Network defense method, network defense module and network switch
Patent Information
- Application Number
- CN202411620318.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-13
- Publication Date
- 2026-09-11
- Estimated Expiration
- 2044-11-13
AI Technical Summary
然而,传统的网络防御装置主要针对单一网络威胁进行防御,对于复杂情况下的网络威胁的防御效果不佳,网络安全可靠性差
[0032]The aforementioned network defense method is executed by a network defense module deployed on a network switch. This module acquires traffic collected by the network switch, processes and analyzes the acquired traffic to identify network threats, and then implements defenses. The traffic acquired by the network defense module of this disclosure includes both lateral traffic within the internal network and vertical traffic between the internal and external networks. Therefore, this disclosure can determine network threats within the internal network and network threats between the internal and external networks through traffic analysis. These network threats include both known and unknown threats within the network.
Smart Images

Figure CN119675901B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network security technology, and in particular to a network defense method, a network defense module, and a network switch. Background Technology
[0002] With the development of computer technology, information technology, and network technology, and the gradual popularization of internet applications, people's production and lives have become much more convenient. However, the rapid development of internet technology has also brought enormous challenges to network security.
[0003] In response to the increasingly prominent cybersecurity issues, network defense technologies are constantly improving, and various network defense measures are emerging one after another. However, traditional network defense devices mainly target single network threats and are ineffective against network threats in complex situations, resulting in poor network security reliability. Summary of the Invention
[0004] Therefore, it is necessary to provide a network defense method, network defense module, and network switch that can improve network security reliability in response to the above-mentioned technical problems.
[0005] To achieve the above objectives, in a first aspect, some embodiments of this disclosure provide a network defense method, which is executed by a network defense module deployed on a network switch. The network defense method includes:
[0006] Acquire the horizontal and vertical traffic collected by the network switch. Horizontal traffic represents the traffic in the internal network, and vertical traffic represents the traffic between the internal and external networks.
[0007] Analyze and process lateral and longitudinal traffic to identify network threats within the internal network and between internal and external networks. These network threats include both known and unknown threats.
[0008] In some embodiments of this disclosure, lateral and longitudinal traffic are analyzed and processed to determine network threats within the internal network and between internal and external networks, including:
[0009] When the network defense module obtains lateral and vertical traffic through mirrored traffic, it analyzes the lateral traffic based on machine learning methods to identify known threats in the internal network, and identifies known threats in the internal and external networks based on the network threat database in the vertical traffic.
[0010] When the network defense module is connected to the internal network as a network device, the detection container on the network defense module determines known threats in the internal network and known threats in both internal and external networks, and the mimicry executor on the network defense module detects unknown threats in the internal network and unknown threats in both internal and external networks.
[0011] In some embodiments of this disclosure, a mimicry execution entity on the network defense module is used to detect unknown threats in the internal network and unknown threats in both internal and external networks, including:
[0012] In the network defense module, open execution entities and hidden execution entities are deployed on the target operating system, with the open execution entities exposed on the internal network.
[0013] The system runs the same process on both the open and hidden executables and acquires the system resources of both the open and hidden executables in real time. If the difference between the first resource parameter corresponding to the open executable and the second resource parameter corresponding to the hidden executable exceeds a preset threshold, it is determined that the internal network poses an unknown threat to the target operating system.
[0014] In some embodiments of this disclosure, the known threats in the internal network and the known threats in the internal and external networks are determined by a detection container on the network defense module, including:
[0015] Acquire known threat data and extract attack characteristics from known threats, and determine several detection containers based on the attack characteristics;
[0016] Each detection container is deployed in the internal network through the network defense module. The detection containers are used to identify known threats in the internal network that correspond to the type of the detection container, and to identify known network threats in both the internal and external networks that correspond to the type of the detection container.
[0017] In some embodiments of this disclosure, known threat data is acquired and attack features are extracted from the known threats. Based on the attack features, several detection containers are determined, including:
[0018] Obtain abnormal network data collected by the open execution entity on the network defense module, extract attack characteristics from the abnormal network data, and generate a detection container.
[0019] In some embodiments of this disclosure, lateral traffic is analyzed using machine learning methods to identify known threats in the internal network, including:
[0020] Obtain the traffic identification model, which is trained based on historical horizontal traffic.
[0021] The lateral traffic is input into the traffic identification model, and abnormal traffic in the lateral traffic is identified based on the traffic identification model. Known threats in the internal network are then determined through the abnormal traffic.
[0022] In some embodiments of this disclosure, the method further includes:
[0023] Extract network feature data from lateral traffic; analyze and correlate network feature data to determine the connection relationships of devices in the intranet network, and determine the network topology of the intranet network based on the connection relationships.
[0024] Identify the target network threat, determine the target isolation domain where the target network threat is located based on the network topology, and isolate the target isolation domain to prevent the target network threat from threatening other devices in the internal network.
[0025] Secondly, some embodiments of this disclosure provide a network defense module, which is deployed on a network switch and includes:
[0026] The traffic mirroring unit is configured to acquire the horizontal and vertical traffic collected by the network switch. The horizontal traffic represents the traffic in the internal network, and the vertical traffic represents the traffic between the internal and external networks.
[0027] The computing unit is configured to analyze and process lateral and longitudinal traffic to identify network threats within the internal network and between internal and external networks, including known and unknown threats.
[0028] In some embodiments of this disclosure, the computing unit includes:
[0029] The first processing subunit is configured to acquire lateral and longitudinal traffic through mirrored traffic, analyze the lateral traffic based on machine learning methods to identify known threats in the intranet network, and identify known threats in the intranet network and known threats in the internal and external networks based on the network threat database in the longitudinal traffic.
[0030] The second processing subunit is configured to connect the network defense module as a network device to the intranet network, so as to identify known threats in the intranet network and known threats in the internal and external networks through the detection container on the network defense module, and to detect unknown threats in the intranet network and unknown threats in the internal and external networks through the mimicry executor on the network defense module.
[0031] Thirdly, some embodiments of this disclosure provide a network switch on which the network defense module provided in the second aspect is deployed.
[0032] The aforementioned network defense method is executed by a network defense module deployed on a network switch. This module acquires traffic collected by the network switch, processes and analyzes the acquired traffic to identify network threats, and then implements defenses. The traffic acquired by the network defense module of this disclosure includes both lateral traffic within the internal network and vertical traffic between the internal and external networks. Therefore, this disclosure can determine network threats within the internal network and network threats between the internal and external networks through traffic analysis. These network threats include both known and unknown threats within the network.
[0033] This disclosed network defense method directly defends against network threats at the network switch, directly acquiring network traffic within the network switch and simultaneously defending against network threats within the internal network and between internal and external networks. Compared to traditional methods that primarily target single network threats, this disclosure can simultaneously identify and defend against network threats in both lateral and vertical traffic, resulting in high reliability. The network defense module proposed in this disclosure has a simple structure, low maintenance costs, and good applicability. Attached Figure Description
[0034] To more clearly illustrate the technical solutions in the embodiments or related technologies of this application, the accompanying drawings used in the description of the embodiments or related technologies will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0035] Figure 1 This is a flowchart illustrating the network defense method in some embodiments;
[0036] Figure 2 This is a schematic diagram of the mimicry camouflage topology in some embodiments;
[0037] Figure 3 This is a schematic diagram of the mimicry and camouflage threat assessment process in some embodiments;
[0038] Figure 4 This is a schematic diagram of the network defense module in some embodiments;
[0039] Figure 5 This is a schematic diagram illustrating the deployment of the network defense module in some specific embodiments;
[0040] Figure 6 This is a connection diagram of the network defense module in some embodiments;
[0041] Figure 7 This is a schematic diagram illustrating the process of deploying a network defense module in one embodiment.
[0042] Explanation of reference numerals in the attached figures:
[0043] 100. Network defense module; 10. First processing subunit; 20. Second processing subunit. Detailed Implementation
[0044] To facilitate understanding of this disclosure, a more complete description will now be given with reference to the accompanying drawings, in which preferred embodiments of the present disclosure are shown. However, this disclosure may be implemented in many different forms and is not limited to the embodiments described herein. Rather, these embodiments are provided so that this disclosure will be thorough and complete.
[0045] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this disclosure belongs. The terminology used herein is for the purpose of describing particular embodiments only and is not intended to be limiting of this disclosure.
[0046] It is understood that the terms "first," "second," etc., used in this application may be used herein to describe various elements, but these elements are not limited by these terms. These terms are only used to distinguish one element from another. For example, without departing from the scope of this application, a first module may be referred to as a second module, and similarly, a second module may be referred to as a first module. Both the first module and the second module are modules, but they are not the same module.
[0047] It should be understood that when one element is considered to be "connected" to another element, it can be directly connected to the other element or connected to the other element through an intermediary element. Furthermore, in the following embodiments, "connection" should be understood as "electrical connection," "communication connection," etc., if there is a transmission of electrical signals or data between the connected objects.
[0048] It should be understood that "at least one" means one or more, and "multiple" means two or more. "At least a part of an element" means part or all of an element. The singular forms "a," "an," and "the" may also include the plural forms unless the context clearly indicates otherwise. It should also be understood that the terms "comprising / including" or "having," etc., specify the presence of the stated features, integrals, steps, operations, components, parts, or combinations thereof, but do not preclude the possibility of the presence or addition of one or more other features, integrals, steps, operations, components, parts, or combinations thereof.
[0049] Current cyber threat methods are ineffective against complex cyber threats, resulting in poor network security reliability. For example... Figure 1As shown, in some embodiments, a network defense method is provided, which is executed by a network defense module 100 deployed on a network switch. The network defense method includes steps 102 to 104. Wherein:
[0050] Step 102: Obtain the horizontal and vertical traffic collected by the network switch. Horizontal traffic represents the traffic in the internal network, and vertical traffic represents the traffic between the internal and external networks.
[0051] Because network switches connect to both LANs (Local Area Networks) and WANs (Wide Area Networks), they can collect traffic between network devices within the LAN, as well as traffic exchanged between the LAN and the external WAN. For ease of understanding, the LAN will be referred to as the intranet in the following description, representing a network within a specific area, such as within a company or home. In an intranet, a network switch connects the various network devices and provides efficient local communication between them. In a WAN, the network switch does not directly connect to network devices; its primary function is to forward data traffic between networks, enabling interconnection between different networks.
[0052] Horizontal traffic refers to the traffic collected by a network switch between network devices within a local area network (LAN), i.e., traffic within the internal network. Vertical traffic refers to the traffic collected by a network switch between the LAN and the WAN.
[0053] Step 104: Analyze and process lateral and longitudinal traffic to identify network threats within the intranet and between the intranet and the intranet. These network threats include known and unknown threats.
[0054] This embodiment uses a network defense module 100 deployed on a network switch to detect threats in the network. Because this embodiment can directly analyze and process the traffic collected by the network switch, it can identify not only network threats within the internal network but also those between the internal and external networks. Furthermore, when identifying and detecting network threats, this embodiment can identify not only known threats based on existing attack patterns, vulnerabilities, and malware, but also unknown threats in the network.
[0055] Compared to traditional defenses that primarily target a single network threat, this embodiment uses a network defense module deployed on a network switch to acquire both lateral traffic within the internal network and vertical traffic between the internal and external networks. This allows for the simultaneous identification and defense of network threats within both lateral and vertical traffic, making it highly reliable for identifying different types of network threats.
[0056] In some further embodiments, step 104 analyzes and processes lateral and longitudinal traffic to determine network threats in the intranet and between the intranet and the intranet. Based on the method by which the network defense module 100 accesses the intranet, the process is divided into the following two cases.
[0057] The first scenario involves the network defense module 100 being connected to a network switch, where mirrored traffic is used to obtain lateral and longitudinal traffic collected by the network switch. The network defense method provided in this embodiment can analyze lateral traffic using machine learning to identify known threats within the internal network; it can also identify known threats in both internal and external networks based on a network threat database within the longitudinal traffic.
[0058] Since threats within an intranet may share certain similarities depending on their type, machine learning methods can be used to perform correlation analysis on the acquired traffic, identify traffic that differs from normal traffic, and thus recognize abnormal traffic.
[0059] For example, a traffic identification model can be built based on machine learning methods. The acquired intranet traffic data can be used for model training and optimization. After the traffic identification model is built, abnormal traffic data can be identified through the trained model to achieve defense against attack threats in the intranet.
[0060] For known threats within and outside networks, threat detection and defense can be achieved by matching acquired traffic with threat data in a network threat database. For example, acquired vertical traffic can be matched with the virus database in the network threat database. If the vertical traffic matches virus characteristics in the network threat database, it indicates that the vertical traffic contains an attack threat corresponding to that virus characteristic, and defense against that attack threat is necessary.
[0061] Optionally, when performing threat detection based on a network threat database, the DPDK (DataPlane Development Kit) technology can be combined to handle the largest possible network traffic detection. Traffic detection requires mirroring the inbound and outbound traffic of the network switch ports to an internal port of the network switch, which is directly connected to the network defense device 100 via a 10 Gigabit Ethernet port. Since all inbound and outbound traffic from the network switch ports needs to be sent to the network defense module 100 to collect data from the network card port, conventional intrusion detection methods such as pcap and nfqueue are ineffective. Therefore, the DPDK plugin is combined to optimize and improve the packet collection method, allowing traffic detection to bypass the operating system kernel and directly access network hardware devices, avoiding operating system overhead and providing lower latency and higher throughput.
[0062] In some implementations, after identifying abnormal traffic data based on machine learning models, analysis of the abnormal traffic data can yield data on network threats such as viruses. The network threat database can then be updated based on the identified network threat data to achieve coordinated defense against network threats and improve the reliability of network defense.
[0063] The second scenario is when the network defense module 100 is connected to the intranet as a network device. The detection container on the network defense module 100 determines known threats in the intranet and known threats in the internal and external networks, and the mimicry executor on the network defense module 100 detects unknown threats in the intranet and unknown threats in the internal and external networks.
[0064] In this embodiment, when defending against network threats, the network defense module 100 can also be connected to the intranet network as a network device, and the detection and defense against network threats can be achieved by running the network defense module 100 in the intranet network.
[0065] For example, in the network defense module 100, detection containers are created according to different types of known attack threats, and these detection containers are then deployed in the internal network. Once a certain type of attack exists in the internal network, the detection container corresponding to that attack type can detect the attack information, thereby achieving defense against the network attack.
[0066] Meanwhile, after the network defense module 100 is connected to the network as a network device, it can also create two mimicry execution entities in the same operating system through mimicry camouflage, and run the same process on the two mimicry execution entities. By detecting the state differences between the two mimicry execution entities, it can detect unknown threats in the internal network and unknown threats in the internal and external networks.
[0067] In some specific embodiments, the network defense module uses a mimicry executor to detect unknown threats in the intranet and in both internal and external networks. This includes: deploying an open executor and a hidden executor in the network defense module, respectively, on the target operating system, with the open executor exposed in the intranet; running the same process on both the open and hidden executors and acquiring their system resources in real time; and determining that the intranet poses an unknown threat to the target operating system if the difference between the first resource parameter corresponding to the open executor and the second resource parameter corresponding to the hidden executor exceeds a preset threshold.
[0068] A mimicry executor is an executable that identifies network threats by simulating the behavior of a normal operating system. Please refer to [link / reference]. Figure 2The mimicry camouflage topology diagram shown illustrates that when network threat perception is performed through mimicry camouflage, the network defense module 100 includes a scheduling unit for scheduling mimicry executors and an adjudication unit for adjudicating the system resource parameters corresponding to the mimicry executors.
[0069] In this embodiment, when using mimicry for threat defense, it is necessary to first build image pools based on different operating systems. These image pools store system images of different operating systems. Building image pools for different operating systems can improve the system's defense capabilities by deceiving network attacks, and can also be used for data collection and analysis of attacks under different operating systems.
[0070] The scheduling unit extracts different operating systems from the image pool for deployment. For each operating system, it creates two identical mimic execution entities. These two mimic execution entities represent an open execution entity exposed on the internal network and a hidden execution entity hidden on the internal network, respectively. It should be noted that the open execution entity exposed on the internal network means that other network devices on the internal network can access this mimic execution entity. Figure 2 The solid lines represent Ubuntu2, CentOS2, and Fedora2. A hidden mimicry execution instance hidden within the internal network means that other network devices on the internal network cannot access this mimicry execution instance. Figure 2 The three terms are represented as Ubuntu1, Centos1, and Fedora1 within the dashed boxes.
[0071] When two mimicking executors running the same operating system execute the same process, the scheduling unit also obtains the system resource parameters of both mimicking executors and transmits these parameters to the adjudication unit for analysis and judgment. If the difference in the system resource parameters corresponding to the two mimicking executors exceeds a preset threshold, it is determined that there is an unknown network threat in the current intranet.
[0072] For example, still using Figure 2 The topology diagram shown is an example. The operating systems in the constructed image pool include, but are not limited to, Ubuntu, CentOS, Fedora, Debian, and MIPS. The current mimicry operation constructs mimicry executables based on Ubuntu, CentOS, and Fedora operating systems. It should be noted that mimicry executables can also be constructed based on other operating systems, or mimicry executables under other numbers of operating systems. This embodiment does not limit the number of mimicry executables constructed from the selected operating systems, nor the types of operating systems selected.
[0073] The scheduling unit monitors the constructed open and hidden executors in real time, obtaining system resource parameters corresponding to different mimicking executors, such as CPU utilization, memory utilization, disk utilization, and network resource utilization. The adjudication unit compares and determines the system resource parameters corresponding to two mimicking executors under the same operating system.
[0074] Combination Figure 2 topology and Figure 3 This flowchart illustrates a network threat assessment process, using CPU utilization obtained during the runtime of a simulated executable as an example of a system resource parameter for network threat detection. Simultaneously, the CPU utilization of two executables operating within the same operating system is acquired. If the difference in CPU utilization between the two systems exceeds a preset threshold, it can be determined that the exposed executable is experiencing system anomalies due to external attacks or internal vulnerabilities, indicating the presence of an unknown network threat within the internal network. This preset threshold can be 20% or other values; different thresholds can be set based on different network environments and network security standards during network threat detection.
[0075] Once a network threat is detected through mimicry and camouflage, the identified anomaly information is written to the network log. The exposed execution entity stores and encapsulates the collected IP, MAC, and other address information of the attacking device, as well as attack operation information, and sends the encapsulated message to the network defense module 100. The network defense module 100 backs up and analyzes the attack-related information. At the same time, it can also convert the attack into a known attack based on the analysis of the attack information for threat defense.
[0076] In other specific embodiments, the known threats in the intranet and the known threats in the internal and external networks are determined by the detection containers on the network defense module. This includes: acquiring known threat data and extracting attack features from the known threats; determining a number of detection containers based on the attack features; deploying each detection container in the intranet through the network defense module; determining known threats in the intranet that correspond to the type of detection container; and determining known network threats in the internal and external networks that correspond to the type of detection container.
[0077] Detection containers represent isolated virtualized environments used to detect, isolate, and analyze potential network threats. By creating isolated environments, detection containers separate threat detection from the normal operating environment, preventing malicious attacks from impacting other network devices. However, current detection containers are based on known network attacks and thus have a degree of indiscriminate targeting, resulting in poor effectiveness in detecting network threats.
[0078] This embodiment, based on traditional detection containers, performs feature analysis on common attack information to obtain characteristic information of different types of viruses, and then creates detection containers based on the extracted virus characteristic information. For example, it extracts characteristic information of common attacks such as script attacks, injection attacks, path (directory) traversal attacks, distributed denial-of-service attacks, brute-force attacks, and replay attacks. By analyzing and extracting the characteristics of each attack, creating detection containers, and deploying them in the internal network, the efficiency of capturing common attacks can be improved.
[0079] The detection container in this embodiment is constructed by extracting feature information of different attack types. Once an attack of the same type exists in the internal network, the container of the corresponding attack type can detect it and record and report the attack information. At the same time, this embodiment can also lure the attacker based on the attack source to obtain more information about the attacker, so as to trace and defend against it.
[0080] For example, before detecting known threats through detection containers, the type, number, VLAN (Virtual Local Area Network), and IP information of the detection containers can be configured. By properly configuring the type and number of detection containers, attackers can be effectively attracted and their attack messages captured. By configuring the VLAN and IP information, the detection containers can be isolated, preventing attackers from breaching the detection containers and affecting other network devices.
[0081] The type of detection container corresponds to the network service or system to be simulated, such as common network services like Web (HTTP / HTTPS), FTP (File Transfer Protocol), and SSH (Secure Shell Protocol). Detection containers can also simulate the full functionality of a real system. By configuring different types of detection containers, the appropriate container can be selected based on different network threat methods, improving the efficiency of detecting known threats. The number of detection containers can be used to increase the probability of decoyting network threats and to disperse attack traffic, preventing attackers from concentrating their attacks on the real network. VLANs separate different logical groups within the network; deploying detection containers in different VLANs isolates attack traffic from affecting other network devices. IP settings provide detection containers with IP addresses that closely resemble the actual network structure, making them appear more like real network services or systems, attracting more attackers to scan and attack.
[0082] Let's take setting up a detection container for monitoring SSH network services as an example. The SSH detection container simulates the SSH service, and the number of detection containers, VLANs, and IP addresses are determined. Before launching an attack, an attacker will use SSH probing devices to gather information. When the SSH detection container detects that its open ports are being accessed, it can determine that an attack is occurring on the internal network, recording the attacker's IP address, commands executed, uploaded files, or session logs for later tracing. Simultaneously, depending on the settings, the attacker's IP address can be sent to the decision control module for interception and defense.
[0083] In some exemplary embodiments, acquiring known threat data and extracting attack features from known threats, and determining several detection containers based on the attack features, includes: acquiring abnormal network data collected by the open execution entity on the network defense module, acquiring attack features from the abnormal network data, and generating detection containers.
[0084] As shown in the previous embodiment, when an unknown threat is detected and an alarm is generated through an open execution entity, the network defense module 100 also extracts attack information, including attack characteristics, attacker IP address, MAC address, and other attacker information. This embodiment can convert the analyzed attacker characteristic information into a known threat detection container, improving the efficiency of subsequent network threat detection.
[0085] In other specific embodiments, lateral traffic is analyzed based on machine learning methods to identify known threats in the intranet network, including: obtaining a traffic identification model trained based on historical lateral traffic; inputting lateral traffic into the traffic identification model; identifying abnormal traffic in the lateral traffic based on the traffic identification model; and identifying known threats in the intranet network through the abnormal traffic.
[0086] Referring to the foregoing embodiments, analyzing lateral traffic and identifying known threats based on machine learning methods mainly includes two steps: traffic learning and traffic analysis. Traffic learning involves training a traffic identification model based on lateral traffic acquired over historical time periods, while traffic analysis involves using the trained traffic identification model to identify abnormal traffic within the lateral traffic.
[0087] For example, traffic learning and traffic identification may include the following steps:
[0088] (A1) Traffic data collection
[0089] The system collects data from the acquired lateral traffic and parses information such as IP address, MAC address, port number, packet length, and data transmission latency from the traffic data.
[0090] (A2) Traffic data preprocessing
[0091] Optionally, the collected information can be preprocessed, such as removing miscellaneous packets, erroneous packets, and other noise from the data.
[0092] (A3) Traffic data feature extraction and feature data association
[0093] Feature extraction and correlation analysis are performed based on the characteristics of the traffic data. The analyzed traffic data includes the five-tuple of traffic collection, packet size, data transmission latency information, etc.
[0094] (A4) Model building and model training
[0095] A traffic identification model is built based on machine learning algorithms, such as widely used neural network models for traffic learning. The model is trained using traffic data after feature extraction and correlation to obtain the traffic identification model. The collected traffic data can also be used to optimize the model parameters of the traffic identification model.
[0096] (A5) Abnormal Traffic Identification
[0097] The trained traffic identification model identifies abnormal traffic, enabling defense against network threats. Further traffic analysis and backup can be performed on the identified abnormal traffic. For example, after obtaining network threat information based on the identified abnormal traffic, the network threat database can be updated based on this known network threat information to achieve coordinated network threat defense.
[0098] In some further embodiments, the method further includes: extracting network feature data from lateral traffic; analyzing and correlating the network feature data to determine the connection relationships of devices in the intranet network, and determining the network topology of the intranet network based on the connection relationships; identifying the target network threat, determining the target isolation domain where the target network threat is located based on the network topology, and isolating the target isolation domain to prevent the target network threat from threatening other devices in the intranet network.
[0099] When analyzing and processing lateral traffic, the connection relationships of various network devices in the intranet can be analyzed based on network characteristic data such as source IP, destination IP, source MAC, destination MAC, and device port identifier in the lateral traffic, to determine the association between various network devices in the intranet and obtain the network topology map of the intranet.
[0100] Furthermore, this embodiment can divide isolation domains based on the obtained network topology map. For example, the network area where the target network threat is identified can be divided to obtain the target isolation domain. After a device in the internal network is attacked, the division of the isolation domain limits the network threat to the isolation domain, preventing it from threatening other devices in the internal network. It can be understood that the target network threat here includes network threats identified by abnormal traffic through traffic identification models, network threats obtained by comparing with a network threat feature database, network threats identified by detecting containers, or network threats identified by mimicry camouflage.
[0101] In some other implementations, areas of high importance or priority can be isolated from other areas by dividing them into isolation domains, thereby improving the security of the isolation domain.
[0102] In conjunction with the above network defense methods, please refer to Figure 4 In some embodiments, a network defense module 100 is provided, which is deployed on a network switch and includes a traffic mirroring unit and a computing unit. The traffic mirroring unit is configured to directly acquire network traffic collected by the network switch, and the computing unit is configured to analyze and process the traffic acquired by the traffic mirroring unit to identify network threats.
[0103] The network switch and the network defense module 100 are connected via internal printed circuit board wiring. In this embodiment, when the traffic mirroring unit of the network defense module 100 acquires the traffic collected by the network switch, it mirrors the network switch panel port to the internal port of the network switch's switching chip. This optimizes the internal wiring and layout of the network switch, facilitating the acquisition of network switch traffic by the traffic mirroring unit in the network defense module 100. Since the network defense module 100 and the internal port of the switching chip can be connected discreetly via internal printed circuit board wiring, the issues of exposed wiring affecting connection performance and space occupation are avoided.
[0104] In this embodiment, the network defense module 100 is deployed on a network switch. The traffic acquired by the traffic mirroring unit includes both lateral and longitudinal traffic. When the computing unit analyzes the acquired traffic, it can determine network threats within the internal network as well as network threats between the internal and external networks. Furthermore, the network threats determined by the network defense module 100 in this embodiment include both known threats that can be directly identified and prevented, and unknown threats.
[0105] The network defense module 100 proposed in this embodiment is directly deployed on the network switch, resulting in a simple and easy-to-implement structure. Compared to traditional methods that target individual network devices for defense, the network defense device in this embodiment reduces resource consumption during network threat handling and has low maintenance costs. The network defense module 100 directly acquires traffic collected by the network switch, enabling it to identify and defend against network threats in both lateral and vertical traffic, offering strong applicability and high reliability in network defense.
[0106] Please refer to Figure 5 In some specific embodiments, the computing unit includes a first processing subunit 10 and a second processing subunit 20. The first processing subunit 10 and the second processing subunit 20 enable the network defense module 100 to be set up in the intranet network in different ways, so as to respectively implement defense against different types of network threats.
[0107] The first processing subunit 10 is configured to directly acquire lateral and longitudinal traffic collected by the network switch through traffic mirroring, and to defend against network threats based on the analysis and processing of the acquired traffic. Specifically, the first processing subunit 10 analyzes the acquired lateral traffic using machine learning methods to identify known threats in the internal network, and identifies known threats in the internal network and known threats in both internal and external networks based on a network threat database in the longitudinal traffic.
[0108] The second processing subunit 20 is configured to connect the network defense module 100 as a network device to the intranet network, set up the network defense module 100 as a network device in the intranet network, and implement defense against network threats through the second processing subunit 20. Specifically, the second processing subunit 20 determines known threats in the intranet network and known threats in both internal and external networks through detection containers, and detects unknown threats in the intranet network and unknown threats in both internal and external networks through the mimicry executor on the network defense module 100.
[0109] Please refer to Figure 5 The network switch includes a switching chip. When the network defense module 100 is deployed on the network switch, it connects to the switching chip to achieve data transmission. The network interface eh1 of the first processing subunit 10 is connected to the port of the switching chip in the network switch, directly acquiring the horizontal and vertical traffic collected by the network switch, and performing analysis and threat perception on the acquired traffic in the first processing subunit 10. The network interface eh2 of the second processing subunit 20 is connected to the port of the switching chip in the network switch. At this time, the network defense module 100 is connected to the network switch as a network device, and detects and perceives network threats through the detection container and mimicry execution entity set in the second processing subunit 20.
[0110] Furthermore, the first processing subunit 10 is also connected to the second processing subunit 20, such as... Figure 5 As shown, the first processing subunit 10 and the second processing subunit 20 are connected via network port eh3 to interact on traffic data or perceived threat data, thereby achieving coordinated defense against network threats. Optionally, the first processing subunit 10 and the second processing subunit 20 can be connected discreetly via internal wiring to avoid obvious plugging and unplugging affecting interaction performance and reduce space occupation.
[0111] In some implementations, the hardware implementation of the first processing unit 10 and the second processing unit 20 can be two separate computing modules, such as an embedded COME computing module. Since network threat defense may face extreme situations with upper limits of 10 gigabits, the requirements for computing and storage resources are high. Deploying the first processing subunit 10 and the second processing subunit 20 on different computing modules can ensure the processing efficiency and resource allocation of each computing module. Furthermore, deploying the first processing subunit 10 and the second processing subunit 20 separately also facilitates subsequent expansion of the functionality of the network defense module 100.
[0112] In some implementations, the first processing subunit 10 and the second processing subunit 20 can also be deployed on a single computing module to reduce hardware costs. In this embodiment, the deployment method of the first processing subunit 10 and the second processing subunit 20 can be determined based on the actual application scenario and requirements.
[0113] The hardware implementation of this embodiment is simple. It only requires reserving space on the existing network switch hardware platform for the computing modules of the first processing unit 10 and the second processing unit 20, and mirroring the traffic collected by the network switch panel port to the internal interface, and then connecting to the first processing unit 10 and the second processing unit 20 through the internal interface. No additional hardware development is required, and the deployment is simple, easy to implement and low in cost.
[0114] Please refer to Figure 6 The software diagram of the network defense module is shown below. In one specific embodiment, the network switch further includes a decision control module and an interaction module. The decision control module is connected to the network defense module 100 and is used to issue control commands to the network defense module 100. The interaction module is connected to the decision control module and is used to interact with the decision control module to exchange commands and provide visual displays.
[0115] like Figure 6 As shown, the network defense module 100 is connected to the decision control module in the network switch, acquires the horizontal and vertical traffic collected by the network switch, and performs network defense based on the acquired traffic through traffic insight, intrusion detection, holographic trapping and mimicry.
[0116] When defending against network threats through traffic insight and intrusion detection, the network defense module 100 acquires the lateral and vertical traffic of the network switch through mirrored traffic units. By analyzing and comparing the traffic, it can detect known network threats. When defending against network threats through holographic deception and mimicry, the network defense module 100 connects to the internal network as a network device through a virtual interface. By running programs on the network defense module 100 or setting up detection containers, it can detect both known and unknown network threats.
[0117] Traffic insights represent the analysis of lateral traffic using machine learning methods to identify known threats within the internal network. Since all traffic from internal network devices is relayed through network switch 100, the system can learn the behavioral habits of internal network devices based on the switched internal traffic over a certain period. Furthermore, machine learning is used to self-model network traffic, establishing an intuitive and visual lateral user relationship view.
[0118] Intrusion detection refers to identifying known threats within and outside networks by analyzing network traffic longitudinally using a network threat database. During intrusion detection, internal network traffic is analyzed and matched against a virus database to detect potential threats. The current virus database supports the detection of nearly 4 million viruses, covering over 3,000 attack events including Trojans, backdoors, buffer overflows, denial-of-service attacks, and security auditing. Furthermore, the database is periodically updated based on newly identified network threats.
[0119] Holographic decoy refers to the identification of known threats within the internal network and between internal and external networks through detection containers on the network defense module 100. Centralized orchestration technology of detection containers allows for the centralized deployment of detection containers with different decoy types and interaction levels within the internal network.
[0120] Mimicry refers to the use of mimicry-based execution entities on the network defense module 100 to detect unknown threats within the internal network and between internal and external networks. Because attackers need to scan, collect, and tamper with network device resources during penetration of internal network devices, leading to abnormal system resource operation, monitoring system resource parameters can promptly capture attack threats targeting internal network devices. When constructing the mimicry execution entity, the mirror pool includes various heterogeneous operating systems. Each operating system can create two execution entities, one open and one hidden within the internal network. By comparing and adjudicating the states of two execution entities from the same operating system, unknown threats within the internal network can be captured promptly.
[0121] Threat detection using both containers and mimicking executors allows for the analysis of attack behavior, luring intruders into spoofed interactions. This not only deciphers and records their attack methods but also consumes their time and effort. Optionally, proactive interception can be performed based on extracted attacker identity information, achieving proactive defense. Specific network defense methods have been discussed in detail in the aforementioned embodiments and will not be repeated here.
[0122] In some other implementations, in order to more accurately capture attacker behavior, this embodiment supports deploying the mimicry execution entity and detection container to a designated VLAN domain by combining the virtual network partitioning function of the network switch.
[0123] This embodiment can also generate web page and log alerts for the matched suspicious traffic, and send threat information to the decision control center to issue switch interception commands or provide reliable basis for third-party device decision-making.
[0124] In other implementations, machine learning can be used to segment network zones containing different network devices, blocking hidden and unknown lateral threats within the internal network. For each specific network zone, operations such as adding, deleting, modifying, and enabling specific rules are supported. When access control is enabled and specific rules are activated, network zones can be re-segmented based on those rules to form new network zones. This ensures that even if a network device within the internal network is attacked, the risk is contained within the network zone containing that device, preventing the attack threat from spreading to other hosts and guaranteeing the security of other network devices within the internal network.
[0125] like Figure 6 As shown, the decision control module is located in the network switch and serves as the control center of the network defense module 100. It supports other interactive modules, such as web pages, in distributing basic configurations to various defense units within the defense module through its central function. Simultaneously, based on the network threat perception results in the network defense module 100, it sends flow control commands to the switching chip through interface modules such as the SDK, achieving the purpose of intercepting attack threats and defending the internal network.
[0126] The interactive module is used for configuring network defense parameters and dynamically visualizing the processing resources of the network defense module. For example, the interactive module can be a web module, allowing users to configure network defense settings through a web interface, such as setting parameters for each unit, restoring the system to factory settings, displaying lists, and downloading attack reports. Simultaneously, the web interface allows users to query attack logs and understand information about attackers, as well as the system's operational and attack status.
[0127] In some specific embodiments, such as Figure 7As shown, a method for deploying a network defense module is disclosed, which includes the following steps 702 to 708. Wherein:
[0128] Step 702: Perform network authentication and authorization for the network defense module through the web interface of the interactive module.
[0129] Network authentication, such as public network authentication, can be completed by entering an assigned serial number.
[0130] Step 704: Configure parameters via the web interface.
[0131] Parameter settings can include configuring parameters such as IP addresses and MAC addresses. For example, first, set the IP address range for each network device in the internal network corresponding to the network switch. Then, enter the IP address and MAC address of each network device and bind them one by one. In addition to setting the information of each network device in the internal network, you also need to configure the VLAN virtual interface information of the network switch.
[0132] Step 706: Issue defense commands to the network defense module through the web interface.
[0133] When defense control commands are issued to the network defense module 100, the module can primarily defend against network threats through traffic insight, intrusion detection, holographic decoys, and mimicry. Traffic insight identifies traffic after traffic learning. Intrusion detection compares acquired traffic with a network threat database. Holographic decoys are implemented by setting up detection containers within the network defense module 100. During holographic decoys, the type, number, VLAN, and IP information of the decoy containers can be configured via a web interface. Mimicry defends against network threats by constructing open and hidden execution entities within the network defense module 100.
[0134] In this embodiment, when defending against network threats, a blocking threshold can be set through the interactive module. When the number of network threat attacks reaches the blocking threshold, the attack traffic will be intercepted. When no interception is performed, the attack information will be recorded through the WEB interface.
[0135] Optionally, after identifying a network threat, the area where the threat resides can be isolated. By controlling and restricting the isolated area, lateral penetration of the threat can be prevented. Since traffic learning is required before identifying abnormal traffic, the application can perform traffic learning for a period of time before determining the network area to be isolated. This is the embodiment.
[0136] It is understandable that when identifying and isolating traffic, a whitelist can be set up through a web interface. The IP address and MAC information of a network device in the intranet can be entered into the whitelist to ensure that the device has the highest privileges and that any operation of the device will not be blocked by the network defense device.
[0137] Step 708: Conduct threat tracing through the web interface.
[0138] By tracing and reconstructing threat attack traffic, attackers' attack paths can be viewed through their IP addresses, attack trends can be observed, and attack information such as threat source, attack events, and attack frequency can be visualized. Optionally, this embodiment may also include a download center to allow users to download network threat reports.
[0139] The network defense module 100 in this embodiment has a simple structure. It can detect network threats corresponding to the network switch by plugging and unplugging it. It has a simple structure, low cost, and high applicability.
[0140] In some other embodiments, a network switch is disclosed on which the network defense module 100 provided in the above embodiments is deployed.
[0141] This network switch features high security, proactive defense, and dynamic operational visualization. It provides bidirectional security for both lateral and longitudinal traffic. Specifically, when the network defense module obtains lateral and longitudinal traffic through mirroring, it analyzes the lateral traffic using machine learning methods to identify known threats within the internal network and identifies known threats in the longitudinal traffic from both the internal and external networks based on a network threat database. When the network defense module is connected to the internal network as a network device, it uses a detection container on the module to identify known threats in both the internal and external networks, and a mimicry executor on the module to detect unknown threats in both the internal and external networks.
[0142] The network switch in this embodiment links lateral attack defense with vertical attack defense, improving the reliability of network defense and reducing resource consumption during network threat handling, resulting in low cost.
[0143] Those skilled in the art will understand that all or part of the processes in the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium. When executed, the computer program can include the processes of the embodiments described above. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM). The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, etc., and are not limited to these.
[0144] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0145] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are specific and detailed, they should not be construed as limiting the scope of this patent application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this application should be determined by the appended claims.
Claims
1. A network defense method, characterized in that, The method is executed by a network defense module deployed on a network switch, and includes: The network switch collects horizontal and vertical traffic, where horizontal traffic represents traffic within the internal network and vertical traffic represents traffic between the internal and external networks. The horizontal and vertical traffic are analyzed and processed to determine network threats within the intranet and between the intranet and the intranet, wherein the network threats include known threats and unknown threats; The analysis and processing of the lateral and longitudinal traffic to determine network threats within the intranet and between the intranet and extranet includes: When the network defense module is connected to the intranet network as a network device, the mimicry execution entity on the network defense module is used to detect unknown threats in the intranet network and unknown threats in both internal and external networks. The step of detecting unknown threats in the internal network and unknown threats in both internal and external networks through the mimicry execution entity on the network defense module includes: In the network defense module, an open execution entity and a hidden execution entity are deployed respectively using the same target operating system, with the open execution entity exposed in the internal network; The same process is run on the open executable and the hidden executable, and the system resources of the open executable and the hidden executable are acquired in real time; if the difference between the first resource parameter corresponding to the open executable and the second resource parameter corresponding to the hidden executable exceeds a preset threshold, it is determined that the intranet network poses an unknown threat to the target operating system.
2. The method according to claim 1, characterized in that, The analysis and processing of the lateral and longitudinal traffic to determine network threats within the intranet and between the intranet and extranet also includes: When the network defense module obtains the lateral traffic and the vertical traffic through mirrored traffic, it analyzes the lateral traffic based on machine learning methods to identify known threats in the internal network, and identifies known threats in the internal and external networks based on the network threat database in the vertical traffic. When the network defense module is connected to the internal network as a network device, the known threats in the internal network and the known threats in the internal and external networks are determined by the detection container on the network defense module.
3. The method according to claim 2, characterized in that, The process of determining known threats in the internal network and known threats in both internal and external networks through the detection container on the network defense module includes: Acquire known threat data and extract attack features from the known threats, and determine several detection containers based on the attack features; Each of the detection containers is deployed in the intranet network through the network defense module. The detection containers are used to determine known threats in the intranet network that correspond to the type of the detection container, and to determine known network threats in both the internal and external networks that correspond to the type of the detection container.
4. The method according to claim 3, characterized in that, The process of acquiring known threat data and extracting attack features from known threats, and determining several detection containers based on the attack features, includes: Obtain abnormal network data collected by the open execution entity on the network defense module, and obtain the attack characteristics in the abnormal network data to generate a detection container.
5. The method according to claim 2, characterized in that, The analysis of lateral traffic based on machine learning methods to identify known threats in the internal network includes: A traffic identification model is obtained, which is trained based on historical horizontal traffic. The lateral traffic is input into the traffic identification model, and abnormal traffic in the lateral traffic is identified according to the traffic identification model. The known threats in the intranet are determined through the abnormal traffic.
6. The method according to claim 1, characterized in that, The method further includes: Extract network feature data from the horizontal traffic; analyze and correlate the network feature data to determine the connection relationship of devices in the intranet network, and determine the network topology of the intranet network based on the connection relationship. Identify the target network threat, determine the target isolation domain where the target network threat is located based on the network topology, and isolate the target isolation domain to prevent the target network threat from threatening other devices in the internal network.
7. A network defense module, characterized in that, The network defense module is deployed on a network switch to implement the network defense method as described in claim 1, and the module includes: The traffic mirroring unit is configured to acquire the horizontal and vertical traffic collected by the network switch, wherein the horizontal traffic represents the traffic in the internal network and the vertical traffic represents the traffic between the internal and external networks. The computing unit is configured to analyze and process the lateral traffic and the vertical traffic to determine network threats in the intranet network and network threats between the intranet and the intranet, wherein the network threats include known threats and unknown threats; The computing unit includes a second processing subunit, which is configured to connect the network defense module as a network device to the intranet network and detect unknown threats in the intranet network and unknown threats in both internal and external networks through the mimicry execution entity on the network defense module.
8. The module according to claim 7, characterized in that, The computing unit further includes: The first processing subunit is configured to acquire the horizontal traffic and the vertical traffic through mirrored traffic, analyze the horizontal traffic based on machine learning methods to identify known threats in the intranet network, and identify known threats in the intranet network and known threats in the internal and external networks based on the network threat database in the vertical traffic. The second processing subunit also uses the detection container on the network defense module to determine known threats in the internal network and known threats in both internal and external networks.
9. A network switch, characterized in that, The network switch is equipped with a network defense module as described in any one of claims 7-8.
Citation Information
Patent Citations
WEB malicious request depth detection system and method based on machine learning
CN109547423A
Detection system and method based on mimicry technology and machine learning, equipment and medium
CN113973008A