A network admission method, apparatus, device, medium and product
By employing link and traffic verification schemes and offline network access authentication, the problem of terminal devices being unable to access the intranet due to network link failures has been solved, ensuring enterprise information security and office continuity, and identifying security risks of external devices.
Patent Information
- Application Number
- CN202411985847.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-31
- Publication Date
- 2025-11-25
- Estimated Expiration
- 2044-12-31
AI Technical Summary
In existing technologies, terminal devices need to rely on 802.1x authentication by a switch when accessing the network. If the authentication link fails, they will not be able to access the intranet, and the switch cannot recognize the access of the external hub on the port, which poses a security risk.
Link verification and traffic verification schemes are used to verify the permissions of terminal devices and external devices to ensure the comprehensiveness of the verification. In the event of a network access server link failure, offline network access authentication is used to quickly verify terminal permissions using AI algorithms.
When the network link is interrupted, terminal permissions can be quickly verified and external devices can be identified to ensure the security of internal enterprise information and avoid the risk of link failure affecting normal office work and external device access.
Smart Images

Figure CN119835050B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of information security technology and can be applied to the field of financial technology. In particular, it relates to a network access method, apparatus, device, medium, and product. Background Technology
[0002] To ensure the security of internal corporate information, network access permissions must be verified to prevent unauthorized terminals from accessing internal corporate information and causing data leaks.
[0003] Currently, the network access control method for terminals involves a switch sending data packets to a network access control server. The server then authenticates the terminal's access rights based on information such as the account, password, digital certificate, and product serial number (SN) in the data packet, and returns the authentication result to the terminal, enabling it to access data or perform secondary authentication. On one hand, terminal access control relies on the switch's 802.1x authentication (a port-based network access control protocol). If the authentication link of the network access control server fails, the terminal will be unable to access the intranet, preventing it from accessing internal enterprise information and conducting normal office work. On the other hand, the method by which the switch forwards access request information and the access control server determines the terminal's access permissions cannot identify the access of external hubs, posing a security risk to external devices accessing the enterprise intranet. Summary of the Invention
[0004] This invention provides a network access control method, apparatus, device, medium, and product that can be applied to the financial technology field. It deploys two permission verification methods for access by terminal devices and access by external devices, ensuring the comprehensiveness of permission verification and protecting the security of internal enterprise information.
[0005] According to one aspect of the present invention, a network access method is provided, the method comprising:
[0006] Obtain network access information and determine the access permission verification scheme for the device to be tested based on the network access information. The network access information is network traffic data and / or access request information of terminal devices, and the access permission verification scheme is a link verification scheme and / or a traffic verification scheme.
[0007] Based on the link verification scheme and the access requirement information of the terminal device, determine the first permission verification result of the device to be tested, and / or, based on the traffic verification scheme and network traffic data, determine the second permission verification result of the device to be tested.
[0008] Based on the first permission verification result and / or the second permission verification result, control the device under test to access intranet information and / or adjust device parameters.
[0009] According to another aspect of the present invention, a network access control device is provided for implementing the network access control method in any embodiment of the present invention. The device includes:
[0010] The acquisition module is used to acquire network access information and determine the access permission verification scheme of the device to be inspected based on the network access information. The network access information is network traffic data and / or access request information of terminal devices, and the access permission verification scheme is a link verification scheme and / or a traffic verification scheme.
[0011] The determination module is used to determine the first permission verification result of the device under test based on the link verification scheme and the access requirement information of the terminal device, and / or, based on the traffic verification scheme and network traffic data, determine the second permission verification result of the device under test.
[0012] The verification module is used to control the device under test to access intranet information and / or adjust device parameters based on the results of the first permission verification and / or the second permission verification.
[0013] According to another aspect of the present invention, an electronic device is provided, the electronic device comprising:
[0014] At least one processor; and a memory communicatively connected to the at least one processor;
[0015] The memory stores a computer program that can be executed by at least one processor, such that the at least one processor can perform the network access method in any embodiment of the present invention.
[0016] According to another aspect of the present invention, a computer-readable storage medium is provided that stores computer instructions for causing a processor to execute and implement the network access method of any embodiment of the present invention.
[0017] According to another aspect of the present invention, a computer program product is provided, the computer program product including a computer program that, when executed by a processor, implements the network access method of any embodiment of the present invention.
[0018] The network access control method of the present invention includes: acquiring network access control information, and determining an access permission verification scheme for the device to be tested based on the network access control information, wherein the network access control information is network traffic data and / or access request information of terminal devices, and the access permission verification scheme is a link verification scheme and / or a traffic verification scheme; determining a first access permission verification result for the device to be tested based on the link verification scheme and the access request information of the terminal devices, and / or determining a second access permission verification result for the device to be tested based on the traffic verification scheme and network traffic data; and controlling the device to be tested to access intranet information and / or adjusting device parameters based on the first access permission verification result and / or the second access permission verification result. The present invention sets up two access permission verification methods (i.e., link verification scheme and traffic verification scheme). First, it specifically handles different types of access (i.e., access from terminal devices and access from external devices) to ensure the comprehensiveness of access permission verification and protect the security of internal enterprise information. Second, the link verification scheme of the present invention supports offline network access authentication, ensuring that the access permissions of terminal devices can be verified and evaluated in a timely manner, ensuring the real-time nature of access while guaranteeing information security. This solution addresses the issue that terminal access relies on 802.1x authentication via switches, and if the authentication link of the network access server fails, terminals will be unable to access the intranet, thus hindering access to internal enterprise information and normal office work. It also resolves the security risk of external devices accessing the enterprise intranet due to the inability of the switch to forward access request information and the access server to determine terminal access permissions to identify external hubs.
[0019] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of the present invention, nor is it intended to limit the scope of the invention. Other features of the invention will become readily apparent from the following description. Attached Figure Description
[0020] To more clearly illustrate the technical solutions in this invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0021] Figure 1 This is a flowchart illustrating a network access control method provided by the present invention;
[0022] Figure 2 This is a schematic diagram of the structure of a network access control device provided by the present invention;
[0023] Figure 3 This is a schematic diagram of the structure of an electronic device provided by the present invention. Detailed Implementation
[0024] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are merely some, not all, of the embodiments of the present invention. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without creative effort should fall within the scope of protection of the present invention.
[0025] It should be noted that the terms "first," "second," "initial," "candidate," "intermediate," "target," etc., used in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0026] Industries such as finance and healthcare have stringent data security requirements, necessitating the verification of terminal access permissions. Failure to verify and restrict terminals accessing internal information systems poses the following problems: 1) Unauthorized terminals accessing the corporate network increase the risk of hacker attacks and malware infections. 2) Sensitive information may be accessed by unauthorized terminals, posing a data leakage risk. 3) In the event of a security incident, it becomes impossible to trace the terminal or user, increasing the difficulty of investigation and analysis. 4) Allowing terminals to directly log into the corporate network without checking the security status of accessing terminals (e.g., operating system updates, antivirus software installation, etc.) or confirming that terminal configurations meet internal requirements poses a non-compliance risk. To ensure the secure and stable operation of internal information systems and avoid the above problems, enterprises must implement network access control before terminals access the corporate network, allowing only terminals that meet internal requirements to access internal information systems and data.
[0027] Figure 1 This is a flowchart illustrating a network access control method provided by the present invention. This embodiment is applicable to comprehensively assessing the access permissions of devices with access needs, ensuring the security of data within an enterprise intranet, and other similar situations. This method can be executed by the network access control device provided by the present invention. This device can be implemented in hardware and / or software. In a specific embodiment, the device can be integrated into an electronic device. The following embodiments will illustrate this using the integration of the device into an electronic device as an example. (Refer to...) Figure 1The method specifically includes the following steps:
[0028] S101. Obtain network access information and determine the access permission verification scheme for the device to be tested based on the network access information.
[0029] Network access control is a network security technology that uses a series of verification measures, including identity verification, authorization, and compliance checks, to prevent unauthorized devices from accessing protected computer networks (e.g., intranet databases of financial institutions or medical institutions). Devices to be verified can be understood as those requiring access permission verification. Generally, the entity performing the access verification can be a terminal (forwarding information via a switch) or an interface device (forwarding information via a port). Therefore, devices to be verified include terminals and external devices. Network access information can be understood as the access information of the devices to be verified. This information includes network traffic data and / or access request information from terminal devices. Network traffic data is generated by external devices and can be determined by monitoring port information. Access request information is forwarded by the terminal device (i.e., the terminal itself) via a switch. This access request information includes the terminal's account, password, digital certificate, serial number, etc., and is used to assist the access control server in determining the terminal's operating system patch version, firewall settings, antivirus software version, malware data, etc., thereby assessing whether the terminal can access the corporate intranet. The access permission verification scheme is a link verification scheme and / or a traffic verification scheme. The link verification scheme is used to verify the access permissions of the terminal device, and the traffic verification scheme is used to verify the access permissions of the external device.
[0030] In one implementation, S101 may specifically include: using an information acquisition device deployed on the access verification server to acquire network traffic data and / or access request information of terminal devices; the access request information of terminal devices is generated by a first device to be verified (i.e., a terminal), and the network traffic data is generated by a second device to be verified (i.e., an external device); when the network access information is network traffic data, the access permission verification scheme is determined to be a traffic verification scheme; when the network access information is access request information of terminal devices, the access permission verification scheme is determined to be a link verification scheme; when the network access information is both network traffic data and access request information of terminal devices, the access permission verification scheme is determined to be both a traffic verification scheme and a link verification scheme.
[0031] Since different types of devices have different permission verification methods, in order to ensure the security of internal enterprise information and completely prohibit unauthorized devices from accessing internal enterprise information, this invention sets up two permission verification methods: link verification scheme and traffic verification scheme. Based on network access information, the type of device that needs to be verified is determined, and then the verification scheme is activated in a targeted manner, so as to improve verification efficiency while ensuring the smooth verification process.
[0032] S102. Based on the link verification scheme and the access requirement information of the terminal device, determine the first permission verification result of the device to be tested, and / or, based on the traffic verification scheme and network traffic data, determine the second permission verification result of the device to be tested.
[0033] Specifically, the first permission verification result can be understood as the permission verification result of the first device to be tested, indicating whether the first device to be tested can access the company's internal data. The second permission verification result can be understood as the permission verification result of the second device to be tested, indicating whether the second device to be tested can access the company's internal data. When the permission verification result is authorized, the corresponding device is allowed to access the company's internal data. When the permission verification result is unauthorized, the corresponding device is prohibited from accessing the company's internal data or is only allowed to access the company's publicly available data. In other words, the company's data is classified into different levels, and different data is opened to devices with different permissions.
[0034] When the network access information only includes network traffic data and the access permission verification scheme is a traffic verification scheme, the only device with access requirements is the terminal. Only the first access verification result needs to be determined. S102 determines the first access verification result of the device to be tested based on the link verification scheme and the terminal device's access requirement information. Similarly, when the network access information only includes the terminal device's access requirement information and the access permission verification scheme is a link verification scheme, the only device with access requirements is the external device. Only the second access verification result needs to be determined. S102 determines the second access verification result of the device to be tested based on the traffic verification scheme and network traffic data. When the network access information includes both network traffic data and the terminal device's access requirement information, the access permission verification scheme is a link verification scheme and a traffic verification scheme. The devices with access requirements include both the terminal and the external device. The access permissions of the corresponding devices are verified using the link verification scheme and the traffic verification scheme, respectively. S102 determines the first access verification result of the device to be tested based on the link verification scheme and the terminal device's access requirement information, and determines the second access verification result of the device to be tested based on the traffic verification scheme and network traffic data.
[0035] On the one hand, based on the link verification scheme and the access requirement information of the terminal device, the first permission verification result of the device to be tested is determined, including: determining whether the access verification server's access link is faulty; if the access verification server's access link is normal, the access verification server is used to process the access requirement information of the terminal device to obtain the first permission verification result; if the access verification server's access link is faulty, a self-test command is sent to the device to be tested so that the device to be tested can determine the first permission verification result based on the terminal device's access requirement information and the pre-trained target permission prediction model.
[0036] When the access control link is functioning correctly, it will be used first to verify the terminal's access permissions. This process includes: 1) The terminal sends data packets to the network access control server via a switch; 2) The network access control server performs access authentication based on information such as the account, password, digital certificate, and serial number in the data packet, determining the terminal's operating system patch version, firewall settings, antivirus software version, and malware information, thus obtaining the network authentication result; 3) Based on the network authentication result and compliance check, the network access control server determines the terminal's access permissions and returns the corresponding network access permission policy to the terminal; 4) If the network access permission policy indicates that the terminal is authorized, then the terminal is allowed to access internal enterprise data; if the network access permission policy indicates that the compliance check fails, the terminal will be isolated to a restricted network area, and the user will be prompted to repair the terminal according to the guidelines to re-enter the authentication process. It is worth noting that the network access control server continuously monitors the network behavior of authenticated devices to ensure they always comply with security policies. If device behavior is abnormal, access will be immediately restricted or the terminal isolated, thereby protecting the enterprise's internal data.
[0037] If the access control link fails, it may cause widespread terminal access failures, affecting users' daily work. Therefore, this invention sets up an offline network access authentication method. The self-test command can be understood as the start instruction for offline network access authentication, and the target permission prediction model can be understood as an algorithm pre-trained and stored on the terminal that can predict and parse the terminal's access permissions. This invention can achieve offline network access control, that is, by deploying the algorithm model on the terminal, when the network access control link fails, the control terminal uses the Artificial Intelligence (AI) algorithm model to analyze the terminal's local knowledge base, and then decides whether the terminal has network access permissions, quickly realizing network access and avoiding the inability of terminals to access internal enterprise data due to the suspension of network access control, thus avoiding the impact on users' work.
[0038] Determining the target permission prediction model includes: obtaining historical access verification information from the access verification server, which includes terminal information, user information, and log information; training an initial permission prediction model based on the terminal information, user information, and log information; and determining the trained initial permission prediction model as the target permission prediction model when the initial permission prediction model meets the pre-set model convergence conditions (including but not limited to the number of iterations and the loss function).
[0039] This invention, when the access control link is normal, periodically controls each terminal to interact with the network access control server to obtain permission verification data from the server. A local knowledge base containing network access control information is built on each terminal, and a permission prediction model is trained to verify terminal access permissions in the event of access control link failure, ensuring the stability and feasibility of the verification process. The model's data is real and reliable, thus guaranteeing the accuracy of the prediction results. Furthermore, the model is periodically optimized to ensure both real-time performance and the accuracy of the prediction results.
[0040] Historical access verification information can be understood as permission verification information recorded on the network access server. Terminal information includes, but is not limited to, the terminal's Media Access Control Address (MAC), Internet Protocol (IP) address, and device type; user information includes, but is not limited to, account and password; log information includes, but is not limited to, network usage logs and historical behavior patterns of the device. Furthermore, historical access verification information may also include security policies and compliance requirements that the terminal must comply with, such as the operating system version number, minimum operating system patch number requirements, software version number, minimum software patch number requirements, antivirus software installation requirements, antivirus software virus definition update requirements, user permission requirements, and blacklisted software, etc. Specific information can be set and adjusted according to terminal management and verification needs, and this invention does not limit this.
[0041] The model training process includes: deploying AI algorithms on the terminal to achieve data analysis and access decision functions. This invention may involve supervised learning algorithms, unsupervised learning algorithms, and deep learning algorithms. Supervised learning algorithms can train classification models based on historical data to identify and predict the authorization status of devices. Unsupervised learning algorithms can discover unknown device behavior patterns. Deep learning algorithms can handle more complex patterns and predictions. The purpose of this setup is to train a highly accurate, highly flexible, and highly universal permission prediction model.
[0042] The decision-making access authentication includes: in the event of an access link failure, based on the current terminal's device information (i.e., the terminal device's access request information), using a trained model to identify whether the current terminal is an authorized device, and then judging whether the current terminal meets the access conditions based on the security policies and compliance information in the current knowledge base; simultaneously, it also needs to detect whether the terminal has abnormal behavior, such as whether blacklisted software is installed, or whether there is an attack, etc. If the model identifies the terminal as an authorized device and its behavior is normal, the first permission verification result is determined to be passed, that is, the current terminal is allowed to access the enterprise intranet. Otherwise, the current terminal is denied access to the enterprise intranet, and a security detection mechanism can be triggered to perform security checks on the terminal. Furthermore, this invention can also optimize the model's functionality, enabling it to automatically access the network and initiate security detection mechanisms, saving manpower and processor workload, reducing costs and increasing efficiency.
[0043] On the other hand, the second permission verification result of the device to be tested is determined based on the traffic verification scheme and network traffic data, including: using pre-determined device behavior data to determine interface device detection information; and determining the second permission verification result based on the interface device detection information and network traffic data.
[0044] Network traffic data is typically obtained through the external port status identification component of the network access control module. The network access control module can collect network traffic data from the network access control server, analyze normal network traffic (device behavior data), and parse information such as user browsing habits and communication frequency to determine the operating parameters of external devices to which access permissions are granted, i.e., interface device detection information.
[0045] This invention collects network traffic data from the network access server in real time and analyzes its traffic patterns. If the network traffic data is abnormal (e.g., a sudden increase in traffic, abnormal communication patterns, etc.), it indicates that an external device is accessing through the Hub. At that time, pattern matching technology is used to identify whether the external device is a known device (i.e., whether it is a device included in the interface device detection information). If it is a known device, the external device's permissions are determined to be authorized; if it is not a known device, the external device's permissions are determined to be unauthorized, and an alarm will be issued to alert the user that there is a security threat.
[0046] It is worth noting that this invention can also train a network information detection model, which is a model for judging the current network state and used to identify normal and abnormal network behaviors. This setup aims to improve the diagnostic efficiency of network traffic data. Similarly, the model will be optimized periodically to adapt to network changes and new security threats.
[0047] S103. Based on the first permission verification result and / or the second permission verification result, control the device under test to access intranet information and / or adjust device parameters.
[0048] This invention can initiate different processing tasks based on different verification results, which can not only ensure the security of access to intranet information, but also adjust the parameters of abnormal terminal devices to improve terminal stability.
[0049] On the one hand, when the first permission verification result is authorized, the first device under test is controlled to access intranet information; when the first permission verification result is unauthorized, the first device under test is controlled to perform security detection, and the device parameters of the first device under test are adjusted according to the security detection result of the first device under test.
[0050] For example, when a security test indicates that the terminal's operating system patch version is too low, the terminal's operating system patch should be upgraded. This not only improves the terminal's performance but also prepares the terminal for a second access attempt, increasing the success rate of the second access.
[0051] On the other hand, when the second permission verification result is authorized, the second device to be tested is controlled to access intranet information; when the second permission verification result is unauthorized, the first warning message is generated.
[0052] The first warning message is used to instruct users to promptly handle abnormal external devices and ensure the security of information on the internal network.
[0053] This invention establishes two permission verification methods (i.e., link verification scheme and traffic verification scheme). First, it specifically handles different types of access (i.e., access from terminal devices and access from external devices) to ensure the comprehensiveness of permission verification and protect the security of internal enterprise information. Second, the link verification scheme of this invention supports offline network access authentication, ensuring that the access permissions of terminal devices can be verified and evaluated in a timely manner, ensuring the real-time nature of access while guaranteeing information security. It solves the problem that terminal access relies on 802.1x authentication via switches. If the authentication link of the network access server fails, the terminal will be unable to access the intranet, thus preventing access to internal enterprise information and normal office work. It also solves the problem that the method of switches forwarding access request information and access servers determining terminal access permissions cannot identify external hubs, posing a security risk to external devices accessing the enterprise intranet. The beneficial effects of this invention include: 1) quickly verifying terminal access permissions through offline network access when the network access link is interrupted; 2) identifying external devices such as hubs, avoiding security threats from port-based devices.
[0054] Figure 2 This is a schematic diagram of the structure of a network access control device provided by the present invention. Figure 2 As shown, the device includes: an acquisition module 201, a determination module 202, and a verification module 203.
[0055] The acquisition module 201 is used to acquire network access information and determine the access permission verification scheme of the device to be tested based on the network access information. The network access information is network traffic data and / or access requirement information of terminal devices, and the access permission verification scheme is a link verification scheme and / or a traffic verification scheme.
[0056] The determination module 202 is used to determine the first permission verification result of the device to be tested based on the link verification scheme and the access requirement information of the terminal device, and / or, based on the traffic verification scheme and network traffic data, determine the second permission verification result of the device to be tested.
[0057] The verification module 203 is used to control the device under test to access intranet information and / or adjust device parameters based on the first permission verification result and / or the second permission verification result.
[0058] Optionally, the acquisition module 201 is specifically used to acquire network traffic data and / or access request information of terminal devices using an information acquisition device deployed on the access verification server; wherein, the access request information of the terminal devices is generated by the first device to be verified, and the network traffic data is generated by the second device to be verified; when the network access information is network traffic data, the access permission verification scheme is determined to be a traffic verification scheme; when the network access information is access request information of terminal devices, the access permission verification scheme is determined to be a link verification scheme; when the network access information is both network traffic data and access request information of terminal devices, the access permission verification scheme is determined to be both a traffic verification scheme and a link verification scheme.
[0059] Optionally, the determining module 202 is specifically used to determine whether the access verification server's access link is faulty; if the access verification server's access link is normal, the access verification server processes the access request information of the terminal device to obtain the first permission verification result; if the access verification server's access link is faulty, a self-test command is sent to the device to be tested, so that the device to be tested determines the first permission verification result based on the terminal device's access request information and the pre-trained target permission prediction model.
[0060] Optionally, the network access control device also includes a model training module for determining the target access control prediction model. Specifically, it acquires historical access control verification information from the access control verification server, including terminal information, user information, and log information. Based on the terminal information, user information, and log information, it trains the initial access control prediction model and determines the trained initial access control prediction model as the target access control prediction model when the initial access control prediction model meets the pre-set model convergence conditions.
[0061] Optionally, the determining module 202 is specifically used to determine the interface device detection information using pre-determined device behavior data; and to determine the second permission verification result based on the interface device detection information and network traffic data.
[0062] Optionally, the verification module 203 is specifically used to control the first device under test to access intranet information when the first permission verification result is authorized; to control the first device under test to perform security detection and adjust the device parameters of the first device under test according to the security detection result when the first permission verification result is unauthorized; and / or to control the second device under test to access intranet information when the second permission verification result is authorized; and to generate a first warning message when the second permission verification result is unauthorized.
[0063] The network access control device provided by the present invention can execute the network access control method provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the method.
[0064] Figure 3 This is a schematic diagram of the structure of an electronic device provided by the present invention. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices (such as helmets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the invention described and / or claimed herein.
[0065] like Figure 3 As shown, the electronic device 10 includes at least one processor 11 and a memory, such as a read-only memory (ROM) 12 or a random access memory (RAM) 13, communicatively connected to the at least one processor 11. The memory stores computer programs executable by the at least one processor. The processor 11 can perform various appropriate actions and processes based on the computer program stored in the read-only memory (ROM) 12 or loaded from storage unit 18 into the random access memory (RAM) 13. The RAM 13 can also store various programs and data required for the operation of the electronic device 10. The processor 11, ROM 12, and RAM 13 are interconnected via a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.
[0066] Multiple components in electronic device 10 are connected to I / O interface 15, including: input unit 16, such as keyboard, mouse, etc.; output unit 17, such as various types of displays, speakers, etc.; storage unit 18, such as disk, optical disk, etc.; and communication unit 19, such as network card, modem, wireless transceiver, etc. Communication unit 19 allows electronic device 10 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.
[0067] Processor 11 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. Processor 11 performs the various methods and processes described above, such as network admission methods.
[0068] In some embodiments, the network admission method may be implemented as a computer program tangibly contained in a computer-readable storage medium, such as storage unit 18. In some embodiments, part or all of the computer program may be loaded and / or mounted on electronic device 10 via ROM 12 and / or communication unit 19. When the computer program is loaded into RAM 13 and executed by processor 11, one or more steps of the network admission method described above may be performed. Alternatively, in other embodiments, processor 11 may be configured to perform the network admission method by any other suitable means (e.g., by means of firmware).
[0069] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), payload-programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.
[0070] Computer programs used to implement the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when executed by the processor, the computer programs cause the functions / operations specified in the flowcharts and / or block diagrams to be performed. The computer programs may be executed entirely on a machine, partially on a machine, or as a standalone software package, partially on a machine and partially on a remote machine, or entirely on a remote machine or server.
[0071] In the context of this invention, a computer-readable storage medium can be a tangible medium that may contain or store a computer program for use by or in conjunction with an instruction execution system, apparatus, or device. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination thereof. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.
[0072] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).
[0073] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), middleware components (e.g., application servers), or frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include local area networks (LANs), wide area networks (WANs), blockchain networks, and the Internet.
[0074] A computing system can include clients and servers. Clients and servers are generally located far apart and typically interact through a communication network. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or cloud host, which is a hosting product within the cloud computing service system to address the shortcomings of traditional physical hosts and VPS services, such as high management difficulty and weak business scalability.
[0075] In one embodiment, the present invention further includes a computer program product comprising a computer program that, when executed by a processor, implements the network access method of any embodiment of the present invention.
[0076] In implementing the computer program product, computer program code for performing the operations of this invention can be written in one or more programming languages or a combination thereof. Programming languages include object-oriented programming languages such as Java, Smalltalk, and C++, as well as conventional procedural programming languages such as C or similar languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a local area network (LAN) or a wide area network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).
[0077] It should be understood that the various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps described in this invention can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution of this invention can be achieved, and this is not limited herein.
[0078] The specific embodiments described above do not constitute a limitation on the scope of protection of this invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this invention should be included within the scope of protection of this invention.
Claims
1. A network access control method, characterized in that, include: Obtain network access information and determine the access permission verification scheme for the device to be tested based on the network access information, wherein the network access information is network traffic data and access request information of terminal devices, and the access permission verification scheme is a link verification scheme and a traffic verification scheme; Based on the link verification scheme and the access requirement information of the terminal device, the first permission verification result of the device to be tested is determined, and based on the traffic verification scheme and the network traffic data, the second permission verification result of the device to be tested is determined. Based on the first permission verification result and the second permission verification result, control the device under test to access intranet information and / or adjust device parameters; Based on the link verification scheme and the access requirement information of the terminal device, the first permission verification result of the device to be tested is determined, including: Determine if the access verification server's access link is faulty; If the access verification server's access link is normal, the access verification server is used to process the terminal device's access request information to obtain the first permission verification result. If the access verification server experiences an access link failure, it sends a self-test command to the device under test, enabling the device under test to determine the first permission verification result based on the access requirement information of the terminal device and a pre-trained target permission prediction model.
2. The method according to claim 1, characterized in that, The device to be inspected includes a first device to be inspected and a second device to be inspected. The step of acquiring network access information and determining an access permission verification scheme for the device to be inspected based on the network access information includes: Using an information acquisition device deployed on an access verification server, the network traffic data and the access request information of the terminal device are acquired; wherein, the access request information of the terminal device is generated by the first device to be verified, and the network traffic data is generated by the second device to be verified. When the network access information is the network traffic data, the access permission verification scheme is determined to be the traffic verification scheme; When the network access information is the access request information of the terminal device, the access permission verification scheme is determined to be the link verification scheme; When the network access information is the network traffic data and the access request information of the terminal device, the access permission verification scheme is determined to be the traffic verification scheme and the link verification scheme.
3. The method according to claim 1, characterized in that, Determining the target permission prediction model includes: Obtain historical access verification information from the access verification server, wherein the historical access verification information includes terminal information, user information, and log information; The initial permission prediction model is trained based on the terminal information, the user information, and the log information. When the initial permission prediction model meets the pre-set model convergence conditions, the trained initial permission prediction model is determined as the target permission prediction model.
4. The method according to claim 1, characterized in that, The step of determining the second authorization verification result of the device under test based on the traffic verification scheme and the network traffic data includes: Using pre-defined device behavior data, determine the interface device detection information; Based on the interface device detection information and the network traffic data, the second permission verification result is determined.
5. The method according to claim 2, characterized in that, The step of controlling the device under test to access intranet information and / or adjust device parameters based on the first permission verification result and the second permission verification result includes: When the first permission verification result is authorized, the first device under test is controlled to access intranet information; when the first permission verification result is unauthorized, the first device under test is controlled to perform security detection, and the device parameters of the first device under test are adjusted according to the security detection result of the first device under test. When the second permission verification result is authorized, the second device to be tested is controlled to access intranet information; when the second permission verification result is unauthorized, a first warning message is generated.
6. A network access control device, characterized in that, For implementing the network access control method according to any one of claims 1 to 5, the network access control device comprises: The acquisition module is used to acquire network access information and determine the access permission verification scheme of the device to be tested based on the network access information. The network access information is network traffic data and access request information of terminal devices, and the access permission verification scheme is a link verification scheme and a traffic verification scheme. The determination module is used to determine the first permission verification result of the device to be tested based on the link verification scheme and the access requirement information of the terminal device, and to determine the second permission verification result of the device to be tested based on the traffic verification scheme and the network traffic data. The verification module is used to control the device under test to access intranet information and / or adjust device parameters based on the first permission verification result and the second permission verification result; The determining module is specifically used to: determine whether the access link of the access verification server is faulty; if the access link of the access verification server is normal, then use the access verification server to process the access request information of the terminal device to obtain the first permission verification result; if the access link of the access verification server is faulty, then send a self-test command to the device to be tested, so that the device to be tested can determine the first permission verification result based on the access request information of the terminal device and the pre-trained target permission prediction model.
7. An electronic device, characterized in that, The electronic device includes: At least one processor; and a memory communicatively connected to said at least one processor; The memory stores a computer program that can be executed by the at least one processor, the computer program being executed by the at least one processor to enable the at least one processor to perform the network access method according to any one of claims 1 to 5.
8. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions that cause a processor to execute and implement the network access method according to any one of claims 1 to 5.
9. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the network access method as described in any one of claims 1 to 5.
Citation Information
Patent Citations
Enterprise level network access method and system
CN106936832A
Access control method and system based on security state of terminal host
CN107332803A