Method for detecting privately built internet exit, related device and computer storage medium

By recording and analyzing the triplet information accessed by the unit's unified promotion software, and combining it with regulations and systems, the problem of detecting privately built Internet exits was solved, and efficient and accurate identification of privately built Internet exits was achieved.

CN119675972BActive Publication Date: 2025-11-07STATE GRID INFORMATION & TELECOMM BRANCH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411882065.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-19
Publication Date
2025-11-07
Estimated Expiration
2044-12-19

AI Technical Summary

Technical Problem

Existing technologies are insufficient to effectively detect privately built internet exit IP addresses of company branches, especially in IPv6 network environments where the number of IP addresses is enormous, making proactive detection methods impractical.

Method used

By recording the triplet information of each unit's unified promotion software access detection server, including the Internet exit IP address, access time and location information, and combining it with the unit's rules and regulations, suspicious triplet information is screened and statistically analyzed to identify privately built Internet exits.

Benefits of technology

It enables accurate detection of privately built internet exits, reduces false alarms, and improves detection efficiency and accuracy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119675972B_ABST
    Figure CN119675972B_ABST
Patent Text Reader

Abstract

The application provides a detection method for privately-built Internet export, related devices and a computer storage medium. Triplet information when each unit pushes software accesses a detection server is recorded, wherein the triplet information comprises an Internet export IP address, access time and positioning information; for each unit, the rules and regulations of the unit and the received triplet information of the unit are analyzed to obtain an analysis result. The application uses the unit pushing software that cannot be bypassed to detect the privately-built Internet export, that is, whether each unit privately builds an Internet export is judged by recording the triplet information when each unit pushing software accesses the detection server.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of computer, in particular to a detection method for privately-built Internet exit, related device and computer storage medium. BACKGROUND

[0002] Currently, detecting privately-built Internet exit technically is actually detecting the IP address of the Internet exit used by the branch of a company. The Internet exit legally established according to the company system is reported to the headquarters by each unit, and the privately-built Internet exit is not reported to the headquarters by each unit because it is not allowed by the headquarters, so the headquarters is difficult to master the relevant information.

[0003] The technical difficulty of checking privately-built Internet exit is that each unit will not voluntarily report such illegal behavior to the headquarters, and there are currently more than 3 billion global IP addresses, and the headquarters cannot determine which IP address among the 3 billion IP addresses is the IP address of the privately-built Internet exit used by the branch of the company. After the domestic network gradually shifts to IPv6 network in the future, the IP address will reach a larger order of magnitude, and it is more impossible to detect the IP address of the privately-built Internet exit by active detection. SUMMARY

[0004] Therefore, the present application provides a detection method for privately-built Internet exit, related device and computer storage medium, which uses the unified push software that each unit cannot bypass to detect the privately-built Internet exit, that is, by recording the triple information of each unit when the unified push software accesses the detection server, to determine whether each unit has privately built an Internet exit.

[0005] The first aspect of the present application provides a detection method for privately-built Internet exit, comprising:

[0006] Recording the triple information of each unit when the unified push software accesses the detection server, wherein the triple information comprises an Internet exit IP address, an access time and positioning information;

[0007] For each unit, analyzing the rules and regulations of the unit and the received triple information of the unit to obtain an analysis result.

[0008] Optionally, if the rules and regulations of the unit prohibit the devices connected to the Internet from taking out the unit and only allow the devices connected to the Internet to access the unit network to access the Internet, the analysis of the rules and regulations of the unit and the received triple information of the unit for each unit to obtain an analysis result comprises:

[0009] If the IP address in the triple information is not in the list of legal Internet exit IP addresses, it is determined that the unit sending the triple information has the behavior of privately building an Internet exit.

[0010] Optionally, if the rules and regulations of the unit are that the devices connected to the Internet can be taken out of the unit, and can temporarily access the Internet through other networks, the analysis unit is configured to, for each unit, analyze the rules and regulations of the unit and the received triplet information of the unit to obtain an analysis result, including:

[0011] For each triplet information sent by the unit, triplet information in which the IP address is not in the list of legal Internet exit IP addresses is suspicious triplet information; wherein the suspicious triplet information includes a suspicious IP address, access time, and positioning information;

[0012] Statistical information is obtained by counting all suspicious triplet information within the legal working hours; wherein the statistical information at least includes a suspicious IP address and a report count;

[0013] If the report count is greater than a preset number threshold within a preset time interval, it is determined that the suspicious IP address is a privately built Internet exit IP address.

[0014] Optionally, if the report count is greater than a preset number threshold within a preset time interval, it is determined that the suspicious IP address is a privately built Internet exit IP address, and further comprising:

[0015] For each privately built Internet exit, the corresponding positioning information is obtained from the triplet information according to the privately built Internet exit IP address;

[0016] The unit in which the privately built Internet exit exists is determined according to the positioning information corresponding to the privately built Internet exit IP address.

[0017] The second aspect of the present application provides a privately built Internet exit detection device, comprising:

[0018] A recording unit is configured to record triplet information when each unit pushes software to access a detection server; wherein the triplet information includes an Internet exit IP address, access time, and positioning information;

[0019] An analysis unit is configured to, for each unit, analyze the rules and regulations of the unit and the received triplet information of the unit to obtain an analysis result.

[0020] Optionally, if the rules and regulations of the unit are that the devices connected to the Internet are prohibited to be taken out of the unit, and only allow access to the unit network to access the Internet, the analysis unit comprises:

[0021] The first analysis subunit is configured to determine that the unit sending the triple information exists the behavior of privately building an Internet exit if the IP address in the triple information is not in the list of legal Internet exit IP addresses.

[0022] Optionally, if the regulation of the unit is that the equipment connected to the Internet can be taken out of the unit, and the Internet can be accessed temporarily through other networks, the analysis unit comprises:

[0023] The screening unit is configured to screen the triple information in which the IP address is not in the list of legal Internet exit IP addresses as suspicious triple information for each triple information sent by the unit; wherein the suspicious triple information comprises a suspicious IP address, an access time and positioning information.

[0024] The statistical unit is configured to statistically analyze all the suspicious triple information in the legal working hours to obtain statistical information; wherein the statistical information at least comprises a suspicious IP address and a report count.

[0025] The first determination unit is configured to determine that the suspicious IP address is a privately built Internet exit IP address if the report count is greater than a preset quantity threshold in a preset time interval.

[0026] Optionally, the detection device of the privately built Internet exit further comprises:

[0027] The second determination unit is configured to obtain corresponding positioning information in the triple information according to the privately built Internet exit IP address for each privately built Internet exit.

[0028] The third determination unit is configured to determine the unit existing the behavior of privately building an Internet exit according to the positioning information corresponding to the privately built Internet exit IP address.

[0029] The third aspect of the present application provides an electronic device comprising:

[0030] One or more processors;

[0031] A storage device having one or more programs stored thereon;

[0032] When the one or more programs are executed by the one or more processors, the one or more processors implement the detection method of the privately built Internet exit according to any one of the first aspect.

[0033] The fourth aspect of the present application provides a computer storage medium having a computer program stored thereon, wherein the computer program is executed by a processor to implement the detection method of the privately built Internet exit according to any one of the first aspect.

[0034] From the above scheme, the application provides a detection method for private Internet export, related device and computer storage medium, by recording the triple information of each unit pushing software accessing the detection server; wherein, the triple information includes Internet export IP address, access time and positioning information; for each unit, according to the rules and regulations of the unit and the received triple information of the unit, the analysis result is obtained. The application uses the unit pushing software which cannot be bypassed to realize the detection of private Internet export, that is, by recording the triple information of each unit pushing software accessing the detection server, whether each unit has built a private Internet export is judged. BRIEF DESCRIPTION OF DRAWINGS

[0035] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings needed to be used in the embodiments or prior art description. Obviously, the drawings in the following description are only a part of the present application, and for those skilled in the art, other drawings can be obtained without creative labor based on the provided drawings.

[0036] Figure 1 The flow chart of a detection method for private Internet export provided by the embodiment of the present application;

[0037] Figure 2 The flow chart of a detection method for private Internet export provided by another embodiment of the present application;

[0038] Figure 3 The schematic diagram of a detection device for private Internet export provided by another embodiment of the present application;

[0039] Figure 4 The schematic diagram of an electronic device for realizing the detection method of private Internet export provided by another embodiment of the present application. DETAILED DESCRIPTION

[0040] The technical solutions in the embodiments of the present application will be described clearly and completely in combination with the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, not all. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor are within the scope of protection of the present application.

[0041] As used herein, the term "includes" and its variants are to be read to be analogous to "comprises," "comprising," "includes," "including," and "has," "having," "contains" or "containing." The term "based on" is to be read as "based, at least in part, on." The term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one additional embodiment"; the term "some embodiments" means "at least some embodiments." Related definitions are given below in the description of the application.

[0042] It should be noted that the information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in the present application are all information and data authorized by the user or authorized by all parties, and the collection, use and processing of related data need to comply with relevant laws, regulations and standards of relevant countries and regions.

[0043] It should be noted that the "first", "second", and the like concepts mentioned in the present application are only used to distinguish different devices, modules or units, and are not used to limit the order or interdependence of the functions performed by these devices, modules or units.

[0044] It should be noted that the "one", "multiple" modification mentioned in the present application is illustrative and not limiting, and those skilled in the art should understand that unless otherwise explicitly indicated in the context, it should be understood as "one or more".

[0045] First, the technical terms appearing in the present application are explained and described:

[0046] IP: Internet Protocol, the purpose of designing IP is to improve the scalability of the network: one is to solve the Internet problem, to realize the interconnection of large-scale, heterogeneous networks; two is to separate the coupling relationship between the top network application and the bottom network technology, so as to facilitate the independent development of the two.

[0047] IP address: IP protocol provides a unified address format, which allocates a logical address for each network and each host on the Internet, so as to shield the difference of physical address. The mainstream IP protocol is divided into IPv4 and IPv6, among which the address length of IPv4 is 32 bits, and the address length of IPv6 is 128 bits.

[0048] HTTP request: from entering a URL in the browser to the server returning the result, the following steps are taken: ① The browser performs DNS domain name resolution to obtain the IP address corresponding to the domain name; ② According to this IP address, find the corresponding server, and establish a TCP connection through three handshakes; ③ After establishing the TCP connection, the browser sends an HTTP request message to the server, including request line, request header, request body, etc. Information; ④ The server responds to the HTTP request and sends the browser response message, including status line, response header, response data, etc. Information, the browser gets the HTML code; ⑤ The browser parses the HTML code and requests resources (such as js, css, images, etc.) in the HTML code; ⑥ The browser renders the page and presents it to the user; ⑦ The server closes the TCP connection. Among them, the alarm of the security device mainly occurs in stages ③ and ④. During the attack, the attacker usually adds offensive content in the request at stage ③, so that the security device can identify and alarm, and some security devices can also identify abnormal response content from the server at stage ④, so that the server may have been attacked. Because the HTTP protocol is based on the TCP protocol, and the TCP protocol is connection-oriented and traceable, the security device alarm can associate requests and returns.

[0049] Internet exit: Due to the limited number of IPv4 addresses, the IP addresses used by units, mobile phones, and home networks are usually internal network IP addresses (similar to 10.*.*.* and 192.168.*.* addresses). Such IP addresses will not appear on the Internet. When users using such IP addresses access the Internet, the internal network IP address will be mapped to a public network IP address. From the perspective of the website being accessed, the user uses the mapped public network IP address to access the website. This mapped public network IP address is the Internet exit IP address. Generally speaking, a unit may have hundreds of computers, but the final mapped Internet exit IP address is usually only one or a small number of several. From the perspective of the website, if there are a large number of accesses to an Internet IP address, it means that the Internet IP address is used by many people, which means that the Internet IP address is actually the Internet exit of a larger internal network (usually a unit, Internet cafe, hotel, etc. Scene) Internet exit IP address.

[0050] Unified push software: Large enterprises usually purchase or develop their own internal use of dedicated terminal management software, internal communication / enterprise management APP, and install it on the terminal and mobile phone. Such software is called unified push software. For example, State Grid Corporation has installed the "i State Grid" APP on mobile phones. It is a kind of unified push software, and almost all State Grid employees will install the APP on their mobile phones. In the process of terminal management, similar software will also be installed on the terminal connected to the network.

[0051] The embodiment of the application provides a detection method of private Internet export. First, the supervision unit deploys a detection server on the Internet. The push software provided to each unit of the company is set to visit the detection server regularly (which can be a function of the push software or a program / script executed through the push software, which is not limited here). Each branch and unit records the legal Internet export IP address to the supervision unit, which is stored by the supervision unit to form a list of legal Internet export IP addresses, as shown in Figure 1 An embodiment of the detection method of private Internet export specifically comprises the following steps:

[0052] S101, record the three tuple information of each unit push software visiting the detection server.

[0053] The three tuple information includes the Internet export IP address, the access time and the positioning information.

[0054] It should be noted that the Internet export IP address can be obtained by the server according to the description of the Internet export IP, and the positioning information includes but is not limited to the user, the unit, the login account, the geographical positioning and other information used for illegal traceability, which is not limited here. It should be noted that although this information cannot be obtained, the push software of general units will collect such information, and as long as the push software has the corresponding function, it can report such information.

[0055] In the specific implementation process of the application, the push software of each unit tries to access the detection server regularly (for example, every 10 minutes after the computer or mobile phone is started, which is not limited here), and the detection server records the three tuple information of each unit push software visiting the detection server.

[0056] It should be noted that the timing is for software / APP that does not access the server of the supervision unit (for example: headquarters, superior unit, or unit entrusted by the headquarters and superior unit) through the Internet at ordinary times, such as enterprise communication APP. Since such APP has the feature of continuous access, it can also not be timed, at this time, the detection server can reuse the server of the communication APP / software, which is not limited here.

[0057] It should be noted that the "user, unit, login account, and geographical positioning" in the positioning information are example information, and in actual operation, it is not necessary to obtain all of them, and it is not limited to obtaining these four kinds of information. The essence of the positioning information is that when a violation is found, the positioning information can be used to find the information of the responsible unit or the responsible person. For example, for the supervision unit, the simplest positioning information can only include unit information (the supervision unit only needs to hold the responsible unit accountable), which is also not limited here.

[0058] In the practical application of the present application, the triple information can be stored in a designated database on the detection server, without limitation.

[0059] S102, for each unit, according to the rules and regulations of the unit and the received triple information of the unit, analysis is carried out to obtain the analysis result.

[0060] Among them, the unit can be the supervised unit, that is, only for the supervised unit, according to the rules and regulations of the unit and the received triple information of the supervised unit, analysis is carried out to obtain the analysis result, without limitation.

[0061] It can be understood that, since the rules and regulations of different units may be different, the rules and regulations of the unit and the received triple information of the unit need to be combined for comprehensive analysis when analyzing.

[0062] For example: the rules and regulations of a unit are that the devices connected to the Internet are prohibited from being taken out of the unit, and only access to the unit network is allowed to access the Internet, such as company research and development test computers, or computers involving enterprise sensitive information, or servers, etc., without limitation. As long as there is an address outside the record, it means that the company's assets have been taken out of the company, that is, if the IP address in the triple information is not in the list of legal Internet exit IP addresses, it is determined that the unit sending the triple information has the behavior of privately building an Internet exit. Subsequent punishment, report, etc. for the unit, without limitation,

[0063] For example: the rules and regulations of the unit are that the devices connected to the Internet can be taken out of the unit, and can temporarily access the Internet through other networks. For each unit, according to the rules and regulations of the unit and the received triple information of the unit, analysis is carried out to obtain the analysis result, one embodiment of which is shown in Figure 2 , which includes:

[0064] S201, for each triple information sent by the unit, the triple information whose IP address is not in the list of legal Internet exit IP addresses is suspicious triple information.

[0065] Among them, the suspicious triple information includes suspicious IP address, access time and positioning information.

[0066] Specifically, if the IP address in the triple information is in the triple information of the list of legal Internet exit IP addresses, it can be directly filtered out.

[0067] S202, all suspicious triple information is counted within the legal working hours to obtain statistical information.

[0068] The statistical information at least includes a suspicious IP address and a report count.

[0069] It should be noted that the reason for defining the legal working time period is that the device that can access the Internet can generally be taken home (if the regulations allow), and since the company does not need to manage the home network, it only needs to be responsible for the legal Internet export IP address on record. If an employee often takes a device of the unit home, it may cause the IP address of the home broadband to be mistakenly determined as a privately built Internet export. After defining the legal working time, the possibility of false alarm will be greatly reduced.

[0070] It can be understood that since the positioning information in the suspicious triple information is temporarily not needed, it can be temporarily ignored, and can be obtained in the database storing the triple information subsequently. Of course, the positioning information can not be ignored, and the suspicious triple information can be directly used for statistics, that is, the statistical information obtained includes: suspicious IP address, access time and positioning information. Of course, additional information can also be added, which is not limited here.

[0071] It should be noted that the statistical information at least including a suspicious IP address and a report count is only the minimum data requirement of the present application. If additional data is added on the basis of the minimum data (for example, the positioning information is not removed, and the triple is finally retained, or even additional information is added), as long as its algorithm is based on IP address and access time for the same calculation as the present patent, it should still be regarded as using the method of the present application.

[0072] S203, if the report count is greater than the preset number threshold in the preset time interval, the suspicious IP address is determined as a privately built Internet export IP address.

[0073] The preset time interval, the preset number threshold, and the like are pre-set, changed by technical personnel, experts, and the like, which is not limited here.

[0074] The preset number threshold is set because there are situations of taking a company's office notebook computer out of the office and using a mobile phone APP without using the company's network. In these situations, the access frequency of the public network IP is small. When going out of the office, a large number of personnel of the unit will not appear at the destination, so the frequency is small. When using a mobile phone, the operator has a large number of Internet IPs that can be mapped, and eventually different access personnel will be dispersed to a large number of Internet export IPs, resulting in a very limited number of access personnel for each IP. These two situations are very different from the situation of privately building an Internet export of an enterprise (a large number of personnel of the enterprise access the Internet through a small number of IPs).

[0075] The preset number threshold is generally an access density index such as access count / hour, access count / day, user number / hour, user number / day, which is not limited here.

[0076] In the practical application of the present application, after determining the privately-built Internet exit IP address, one embodiment of the detection method of the privately-built Internet exit further comprises:

[0077] For each privately-built Internet exit, corresponding positioning information is obtained from the privately-built Internet exit IP address in the triple information; and the unit that exists the behavior of privately building the Internet exit is determined according to the positioning information corresponding to the privately-built Internet exit IP address.

[0078] Specifically, if the positioning information corresponding to the privately-built Internet exit IP address is "attributed to" the same unit, and appears continuously in a long period of time, the IP address is determined to be a privately-built Internet exit IP address, and the unit involved is notified.

[0079] It should be noted that the meaning of "attributed to" is that most (for example, more than 80%) of all positioning information of the exit IP is attributed to the same unit. In this way, false positives caused by "positioning information noise" caused by access of external units are avoided. If a competitor uses "completely attributed to", it should be considered as a special case of "attributed to" of the present application, that is, 100% attributed to the same unit.

[0080] The meaning of continuous appearance is that the alarm condition is met continuously for several hours or several days. This is to eliminate false alarms caused by temporary meetings of all units / departments, such as holding annual meetings in a hotel.

[0081] As can be seen from the above scheme, the present application provides a detection method of a privately-built Internet exit, which uses a unified push software that cannot be bypassed by each unit to detect the privately-built Internet exit, that is, by recording the triple information of each unit when the unified push software accesses the detection server, whether each unit privately builds an Internet exit is determined.

[0082] The present application provides a detection device of a privately-built Internet exit, as shown in Figure 3 Specifically, it comprises:

[0083] The recording unit 301 is used to record the triple information of each unit's unified push software.

[0084] The triple information includes an Internet exit IP address, an access time, and positioning information.

[0085] The analysis unit 302 is used to analyze the received triple information of each unit according to the rules and regulations of the unit, and obtain an analysis result.

[0086] The specific working processes of the units disclosed in the above embodiments of the present application can be found in the corresponding method embodiment contents, which will not be repeated here. Figure 1

[0087] Optionally, in another embodiment of the present application, if the rules and regulations of the unit are that the devices connected to the Internet are prohibited from being taken out of the unit, and only access to the unit network is allowed to access the Internet, an implementation of the analysis unit comprises:

[0088] The first analysis sub-unit is configured to determine that the unit sending the triple information exists the behavior of privately building an Internet exit if the IP address in the triple information is not in the list of legal Internet exit IP addresses.

[0089] The specific working processes of the units disclosed in the above embodiments of the present application can be found in the corresponding method embodiment contents, which will not be repeated here.

[0090] Optionally, in another embodiment of the present application, if the rules and regulations of the unit are that the devices connected to the Internet are allowed to be taken out of the unit, and can temporarily access the Internet through other networks, an implementation of the analysis unit comprises:

[0091] The screening unit is configured to, for each triple information sent by the unit, take the triple information in which the IP address is not in the list of legal Internet exit IP addresses as suspicious triple information.

[0092] The suspicious triple information comprises a suspicious IP address, an access time, and positioning information.

[0093] The statistical unit is configured to statistically analyze all suspicious triple information within the legal working hours to obtain statistical information.

[0094] The statistical information at least comprises a suspicious IP address and a report count.

[0095] The first determination unit is configured to determine that the suspicious IP address is a privately built Internet exit IP address if the report count is greater than a preset number threshold within a preset time interval.

[0096] The specific working processes of the units disclosed in the above embodiments of the present application can be found in the corresponding method embodiment contents, which will not be repeated here. Figure 2

[0097] Optionally, in another embodiment of the present application, an implementation of the privately built Internet exit detection device further comprises:

[0098] The second determination unit is configured to, for each privately built Internet exit, obtain corresponding positioning information from the triple information according to the privately built Internet exit IP address. ​​

[0099] The third determining unit is configured to determine the unit that has the behavior of privately building the Internet exit according to the positioning information corresponding to the privately built Internet exit IP address.

[0100] The specific working process of the units disclosed in the above embodiments of the application can be referred to the corresponding method embodiment contents, which will not be repeated here.

[0101] As can be seen from the above solution, the application provides a detection device for privately built Internet exit, which uses the unified push software that cannot be bypassed by each unit to detect the privately built Internet exit, that is, by recording the triple information of each unit when accessing the detection server, it is judged whether each unit has privately built the Internet exit.

[0102] The functions described above in this document can be performed, at least in part, by one or more hardware logic components. For example, and without limitation, exemplary types of hardware logic components that can be used include: field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), system on a chip (SOCs), complex programmable logic devices (CPLDs), etc.

[0103] Another embodiment of the application provides an electronic device, as shown in the figure, comprising: Figure 4

[0104] One or more processors 401.

[0105] A storage device 402, which stores one or more programs.

[0106] When the one or more programs are executed by the one or more processors 401, the one or more processors 401 implement the detection method for privately built Internet exit as described in any one of the above embodiments.

[0107] Another embodiment of the application provides a computer storage medium, which stores a computer program, wherein the computer program is executed by a processor to implement the detection method for privately built Internet exit as described in any one of the above embodiments.

[0108] ​In the context of this application, a machine-readable medium can be any tangible medium that can contain, or store a program for use by or in connection with an instruction execution system, apparatus, or device. The machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples of the machine-readable storage medium will include one or more of: a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0109] Note that the computer-readable medium described above in the present application can be a computer-readable signal medium or a computer-readable storage medium or any combination thereof. The computer-readable storage medium, for example, can be, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination thereof. More specific examples of the computer-readable storage medium can include, but are not limited to, an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing. In the present application, the computer-readable storage medium can be any tangible medium that contains or stores a program for use by or in connection with an instruction execution system, apparatus, or device. In the present application, the computer-readable signal medium can include a computer-readable storage medium in a baseband or propagated as a carrier wave in a propagated signal, where the computer-readable program code can be loaded onto an instruction execution system, apparatus, or device. Such a propagated signal can take any of a variety of forms, including, but not limited to, electro-magnetic, optical, or any suitable combination thereof. The computer-readable signal medium can also be any computer-readable medium that is not a computer-readable storage medium and that can communicate, propagate, or transport a program for use by or in connection with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted using any suitable medium, including, but not limited to, wire, cable, RF, or any suitable combination thereof.

[0110] The computer-readable medium described above can be included in the electronic device described above; or can exist separately from the electronic device and be not assembled into the electronic device.

[0111] Another embodiment of the present application provides a computer program product, which, when executed, performs the above-mentioned method for detecting a privately-built Internet exit.

[0112] In particular, according to embodiments of the present application, the processes described above with reference to the flowcharts can be implemented as a computer software program. For example, embodiments of the present application include a computer program product comprising a computer program carried on a non-transitory computer-readable medium, the computer program containing program code for performing the methods illustrated by the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via a communication device, or installed from a storage device, or installed from a ROM. When the computer program is executed by a processing device, the above-mentioned functions defined in the methods of the embodiments of the present application are performed.

[0113] Although the subject matter has been described in language specific to structural features and / or methodological acts, it is to be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or acts described above. Rather, the specific features and acts described above are disclosed as example forms of implementing the claims.

[0114] While several inventive embodiments have been described and illustrated relating to specific features and / or methodological acts, these are not to be considered in a limiting sense as the scope of the present application is defined in the appended claims. Certain features described in the context of separate embodiments can also be implemented in combination in a single embodiment. Conversely, various features described in the context of a single embodiment can also be implemented in multiple embodiments separately or in any suitable sub-combination.

[0115] The above description is only preferred embodiments of the present application and the explanation of the technical principles used. Those skilled in the art should understand that the scope of the application involved in the present application is not limited to the technical solutions formed by the specific combinations of the above technical features, and should also cover other technical solutions formed by any combinations of the above technical features or their equivalent features without departing from the above application concept. For example, the technical solutions formed by mutually replacing the above features with technical features having similar functions applied in the present application (but not limited to) form technical solutions.

Claims

1. A method for detecting a private Internet exit, characterized in that, The method comprises: recording the triple information of each unit when the unit pushes software to access the detection server; wherein the triple information comprises an Internet exit IP address, access time and positioning information; for each unit, analyzing the received triple information of the unit according to the rules and regulations of the unit to obtain an analysis result; wherein, if the rules and regulations of the unit stipulate that the devices connected to the Internet are prohibited from being taken out of the unit and only allow access to the unit network to access the Internet, the analysis of the received triple information of the unit according to the rules and regulations of the unit to obtain an analysis result comprises: if the IP address in the triple information is not in the list of legal Internet exit IP addresses, it is determined that the unit sending the triple information has the behavior of privately building an Internet exit; wherein, if the rules and regulations of the unit stipulate that the devices connected to the Internet can be taken out of the unit and can temporarily access the Internet through other networks, the analysis of the received triple information of the unit according to the rules and regulations of the unit to obtain an analysis result comprises: for each triple information sent by the unit, the triple information in which the IP address is not in the list of legal Internet exit IP addresses is regarded as suspicious triple information; wherein the suspicious triple information comprises a suspicious IP address, access time and positioning information; statistically analyzing all suspicious triple information within the legal working hours to obtain statistical information; wherein the statistical information at least comprises a suspicious IP address and a report count; if the report count is greater than a preset number threshold within a preset time interval, the suspicious IP address is determined to be a privately built Internet exit IP address.

2. The method of claim 1, wherein the method further comprises: if the report count is greater than a preset number threshold within a preset time interval, the suspicious IP address is determined to be a privately built Internet exit IP address, and further comprising: for each privately built Internet exit, obtaining the corresponding positioning information in the triple information according to the privately built Internet exit IP address; determining the unit having the behavior of privately building an Internet exit according to the positioning information corresponding to the privately built Internet exit IP address.

3. A device for detecting a private Internet exit, characterized by comprising: The method comprises: a recording unit configured to record the triple information of each unit when the unit pushes software to access the detection server; wherein the triple information comprises an Internet exit IP address, access time and positioning information; an analysis unit configured to analyze the received triple information of the unit according to the rules and regulations of the unit to obtain an analysis result for each unit; wherein, if the rules and regulations of the unit stipulate that the devices connected to the Internet are prohibited from being taken out of the unit and only allow access to the unit network to access the Internet, the analysis unit comprises: a first analysis subunit configured to determine that the unit sending the triple information has the behavior of privately building an Internet exit if the IP address in the triple information is not in the list of legal Internet exit IP addresses; wherein, if the rules and regulations of the unit stipulate that the devices connected to the Internet can be taken out of the unit and can temporarily access the Internet through other networks, the analysis unit comprises: The screening unit is configured to, for each of the triplet information sent by the unit, screen triplet information in which an IP address is not in the list of legal Internet exit IP addresses as suspicious triplet information; wherein the suspicious triplet information comprises a suspicious IP address, access time, and positioning information; The statistical unit is configured to count all suspicious triplet information within a legal working time to obtain statistical information; wherein the statistical information at least comprises a suspicious IP address and a report count; The first determination unit is configured to determine that the suspicious IP address is a privately-built Internet exit IP address if the report count is greater than a preset quantity threshold within a preset time interval.

4. The apparatus for detecting a private Internet exit according to claim 3, wherein Further comprising: The second determination unit is configured to, for each privately-built Internet exit, obtain corresponding positioning information from the privately-built Internet exit IP address in the triplet information; The third determination unit is configured to determine the unit that exists the behavior of privately-built Internet exit according to the positioning information corresponding to the privately-built Internet exit IP address.

5. An electronic device, comprising: Comprise: One or more processors; A storage device having one or more programs stored thereon; When the one or more programs are executed by the one or more processors, the one or more processors implement the detection method of the privately-built Internet exit according to any one of claims 1 to 2.

6. A computer storage medium, characterized in that A computer program is stored thereon, wherein the computer program is executed by a processor to implement the detection method of the privately-built Internet exit according to any one of claims 1 to 2.

Citation Information

Patent Citations

  • Method, device and system for detecting illegal external connection, storage medium and equipment

    CN112738095A

  • Method for discovering intranet illegal external connection equipment user based on JS plug-in

    CN117938436A