A monitoring integration system and method for detecting an unlicensed access security network

By analyzing the data volume and configuration information of remote devices through the monitoring unit, and combining background data and forwarding records, unauthorized devices can be accurately identified and blocked from accessing the network. This solves the problem of low detection accuracy in existing technologies and achieves more efficient network security protection.

CN119520099BActive Publication Date: 2025-11-18HENAN YISEC ELECTRONIC TECH CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202411653981.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-19
Publication Date
2025-11-18
Estimated Expiration
2044-11-19

AI Technical Summary

Technical Problem

Existing technologies are insufficient to effectively detect and block complex and covert unauthorized device access, resulting in low detection accuracy.

Method used

The monitoring unit periodically receives data from remote monitoring devices, compares the data volume with configuration information, and combines background data and forwarding records to determine whether the device is unauthorized and takes blocking measures.

Benefits of technology

It improves the accuracy of identifying unauthorized devices, promptly blocks data intrusion and leakage, and ensures network security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119520099B_ABST
    Figure CN119520099B_ABST
Patent Text Reader

Abstract

The present application relates to the technical field of fraud detection, more particularly to a kind of monitoring integration system and method for detecting unauthorised access security network.The method comprises: receiving monitoring data from each remote monitoring device in the security network, and obtaining the sending information of each remote monitoring device;Compare the first data amount in the sending information of each remote monitoring device with the reference data amount, obtain the first comparison result, and determine whether the remote monitoring device is the first unauthorised device according to the first comparison result;When the remote monitoring device is not the first unauthorised device, compare the sending information with the communication record in the forwarding information, and determine whether there is a second unauthorised device near the location of the remote monitoring device;When there is a first unauthorised device or a second unauthorised device, real-time block data sending, and send alarm information to the cloud monitoring platform.The present application solves the problem of low accuracy of security network detection of unauthorised device, and improves the detection accuracy.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of fraud detection technology, and more specifically to an integrated monitoring system and method for detecting unauthorized access to secure networks. Background Technology

[0002] With the continuous development of computer and communication technologies, the types of attacks faced by secure networks are gradually increasing, making network security protection indispensable. Currently, the main security protection methods include firewalls and intrusion detection. A similar existing technology is Chinese Patent Publication No. CN118678356A, which proposes a wireless network intrusion detection method based on an arithmetic optimization algorithm. This method includes: acquiring a dataset of the wireless network to be tested and preprocessing it; specifically, the preprocessing involves normalizing and quantifying the traffic data in the dataset to obtain a preprocessed dataset; and inputting the preprocessed dataset into a final intrusion detection model to obtain the intrusion detection result. Furthermore, similar prior art exists in US Patent Publication No. US20230362173A1, which proposes a satellite communication network intrusion detection system and method. This system may include a non-transitory memory containing a set of instructions, and may also include a processor operatively coupled to the non-transitory memory configured to execute the instruction set. One of these instructions may include acquiring streaming metric data from a satellite network management system; another instruction may include identifying a terminal in an intrusion detection database; yet another instruction may include determining, based on the streaming metric data, whether a confidence score providing an indication of the authenticity of the identified terminal meets or exceeds a predetermined threshold; and yet another instruction may include generating an alarm based on this determination. Both of these patents address the problem of illegal intrusion detection, but they can only filter a portion of intrusion behaviors and cannot handle complex and covert unauthorized device access, resulting in low detection accuracy. Summary of the Invention

[0003] To better address the aforementioned problems, this invention provides an integrated regulatory method for detecting unauthorized access to secure networks, the method comprising the following steps:

[0004] Step S1: The monitoring unit periodically receives monitoring data from each remote monitoring device in the security network and obtains the transmission information of each remote monitoring device. The monitoring unit also obtains the forwarding information when the switch forwards the monitoring data.

[0005] Step S2: Compare the first data volume of the monitoring data in the sent information corresponding to each remote monitoring device with the reference data volume stored in the storage unit, and obtain the first comparison result. When the first comparison result is greater than the first threshold, determine whether the remote monitoring device is the first unauthorized device based on the first comparison result and the configuration information of the remote monitoring device.

[0006] Step S3: When the first comparison result is less than or equal to the first threshold, the monitoring unit compares the monitoring data of each remote monitoring device forwarded by the switch with the corresponding background data at a preset period to obtain a second comparison result, and determines whether the remote monitoring device is a first unauthorized device based on the second comparison result;

[0007] Step S4: When the remote monitoring device is not the first unauthorized device, the monitoring unit compares each of the transmitted information and the corresponding forwarded information, obtains a third comparison result, and determines whether there is a second unauthorized device near the location of the remote monitoring device based on the third comparison result;

[0008] Step S5: When the first unauthorized device and the second unauthorized device exist in the secure network, the monitoring unit takes corresponding measures to block data transmission in real time and sends alarm information to the cloud monitoring platform.

[0009] As a preferred technical solution of the present invention, in step S1, the sending information of the remote monitoring device includes the size of the monitoring data being sent, the sending time, the address of the remote monitoring device, and the destination address of the data being sent; the forwarding information of the switch includes the address of the remote monitoring device corresponding to the forwarded monitoring data, the corresponding monitoring data, the size of the monitoring data, and the receiving time.

[0010] As a preferred embodiment of the present invention, step S2 includes:

[0011] Step S21: Take the size of the monitoring data in the transmitted information corresponding to each of the remote monitoring devices as the first data volume, and obtain the transmission time of the monitoring data;

[0012] Step S22: Compare the first data volume corresponding to the remote monitoring device with the reference data volume stored in the storage unit and corresponding to the remote monitoring device, and obtain the first comparison result. When the first comparison result is greater than the first threshold, send a query command to the corresponding remote monitoring device, wherein the reference data volume corresponds to the same time as the sending time.

[0013] Step S23: After receiving the query command, the remote monitoring device sends configuration information and modification records to the monitoring unit. The monitoring unit uses the modification records to determine whether the configuration information of the remote monitoring device has been modified. If the configuration information of the remote monitoring device has been modified, the monitoring unit calculates the second data volume that the switch forwards to the remote monitoring device in a single transaction based on the data acquisition cycle, single data acquisition volume, and transmission cycle in the configuration information. The monitoring unit calculates the difference between the second data volume and the first data volume. If the configuration information has not been modified or the difference is greater than a set difference, the remote monitoring device is a first unauthorized device; if the difference is less than or equal to the set difference, the remote monitoring device is not a first unauthorized device.

[0014] As a preferred embodiment of the present invention, step S3 includes:

[0015] Step S31: When the first comparison result is less than or equal to the first threshold, the monitoring unit compares the monitoring data of each remote monitoring device forwarded by the switch with the background data corresponding to the remote monitoring device stored in the database at a preset period, and obtains the second comparison result;

[0016] Step S32: When the second comparison result shows that the similarity between the monitoring data and the background data is less than or equal to the first set threshold, the remote monitoring device is the first unauthorized device; otherwise, the remote monitoring device is not the first unauthorized device.

[0017] As a preferred embodiment of the present invention, step S4 includes:

[0018] Step S41: When the remote monitoring device is not the first unauthorized device, the monitoring unit compares the transmission record in the transmission information of each remote monitoring device with the forwarding record in the forwarding information of the switch, and obtains a third comparison result;

[0019] Step S42: When the third comparison result is that the forwarding record includes the sending record of the remote monitoring device, the second unauthorized device is not present at the location of the remote monitoring device; when the third comparison result is that the forwarding record does not completely include the sending record of the remote monitoring device, the second unauthorized device is present near the location of the remote monitoring device.

[0020] As a preferred embodiment of the present invention, step S5 includes:

[0021] When either the first unauthorized device or the second unauthorized device is present in the secure network, the monitoring unit generates alarm information and sends it to the cloud monitoring platform for display. For the first unauthorized device, the monitoring unit blocks its data transmission and updates the authorization information, enabling each remote monitoring device to re-establish a communication connection with the switch through the authorization information. When the second unauthorized device is present near the location of the remote monitoring device, the address information of the second unauthorized device is obtained through the third comparison result, and the second unauthorized device is identified based on the address information. Simultaneously, the communication connection between the remote monitoring device and the second unauthorized device is disconnected.

[0022] As a preferred technical solution of the present invention, in step S3, when the second comparison result is that the similarity between the monitoring data of the remote monitoring device and the background data is greater than the first set threshold and less than or equal to the second set threshold for a duration greater than or equal to a set time, the monitoring data is used as the new background data.

[0023] As a preferred technical solution of the present invention, the monitoring unit also forwards the corresponding monitoring data through the switch according to the authorization period in the authorization information of the remote monitoring device authorized in the security network. After the authorization period expires, the forwarding of the monitoring data is stopped. The switch is a 1-fiber 5-electrical gigabit switch, and the lightning protection standard of the switch's network port is 5KA.

[0024] This invention also provides an integrated monitoring system for detecting unauthorized access to secure networks, the system being used to implement the above-described method, the system comprising:

[0025] The monitoring unit is used to periodically receive monitoring data from various remote monitoring devices in the security network and obtain the transmission information of each of the remote monitoring devices. The monitoring unit also obtains the forwarding information when the switch forwards the monitoring data.

[0026] The switch is used to forward the monitoring data sent by each of the remote monitoring devices;

[0027] The judgment unit is configured to: compare the first data volume of the monitoring data in the transmission information corresponding to each remote monitoring device with the reference data volume stored in the storage unit, and obtain a first comparison result; when the first comparison result is greater than a first threshold, determine whether the remote monitoring device is a first unauthorized device based on the first comparison result and the configuration information of the remote monitoring device; when the first comparison result is less than or equal to the first threshold, compare the monitoring data of each remote monitoring device forwarded by the switch with the corresponding background data through the monitoring unit at a preset period, obtain a second comparison result, and determine whether the remote monitoring device is a first unauthorized device based on the second comparison result; when the remote monitoring device is not a first unauthorized device, compare each transmission information obtained by the monitoring unit with the corresponding forwarding information, obtain a third comparison result, and determine whether there is a second unauthorized device at the location of the remote monitoring device based on the third comparison result.

[0028] The early warning unit is used to take corresponding measures through the monitoring unit to block data transmission in real time and send alarm information to the cloud supervision platform when the first unauthorized device or the second unauthorized device exists in the security network.

[0029] The present invention also provides a computer storage medium storing program instructions, wherein the program instructions, when executed, control the device where the storage medium is located to perform the above-described method.

[0030] Compared with the prior art, the beneficial effects of the present invention are at least as follows:

[0031] This invention compares the first data volume of each remote monitoring device with the corresponding reference data volume using a monitoring unit, obtains a first comparison result, and determines whether the data volume of the remote monitoring device is abnormal, i.e., whether it is a first unauthorized device maliciously occupying bandwidth. If the first comparison result is greater than a first threshold, the remote monitoring device is identified as the first unauthorized device. If the data volume is less than the first threshold, the monitoring data of the remote monitoring device obtained by the switch is compared with the background dataset to determine whether the monitoring area has changed, thereby further determining whether the remote monitoring device is the first unauthorized device. Furthermore, the invention compares the sending records of each remote monitoring device with the forwarding records of the switch to determine whether the data of the remote monitoring device has been illegally obtained by a second unauthorized device. The first unauthorized device can be an unauthorized network camera, an unauthorized multi-NIC device, or other unauthorized terminal devices. The second unauthorized device can be an unauthorized wireless router or other unauthorized access point. When either the first or second unauthorized device exists in the secure network, corresponding measures are taken to prevent data intrusion or data leakage. Through the cooperation of these technical solutions, the detection accuracy of unauthorized devices in the secure network is improved. Attached Figure Description

[0032] Figure 1 This is a flowchart of an integrated regulatory method for detecting unauthorized access to a secure network, as described in this invention.

[0033] Figure 2 This is a structural diagram of an integrated monitoring system for detecting unauthorized access to secure networks according to the present invention. Detailed Implementation

[0034] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the invention.

[0035] This invention provides an integrated monitoring method for detecting unauthorized access to a secure network. The method involves a monitoring unit determining whether the first data volume of each remote monitoring device is abnormal, i.e., whether it is a first unauthorized device maliciously consuming bandwidth, based on the difference between the first data volume and a reference data volume. When the difference is less than a first threshold, the monitoring data of the remote monitoring device obtained by the switch is compared with background data to determine if the monitored area has changed, thereby further determining whether the remote monitoring device is a first unauthorized device. Furthermore, the method compares the transmission records of each remote monitoring device with the forwarding records of the switch to determine whether the data of the remote monitoring device has been illegally obtained by a second unauthorized device. The first unauthorized device can be an unauthorized network camera, an unauthorized multi-NIC device, or other unauthorized terminal devices. The second unauthorized device can be an unauthorized wireless router or other unauthorized access point. When either the first or second unauthorized device exists in the secure network, corresponding measures are taken to prevent data intrusion or data leakage. Figure 1 As shown, the method includes the following steps:

[0036] Step S1: The monitoring unit periodically receives monitoring data from each remote monitoring device in the security network and obtains the transmission information of each remote monitoring device. The monitoring unit also obtains the forwarding information when the switch forwards the monitoring data.

[0037] Specifically, the aforementioned security network includes multiple remote monitoring devices. Each remote monitoring device periodically sends the collected monitoring data to the corresponding port of the aforementioned switch, and the switch forwards the monitoring data to the data server. When the remote monitoring device sends the monitoring data, it also sends a transmission record, i.e., the transmission information, to the monitoring unit. At the same time, when the switch forwards the monitoring data from the remote monitoring device, it also sends the forwarding record, i.e., the forwarding information, to the monitoring unit. The transmission information and the forwarding information of the same remote monitoring device appear in pairs, and the transmission time and reception time correspond. Through the above technical solution, a foundation is laid for determining whether there is a second unauthorized device, i.e., an unauthorized route or other unauthorized access point, near the remote monitoring unit based on the transmission information and the forwarding information.

[0038] Step S2: Compare the first data volume of the monitoring data in the sent information corresponding to each remote monitoring device with the reference data volume stored in the storage unit, and obtain the first comparison result. When the first comparison result is greater than the first threshold, determine whether the remote monitoring device is the first unauthorized device based on the first comparison result and the configuration information of the remote monitoring device.

[0039] Specifically, the size of the monitoring data sent in the information transmitted by the remote monitoring device is used as the first data volume. Simultaneously, the transmission time of the monitoring data is also obtained. The first data volume is compared with the reference data volume, and a first comparison result is obtained. The reference data volume is consistent with the transmission time of the monitoring data. Since the reference data volume is a historical statistical result of the remote monitoring device, under normal circumstances, the difference between the monitoring data volume (i.e., the first data volume) sent by the remote monitoring device within a set time period and the corresponding reference data volume should be less than the first threshold. However, when the remote monitoring device is an unauthorized device (i.e., an unauthorized network camera, an unauthorized multi-NIC device, or other illegal terminal), the first data volume may surge. Another situation is when the configuration information of the remote monitoring device changes, and the configuration information causes a surge in data volume. When the monitoring data is sent for the first time, the second comparison result may exceed the first threshold. Therefore, it is necessary to send a query command through the monitoring unit to obtain the configuration information modification record and configuration information of the remote monitoring device. The modification record is then used to determine whether the configuration information of the remote monitoring device has been modified. If no modification has been made, a surge in the data volume may indicate that an unauthorized camera, an unauthorized multi-NIC device, or other unauthorized terminal has illegally accessed the security network. When the configuration information has been modified, the difference between the modified second data volume sent in a single transmission and the actual first data volume sent is calculated. Based on this difference, it is determined whether the remote monitoring device is the first unauthorized device. Through the above technical solution, it is possible to accurately determine whether the remote monitoring device is the first unauthorized device when the data volume sent by the remote monitoring device surges.

[0040] Step S3: When the first comparison result is less than or equal to the first threshold, the monitoring unit compares the monitoring data of each remote monitoring device forwarded by the switch with the corresponding background data at a preset period to obtain a second comparison result, and determines whether the remote monitoring device is a first unauthorized device based on the second comparison result;

[0041] Specifically, even when the first comparison result is less than or equal to the first threshold (i.e., when the first data volume sent by the remote monitoring device is normal), it does not necessarily mean that the remote monitoring device is an authorized device. The authorization status must still be determined by the monitoring data collected by the remote monitoring device. Therefore, the monitoring unit compares the monitoring data acquired by the switch for each remote monitoring device with the background data stored in the database corresponding to the remote monitoring device at a preset cycle. Since the monitoring area corresponding to each remote monitoring device is fixed, and the monitoring area is bound to the address information of the remote monitoring device, although the monitoring data in the monitoring area changes relative to the background data, the changing portion does not obscure the entire background. There is still a certain correlation between the monitoring data and the background data. Therefore, by comparing the monitoring data corresponding to the remote monitoring device with the background data corresponding to the remote monitoring device stored in the database, and obtaining the second comparison result, that is, the similarity between the monitoring data and the background data, if the similarity is greater than the set threshold, the remote monitoring device is not the first unauthorized device; otherwise, if the similarity is less than or equal to the threshold, the remote monitoring device is the first unauthorized device. The first unauthorized device is an unauthorized network camera, unauthorized multi-NIC device, or other unauthorized terminal that illegally steals the address and permission information of the remote monitoring device and sends illegal data to the switch to impersonate monitoring data. Through the above technical solution, the first unauthorized device can be identified more accurately, thereby improving the accuracy of identifying illegal intrusions into the secure network.

[0042] Step S4: When the remote monitoring device is not the first unauthorized device, the monitoring unit compares each of the transmitted information and the corresponding forwarded information, obtains a third comparison result, and determines whether there is a second unauthorized device near the location of the remote monitoring device based on the third comparison result;

[0043] Specifically, when the aforementioned remote monitoring device is not the first unauthorized device, the aforementioned monitoring unit compares the transmission record in each of the aforementioned remote monitoring devices with the forwarding record in the aforementioned switch forwarding information, and obtains a third comparison result. If the third comparison result is that the transmission record is consistent with the corresponding forwarding record of the aforementioned remote monitoring device, it is considered that there is no second unauthorized device illegally accessing the vicinity of the location of the aforementioned collection device. If the third comparison result is that the transmission record of the aforementioned collection device is inconsistent with the forwarding record of the corresponding aforementioned remote monitoring device, it is still possible that the transmission is sent to the aforementioned second unauthorized device, namely an unauthorized router or other illegal access point. Through the aforementioned technical solution, it is possible to accurately determine whether there is a second unauthorized device at the location of each of the aforementioned remote monitoring devices.

[0044] Step S5: When the first unauthorized device and the second unauthorized device exist in the secure network, the monitoring unit takes corresponding measures to block data transmission in real time and sends alarm information to the cloud monitoring platform.

[0045] Specifically, when the first unauthorized device and the second unauthorized device exist in the aforementioned security network, the monitoring unit generates alarm information and sends it to the display platform for display. For the first unauthorized device, the monitoring unit blocks its data transmission. Simultaneously, it updates authorization information, re-authenticates each remote monitoring device in the security network, and establishes a communication connection with the switch, thereby filtering the first unauthorized device out of the security network. For the second unauthorized device, the address information of the second unauthorized device is obtained through the third comparison result—that is, communication records that exist in the remote monitoring device's transmission records but not in the forwarded data. Based on the address information, the second unauthorized device is identified, and the communication connection between the corresponding remote monitoring device and the second unauthorized device is disconnected, thus achieving data blocking. Through this technical solution, not only can the alarm information be generated and displayed in a timely manner, but the data transmission of unauthorized devices can also be blocked promptly.

[0046] Further, in step S1, the sending information of the remote monitoring device includes the size of the monitoring data being sent, the sending time, the address of the remote monitoring device, and the destination address of the data being sent; the forwarding information of the switch includes the address of the remote monitoring device corresponding to the forwarded monitoring data, the corresponding monitoring data, the size of the monitoring data, and the receiving time.

[0047] Specifically, the aforementioned security network includes multiple remote monitoring devices. When a remote monitoring device sends monitoring data, it also sends a transmission record, i.e., the transmission information, to the monitoring unit. The transmission record includes the address of the remote monitoring device, the size of the monitoring data, the transmission time, and the destination of the monitoring data. Simultaneously, when the switch forwards the monitoring data from the remote monitoring device, it also sends a forwarding record, i.e., the forwarding information, to the monitoring unit. The forwarding information includes the address of the remote monitoring device corresponding to the forwarded monitoring data, the monitoring data itself, the size of the monitoring data, and the time when the monitoring data was received. The transmission information and forwarding information of the same remote monitoring device appear in pairs, and the transmission time and reception time correspond. Through the above technical solution, a foundation is laid for determining whether a second unauthorized device exists near the remote monitoring unit based on the transmission information and the forwarding information.

[0048] Further, step S2 includes:

[0049] Step S21: Take the size of the monitoring data in the transmitted information corresponding to each of the remote monitoring devices as the first data volume, and obtain the transmission time of the monitoring data;

[0050] Step S22: Compare the first data volume corresponding to the remote monitoring device with the reference data volume corresponding to the remote monitoring device stored in the storage unit, and obtain the first comparison result. When the first comparison result is greater than the first threshold, send a query command to the corresponding remote monitoring device, wherein the reference data volume corresponds to the same time as the sending time.

[0051] Step S23: After receiving the query command, the remote monitoring device sends configuration information and modification records to the monitoring unit. The monitoring unit uses the modification records to determine whether the configuration information of the remote monitoring device has been modified. If the configuration information of the remote monitoring device has been modified, the monitoring unit calculates the second data volume that the switch forwards to the remote monitoring device in a single transaction based on the data acquisition cycle, single data acquisition volume, and transmission cycle in the configuration information. The monitoring unit calculates the difference between the second data volume and the first data volume. If the configuration information has not been modified or the difference is greater than a set difference, the remote monitoring device is a first unauthorized device; if the difference is less than or equal to the set difference, the remote monitoring device is not a first unauthorized device.

[0052] Specifically, the first data volume is determined by the size of the monitoring data transmitted in the information sent by the remote monitoring device, i.e., the amount of monitoring data transmitted by the remote monitoring device this time. Simultaneously, the transmission time of the monitoring data is also obtained. The first data volume is compared with the reference data volume corresponding to the remote monitoring device stored in the storage unit, and the first comparison result is obtained. If the second comparison result is greater than the first threshold, the monitoring unit sends a query command to obtain the configuration information modification record and configuration information of the remote monitoring device. The modification record is used to determine whether the configuration information of the remote monitoring device has been modified. If no modification has occurred, a surge in the data volume may indicate an unauthorized camera or an unauthorized multi-NIC device. Alternatively, if other unauthorized terminals illegally access the aforementioned security network, when the configuration information is modified, the ratio of the sending period to the data acquisition period in the configuration information is calculated, and the product of the ratio and the amount of data acquired in a single instance is used as the second data amount that the switch forwards to the remote monitoring device in a single instance. The difference between the second data amount and the first data amount is calculated, that is, the difference between the modified single-transmission data amount and the actual data amount sent. When the difference between the two is small, the remote monitoring device may be a normal and legitimate device. When the difference is large, that is, greater than the set difference, the remote monitoring device is the first unauthorized device. Through the above technical solution, it is possible to accurately determine whether the remote monitoring device is the first unauthorized device when the amount of data sent by the remote monitoring device surges.

[0053] Further, step S3 includes:

[0054] Step S31: When the first comparison result is less than or equal to the first threshold, the monitoring unit compares the monitoring data of each remote monitoring device forwarded by the switch with the background data corresponding to the remote monitoring device stored in the database at a preset period, and obtains the second comparison result;

[0055] Step S32: When the second comparison result shows that the similarity between the monitoring data and the background data is less than or equal to the first set threshold, the remote monitoring device is the first unauthorized device; otherwise, the remote monitoring device is not the first unauthorized device.

[0056] Specifically, even when the first comparison result is less than or equal to the first threshold (i.e., when the first data volume sent by the remote monitoring device is normal), it does not necessarily mean that the remote monitoring device is an authorized device. The authorization status must still be determined by the monitoring data collected by the remote monitoring device. Therefore, the monitoring unit compares the monitoring data acquired by the switch for each remote monitoring device with the background data stored in the database corresponding to the remote monitoring device at a preset cycle. Since the monitoring area corresponding to each remote monitoring device is fixed, and the monitoring area is bound to the address information of the remote monitoring device, although the monitoring data in the monitoring area changes relative to the background data, the changing portion does not obscure the entire background. There is still a certain correlation between the monitoring data and the background data. Therefore, by comparing the monitoring data corresponding to the remote monitoring device with the background data corresponding to the remote monitoring device stored in the database, and obtaining the second comparison result, that is, the similarity between the monitoring data and the background data, if the similarity is greater than the set threshold, the remote monitoring device is not the first unauthorized device; otherwise, if the similarity is less than or equal to the threshold, the remote monitoring device is the first unauthorized device. The first unauthorized device is an unauthorized network camera, unauthorized multi-NIC device, or other unauthorized terminal that illegally steals the address and permission information of the remote monitoring device and sends illegal data to the switch to impersonate monitoring data. Through the above technical solution, the first unauthorized device can be identified more accurately, thereby improving the accuracy of identifying illegal intrusions into the secure network.

[0057] Further, step S4 includes:

[0058] Step S41: When the remote monitoring device is not the first unauthorized device, the monitoring unit compares the transmission record in the transmission information of each remote monitoring device with the forwarding record in the forwarding information of the switch, and obtains a third comparison result;

[0059] Step S42: When the third comparison result is that the forwarding record includes the sending record of the remote monitoring device, the second unauthorized device is not present at the location of the remote monitoring device; when the third comparison result is that the forwarding record does not completely include the sending record of the remote monitoring device, the second unauthorized device is present near the location of the remote monitoring device.

[0060] Specifically, when the aforementioned remote monitoring device is not the first unauthorized device, the monitoring unit compares the transmission record in each of the aforementioned remote monitoring devices with the forwarding record in the forwarding information of the aforementioned switch, and obtains a third comparison result, that is, whether all the monitoring data of the aforementioned remote monitoring devices has been sent to the aforementioned switch. When all the monitoring data of the aforementioned remote monitoring devices has been sent to the aforementioned switch, that is, when the third comparison result is that the transmission record is consistent with the corresponding forwarding record of the aforementioned remote monitoring device, it is considered that there is no second unauthorized device illegally accessing the vicinity of the location of the aforementioned collection device. When the third comparison result is that the transmission record of the aforementioned collection device is inconsistent with the forwarding record of the corresponding aforementioned remote monitoring device, that is, when the forwarding record does not completely include the transmission record, that is, the data sent by the aforementioned remote monitoring device is not completely sent to the aforementioned switch, but may also be sent to the aforementioned second unauthorized device, namely an unauthorized router or other illegal access point. Through the above technical solution, it is possible to accurately determine whether there is a second unauthorized device at the location of each of the aforementioned remote monitoring devices.

[0061] Further, step S5 includes:

[0062] When either the first unauthorized device or the second unauthorized device is present in the secure network, the monitoring unit generates alarm information and sends it to the cloud monitoring platform for display. For the first unauthorized device, the monitoring unit blocks its data transmission and updates the authorization information, enabling each remote monitoring device to re-establish a communication connection with the switch through the authorization information. When the second unauthorized device is present near the location of the remote monitoring device, the address information of the second unauthorized device is obtained through the third comparison result, and the second unauthorized device is identified based on the address information. Simultaneously, the communication connection between the remote monitoring device and the second unauthorized device is disconnected.

[0063] Specifically, when the aforementioned first unauthorized device and the aforementioned second unauthorized device exist in the aforementioned security network, the aforementioned monitoring unit generates alarm information and sends the alarm information to the aforementioned display platform for display. The alarm information includes the address information and IP information of the aforementioned first unauthorized device and / or the aforementioned second unauthorized device. For the aforementioned first unauthorized device, the aforementioned monitoring unit blocks the data transmission of the aforementioned first unauthorized device, i.e., disconnects the communication connection. Simultaneously, it updates the authorization information and re-authenticates each of the aforementioned remote monitoring devices in the aforementioned security network, establishing a communication connection with the switch, thereby filtering the aforementioned first unauthorized device out of the aforementioned security network. For the aforementioned second unauthorized device, the address information of the aforementioned second unauthorized device is obtained through the aforementioned third comparison result, i.e., communication records that exist in the remote monitoring device's transmission records but do not exist in the aforementioned forwarded data. Based on the address information, the aforementioned second unauthorized device is identified, and the communication connection between the corresponding remote monitoring device and the aforementioned second unauthorized device is disconnected, thereby achieving data blocking. Through the above technical solution, not only can the aforementioned alarm information be generated and displayed in a timely manner, but the data transmission of unauthorized devices can also be blocked in a timely manner.

[0064] Further, in step S3, when the second comparison result shows that the similarity between the monitoring data of the remote monitoring device and the background data is greater than the first set threshold and less than or equal to the second set threshold for a duration greater than or equal to a set time, the monitoring data is used as the new background data.

[0065] Specifically, when the second comparison result shows that the similarity between the monitoring data of the remote monitoring device and the background data is greater than the first set threshold and less than or equal to the second set threshold (e.g., the first set threshold is 90%, the second set threshold is 97%), and this state lasts for more than a set time (e.g., 5 minutes), it is considered that the content of the monitoring area corresponding to the remote monitoring device has changed. In order to more accurately identify the first unauthorized device, the monitoring data is used as the new background data and replaces the background data in the database. Through the above technical solution, the identification accuracy of the first unauthorized device is further improved.

[0066] Furthermore, the monitoring unit also forwards the corresponding monitoring data through the switch according to the authorization period in the authorization information of the remote monitoring device authorized in the security network. After the authorization period expires, the forwarding of the monitoring data is stopped. The switch is a 1-fiber 5-electrical gigabit switch, and the surge protection standard of the switch's network port is 5KA.

[0067] This invention also provides an integrated monitoring system for detecting unauthorized access to secure networks, the system being used to implement the above-described method, such as... Figure 2 As shown, the system includes:

[0068] The monitoring unit is used to periodically receive monitoring data from various remote monitoring devices in the security network and obtain the transmission information of each of the remote monitoring devices. The monitoring unit also obtains the forwarding information when the switch forwards the monitoring data.

[0069] The switch is used to forward the monitoring data sent by each of the remote monitoring devices;

[0070] The judgment unit is configured to: compare the first data volume of the monitoring data in the transmission information corresponding to each remote monitoring device with the reference data volume stored in the storage unit, and obtain a first comparison result; when the first comparison result is greater than a first threshold, determine whether the remote monitoring device is a first unauthorized device based on the first comparison result and the configuration information of the remote monitoring device; when the first comparison result is less than or equal to the first threshold, compare the monitoring data of each remote monitoring device forwarded by the switch with the corresponding background data through the monitoring unit at a preset period, obtain a second comparison result, and determine whether the remote monitoring device is a first unauthorized device based on the second comparison result; when the remote monitoring device is not a first unauthorized device, compare each transmission information obtained by the monitoring unit with the corresponding forwarding information, obtain a third comparison result, and determine whether there is a second unauthorized device at the location of the remote monitoring device based on the third comparison result.

[0071] The early warning unit is used to take corresponding measures through the monitoring unit to block data transmission in real time and send alarm information to the cloud supervision platform when the first unauthorized device or the second unauthorized device exists in the security network.

[0072] The present invention also provides a computer storage medium storing program instructions, wherein the program instructions, when executed, control the device where the storage medium is located to perform the above-described method.

[0073] In summary, this invention compares the first data volume of each remote monitoring device with the corresponding reference data volume using a monitoring unit, obtains a first comparison result, and determines whether the data volume of the remote monitoring device is abnormal, i.e., whether it is a first unauthorized device maliciously occupying bandwidth. When the first comparison result is greater than a first threshold, the remote monitoring device is identified as the first unauthorized device. When the data volume is less than the first threshold, the monitoring data of the remote monitoring device obtained by the switch is compared with the background dataset to determine whether the monitoring area has changed, thereby further determining whether the remote monitoring device is the first unauthorized device. Furthermore, the invention compares the sending records of each remote monitoring device with the forwarding records of the switch to determine whether the data of the remote monitoring device has been illegally obtained by a second unauthorized device. The first unauthorized device can be an unauthorized network camera or an unauthorized multi-NIC device, or other unauthorized terminal devices. The second unauthorized device can be an unauthorized wireless router or other unauthorized access point. When the first or second unauthorized device exists in the secure network, corresponding measures are taken to prevent data intrusion or data leakage. Through the cooperation of the above technical solutions, the identification accuracy of unauthorized devices in the secure network is improved.

[0074] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0075] The above-described embodiments are merely illustrative of several implementations of the present invention, and while the descriptions are specific and detailed, they should not be construed as limiting the scope of the present invention. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of the present invention, and these modifications and improvements all fall within the scope of protection of the present invention. Therefore, the scope of protection of this patent should be determined by the appended claims.

[0076] The above description is merely a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.

Claims

1. A method for integrated supervision of detecting unauthorized access to secure networks, characterized in that, The method includes the following steps: Step S1: The monitoring unit periodically receives monitoring data from each remote monitoring device in the security network and obtains the transmission information of each remote monitoring device. The monitoring unit also obtains the forwarding information when the switch forwards the monitoring data. Step S2: Compare the first data volume of the monitoring data in the sent information corresponding to each remote monitoring device with the reference data volume stored in the storage unit, and obtain the first comparison result. When the first comparison result is greater than the first threshold, determine whether the remote monitoring device is the first unauthorized device based on the first comparison result and the configuration information of the remote monitoring device. Step S3: When the first comparison result is less than or equal to the first threshold, the monitoring unit compares the monitoring data of each remote monitoring device forwarded by the switch with the corresponding background data at a preset period to obtain a second comparison result, and determines whether the remote monitoring device is a first unauthorized device based on the second comparison result; Step S4: When the remote monitoring device is not the first unauthorized device, the monitoring unit compares each of the transmitted information and the corresponding forwarded information, obtains a third comparison result, and determines whether there is a second unauthorized device near the location of the remote monitoring device based on the third comparison result; Step S5: When the first unauthorized device and the second unauthorized device exist in the secure network, the monitoring unit takes corresponding measures to block data transmission in real time and sends alarm information to the cloud monitoring platform.

2. The method according to claim 1, characterized in that, In step S1, the sending information of the remote monitoring device includes the size of the monitoring data being sent, the sending time, the address of the remote monitoring device, and the destination address. The forwarding information of the switch includes the address of the remote monitoring device corresponding to the forwarded monitoring data, the corresponding monitoring data, the size of the monitoring data, and the receiving time.

3. The method according to claim 1, characterized in that, Step S2 includes: Step S21: Take the size of the monitoring data in the transmitted information corresponding to each of the remote monitoring devices as the first data volume, and obtain the transmission time of the monitoring data; Step S22: Compare the first data volume corresponding to the remote monitoring device with the reference data volume stored in the storage unit and corresponding to the remote monitoring device, and obtain the first comparison result. When the first comparison result is greater than the first threshold, send a query command to the corresponding remote monitoring device, wherein the reference data volume corresponds to the same time as the sending time. Step S23: After receiving the query command, the remote monitoring device sends configuration information and modification records to the monitoring unit. The monitoring unit uses the modification records to determine whether the configuration information of the remote monitoring device has been modified. If the configuration information of the remote monitoring device has been modified, the monitoring unit calculates the second data volume that the switch forwards to the remote monitoring device in a single transaction based on the data acquisition cycle, single data acquisition volume, and transmission cycle in the configuration information. The monitoring unit calculates the difference between the second data volume and the first data volume. If the configuration information has not been modified or the difference is greater than a set difference, the remote monitoring device is a first unauthorized device; if the difference is less than or equal to the set difference, the remote monitoring device is not a first unauthorized device.

4. The method according to claim 1, characterized in that, Step S3 includes: Step S31: When the first comparison result is less than or equal to the first threshold, the monitoring unit compares the monitoring data of each remote monitoring device forwarded by the switch with the background data corresponding to the remote monitoring device stored in the database at a preset period, and obtains the second comparison result; Step S32: When the second comparison result shows that the similarity between the monitoring data and the background data is less than or equal to the first set threshold, the remote monitoring device is the first unauthorized device; otherwise, the remote monitoring device is not the first unauthorized device.

5. The method according to claim 1, characterized in that, Step S4 includes: Step S41: When the remote monitoring device is not the first unauthorized device, the monitoring unit compares the transmission record in the transmission information of each remote monitoring device with the forwarding record in the forwarding information of the switch, and obtains a third comparison result; Step S42: When the third comparison result is that the forwarding record includes the sending record of the remote monitoring device, the second unauthorized device is not present at the location of the remote monitoring device; when the third comparison result is that the forwarding record does not completely include the sending record of the remote monitoring device, the second unauthorized device is present near the location of the remote monitoring device.

6. The method according to claim 1, characterized in that, Step S5 includes: When either the first unauthorized device or the second unauthorized device is present in the secure network, the monitoring unit generates alarm information and sends it to the cloud monitoring platform for display. For the first unauthorized device, the monitoring unit blocks its data transmission and updates the authorization information, enabling each remote monitoring device to re-establish a communication connection with the switch through the authorization information. When the second unauthorized device is present near the location of the remote monitoring device, the address information of the second unauthorized device is obtained through the third comparison result, and the second unauthorized device is identified based on the address information. Simultaneously, the communication connection between the remote monitoring device and the second unauthorized device is disconnected.

7. The method according to claim 1, characterized in that, In step S3, when the second comparison result shows that the similarity between the monitoring data of the remote monitoring device and the background data is greater than a first set threshold and less than or equal to a second set threshold for a duration greater than or equal to a set time, the monitoring data is used as the new background data.

8. The method according to claim 1, characterized in that, The monitoring unit also forwards the corresponding monitoring data through the switch according to the authorization period in the authorization information of the remote monitoring device authorized in the security network. After the authorization period expires, the forwarding of the monitoring data is stopped. The switch is a 1-fiber 5-electrical gigabit switch, and the lightning protection standard of the switch's network port is 5KA.

9. A monitoring system for detecting unauthorized access to a secure network, the system being used to implement the method as described in any one of claims 1-8, characterized in that, The system includes: The monitoring unit is used to periodically receive monitoring data from various remote monitoring devices in the security network and obtain the transmission information of each of the remote monitoring devices. The monitoring unit also obtains the forwarding information when the switch forwards the monitoring data. The switch is used to forward the monitoring data sent by each of the remote monitoring devices; The judgment unit is configured to: compare the first data volume of the monitoring data in the transmission information corresponding to each remote monitoring device with the reference data volume stored in the storage unit, and obtain a first comparison result; when the first comparison result is greater than a first threshold, determine whether the remote monitoring device is a first unauthorized device based on the first comparison result and the configuration information of the remote monitoring device; when the first comparison result is less than or equal to the first threshold, compare the monitoring data of each remote monitoring device forwarded by the switch with the corresponding background data through the monitoring unit at a preset period, obtain a second comparison result, and determine whether the remote monitoring device is a first unauthorized device based on the second comparison result; when the remote monitoring device is not a first unauthorized device, compare each transmission information obtained by the monitoring unit with the corresponding forwarding information, obtain a third comparison result, and determine whether there is a second unauthorized device at the location of the remote monitoring device based on the third comparison result. The early warning unit is used to take corresponding measures through the monitoring unit to block data transmission in real time and send alarm information to the cloud monitoring platform when the first unauthorized device and the second unauthorized device are present in the security network.

10. A computer storage medium, characterized in that, The storage medium stores program instructions, wherein when the program instructions are executed, the device containing the storage medium is controlled to perform the method described in any one of claims 1-8.

Citation Information

Patent Citations

  • Wireless network intrusion detection method based on arithmetic optimization algorithm

    CN118678356A

  • Satellite communications network intrusion detection systems and methods

    US20230362173A1

  • Digital camera intrusion detection and defense system

    CN107590935A

  • Intrusion detection apparatus and method for securing wireless sensor networks

    KR1020130020406A