Secure connection method, device, medium, electronic equipment and program product
By deploying a pre-defined application process on the terminal, responding to DNS requests and adding tags, the problem of login restrictions on the web page is solved, enabling secure control of enterprise data and preventing data leakage.
Patent Information
- Application Number
- CN202411858321.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-16
- Publication Date
- 2026-01-16
- Estimated Expiration
- 2044-12-16
AI Technical Summary
Existing technologies cannot effectively restrict user account logins on web pages, leading to the risk of enterprise data leakage.
By deploying a pre-defined application process on the terminal, responding to DNS requests and adding pre-defined tags, the system identifies authorized terminals, controls the business request messages of the target application, and achieves complete capture and control of traffic data on both the web page and the APP.
It enables complete capture of target application traffic data at the device level, preventing data leakage and ensuring enterprise data security.
Smart Images

Figure CN119363806B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present disclosure relates to the technical field of network security, in particular, to an application security connection method and device, a medium, an electronic device and a program product. BACKGROUND
[0002] The rapid development of informatization makes information security problems more and more valued. For enterprises, in order to avoid data leakage, employees usually need to log in to the enterprise account on the designated device, and limit the login of personal accounts and other enterprise accounts on the designated device.
[0003] In related technologies, only the account logged in by the user through the APP end can be limited, and the login account of the web end cannot be limited, resulting in the risk of data leakage. SUMMARY
[0004] This summary is provided to introduce a selection of concepts that are further described below in the detailed description. This summary is not intended to identify key or essential features of the claimed subject matter, nor is it intended to be used to limit the scope of the claimed subject matter.
[0005] In a first aspect, the present disclosure provides an application security connection method, comprising:
[0006] In response to a terminal initiating a domain name system (DNS) request, determining domain name information corresponding to the DNS request;
[0007] In a case where the domain name information is a preset domain name corresponding to a target application, adding a preset mark to a business request message of the target application through a preset application process, the preset mark being used to identify that the terminal is a preset authorized terminal corresponding to the target application, and the preset application process being an application process deployed on the preset authorized terminal;
[0008] Sending the business request message added with the preset mark to a target server corresponding to the target application, so that the target server establishes a connection with the target application according to the preset mark.
[0009] In a second aspect, the present disclosure provides an application security connection device, comprising:
[0010] A determination module, configured to determine domain name information corresponding to a domain name system (DNS) request initiated by a terminal in response to the terminal initiating the DNS request;
[0011] a marking module, configured to add a preset mark to a service request message of the target application by a preset application process in a case where the domain name information is a preset domain name corresponding to the target application, the preset mark being used to identify that the terminal is a preset authorized terminal corresponding to the target application, and the preset application process being an application process deployed on the preset authorized terminal;
[0012] a connecting module, configured to send the service request message added with the preset mark to a target server corresponding to the target application, so that the target server establishes a connection with the target application according to the preset mark.
[0013] In a third aspect, the present disclosure provides a computer readable medium, having a computer program stored thereon, which, when executed by a processing device, implements the steps of the method of the first aspect of the present disclosure.
[0014] In a fourth aspect, the present disclosure provides an electronic device, comprising:
[0015] a storage device, having a computer program stored thereon;
[0016] a processing device, configured to execute the computer program in the storage device to implement the steps of the method of the first aspect of the present disclosure.
[0017] In a fifth aspect, the present disclosure provides a computer program product, comprising a computer program, which, when executed by a processor, implements the steps of the method of the first aspect of the present disclosure.
[0018] According to the above technical solution, in response to a domain name system (DNS) request initiated by a terminal, domain name information corresponding to the DNS request is determined; in a case where the domain name information is a preset domain name corresponding to a target application, a preset mark is added to a service request message of the target application by a preset application process, the preset mark being used to identify that the terminal is a preset authorized terminal corresponding to the target application, and the preset application process being an application process deployed on the preset authorized terminal; the service request message added with the preset mark is sent to a target server corresponding to the target application, so that the target server establishes a connection with the target application according to the preset mark. In this way, by deploying the preset application process on the preset authorized terminal of the target application and adding the preset mark to the service request message from the target application based on the preset application process, traffic data containing APP and web pages passing through the target application can be completely captured in the device dimension, and the target server can also control the terminal device logged into the target application by identifying the preset mark, thereby avoiding data leakage of the target application.
[0019] Other features and advantages of the present disclosure will be described in detail in the following detailed description. BRIEF DESCRIPTION OF DRAWINGS
[0020] The above and other features, advantages, and aspects of the embodiments of this disclosure will become more apparent from the accompanying drawings and the following detailed description. Throughout the drawings, the same or similar reference numerals denote the same or similar elements. It should be understood that the drawings are schematic, and the originals and elements are not necessarily drawn to scale. In the drawings:
[0021] Figure 1 This is a flowchart illustrating an application secure connection method according to an exemplary embodiment.
[0022] Figure 2 It is based on Figure 1 The illustrated embodiment shows a flowchart of an application secure connection method.
[0023] Figure 3 This is a schematic diagram of a signaling interaction according to an exemplary embodiment of the present disclosure.
[0024] Figure 4 It is based on Figure 1 The illustrated embodiment shows a flowchart of an application secure connection method.
[0025] Figure 5 This is a schematic diagram illustrating a packet coloring process using MITM according to an exemplary embodiment.
[0026] Figure 6 It is based on Figure 1 The illustrated embodiment shows a flowchart of an application secure connection method.
[0027] Figure 7 It is based on Figure 1 The illustrated embodiment shows a flowchart of an application secure connection method.
[0028] Figure 8 It is based on Figure 1 The illustrated embodiment shows a flowchart of an application secure connection method.
[0029] Figure 9 It is based on Figure 1 The illustrated embodiment shows a flowchart of an application secure connection method.
[0030] Figure 10 This is a block diagram illustrating an application-safe connection device according to an exemplary embodiment.
[0031] Figure 11 It is based on Figure 10 The illustrated embodiment shows a block diagram of an application-safe connection device.
[0032] Figure 12 It is based on Figure 10A block diagram of an application security connection apparatus shown in an embodiment.
[0033] Figure 13 A block diagram of an application security connection apparatus shown in an embodiment. Figure 10 A block diagram of an application security connection apparatus shown in an embodiment.
[0034] Figure 14 A structural schematic diagram of an electronic device shown in an embodiment according to the present disclosure. DETAILED DESCRIPTION
[0035] Embodiments of the present disclosure will be described in more detail with reference to the drawings. While certain embodiments of the present disclosure will be shown in the drawings and described below, it should be understood that the present disclosure can be embodied in various forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided so that this disclosure will be thorough and complete, and fully convey the scope of the present disclosure to those skilled in the art.
[0036] It should be understood that each step recited in the method embodiments of the present disclosure can be executed in different orders and / or in parallel. In addition, the method embodiments can include additional steps and / or omit the execution of the steps shown. The scope of the present disclosure is not limited in this respect.
[0037] The term "comprising" and variations thereof as used herein are used inclusively, i.e., "comprising but not limited to." The term "based on" is "based at least in part on." The term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one additional embodiment"; the term "some embodiments" means "at least some embodiments." Related terms are defined in the description that follows.
[0038] It should be noted that the terms "first", "second", and the like in the present disclosure are used only to distinguish different devices, modules or units, and do not imply the order or the mutual dependency of the functions performed by these devices, modules or units.
[0039] It should be noted that the terms "one", "multiple", and the like in the present disclosure are illustrative and not limiting, and those skilled in the art should understand that, unless otherwise explicitly stated in the context, it should be understood as "one or more".
[0040] The names of the messages or information exchanged between the devices in the embodiments of the present disclosure are only for illustrative purposes, and are not intended to limit the scope of the messages or information.
[0041] It can be understood that, before using the technical solutions disclosed in the embodiments of the present disclosure, the type, use range, use scenario, etc. of the personal information involved in the present disclosure should be informed to the user and the authorization of the user should be obtained through appropriate means according to relevant laws and regulations.
[0042] For example, in response to receiving an active request of a user, prompt information is sent to the user to explicitly prompt the user that the operation requested to be performed will require obtaining and using personal information of the user. Thus, the user can autonomously select whether to provide personal information to the software or hardware such as an electronic device, an application program, a server or a storage medium, etc. that performs the operation of the technical solutions of the present disclosure according to the prompt information.
[0043] As an optional but non-limiting implementation manner, in response to receiving an active request of a user, the manner of sending prompt information to the user may, for example, be a pop-up window manner, and the prompt information may be presented in the form of text in the pop-up window. In addition, the pop-up window may also carry selection controls for the user to select “agree” or “disagree” to provide personal information to the electronic device.
[0044] It can be understood that the above notification and obtaining of user authorization process is only illustrative, and does not limit the implementation manners of the present disclosure, and other manners that meet relevant laws and regulations can also be applied to the implementation manners of the present disclosure.
[0045] At the same time, it can be understood that the data (including but not limited to the data itself, the acquisition or use of the data) involved in the present technical solutions should comply with the requirements of relevant laws and regulations and relevant provisions.
[0046] The present disclosure is mainly applied to the scenario of restricting the login account when logging into a target application on a specified device to avoid the risk of data leakage of an enterprise.
[0047] In the related art, the restriction on user account login and switching can be implemented in the APP end of the target application. In actual application scenarios, the target application usually also has a web end. The web end cannot obtain the unique identifier of the device, so it cannot simply implement the function of restricting user account login and switching by specifying the device identifier. That is, the related art can implement account login restriction in the APP of the target application, but cannot prevent the user from logging in and switching accounts through the web end, which obviously affects information security and poses a risk of data leakage of an enterprise.
[0048] To solve the above problems, the present disclosure provides an application security connection method, device, medium, electronic device and program product. The specific embodiments of the present disclosure will be described in detail below with reference to the accompanying drawings.
[0049] Figure 1is a flow chart of an application security connection method according to an exemplary embodiment, which can be applied to terminal equipment (such as mobile phones, computers, notebooks, tablets, etc.). As shown in Figure 1 the method comprises the following steps:
[0050] In step S101, in response to the terminal initiating a domain name system (DNS) request, the domain name information corresponding to the DNS request is determined.
[0051] In actual application scenarios, after the terminal detects that the user has entered a certain website (such as the website address of the web page of the target application) in the browser, it can trigger the DNS (Domain Name System) request to obtain the IP address corresponding to the domain name information based on the DNS request.
[0052] Generally, the DNS request can be sent directly to the DNS server to obtain the IP address corresponding to the domain name information based on the DNS server. Based on the DNS interception technology, the preset application process deployed on the terminal can obtain the DNS request, and the domain name information corresponding to the DNS request can be determined based on the preset application process, so that in the case that the domain name information of the DNS request is a preset domain name corresponding to the target application, the preset application process can add a preset mark to the service request message subsequently initiated by the target application, so that after the service request message is sent to the target server (i.e., the service server corresponding to the target application), the target server can determine whether the service request message is from the preset authorized terminal of the target application based on the preset mark, and establish a connection with the target application if it is determined to be from the preset authorized terminal, otherwise, the user is refused to log in the target application.
[0053] The preset application process refers to an application process pre-deployed on the preset authorized terminal of the target application, thereby realizing the function of limiting tenant switching and the function of security reinforcement based on the terminal equipment. For example, the preset application process can be an LSA (Lark Secure Access) service.
[0054] In this step, the DNS request can be obtained through the preset application process in response to the terminal initiating the DNS request, and the domain name information can be obtained after the DNS request is parsed.
[0055] In step S102, in the case that the domain name information is a preset domain name corresponding to the target application, a preset mark is added to the service request message of the target application through the preset application process, and the preset mark is used to identify that the terminal is a preset authorized terminal corresponding to the target application, and the preset application process is an application process deployed on the preset authorized terminal.
[0056] The preset domain name corresponding to the target application refers to one or more domain names corresponding to the target application which are set in advance. The target application can be one or more applications which are set in advance to require tenant login restriction. The preset authorized terminal refers to a terminal device which can log in to the target application and is set in advance. In a possible implementation of the present disclosure, the subsequent login of the terminal device to the target application can be authorized by pre-deploying the preset application process on the preset authorized terminal.
[0057] In an implementation, the preset domain name of the target application can be defined in advance through the accounts domain. If it is determined that the domain name information belongs to the domain name in the accounts domain of the target application, the domain name information is regarded as the preset domain name corresponding to the target application.
[0058] If the domain name information is the preset domain name corresponding to the target application, the DNS request at present and the service request message sent by the IP address returned by the response message based on the DNS request are traffic data of the target application which requires tenant login restriction. This part of traffic data needs to be checked to determine whether it is traffic data initiated by the preset authorized terminal of the target application, so as to avoid unauthorized devices logging in to the target application and reduce the risk of data leakage.
[0059] In order to check the traffic data, the present disclosure can add a preset mark to the service request message of the target application through the preset application process. The preset mark can identify that the terminal is the preset authorized terminal corresponding to the target application. In this way, the server can control the terminal device logging in to the target application by identifying the preset mark.
[0060] In step S103, the service request message added with the preset mark is sent to the target server corresponding to the target application, so that the target server establishes a connection with the target application according to the preset mark.
[0061] The target server refers to a service server providing services for the target application.
[0062] Since this preset tag is used to identify the terminal as a preset authorized terminal corresponding to the target application, if the target server determines that the received service request message carries this preset tag, it can assume that the service request message was sent by the target application's preset authorized terminal. In this case, the server can respond normally to the service request message so as to establish a connection with the target application and provide service responses to it. If the target server determines that the service request message does not carry this preset tag, it can consider that the service request message was initiated by an unauthorized terminal device (i.e., a terminal device without login permissions to the target application). In this case, the target server can refuse the user's login to the target application, that is, it will not establish a communication connection with the target application.
[0063] By using the above method, the preset application process is deployed on the preset authorized terminal of the target application, and a preset tag is added to the business request message from the target application based on the preset application process. This enables complete capture of traffic data passing through the target application, including the APP and web pages, at the device level. It also allows the target server to control the terminal device that logs into the target application by recognizing the preset tag, thus preventing data leakage of the target application.
[0064] In one possible implementation of this disclosure, the preset application process can be deployed in the system user space, and the preset application process includes a virtual network interface card (NIC) and a domain name acquisition thread, which are two threads within the preset application process. The virtual NIC can be considered a software-defined network interface that simulates the function of a physical NIC but typically does not depend on physical hardware. In the operating system architecture, the virtual NIC is usually integrated into the system network stack. Therefore, this disclosure, based on this virtual NIC technology, can achieve interaction with the operating system kernel layer to capture network packets from the operating system kernel layer through the virtual NIC. These network packets can be transmitted to applications in the system user space, or the virtual NIC can be used to transmit data packets from the system user space to the operating system kernel layer. The domain name acquisition thread refers to a thread that retrieves domain name information based on DNS packets. Furthermore, the preset application process may further include a local proxy (also a thread within the preset application process), which can be considered an intermediary layer between the client of the target application and the target server.
[0065] Figure 2 It is based on Figure 1 The illustrated embodiment presents a flowchart of an application secure connection method. For example... Figure 2 As shown, step S101 includes the following sub-steps:
[0066] In step S1011, the DNS data packet of the DNS request is obtained from the operating system kernel layer of the terminal through the virtual network card, and then transmitted to the domain name obtaining thread.
[0067] As described above, the present disclosure can transmit the data packet of the operating system kernel layer to the application in the system user state through the virtual network card, and thus, in the present step, the DNS data packet of the DNS request can be obtained from the operating system kernel layer of the terminal through the virtual network card, and then transmitted to the domain name obtaining thread deployed in the system user state.
[0068] In a possible implementation manner, the DNS data packet can be obtained from the operating system kernel layer through the virtual network card based on the modified route of the DNS request.
[0069] The DNS request is usually initiated by the target application, and then transmitted from the system user state to the operating system kernel layer, and the virtual network card can read the DNS data packet from the operating system kernel layer based on the modified route.
[0070] For example, the DNS list corresponding to the system default network card (such as the physical network card of the system) can be queried, and the DNS list records the IP address of the DNS server. By modifying the route, the DNS request message flowing to the DNS server IP address can be imported from the operating system kernel layer to the virtual network card.
[0071] In step S1012, the domain name information is obtained by parsing the DNS data packet through the domain name obtaining thread.
[0072] In a possible implementation manner of the present step, the domain name obtaining thread can detect whether the DNS data packet is a data packet corresponding to port 53, and in the case of determining that the data packet belongs to port 53, the domain name information can be obtained by parsing the DNS data packet based on the DNS protocol. In addition, the DNS data packet is usually a UDP (User Datagram Protocol, User Datagram Protocol) type data packet.
[0073] For example, Figure 3 is a signaling interaction schematic diagram according to an example embodiment of the present disclosure, as Figure 3 As shown in the figure, the signaling interaction subjects include a terminal and a target server, wherein the terminal is further divided into three interaction sub-subjects, i.e., a target application, an operating system kernel layer and a preset application process. As Figure 3As shown, the preset application process can set a routing table to obtain DNS traffic through the virtual network card at step S1, the target application initiates a DNS request at step S2, and the DNS request is transmitted to the kernel layer of the operating system. At step S3, the DNS data packet corresponding to the DNS request can be read through the virtual network card, and the DNS data packet is transmitted to the domain name acquisition thread in the preset application process. The domain name acquisition thread can parse the DNS data packet by performing step S4 to obtain domain name information.
[0074] In a possible embodiment of the present disclosure, the preset application process can also cache the domain name information and the real destination address corresponding to the domain name information. The real destination address refers to the IP address of the target server. The correspondence can be cached in the UDP Nat, as shown in Figure 3 As shown, the correspondence can be accounts.yuming.cn-a.b.c.d, where accounts.yuming.cn is the domain name information of the target application, and a.b.c.d is the IP address of the target server.
[0075] It can be understood that before caching the correspondence in the UDP Nat, the real destination address needs to be determined. In order to obtain the real destination address, the terminal can send the DNS request to the DNS server; according to the first response message returned by the DNS server, the real destination address corresponding to the domain name information is determined, so that the domain name information and the real destination address corresponding to the domain name information can be cached.
[0076] It should be noted that in the process of sending the DNS request to the DNS server, the terminal can use the physical network card of the terminal to send the DNS request to the DNS server based on the method of bind.before.connect, so as to avoid the routing loop problem caused by capturing the DNS request by the virtual network card again when sending the DNS request through the virtual network card. In addition, in order to reduce the load pressure of the virtual network card thread and improve the communication efficiency of data, after sending the DNS request to the DNS server using the physical network card of the terminal, another thread can be started in the preset application process to receive the DNS response message (i.e. the first response message), so as to determine the real destination address corresponding to the domain name information based on the DNS response message, and cache the mapping relationship between the domain name information and the real destination address in the preset application process.
[0077] Figure 4 According to the embodiment shown in Figure 1 As shown, step S102 includes the following sub-steps: Figure 4
[0078] In step S1021, a pseudo communication address randomly assigned to the virtual network card is obtained.
[0079] The pseudo-communication address refers to an IP address (also known as a "fake IP") randomly assigned to the virtual network interface card (NIC). By setting the destination address of traffic data (such as the service request message mentioned later) to this pseudo-communication address, the traffic data can be imported into the virtual NIC.
[0080] In step S1022, the service request message is transmitted to the local agent through the virtual network card based on the pseudo communication address.
[0081] The business request message refers to any business request message initiated by the target application after obtaining the IP address based on the DNS request message, using that IP address as the destination address.
[0082] In this step, a DNS response message for the DNS request can be generated through a local proxy based on the pseudo communication address. The DNS response message includes the pseudo communication address. The DNS response message is then transmitted to the target application through the virtual network interface card. After obtaining the service request message through the virtual network interface card based on the pseudo communication address, the service request message is transmitted to the local proxy. The current destination address of the service request message is the pseudo communication address.
[0083] For example, such as Figure 3 As shown, the local agent generates a DNS response message based on a fake IP (71.71.71.101) by executing step S5. Specifically, this DNS response message can be assembled by setting the IP address corresponding to the domain name information accounts.yuming.cn to 71.71.71.101. After transmitting this DNS response message to the operating system kernel layer via the virtual network card, it is further transmitted to the target application (such as...). Figure 3 (Step S6 in the process). After obtaining the fake IP, the target application can send a service request message to the fake IP, such as... Figure 3 As shown, in step S7, the target application sends the service request message with 10.0.0.1:123 as the source address and 71.71.71.101 as the destination address. Since 71.71.71.101 is the pseudo-communication address of the virtual network card, after the service request message is transmitted to the operating system kernel layer, the virtual network card can capture the service request message and send it to the local agent. The above example is only illustrative and is not intended to limit the scope of this disclosure.
[0084] It should be noted that the present disclosure can make the service request message initiated by the target application be captured by the virtual network card by returning the pseudo communication address of the virtual network card to the target application, so as to transmit the service request message to the local agent through the virtual network card, and then add the preset mark to the service request message through the local agent.
[0085] In step S1023, the local agent adds a preset mark to the service request message.
[0086] In this step, the local agent can parse the service request message to obtain the plaintext of the service request message, and then add the preset mark to the header of the plaintext. As shown in Figure 3 , the preset mark can be added to the service request message by performing step S12.
[0087] In the process of parsing the service request message, the local agent can obtain the plaintext of the service request message based on the MITM (Man-in-the-Middle Attack) technology, and send the service request message added with the preset mark to the target server after adding the preset mark (such as Figure 3 , step S13).
[0088] The data packet corresponding to the service request message can be an HTTPS type data packet, and such data packet is usually in the form of ciphertext. In order to add the preset mark in the service request message, the present disclosure can convert the ciphertext of the HTTPS data packet into plaintext through the MITM technology, and then add the preset mark in the plaintext.
[0089] For example, Figure 5 is a process diagram of using MITM to dye data packets according to an exemplary embodiment, and the dyeing of data packets here refers to the process of adding a preset mark to a service request message. As shown in Figure 5As shown, the business request message transmitted from the target application to the local proxy is an encrypted HTTPS data packet. The MITM (Made-to-Manufacturer) in the local proxy has two roles: a MITM server and a MITM client. The MITM server can act as a proxy service for the target server to establish a connection with the target application (i.e., perform the TLS handshake process in the HTTPS protocol), and the MITM client can act as a proxy service for the target application to establish a connection with the target server. Thus, the local proxy can, based on the MITM server and MITM client, interact with the target application and the target server to obtain the decryption data (such as a certificate) used to decrypt the business request message, thereby parsing the message to obtain the plaintext. Furthermore, this disclosure can also use SSL pinning technology to prevent business request messages with preset tags from being modified by untrusted third-party software. The above example is merely illustrative and this disclosure does not limit its scope.
[0090] In yet another possible embodiment of this disclosure, the terminal may also query the domain name information corresponding to the pseudo communication address through a local proxy, determine the real destination address of the target server based on the domain name information, and then record the source address of the service request message and the real destination address corresponding to the source address.
[0091] For example, such as Figure 3 As shown, in step S8, the local agent can query the real destination address abcd from the UDP NAT. Specifically, as... Figure 3 As shown, the UDP NAT records the correspondence between the domain name information accounts.yuming.cn and the target server's real destination address abcd. Therefore, we can first determine that the domain name information corresponding to the pseudo communication address 71.71.71.101 is accounts.yuming.cn, then query the UDP NAT to find the real destination address abcd corresponding to the domain name information accounts.yuming.cn, and record the correspondence between the source address 10.0.0.1:123 and the real destination address abcd:443 of the service request message in the TCP NAT. Here, port 443 is the port of the HTTP protocol. This example is only for illustration and is not intended to limit the scope of this disclosure.
[0092] Figure 6 It is based on Figure 1 The illustrated embodiment shows a flowchart of an application secure connection method, as shown below. Figure 6 As shown, step S103 includes the following sub-steps:
[0093] In step S1031, the source address and destination address of the service request message are modified according to the real destination address and the proxy address of the local proxy.
[0094] As illustrated in the example above, such as Figure 3 As shown, in step S7, the target application sends the service request message with 10.0.0.1:123 as the source address and 71.71.71.101 as the destination address. In order to send the service request message with the preset tag to the target server, and for the target server to also send the second response message of the service request message back to the local proxy, it is necessary to modify the source address and destination address of the service request message.
[0095] For example, such as Figure 3 As shown, by executing step S9, the source address of the service request message is changed from 10.0.0.1:123 to the proxy address of the local proxy 10.0.0.1:4443, and the destination address of the service request message is changed from 71.71.71.101 to the real destination address of the target server abcd:443.
[0096] In step S1032, based on the modified source address and the modified destination address, the service request message with the preset tag is sent to the target server.
[0097] By performing this step, a service request message with a preset tag can be sent to the target server via a local proxy. The target server can then use this preset tag to identify whether the request message was initiated by a preset authorized terminal of the target application. It should be noted that when performing this step, the terminal can also use the `bind.before.connect` method to send the service request message to the target server using its physical network card. This avoids routing loops caused by the service request message being captured again by the virtual network card when sent via a virtual network card.
[0098] It should also be noted that the target application typically initiates this service request message based on TCP (Transmission Control Protocol). After the local proxy obtains this service request message, it modifies the source and destination addresses. The TCP-type service request message can then be returned to the operating system kernel layer for TCP protocol maintenance (such as congestion control and connection control). After passing through the network stack of the operating system kernel layer, the service request message can upgrade the TCP protocol to HTTPS. In this way, the local proxy can obtain the ciphertext of the HTTPS data packets (e.g., ...). Figure 3 Steps S10 and S11 in the process.
[0099] Figure 7 It is based on Figure 1A flowchart of an application security connection method is shown in Figure 7 The method further includes the following steps:
[0100] In step S104, in response to receiving the second response message returned by the target server for the service request message with the preset mark added, the destination address of the second response message is modified to the source address to transmit the second response message to the target application.
[0101] Since the source address of the service request message with the preset mark added is the proxy address 10.0.0.1:4443 of the local proxy, and the destination address is the real destination address a.b.c.d:443 of the target server, the destination address of the second response message returned by the target server for the service request message with the preset mark added is the proxy address 10.0.0.1:4443, and in order to transmit the second response message to the target application, the destination address of the second response message needs to be modified to the source address 10.0.0.1:123 of the service request message initiated by the target application.
[0102] As shown in Figure 3 After step 14, the local proxy of the terminal can receive the second response message, and then the terminal modifies the destination address of the second response message by performing step S15, and then transmits the second response message to the target application based on steps S16 and S17.
[0103] In order to further improve the security mechanism for the user to log in to the target application through the terminal, the disclosure can also detect the risk of the terminal, and send the obtained device risk detection information to the target server together with the service request message with the preset mark added.
[0104] Figure 8 A flowchart of an application security connection method is shown in Figure 1 The method further includes the following steps: Figure 8
[0105] In step S105, the terminal is detected by a preset application process to obtain device risk detection information.
[0106] In this step, the state information of the target security configuration function on the terminal can be obtained, the target security configuration function being at least one preset security configuration function corresponding to the target application, and the device risk detection information is generated according to the state information.
[0107] The target security configuration function can be based on improving the security mechanism of the target application login and preventing the leakage of the corresponding data. This target security configuration function can be pre-configured based on the target application. For example, it can include one or more of the following: application signature verification, screen lock password, automatic screen lock, system firewall, remote login, automatic login, and connection to unencrypted networks. In this way, the terminal can obtain the status information of the target security configuration function through the preset application process. This status information indicates whether the corresponding function is enabled, and the status information of each target security configuration function is used as risk detection information for the device.
[0108] In this way, during the execution of step S103, the device risk detection information and the service request message with the preset tag can be sent to the target server, so that the target server can establish a connection with the target application based on the preset tag and the device risk detection information.
[0109] For example, assuming the target security configuration includes system firewall and remote login functions, it is understandable that if the terminal's system firewall is enabled and the terminal's remote login function is disabled, the risk of data leakage when the terminal logs into the target application is low. Therefore, if the target server determines that the service request message was initiated by a preset authorized terminal based on the preset flag, and the preset authorized terminal's system firewall is enabled and remote login function is disabled, it can determine to establish a secure connection with the target application; otherwise, it will refuse to allow the terminal to log into the target application.
[0110] Based on the above scheme, DNS traffic can be captured by deploying the preset application process on the target application's authorized terminal. After adding preset tags to the corresponding business request messages, control can be achieved over the terminal device logging into the target application. However, for DNS traffic that is not resolved locally (such as browser proxy and system proxy), DNS traffic cannot be captured based on the preset application process. To solve this technical problem, this disclosure allows auditing of traffic passing through the terminal's physical network card to identify the traffic data corresponding to the target application.
[0111] Figure 9 It is based on Figure 1 The illustrated embodiment shows a flowchart of an application secure connection method, as shown below. Figure 9 As shown, the method also includes the following steps:
[0112] In step S106, the target traffic of the target protocol type sent through the physical network card of the terminal is obtained. The target protocol type is the protocol type corresponding to the target application.
[0113] In this step, the physical network card can be subjected to traffic packet capture through libpcap (a library for capturing network packets), and then the target traffic of the target protocol type is filtered based on BPF (Berkeley Packet Filter, a tool for filtering network packets). For example, the target protocol type can be HTTP.
[0114] For example, the target traffic of the HTTP type can be filtered through the BPF syntax , in which tcp indicates that only TCP packets are filtered, tcp[12:1] indicates that the 12th byte of the TCP header is accessed, contains DO and RSV, indicates that the RSV (SYN, ACK) is masked, leaving the upper four bits, indicates that the bit is adjusted by the header length represented by a 32-bit word, and the previous result is divided by 4 to shift to the actual TCP header position, indicates that it is checked whether the first two bits of the TCP header correspond to the ASCII code of CO, such traffic can be regarded as proxy traffic with connect, and such traffic needs to be audited. The example here is only illustrative, and the present disclosure is not limited in this regard.
[0115] It should be noted that by filtering the target traffic of the target protocol type, it is possible to avoid unpacking and searching the payload of all traffic flowing through the physical network card, thereby improving performance and efficiency of traffic auditing.
[0116] In step S107, the target traffic is subjected to traffic auditing.
[0117] In this step, for each piece of target traffic, it can be determined whether the packet content of the traffic includes the preset domain name corresponding to the target application. If it is determined that the packet content of the traffic includes the preset domain name, a target log is generated, which is used to record that the packet content of the traffic includes the preset domain name.
[0118] For example, it can be determined whether the packet content of the traffic includes the preset domain name of accounts.yuming.cn. If so, the piece of traffic is recorded to generate the target log.
[0119] By using this method, the traffic of the target application that bypasses the preset application process can be audited, and the traffic whose packet content includes the preset domain name is recorded to generate the target log, and the user or developer can perform risk assessment based on the target log.
[0120] Figure 10 is a block diagram of an application security connection device according to an example embodiment, as shown in Figure 10As shown, the apparatus comprises:
[0121] The determining module 1001 is configured to determine domain name information corresponding to a domain name system (DNS) request initiated by a terminal.
[0122] The marking module 1002 is configured to add a preset mark to a service request message of a target application via a preset application process in a case where the domain name information is a preset domain name corresponding to the target application, the preset mark being used to identify that the terminal is a preset authorized terminal corresponding to the target application, and the preset application process being an application process deployed on the preset authorized terminal.
[0123] The connecting module 1003 is configured to send the service request message added with the preset mark to a target server corresponding to the target application, so that the target server establishes a connection with the target application according to the preset mark.
[0124] Optionally, the determining module 1001 is configured to acquire the DNS request via the preset application process, parse the DNS request, and then acquire the domain name information in response to the terminal initiating the DNS request.
[0125] Optionally, the preset application process comprises a virtual network card and a domain name acquisition thread, and the determining module 1001 is configured to acquire a DNS data packet of the DNS request from a kernel layer of an operating system of the terminal via the virtual network card, transmit the DNS data packet to the domain name acquisition thread, and parse the DNS data packet via the domain name acquisition thread to obtain the domain name information.
[0126] Optionally, the determining module 1001 is configured to modify a route of the DNS request and acquire the DNS data packet from the kernel layer of the operating system via the virtual network card according to the modified route.
[0127] Optionally, Figure 11 is according to Figure 10 As shown in a block diagram of an application security connection apparatus according to an embodiment, as shown in Figure 11 As shown, the apparatus further comprises:
[0128] The caching module 1004 is configured to send the DNS request to a DNS server, determine a real destination address corresponding to the domain name information according to a first response message returned by the DNS server, and cache the domain name information and the real destination address corresponding to the domain name information.
[0129] Optionally, the preset application process comprises a virtual network card and a local agent; the marking module 1002 is configured to obtain a pseudo-communication address randomly allocated for the virtual network card; transmit the service request message to the local agent through the virtual network card according to the pseudo-communication address; and add the preset mark to the service request message through the local agent.
[0130] Optionally, the marking module 1002 is configured to generate a DNS response message of the DNS request through the local agent according to the pseudo-communication address, wherein the DNS response message comprises the pseudo-communication address; transmit the DNS response message to the target application through the virtual network card; and after obtaining the service request message through the virtual network card according to the pseudo-communication address, transmit the service request message to the local agent, wherein a current destination address of the service request message is the pseudo-communication address.
[0131] Optionally, the marking module 1002 is configured to parse the service request message through the local agent to obtain a plaintext of the service request message; and add the preset mark to a header of the plaintext.
[0132] Optionally, the cache module 1004 is further configured to query the domain name information corresponding to the pseudo-communication address, and determine a real destination address of the target server according to the domain name information; and record a source address of the service request message and the real destination address corresponding to the source address.
[0133] Optionally, the connection module 1003 is configured to modify the source address and the destination address of the service request message according to the real destination address and a proxy address of the local agent; and send the service request message added with the preset mark to the target server based on the modified source address and the modified destination address.
[0134] Optionally, the connection module 1003 is further configured to modify a destination address of a second response message returned by the target server in response to the service request message added with the preset mark to the source address, so as to transmit the second response message to the target application.
[0135] Optionally, Figure 12 is according to Figure 10 a block diagram of an application security connection device shown in the embodiment, as shown in the embodiment, the device further comprises: Figure 12
[0136] a risk detection module 1005 configured to perform risk detection on the terminal through the preset application process to obtain device risk detection information.
[0137] The connection module 1003 is configured to send the device risk detection information and the service request message added with the preset mark to the target server, so that the target server establishes a connection with the target application according to the preset mark and the device risk detection information.
[0138] Optionally, the risk detection module 1005 is configured to acquire state information of a target security configuration function on the terminal, the target security configuration function being at least one preset security configuration function corresponding to the target application; and generate the device risk detection information according to the state information.
[0139] Optionally, Figure 13 is according to Figure 10 a block diagram of an application security connection device shown in the embodiment, as Figure 13 The device further includes:
[0140] The traffic auditing module 1006 is configured to acquire target traffic of a target protocol type sent through a physical network card of the terminal, the target protocol type being a protocol type corresponding to the target application; and perform traffic auditing on the target traffic.
[0141] Optionally, the traffic auditing module 1006 is configured to, for each piece of traffic in the target traffic, determine whether the data packet content of the traffic includes the preset domain name; and in a case where it is determined that the data packet content of the traffic includes the preset domain name, generate a target log, the target log being used to record that the data packet content of the traffic includes the preset domain name.
[0142] Reference will be made to Figure 14 which shows a structural schematic diagram of an electronic device suitable for implementing the embodiments of the present disclosure. The terminal device in the embodiments of the present disclosure can include, but is not limited to, mobile terminals such as mobile phones, notebook computers, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (Tablet Personal Computers), PMPs (Portable Multimedia Players), vehicle-mounted terminals (for example, vehicle-mounted navigation terminals), and the like, and fixed terminals such as digital TVs, desktop computers, and the like. Figure 6 The electronic device shown is merely an example, and should not bring any limitation to the functions and use range of the embodiments of the present disclosure.
[0143] As Figure 6As shown, the electronic device 1400 can include a processing device (e.g., a central processing unit, a graphics processing unit, etc.) 1401 that can perform various appropriate actions and processes according to programs stored in a read-only memory (ROM) 1402 or loaded into a random access memory (RAM) 1403 from a storage device 1408. Various programs and data required by the electronic device 1400 for its operation are also stored in the RAM 1403. The processing device 1401, the ROM 1402, and the RAM 1403 are connected to each other through a bus 1404. An input / output (I / O) interface 1405 is also connected to the bus 1404.
[0144] Generally, the following devices can be connected to the I / O interface 1405: input devices 1406 including, for example, a touch screen, a touch pad, a keyboard, a mouse, a camera, a microphone, an accelerometer, a gyroscope, etc.; output devices 1407 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; storage devices 1408 including, for example, a magnetic tape, a hard disk, etc.; and communication devices 1409. The communication devices 1409 can allow the electronic device 1400 to exchange data with other devices wirelessly or through wires. Although Figure 14 The electronic device 1400 is shown with various devices, but it should be understood that not all of the shown devices are required to be implemented or present. More or fewer devices can alternatively be implemented or present.
[0145] In particular, the processes described above with reference to the flowcharts can be implemented as a computer software program according to embodiments of the present disclosure. For example, embodiments of the present disclosure include a computer program product comprising a computer program carried on a non-transitory computer-readable medium, the computer program containing program code for performing the methods illustrated by the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network through the communication devices 1409, or installed from the storage devices 1408, or installed from the ROM 1402. When the computer program is executed by the processing device 1401, the above-described functions defined in the methods of embodiments of the present disclosure are performed.
[0146] It is noted that the aforementioned computer-readable medium of the present disclosure can be a computer-readable signal medium or a computer-readable storage medium or any combination thereof. The computer-readable storage medium can be, for example and without limitation, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples of the computer-readable storage medium can include, but are not limited to, an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing. In the present disclosure, the computer-readable storage medium can be any tangible medium that contains or stores a program used by or in connection with an instruction execution system, apparatus, or device. In the present disclosure, the computer-readable signal medium can include a computer-readable program code transmitted by a computer-readable storage medium or carried by a carrier wave in a baseband or as part of a carrier wave. Such a propagated computer-readable signal medium can take various forms, including but not limited to electro-magnetic, optical, or any suitable combination thereof. The computer-readable signal medium can also be any computer-readable medium that can be used to carry or store a program for use by or in connection with an instruction execution system, apparatus, or device. The program code contained in the computer-readable medium can be transmitted by any suitable medium, including but not limited to wire, cable, RF (radio frequency), or the like, or any suitable combination of the foregoing.
[0147] In some embodiments, the client can communicate using any currently known or future developed network protocol, such as HTTP (HyperText Transfer Protocol), and can be interconnected with digital data communications (e.g., a communications network) of any form or medium, such as the Internet or World Wide Web. Examples of communications networks include local area networks ("LANs"), wide area networks ("WANs"), internetworks (e.g., the Internet), and peer-to-peer networks (e.g., ad hoc peer-to-peer networks), as well as any currently known or future developed networks.
[0148] The aforementioned computer-readable medium can be included in the aforementioned electronic device; or can exist separately from the electronic device, and not be assembled into the electronic device.
[0149] The computer readable medium described above carries one or more programs, when the one or more programs are executed by the electronic device, cause the electronic device to: in response to a terminal initiating a domain name system (DNS) request, determine domain name information corresponding to the DNS request; in a case where the domain name information is a preset domain name corresponding to a target application, add a preset mark to a service request message of the target application by a preset application process, the preset mark being used to identify that the terminal is a preset authorized terminal corresponding to the target application, and the preset application process being an application process deployed on the preset authorized terminal; and send the service request message added with the preset mark to a target server corresponding to the target application, so that the target server establishes a connection with the target application according to the preset mark.
[0150] Computer program code for carrying out operations of the present disclosure can be written in one or more programming languages or combinations of languages including object oriented programming languages such as Java, Smalltalk, C++ as well as conventional procedural programming languages such as the "C" programming language or similar programming languages. The program code can execute entirely on the user's computer, partly on the user's computer, as a stand-alone software package, partly on the user's computer and partly on a remote computer or entirely on the remote computer or server. In the latter scenario, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection can be made to an external computer (for example, through the Internet using an Internet Service Provider).
[0151] The flow diagrams and the block diagrams in the drawings are illustrations of architectures, functionalities, and operations of possible implementations of systems, methods, and computer program products according to various embodiments of present disclosure. In this regard, each block in the flow diagrams or block diagrams can represent a module, a procedure, or a part of code, which comprises one or more executable instructions for implementing the specified functions. It should also be noted that, in some alternative implementations, the functions noted in the blocks can occur in a different order than that noted in the figures. For example, two blocks noted in succession can in fact be executed substantially concurrently or in the opposite order, depending on the functionality involved. It should also be noted that each block in the block diagrams and / or flow diagrams, and combinations of blocks in the block diagrams and / or flow diagrams, can be implemented by dedicated hardware-based systems that perform the specified functions or operations, or can be implemented by a combination of dedicated hardware-based systems and computer instructions.
[0152] The modules described in the embodiments of the present disclosure can be implemented in the form of software, or can be implemented in the form of hardware. In some cases, the name of the module does not constitute a limitation on the module itself, for example, the module can also be described as a "module for determining domain name information".
[0153] The functions described above in this document can be performed, at least in part, by one or more hardware logic components. For example, and without limitation, example types of hardware logic components that can be used include Field-programmable Gate Arrays (FPGAs), Application-specific Integrated Circuits (ASICs), Application-specific Standard Products (ASSPs), System-on-a-chip systems (SOCs), Complex Programmable Logic Devices (CPLDs), etc.
[0154] In the context of the present disclosure, a machine-readable medium can be a tangible medium that contains or stores a program for use by or in connection with an instruction execution system, apparatus, or device. The machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. The machine-readable medium can include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the above. More specific examples of the machine-readable storage medium will include one or more lines of electrical connections, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or Flash memory), optical fibers, portable compact disc read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the above.
[0155] According to one or more embodiments of the present disclosure, example 1 provides an application security connection method, comprising:
[0156] In response to a terminal initiating a domain name system (DNS) request, determining domain name information corresponding to the DNS request;
[0157] In a case where the domain name information is a preset domain name corresponding to a target application, adding a preset mark to a service request message of the target application through a preset application process, the preset mark being used to identify that the terminal is a preset authorized terminal corresponding to the target application, and the preset application process being an application process deployed on the preset authorized terminal;
[0158] Sending the service request message added with the preset mark to a target server corresponding to the target application, so that the target server establishes a connection with the target application according to the preset mark.
[0159] According to one or more embodiments of the present disclosure, example 2 provides the method of example 1, wherein the domain name information corresponding to the DNS request is determined in response to the terminal initiating the DNS request, comprising: obtaining the DNS request through the preset application process, and obtaining the domain name information after the DNS request is parsed.
[0160] According to one or more embodiments of the present disclosure, example 3 provides the method of example 2, wherein the preset application process comprises a virtual network card and a domain name obtaining thread, and the domain name information is obtained after the DNS request is obtained through the preset application process and parsed, comprising:
[0161] the DNS data packet of the DNS request is obtained from the operating system kernel layer of the terminal through the virtual network card, and the DNS data packet is transmitted to the domain name obtaining thread;
[0162] the domain name information is obtained by parsing the DNS data packet through the domain name obtaining thread.
[0163] According to one or more embodiments of the present disclosure, example 4 provides the method of example 3, wherein the DNS data packet of the DNS request is obtained from the operating system kernel layer of the terminal through the virtual network card, comprising:
[0164] the route of the DNS request is modified;
[0165] the DNS data packet is obtained from the operating system kernel layer through the virtual network card according to the modified route.
[0166] According to one or more embodiments of the present disclosure, example 5 provides the method of example 3, wherein the method further comprises:
[0167] the DNS request is sent to a DNS server;
[0168] the real destination address corresponding to the domain name information is determined according to a first response message returned by the DNS server;
[0169] the domain name information and the real destination address corresponding to the domain name information are cached.
[0170] According to one or more embodiments of the present disclosure, example 6 provides the method of example 1, wherein the preset application process comprises a virtual network card and a local proxy, and the preset mark is added to the service request message of the target application through the preset application process, comprising:
[0171] a pseudo communication address randomly allocated for the virtual network card is obtained;
[0172] transmit the service request message to the local agent via the virtual network card according to the pseudo communication address;
[0173] add the preset mark to the service request message via the local agent.
[0174] According to one or more embodiments of the present disclosure, example 7 provides the method of example 6, wherein the transmitting the service request message to the local agent via the virtual network card according to the pseudo communication address comprises:
[0175] generating a DNS response message of the DNS request via the local agent according to the pseudo communication address, the DNS response message comprising the pseudo communication address;
[0176] transmitting the DNS response message to the target application via the virtual network card;
[0177] According to one or more embodiments of the present disclosure, example 7 provides the method of example 6, wherein the transmitting the service request message to the local agent via the virtual network card according to the pseudo communication address comprises:
[0178] According to one or more embodiments of the present disclosure, example 8 provides the method of example 6, wherein the adding the preset mark to the service request message via the local agent comprises:
[0179] parsing the service request message via the local agent to obtain a plaintext of the service request message;
[0180] adding the preset mark to a header of the plaintext.
[0181] According to one or more embodiments of the present disclosure, example 9 provides the method of example 6, wherein the method further comprises:
[0182] querying the domain name information corresponding to the pseudo communication address, and determining a real destination address of the target server according to the domain name information;
[0183] recording a source address of the service request message and the real destination address corresponding to the source address.
[0184] According to one or more embodiments of the present disclosure, example 10 provides the method of example 9, wherein the transmitting the service request message added with the preset mark to the target server corresponding to the target application comprises:
[0185] modifying a source address and a destination address of the service request message according to the real destination address and a proxy address of the local agent;
[0186] Based on the modified source address and the modified destination address, the service request message with the preset mark added is sent to the target server.
[0187] According to one or more embodiments of the present disclosure, example 11 provides the method of example 9, the method further comprising:
[0188] In response to receiving a second response message returned by the target server for the service request message with the preset mark added, modifying a destination address of the second response message to the source address to transmit the second response message to the target application.
[0189] According to one or more embodiments of the present disclosure, example 12 provides the method of any one of examples 1-11, the method further comprising:
[0190] Performing risk detection on the terminal through the preset application process to obtain device risk detection information;
[0191] Sending the device risk detection information and the service request message with the preset mark added to the target server, so that the target server establishes a connection with the target application according to the preset mark and the device risk detection information.
[0192] According to one or more embodiments of the present disclosure, example 13 provides the method of example 12, the performing risk detection on the terminal through the preset application process to obtain device risk detection information comprising:
[0193] Obtaining state information of a target security configuration function on the terminal, the target security configuration function being at least one preset security configuration function corresponding to the target application;
[0194] Generating the device risk detection information according to the state information.
[0195] According to one or more embodiments of the present disclosure, example 14 provides the method of any one of examples 1-11, the method further comprising:
[0196] Obtaining target traffic of a target protocol type sent through a physical network card of the terminal, the target protocol type being a protocol type corresponding to the target application;
[0197] Performing traffic auditing on the target traffic.
[0198] According to one or more embodiments of the present disclosure, example 15 provides the method of example 14, the performing traffic auditing on the target traffic comprising:
[0199] For each piece of traffic in the target traffic, determining whether the preset domain name is included in a packet content of the traffic.
[0200] In a case where the preset domain name is included in the data packet content of the traffic, a target log is generated, the target log being used to record that the preset domain name is included in the data packet content of the traffic.
[0201] According to one or more embodiments of the present disclosure, example 16 provides an application security connection apparatus, comprising:
[0202] A determination module is configured to determine domain name information corresponding to a DNS request in response to a terminal initiating the DNS request.
[0203] A marking module is configured to add a preset mark to a service request message of a target application by a preset application process in a case where the domain name information is a preset domain name corresponding to the target application, the preset mark being used to identify that the terminal is a preset authorized terminal corresponding to the target application, and the preset application process being an application process deployed on the preset authorized terminal.
[0204] A connection module is configured to send the service request message added with the preset mark to a target server corresponding to the target application, so that the target server establishes a connection with the target application according to the preset mark.
[0205] According to one or more embodiments of the present disclosure, example 17 provides a computer readable medium having a computer program stored thereon, the computer program being executed by a processing apparatus to implement steps of the method of any one of examples 1-15.
[0206] According to one or more embodiments of the present disclosure, example 18 provides an electronic device, comprising:
[0207] A storage device having a computer program stored thereon;
[0208] A processing apparatus configured to execute the computer program in the storage device to implement steps of the method of any one of examples 1-15.
[0209] According to one or more embodiments of the present disclosure, example 19 provides a computer program product comprising a computer program, the computer program being executed by a processor to implement steps of the method of any one of examples 1-15.
[0210] The above description merely illustrates the preferred embodiment of the disclosure and a principle of applied technologies. It should be understood by those skilled in the art that the disclosed range of the disclosure is not limited to the technical solutions formed by the specific combinations of the technical features described above, and should also cover other technical solutions formed by the combinations of the technical features described above or their equivalent features without departing from the disclosed concept. For example, the technical solutions formed by the mutual replacement of the above-described features and the technical features with similar functions disclosed in the disclosure (but not limited to) can be formed.
[0211] Furthermore, although operations are depicted in a particular, sequential order, this should not be understood as requiring or implying that the operations are performed in the order illustrated or sequentially. In certain circumstances, multitasking and parallel processing can be advantageous. Likewise, although specific implementation details are contained in the above discussion, these should not be construed as limiting the scope of the disclosure. Certain features described in the context of separate embodiments can also be implemented in combination in a single embodiment. Conversely, various features described in the context of a single embodiment can also be implemented in multiple embodiments separately or in any suitable sub-combination.
[0212] Although the subject matter has been described in language specific to structural features and / or methodological acts, it is to be understood that the subject defined in the appended claims is not necessarily limited to the specific features or acts described above. Rather, the specific features and acts described above are merely illustrative of specific forms of implementing the claims. With respect to the devices in the above-described embodiments, the specific manner in which the various modules perform operations has been described in detail in the embodiments related to the method, and will not be described here in detail.
Claims
1. A method for applying a secure connection, characterized by, The method comprises: In response to a terminal initiating a domain name system (DNS) request, obtaining the DNS request by a preset application process and resolving the DNS request to obtain domain name information corresponding to the DNS request, wherein the preset application process is an application process deployed on a preset authorized terminal, and the authorized terminal is a terminal device that can log in to a target application; In a case where the domain name information is a preset domain name corresponding to the target application deployed in the terminal, adding a preset mark to a service request message of the target application by the preset application process, the preset mark being used to identify that the terminal is a preset authorized terminal corresponding to the target application; In response to the terminal sending the service request message added with the preset mark to a target server corresponding to the target application, so that the target server establishes a connection with the target application according to the preset mark.
2. The method of claim 1, wherein, The preset application process comprises a virtual network card and a domain name obtaining thread, and the obtaining the DNS request by the preset application process and resolving the DNS request to obtain the domain name information corresponding to the DNS request comprises: After obtaining a DNS data packet of the DNS request from a kernel layer of an operating system of the terminal through the virtual network card, transmitting the DNS data packet to the domain name obtaining thread; Resolving the DNS data packet by the domain name obtaining thread to obtain the domain name information corresponding to the DNS request.
3. The method of claim 2, wherein, The obtaining the DNS data packet of the DNS request from the kernel layer of the operating system of the terminal through the virtual network card comprises: Modifying a route of the DNS request; According to the modified route, obtaining the DNS data packet from the kernel layer of the operating system through the virtual network card.
4. The method of claim 2, wherein, The method further comprises: Sending the DNS request to a DNS server; According to a first response message returned by the DNS server, determining a real destination address corresponding to the domain name information; Caching the domain name information and the real destination address corresponding to the domain name information.
5. The method of claim 1, wherein, The preset application process comprises a virtual network card and a local agent; The adding the preset mark to the service request message of the target application by the preset application process comprises: Obtaining a pseudo-communication address randomly allocated for the virtual network card; According to the pseudo-communication address, transmitting the service request message to the local agent through the virtual network card; Adding the preset mark to the service request message by the local agent.
6. The method of claim 5, wherein, The transmitting the service request message to the local agent through the virtual network card according to the pseudo-communication address comprises: According to the pseudo-communication address, generating a DNS response message of the DNS request by the local agent, the DNS response message comprising the pseudo-communication address; Transmitting the DNS response message to the target application through the virtual network card; After obtaining the service request message through the virtual network card according to the pseudo-communication address, transmitting the service request message to the local agent, a current destination address of the service request message being the pseudo-communication address.
7. The method of claim 5, wherein, The adding the preset mark to the service request message by the local agent comprises: The local agent parses the service request message to obtain the plaintext of the service request message; The preset mark is added to the header of the plaintext.
8. The method of claim 5, wherein, The method further comprises: Inquiring the domain name information corresponding to the pseudo-communication address, and determining the real destination address of the target server according to the domain name information; Recording the source address of the service request message and the real destination address corresponding to the source address.
9. The method of claim 8, wherein, The sending of the service request message added with the preset mark to the target server corresponding to the target application comprises: According to the real destination address and the proxy address of the local agent, modifying the source address and the destination address of the service request message; Based on the modified source address and the modified destination address, the service request message added with the preset mark is sent to the target server.
10. The method of claim 8, wherein, The method further comprises: In response to receiving a second response message returned by the target server for the service request message added with the preset mark, modifying the destination address of the second response message to the source address to transmit the second response message to the target application.
11. The method according to any one of claims 1 to 10, characterized in that, The method further comprises: Performing risk detection on the terminal by the preset application process to obtain device risk detection information; The device risk detection information and the service request message added with the preset mark are sent to the target server, so that the target server establishes a connection with the target application according to the preset mark and the device risk detection information.
12. The method of claim 11, wherein, The performing of risk detection on the terminal by the preset application process to obtain device risk detection information comprises: Obtaining state information of a target security configuration function on the terminal, the target security configuration function being at least one preset security configuration function corresponding to the target application; Generating the device risk detection information according to the state information.
13. The method according to any one of claims 1 to 10, characterized in that, The method further comprises: Obtaining target traffic of a target protocol type sent through a physical network card of the terminal, the target protocol type being a protocol type corresponding to the target application; Performing traffic auditing on the target traffic.
14. The method of claim 13, wherein, The performing of traffic auditing on the target traffic comprises: For each piece of traffic in the target traffic, determining whether the data packet content of the traffic includes the preset domain name; In a case where it is determined that the data packet content of the traffic includes the preset domain name, generating a target log, the target log being used to record that the data packet content of the traffic includes the preset domain name.
15. A safety connection device for use in applications, characterized in that The application security connection device is arranged in a terminal, and the device comprises: A determination module is configured to, in response to a terminal initiating a domain name system (DNS) request, acquire the DNS request by a preset application process, and parse the DNS request to obtain domain name information corresponding to the DNS request, wherein the preset application process is an application process deployed on a preset authorized terminal, and the authorized terminal is a terminal device that can log in to a target application. The marking module is configured to add a preset mark to a service request message of the target application by the preset application process, in a case where the domain name information is a preset domain name corresponding to the target application deployed in the terminal, and the preset mark is used to identify that the terminal is a preset authorized terminal corresponding to the target application. The connecting module is configured to, in response to the terminal sending the service request message with the preset mark to a target server corresponding to the target application, enable the target server to establish a connection with the target application according to the preset mark.
16. A computer readable medium having stored thereon a computer program, characterized in that, The computer program, when executed by a processing device, implements the steps of the method of any one of claims 1-14.
17. An electronic device, comprising: The computer program, when executed by a processing device, implements the steps of the method of any one of claims 1-14. The computer program, when executed by a processing device, implements the steps of the method of any one of claims 1-14. The computer program, when executed by a processing device, implements the steps of the method of any one of claims 1-14.
18. A computer program product comprising a computer program, characterized in that,
Citation Information
Patent Citations
Access controlling method for network application and device thereof
CN102055813A
Business service request processing method and device, electronic equipment and storage medium
CN116566917A