Monitoring system of tianyan monitoring platform domain name malware disposal application
Patent Information
- Application Number
- CN202411792563.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-07
- Publication Date
- 2025-11-21
- Estimated Expiration
- 2044-12-07
AI Technical Summary
其一:人工对域名进行监控中,是通过天眼监测平台下发监控账号,人为对感染恶意域名终端进行监控,但全部流程包括恶意域名终端监控、下线感染终端、通知用户全面杀毒等过程,处置流程多,处置时间长、效率低
[0015]与现有技术相比本发明的有益效果是:本发明通过意域名创建模块、恶意域名分析模块、恶意域名监控模块、恶意域名处置模块、自动提示模块软件单元及相应的方法共同作用下,通过前期管理资料整理入库、监控结果动态关联、网络准入管理系统联动等,极大地提高了发现并处理天眼监测平台恶意域名软件的工作效率,提升了控制系统安全防护水平,并在勒索病毒应急响应、信息安全攻防演练等工作中发挥了较大作用。且为天眼监测平台稳定可靠运行起到了技术支持。
Smart Images

Figure CN119583186B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of Internet, in particular to a sky eye monitoring platform domain name malicious software processing method and an applied monitoring system. BACKGROUND
[0002] The domain name system protocol including the sky eye monitoring platform is an important part of the Internet, mainly provides domain name resolution function, completes the bidirectional mapping of domain name to IP address, and maps the Internet protocol address difficult to remember to the domain name easy to remember. With the rapid development of information technology, the intensity and diversity of network attacks have reached an unprecedented height, which makes the network security problem including the domain name system protocol become one of the core problems faced by the development of the Internet. Specifically, malicious software controls or botnet programs to control the control system of the sky eye monitoring platform and other systems to carry out various unauthorized malicious damage activities, the malicious program and the center of the control system realize connection, realize the purpose of intrusion and damage. At present, the sky eye monitoring platform generally monitors the access of malicious domain names in network traffic, which can to some extent find and locate the computer terminal infected with malicious programs.
[0003] Although the existing technology solves the problem of the control system of the sky eye monitoring platform being damaged by malicious software to some extent, but due to the limitation of technology, there are still the following technical defects. First, the artificial monitoring of domain name is through the sky eye monitoring platform issuing monitoring account, and the infected malicious domain terminal is monitored artificially, but the whole process including malicious domain terminal monitoring, offline infected terminal, informing users to kill virus, etc. The disposal process is long, the disposal time is long, and the efficiency is low. Second, the domain name monitoring result cannot dynamically associate the account data of the monitoring terminal. Specifically, when the sky eye monitoring platform finds the information of the malicious domain terminal, only the IP address, the accessed domain name, the access time and other information are obtained, which cannot dynamically associate with the existing account data of the monitoring terminal, and manual screening and distribution are required, which is low in efficiency. Third, the domain name monitoring result cannot be linked with the network access management system. Specifically, at present, after the network security personnel monitor the information of the malicious domain terminal, manual processing is required, and the emergency response time is long. SUMMARY
[0004] In order to overcome the malicious domain name monitoring and method of the control system and other applications of the existing sky eye monitoring platform, due to the limitation of technology, there are disadvantages as described in the background art, the present application provides a kind of in the related software unit and process under the joint action, through early management data sorting into warehouse, monitoring result dynamic correlation, network access management system linkage etc., greatly improve the work efficiency of discovering and processing sky eye monitoring platform malicious domain name software, improve the security protection level of control system, and play a greater role in ransomware emergency response, information security attack and defense exercise and other work of sky eye monitoring platform domain name malicious software disposal method and the monitoring system of application.
[0005] The technical solution adopted by the technical solution of the present application is:
[0006] The sky eye monitoring platform domain name malicious software disposal method comprises the following steps: S1: through RPA, python programming tool, create the company malicious domain name feature library set collected by the sky eye monitoring platform itself, and periodically and irregularly synchronize the network to the set by the crawler module The malicious domain name feature library of the sky eye platform in the field is to this set;S2: add the data obtained in step S1 to the malicious domain name resolution pointing server IP, automatically push the hosts file of the latest feature library set to all networked sky eye platform PC terminal, and automatically push in real time after the hosts file is updated, so that the server can analyze whether the office computer terminal is infected with malicious domain name in real time;S3: the server uses winpcap.dll to listen to the local data packet, obtains the tcp network list of the client through API, analyzes whether the network connection in the list matches the ip address and port of the server address, and if there is a match, it is preliminarily judged as a malicious process;S4: issue a malicious program processing program, and the server displays a heartbeat message to dispose, and click to get the process, and get the malicious domain name program through the client, and send it to the server, then perform the antivirus process, directly end the process, and rename the file to other format file;S5: automatically generate a malicious domain name infected terminal information table;S6: associate with the access network management system, automatically offline the office computer terminal according to the information table, eliminate the risk of virus spread, and inform the user of the infected terminal of the virus by communication mode, and strengthen the network security awareness propaganda.
[0007] Further, in step S1, the malicious domain name feature library of the field sky eye platform to the company malicious domain name feature library set is a hosts file, and in the specific operation, the domain name already resolved is retained.
[0008] Further, in step S3, the local other first port is also needed to listen to other client modification hosts file and issue antivirus instruction, and the local other second port is used to obtain the file uploaded by the client.
[0009] Further, in the step S4, if it is not determined whether the program is a malicious domain name program, an upload process option can be clicked to upload the file to the cloud for analysis.
[0010] Further, in the step S5, the information table contains the IP address of the infected terminal, the name of the user, the unit and the contact information.
[0011] The monitoring system applied to the domain name malicious software processing method of the Tianyan monitoring platform comprises a malicious domain name creation module, a malicious domain name analysis module, a malicious domain name monitoring module, a malicious domain name processing module and an automatic prompting module installed in a PC terminal matched with the Tianyan monitoring platform.
[0012] Further, the malicious domain name creation module functions to collect the company malicious domain name feature library set collected by the Tianyan monitoring platform itself; the malicious domain name analysis module functions to analyze whether the office computer terminal is infected with a malicious domain name; the malicious domain name monitoring module functions to judge a malicious process program; the malicious domain name processing module is used for processing the malicious domain name program; and the automatic prompting module communicates and prompts the PC terminal personnel infected with the malicious domain name program.
[0013] Further, the communication mode of the automatic prompting module comprises a short message, an email and a telephone mode.
[0014] Further, the malicious domain name processing module can also store the name, time and processing information data of the virus infected by each Tianyan platform, so as to provide a data basis for subsequent judgment of whether the same type of virus is infected and facilitate the management personnel to review the data.
[0015] Compared with the prior art, the beneficial effects of the present application are that: through the joint action of the malicious domain name creation module, the malicious domain name analysis module, the malicious domain name monitoring module, the malicious domain name processing module, the automatic prompting module software unit and the corresponding method, through the pre-management data sorting into the warehouse, the dynamic correlation of the monitoring result, the network access management system linkage and the like, the work efficiency of discovering and processing the malicious domain name software of the Tianyan monitoring platform is greatly improved, the control system security protection level is improved, and a great role is played in the ransomware emergency response, information security attack and defense exercise and the like. And technical support is provided for stable and reliable operation of the Tianyan monitoring platform. BRIEF DESCRIPTION OF DRAWINGS
[0016] Figure 1 is the architecture block diagram of the monitoring system applied to the domain name malicious software processing method of the Tianyan monitoring platform.
[0017] Figure 2 is a malicious domain name creation module workflow diagram of the domain name malicious software processing method of the Tianyan monitoring platform.
[0018] Figure 3It is a malicious domain name analysis module workflow schematic diagram of the domain name malicious software handling method of the Tianyan monitoring platform.
[0019] Figure 4 It is a malicious domain name monitoring module workflow schematic diagram of the domain name malicious software handling method of the Tianyan monitoring platform.
[0020] Figure 5 It is a malicious domain name monitoring module workflow schematic diagram of the domain name malicious software handling method of the Tianyan monitoring platform.
[0021] Figure 6 It is a malicious domain name monitoring module workflow schematic diagram of the domain name malicious software handling method of the Tianyan monitoring platform. DETAILED DESCRIPTION
[0022] Figure 1 As shown, the monitoring system applied by the domain name malicious software handling method of the Tianyan monitoring platform includes a malicious domain name creation module, a malicious domain name analysis module, a malicious domain name monitoring module, a malicious domain name handling module, and an automatic prompting module installed in the PC end of the Tianyan monitoring platform. The malicious domain name creation module functions to collect the company malicious domain name feature library set of the Tianyan monitoring platform itself. The malicious domain name analysis module functions to analyze whether the office computer terminal is infected with a malicious domain name. The malicious domain name monitoring module functions to judge a malicious process program. The malicious domain name handling module is used for processing the malicious domain name program. The automatic prompting module communicates with the PC end personnel infected with the malicious domain name program. The communication mode of the automatic prompting module includes short message, email, and telephone mode. The malicious domain name handling module can also store the name, time, and handling information data of the virus infected by each Tianyan platform, provide data basis for subsequent judgment of whether to be infected with the same type of virus, and facilitate the management personnel to review the data.
[0023] The domain name malicious software handling method of the Tianyan monitoring platform includes the following steps, step one: Figure 2 As shown, the malicious domain name creation module creates the company malicious domain name feature library set collected by the Tianyan monitoring platform itself through RPA and python programming tools, and periodically and irregularly synchronizes the Tianyan platform malicious domain name feature library in the field to the set through the network crawler module and the Internet. Specifically, the Tianyan platform malicious domain name feature library in the field is a hosts file, and the originally resolved domain name is retained in the specific operation. Step two: Figure 3 As shown, the malicious domain name analysis module adds the data obtained in step one to the malicious domain name resolution pointing server IP, automatically pushes the hosts file of the latest feature library set to all Tianyan platform PC terminal ends, and automatically pushes in real time after the hosts file is updated, so that the server can analyze whether the office computer terminal is infected with a malicious domain name in real time. Step three: Figure 4、 5 , 6, the malicious domain name monitoring module server uses winpcap.dll to listen to the local packet, obtains the tcp network list of the client through API (GetExtendedTcpTable), analyzes whether the network connection in the list exists and the ip address and port (80) of the server address match, if there is a match, it is preliminarily judged as a malicious process; Specifically, it also needs to listen to another local port to obtain other client hosts file modification and antivirus instruction issuing, and listen to another local port to obtain the file uploaded by the client. Step four: the malicious program processing program is issued through the malicious domain name processing module, and the service end displays the heartbeat message, which can be disposed, and the process is clicked to obtain the malicious domain name program, and sent to the server, then the antivirus process is carried out, the process is directly ended, and the file is renamed to other format file; Specifically, if it cannot be determined whether the program is a malicious domain name program, the upload process option interface can be clicked to upload the file to the cloud for analysis. Step five: the malicious domain name infected terminal information table is automatically generated through the malicious domain name processing module; Specifically, the information table contains the IP address of the infected terminal, the name of the user, the unit and the contact method. Step six: the automatic prompt module is associated with the access network management system, and the office computer terminal is automatically offline according to the information table, so as to prevent the spread of virus, and the communication mode is used to inform the user of the infected terminal that the virus is infected, the network security awareness is strengthened, and the safety network knowledge of the relevant personnel is improved.
[0024] Figure 1 、 2 , 3, 4, 5, 6, the malicious domain name analysis module, the malicious domain name monitoring module, the malicious domain name processing module, the automatic prompt module software unit and the corresponding method jointly act, through the pre-management data sorting into the warehouse, the dynamic association of the monitoring result, the linkage of the network access management system, etc., the work efficiency of discovering and processing the malicious domain name software of the Tianyan monitoring platform is greatly improved, the safety protection level of the control system is improved, and a great role is played in the work of ransomware emergency response, information security attack and defense exercise. And it plays a technical support for the stable and reliable operation of the Tianyan monitoring platform.
[0025] The above content gives the basic principle and main features of the present application and the advantages of the present application. For those skilled in the art, it is obvious that the present application is limited to the details of the above exemplary embodiments, and can be realized in other specific forms without departing from the spirit or essential characteristics of the present application. Therefore, from any point of view, the embodiments should be regarded as exemplary and non-limiting, the scope of the present application is defined by the appended claims rather than the above description, therefore all changes falling within the meaning and scope of the equivalent elements of the claims are intended to be included in the present application.
[0026] Furthermore, it should be understood that, although the specification is described in terms of embodiments, the embodiments are merely a representative of a single independent technical solution, and the specification is described in this manner only for clarity, and those skilled in the art should consider the specification as a whole, and the technical solutions in the embodiments can also be appropriately combined to form other embodiments that those skilled in the art can understand.
Claims
1. A monitoring system for handling domain malicious software applications using the Tianyan monitoring platform, characterized in that, The system includes a malicious domain name creation module, a malicious domain name analysis module, a malicious domain name monitoring module, a malicious domain name handling module, and an automatic prompting module installed on the PC terminals of the Tianyan monitoring platform. The Tianyan monitoring platform's method for handling malicious domain name malware includes the following steps: S1: The malicious domain name creation module uses RPA and Python programming tools to create a collection of malicious domain name features collected by the Tianyan monitoring platform itself. The crawler module synchronizes the malicious domain name feature database to this collection periodically and irregularly via the network. S2: The malicious domain name analysis module adds the server IP address pointed to by the malicious domain name resolution to the data obtained in step S1. It automatically pushes the hosts file containing the latest feature database to all networked Tianyan monitoring platform PC terminals. Simultaneously, the updated hosts file is automatically pushed in real-time, allowing the server to analyze in real-time whether the Tianyan monitoring platform PC terminals are logged into malicious domain names. S3: Through the malicious domain name monitoring module, the server uses winpcap.dll to listen to local data packets, obtains the client's TCP network list via API, and analyzes whether there are IP addresses and ports matching the server address in the network connections in the list. If a match is found, it is preliminarily determined that the client contains malicious programs. S4: The malicious domain name handling module issues a malicious program processing program. Once the server displays a heartbeat message, the malicious program can be handled. Clicking "Get Process" retrieves the malicious program from the client and sends it to the server for virus removal. S5: The malicious domain name handling module automatically generates a malicious domain name infection terminal information table. S6: The automatic notification module, in conjunction with the access control network management system, automatically disconnects the terminal of the SkyEye monitoring platform PC based on the malicious domain name infection terminal information table and notifies the user of the SkyEye monitoring platform PC terminal of the virus infection via communication.
2. The monitoring system for handling domain name malware using the Tianyan monitoring platform according to claim 1, characterized in that, In step S1, the malicious domain name feature database transmitted from the Tianyan monitoring platform to the company's malicious domain name feature database is the hosts file. In the actual operation, the domain names that have already been resolved are retained.
3. The monitoring system for handling domain name malware using the Tianyan monitoring platform according to claim 1, characterized in that, In step S3, it is also necessary to listen to the first other port on the local machine to obtain the hosts file modified by other clients and the antivirus commands issued, and to listen to the second other port on the local machine to obtain the files uploaded by the clients.
4. The monitoring system for handling domain name malware using the Tianyan monitoring platform according to claim 1, characterized in that, In step S5, the malicious domain name infection terminal information table includes the IP address of the infected terminal, the user's name, their organization, and contact information.
5. The monitoring system for handling domain name malware using the Tianyan monitoring platform according to claim 1, characterized in that, The malicious domain creation module aggregates the malicious domain feature database collected by the Tianyan monitoring platform itself; the malicious domain analysis module analyzes whether the Tianyan monitoring platform's PC terminal has logged into a malicious domain; the malicious domain monitoring module identifies malicious programs; the malicious domain handling module is used to handle malicious programs; and the automatic prompting module provides communication prompts to personnel on the Tianyan monitoring platform's PC terminal that has been infected with malicious programs.
6. The monitoring system for handling domain name malware using the Tianyan monitoring platform according to claim 1, characterized in that, The automatic prompt module can communicate via SMS, email, and telephone.
7. The monitoring system for handling domain name malware using the Tianyan monitoring platform according to claim 1, characterized in that, The malicious domain name handling module can also store the names and times of virus infections on various SkyEye monitoring platforms, as well as handling information data, providing a data basis for subsequent judgment on whether the same type of virus has been infected, and facilitating data access for management personnel.
Citation Information
Patent Citations
Program monitoring method and apparatus
CN105184162A