnet defense method, device and equipment for multi-level full-period Internet of Things equipment

    CN113037785A

  • Intranet terminal illegal external connection information processing method, device, equipment and medium

    CN114268481A