Method, apparatus, electronic device, and storage medium for processing network messages

By determining whether the mirror message is a blocking message sent by itself in the bypass blocking device, skipping invalid detection, the problem of message storm in the network is solved and the network is operated stably.

CN119865324BActive Publication Date: 2025-07-11QI-ANXIN LEGENDSEC INFORMATION TECH (BEIJING) INC +1
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202410115345.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-01-26
Publication Date
2025-07-11
Estimated Expiration
2044-01-26

AI Technical Summary

Technical Problem

In the prior art, the bypass blocking device repeatedly detects after generating a blocking message, resulting in a message storm in the network, affecting network stability.

Method used

After obtaining the mirror message of the target network message, first determine whether it is a blocking message sent by the bypass blocking device itself. If so, the security detection will be skipped and discarded to avoid infinite loop detection.

Benefits of technology

By distinguishing between normal messages and blocked messages, invalid security detection is avoided, the network is operated stably, and message storms are prevented.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119865324B_ABST
    Figure CN119865324B_ABST
Patent Text Reader

Abstract

The present application provides a method, apparatus, electronic device, and storage medium for processing network messages. The method for processing network messages is applied to a bypass blocking device and includes: obtaining a mirror message of a target network message; determining whether the mirror message is a blocking message sent by the bypass blocking device itself; if so, skipping the security detection of the mirror message and discarding the mirror message. After obtaining the mirror message, instead of directly performing security detection on the mirror message, it is first determined whether the mirror message is a blocking message sent by the bypass blocking device itself. In this way, it is possible to avoid performing security detection on the already sent blocking message again, thereby avoiding infinite loop detection of the blocking message, enabling detection only on the messages transmitted between the two communication parties, and ensuring the stable operation of the network.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security technologies, and in particular, to a method, apparatus, electronic device, and storage medium for processing network messages. Background Art

[0002] In critical information infrastructure, there are high requirements for the security, stability, processing speed, throughput, etc. of network devices. To ensure the information security of network devices, protection devices are connected in series or reverse proxy in network devices. However, when the protection device operates in series in the network device, it will cause a certain network delay to the network device. Therefore, the bypass blocking technology has emerged.

[0003] Currently, to ensure the information security of network devices through the bypass blocking technology, a blocking device is mainly connected in bypass in the network device. Specifically, when a client sends a message to a server, the bypass blocking device mirrors the message between the client and the server. After obtaining the mirrored message, the bypass blocking device matches the content in the mirrored message with the pre-set security protection rules. If the match is successful, the bypass blocking device considers that the message sent by the client to the server has a security problem, and then sends a blocking message to the client and the server to block the communication between the client and the server. If the match fails, the bypass blocking device considers that the message sent by the client to the server has no security problem, and then allows the client to send a message to the server.

[0004] However, under the Internet Protocol (IP) type of blocking, that is, the security protection rules include abnormal IPs, the IP addresses of the blocking messages sent by the bypass blocking device to the client and the server are the same as those of the messages sent between the client and the server. The blocking messages sent to the client and the server will be mirrored by the bypass blocking device and processed using the pre-set security protection rules. The bypass blocking device will then generate a blocking message for the blocking message and send the newly generated blocking message to the client and the server. During the process of sending the new blocking message to the client and the server, it will be mirrored and processed by the bypass blocking device again. In this way, for a message with a security problem sent between the client and the server, blocking messages will be continuously generated, forming a loop storm, thus affecting the stable operation of the network where the client and the server are located. Summary of the Invention

[0005] The purpose of the embodiments of this application is to provide a method, apparatus, electronic device, and storage medium for processing network messages to ensure the stable operation of the network.

[0006] To solve the above technical problems, the embodiments of this application provide the following technical solutions:

[0007] In the first aspect of the present application, a method for processing network messages is provided. The method is applied to a bypass blocking device, and the method includes: obtaining a mirror message of a target network message; determining whether the mirror message is a blocking message sent by the bypass blocking device itself; if so, skipping the security detection of the mirror message and discarding the mirror message.

[0008] Compared with the prior art, in the method for processing network messages provided in the first aspect of the present application, after obtaining the mirror message of the target network message, the security detection of the mirror message is not directly performed. Instead, it is first determined whether the mirror message is a blocking message sent by the bypass blocking device itself. If so, it means that the obtained mirror message at this time is a blocking message sent by the bypass blocking device itself previously. If the security detection is performed again, it will definitely detect that there are security problems, and then a blocking message will be generated and sent, which will cause a message storm. Therefore, the security detection is no longer performed on this mirror message, and the mirror message is discarded. In this way, it is possible to avoid performing the security detection on the already sent blocking message again, and further avoid the infinite loop detection of the blocking message, so that only the messages transmitted between the two communication parties are detected, ensuring the stable operation of the network.

[0009] In some alternative embodiments of the first aspect of the present application, determining whether the mirror message is a blocking message sent by the bypass blocking device itself includes: obtaining an identifier at a preset position in the mirror message; determining whether the identifier exists in a preset list, and the preset list records the identifiers at the preset positions in the already sent blocking messages; if so, determining that the mirror message is a blocking message sent by the bypass blocking device itself; if not, determining that the blocking message is not a blocking message sent by the bypass blocking device itself.

[0010] By recording the relevant content of the already sent blocking messages in the preset list, when determining whether the mirror message is a blocking message sent previously, the corresponding content in the mirror message is matched with the preset list, which can quickly determine whether the mirror message is a blocking message sent by the bypass blocking device previously, thereby improving the efficiency of the security detection of network messages.

[0011] In some alternative embodiments of the first aspect of the present application, the preset position includes a first position and a second position, and the preset list includes the identifier at the first position and the identifier at the second position in the blocking message; determining whether the identifier exists in the preset list includes: determining whether both the identifier at the first position and the identifier at the second position in the mirror message exist in the preset list; if so, determining that the identifier exists in the preset list; if not, determining that the identifier does not exist in the preset list.

[0012] Matching the contents at two different positions in the mirror message with a preset list respectively can avoid the error caused by comparing a single message alone, and improve the accuracy of judging whether the mirror message is the blocking message sent previously.

[0013] In some modified implementation manners of the first aspect of the present application, the identifier at the preset position in the mirror message is a first value obtained by processing the message content at the preset position in the mirror message with a preset algorithm, and the preset list includes the value obtained by processing the message content at the preset position in the blocking message with the preset algorithm; judging whether the identifier exists in the preset list includes: judging whether the first value is the same as the value in the preset list; if so, determining that the identifier exists in the preset list; if not, determining that the identifier does not exist in the preset list to obtain the first value.

[0014] After processing the content in the mirror message according to a preset algorithm and then matching it with the preset list, if there is more corresponding content in the mirror message, through the preset algorithm processing, the data volume can be reduced, thereby reducing the workload of matching with the preset list, and further improving the judgment efficiency of whether the mirror message is sent by itself previously.

[0015] In some modified implementation manners of the first aspect of the present application, the preset position includes a first position and a second position, the identifier at the preset position in the mirror message is a second value obtained by processing the total content formed by the message content at the first position and the message content at the second position in the mirror message with a preset algorithm, and the preset list includes the value obtained by processing the total content formed by the message content at the first position and the message content at the second position in the blocking message with the preset algorithm; judging whether the identifier exists in the preset list includes: judging whether the second value is the same as the value in the preset list; if so, determining that the identifier exists in the preset list; if not, determining that the identifier does not exist in the preset list.

[0016] Obtain the contents at two different positions in the mirror message, then calculate the combined content with a preset algorithm, and then match the calculated value with the value in the preset list. On the one hand, it can avoid the error caused by matching a single content in the message, and on the other hand, it can reduce the data volume of the two contents, thereby improving the efficiency and accuracy of judging whether the mirror message is the blocking message sent by itself.

[0017] In some modified embodiments of the first aspect of the present application, after determining whether the mirrored message is a blocking message sent by the bypass blocking device itself, the method further includes: if not, performing a security check on the mirrored message; when there is a security issue with the mirrored message, generating a blocking message corresponding to the mirrored message; sending the blocking message corresponding to the mirrored message to both communication parties of the target network message; and recording the blocking message corresponding to the mirrored message in a preset list.

[0018] After determining that the mirrored message is not a blocking message, performing a security check on the mirrored message, and detecting that there is a security issue with the mirrored message, while sending the blocking message corresponding to the mirrored message to both communication parties, recording the blocking message in a preset list to ensure that the blocking messages recorded in the preset list are all the previously sent blocking messages, ensuring the integrity of the blocking message records in the preset list, and thereby improving the accuracy of the determination of whether the mirrored message is a blocking message sent by itself.

[0019] In some modified embodiments of the first aspect of the present application, recording the blocking message corresponding to the mirrored message in the preset list includes: obtaining first message content from a first position of the blocking message corresponding to the mirrored message, where the content corresponding to the first position can uniquely represent the corresponding message; obtaining second message content from a second position of the blocking message corresponding to the mirrored message, where the content corresponding to the second position can uniquely represent the corresponding message, and the second position is different from the first position; processing the total content formed by the first message content and the second message content using a preset algorithm to obtain a blocking value; and recording the blocking value in the preset list.

[0020] When recording the blocking message corresponding to the mirrored message in the preset list, instead of recording the content of the blocking message itself, the method selects the message content at two representative positions in the blocking message, combines them, and calculates the value obtained using a preset algorithm. Since the message content at these two positions can uniquely identify the blocking message, it can accurately distinguish each blocking message in the preset list, and calculating the message using a preset algorithm can reduce the amount of information stored in the preset list.

[0021] The second aspect of the present application provides a network message processing device, which is applied to a bypass blocking device. The device includes: an acquisition module for acquiring a mirrored message of a target network message; a judgment module for judging whether the mirrored message is a blocking message sent by the bypass blocking device itself; if so, entering a processing module; and a processing module for skipping the security check on the mirrored message and discarding the mirrored message.

[0022] The third aspect of the present application provides an electronic device, which includes: a processor, a memory, and a bus; wherein, the processor and the memory communicate with each other through the bus; the processor is configured to call program instructions in the memory to execute the method in the first aspect.

[0023] The fourth aspect of the present application provides a computer-readable storage medium, which includes: a stored program; wherein, when the program runs, it controls the device where the storage medium is located to execute the method in the first aspect.

[0024] The network message processing device provided in the second aspect of the present application, the electronic device provided in the third aspect, and the computer-readable storage medium provided in the fourth aspect have the same or similar technical effects as the network message processing method provided in the first aspect. BRIEF DESCRIPTION OF THE DRAWINGS

[0025] By referring to the accompanying drawings and reading the following detailed description, the above and other objects, features, and advantages of the exemplary embodiments of the present application will become easily understandable. In the drawings, several embodiments of the present application are shown in an exemplary rather than restrictive manner, and the same or corresponding reference numerals represent the same or corresponding parts, wherein:

[0026] Figure 1 It is a schematic diagram of the application scenario of the network message processing method in the embodiment of the present application;

[0027] Figure 2 It is a schematic flow chart of the network message processing method in the embodiment of the present application Figure 1 ;

[0028] Figure 3 It is a schematic flow chart of the network message processing method in the embodiment of the present application Figure 2 ;

[0029] Figure 4 It is a schematic diagram of a partial structure of the blocking message in the embodiment of the present application Figure 1 ;

[0030] Figure 5 It is a schematic diagram of a partial structure of the blocking message in the embodiment of the present application Figure 2 ;

[0031] Figure 6 It is a schematic diagram of the structure of the network message processing device in the embodiment of the present application Figure 1 ;

[0032] Figure 7 It is a schematic diagram of the structure of the network message processing device in the embodiment of the present application Figure 2 ;

[0033] Figure 8Schematic diagram of the structure of the electronic device in the embodiments of the present application. Detailed implementation manners

[0034] The exemplary embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although the exemplary embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure can be implemented in various forms and should not be limited by the embodiments set forth herein. On the contrary, these embodiments are provided so that the present disclosure can be more thoroughly understood and the scope of the present disclosure can be fully conveyed to those skilled in the art.

[0035] It should be noted that unless otherwise specified, the technical terms or scientific terms used in this application should have the ordinary meanings understood by those skilled in the art to which this application belongs.

[0036] Currently, while the bypass blocking device acquires, judges, and blocks the messages transmitted in the network, it also acquires the blocking messages sent by itself, judges that there are security problems with the blocking messages, and sends blocking messages again based on the blocking messages. Repeating this way will form a message storm in the network and affect the normal operation of the network.

[0037] In view of this, the embodiments of the present application provide a method, device, electronic device, and storage medium for processing network messages. After acquiring the mirror message of the target network message (or: target message), instead of directly performing security detection on the mirror message, it first judges whether the mirror message is a blocking message previously sent by the bypass blocking device itself. If so, the mirror message is no longer processed. In this way, normal messages can be distinguished from blocking messages in the acquired mirror messages, avoiding performing security detection on the blocking messages again and sending blocking messages, avoiding message storms, and ensuring the normal operation of the network.

[0038] First, the application scenario of the method for processing network messages provided in the embodiments of the present application will be described.

[0039] Figure 1 Schematic diagram of the application scenario of the method for processing network messages in the embodiments of the present application, see Figure 1 As shown, this scenario may include: client 11, server 12, and bypass blocking device 13.

[0040] When the client 11 sends message a to the server 12, the bypass blocking device 13 mirrors message a in the path from the client 11 to the server 12 to obtain a mirrored message. The bypass blocking device 13 matches the mirrored message with a preset security protection rule. If the match is successful, it is determined that there is a security problem with message a, a blocking message is generated based on message a, and the blocking message is sent to the client 11 and the server 12 through the above path. During the process of sending the blocking message to the client 11 and the server 12, the client 11 also sends message b to the server 12. At this time, the bypass blocking device 13 continues to obtain messages, and may obtain the blocking message or may obtain message b. When obtaining message b, the blocking device 11 first determines whether the mirrored message of message b is sent by the bypass blocking device itself previously. If not, it means the mirrored message is a normal message, and the security detection of the mirrored message is no longer performed. When obtaining the blocking message, the blocking device 11 first determines whether the mirrored message of the blocking message is sent by the bypass blocking device itself previously. If so, it means the mirrored message is the blocking message, and the security detection of the mirrored message is no longer performed. In this way, the messages transmitted between the client 11 and the server 12 can be clearly distinguished by the bypass blocking device 13 to determine whether it is a blocking message or a normal message, and further, no blocking message is generated again based on the blocking message, ensuring the normal operation of the network.

[0041] Next, the method for processing network messages provided in the embodiments of the present application will be described in detail.

[0042] Figure 2 The flow diagram of the method for processing network messages in the embodiments of the present application Figure 1 , see Figure 2 As shown, the method may include:

[0043] S21: Obtain the mirrored message of the target network message.

[0044] The target network message here may refer to a message transmitted within a preset network range. The preset network may refer to a private network, that is, an internal network, or may refer to a public network, that is, an external network or a specified area in the external network, or may refer to a combination of a private network and a public network. The specific range of the preset network needs to be determined according to the object of security detection. For example: When it is necessary to perform security detection on the messages transmitted between a certain client and a certain server, the network here is the network formed between the client and the server.

[0045] In the preset network, when it is monitored that there is a message being transmitted, the message is the target network message. While not affecting the normal transmission of the target network message, the target network message is mirrored to obtain a mirrored message.

[0046] During the mirroring process, a splitting device can be set at the port where the core switch on the external network is connected to the operator (i.e., the server operator). The target network message is split through the splitting device to obtain the mirror message. Other existing data replication technologies can also be used to obtain the mirror message of the target network message.

[0047] S22: Determine whether the mirror message is a blocking message sent by the bypass blocking device itself. If so, execute S23; if not, execute S24.

[0048] After obtaining the mirror message, the mirror message is not immediately subjected to security detection. Instead, it is determined whether the mirror message is a blocking message previously sent by itself. Because after the bypass blocking device determines that there is a security problem in the message normally transmitted between the client and the server, it will generate a blocking message and send it to both the client and the server. While normal messages are being transmitted between the client and the server, blocking messages will also be transmitted. When the bypass blocking device obtains the normally transmitted message, it will also obtain the blocking message. If the obtained blocking message is regarded as a normally transmitted message for security detection, it will also be determined that there is a security problem, and then a blocking message of the blocking message will be generated again and transmitted between the client and the server. Repeating this way, there will be more and more blocking messages between the client and the server, forming a message storm. The normally transmitted message here does not refer to a message without security problems, but a message sent from the client to the server or from the server to the client, rather than a message sent by the bypass blocking device.

[0049] In the specific judgment process, the judgment can be made according to the content in the mirror message. For example: when the mirror message is a Transmission Control Protocol (TCP) message, determine whether the Reset (RST) flag bit in it is 1 and whether there is a modification identifier of the bypass blocking device. If it is 1 and carries the modification identifier of the bypass blocking device, it is determined that the mirror message is a blocking message previously sent by the bypass blocking device itself. If it is not 1 or does not carry the modification identifier of the bypass blocking device, it is determined that the mirror message is not a blocking message previously sent by the bypass blocking device itself. Another example: determine whether a preset identifier exists at a preset position in the mirror message. If it exists, it is determined that the mirror message is a blocking message previously sent by the bypass blocking device itself. If it does not exist, it is determined that the mirror message is not a blocking message previously sent by the bypass blocking device itself. It is also possible to query in the record list of blocking messages already sent by the bypass blocking device. If the same message is found, it is determined that the mirror message is a blocking message previously sent by the bypass blocking device itself. If the same message is not found, it is determined that the mirror message is not a blocking message previously sent by the bypass blocking device itself.

[0050] S23: Skip the security detection of the mirrored message and discard the mirrored message.

[0051] When it is determined that the mirrored message is a blocking message previously sent by the bypass blocking device itself, the security detection of the mirrored message is no longer performed, and the mirrored message can be directly discarded.

[0052] S24: Perform security detection on the mirrored message.

[0053] When it is determined that the mirrored message is not a blocking message previously sent by the bypass blocking device itself, it indicates that the mirrored message is a message sent between the two communication parties. At this time, it is necessary to match the mirrored message with the preset security protection rules. If the match is successful, it indicates that there is a security problem with the target network message corresponding to the mirrored message, and it is necessary to block the connection between the two communication parties of the target network message. That is, a blocking message is generated based on the target network message, and then the blocking message is sent to the two communication parties of the target network message. If the match fails, it indicates that there is no security problem with the target network message corresponding to the mirrored message, and no further processing is performed on the target network message, allowing the target network message to continue to flow.

[0054] The preset security protection rules here are the rules used to detect whether a message has security problems, which can include the characteristics of various messages that have been determined to have security problems, such as: black Internet Protocol (IP) addresses, black port numbers, malicious behavior characteristics, sensitive information characteristics, etc.

[0055] The blocking message is a message obtained by adjusting the main content, converting the source and destination IP addresses, and converting the source and destination ports based on the specific content in the target network message, such as: source IP address, source port, destination IP address, destination port, main content, etc.

[0056] As can be seen from the above, in the method for processing network messages provided by the embodiments of the present application, after obtaining the mirrored message of the target network message, the security detection of the mirrored message is not directly performed, but first it is determined whether the mirrored message is a blocking message sent by the bypass blocking device itself. If so, it indicates that the mirrored message obtained at this time is a blocking message previously sent by the bypass blocking device itself. If the security detection is performed again, it will definitely detect that there is a security problem, and then a blocking message will be generated and sent, which will cause a message storm. Therefore, the security detection is no longer performed on the mirrored message, and the mirrored message is discarded. In this way, it is possible to avoid performing security detection on the already sent blocking message again, and further avoid infinite loop detection of the blocking message, so that only the messages transmitted between the two communication parties are detected, ensuring the stable operation of the network.

[0057] Further, as for Figure 2For the refinement and extension of the method shown, embodiments of the present application also provide a method for processing network messages.

[0058] Figure 3 It is a schematic flow of the method for processing network messages in the embodiments of the present application Figure 2 , see Figure 3 As shown, the method may include:

[0059] S31: Obtain a mirror message of the target network message.

[0060] The specific implementation manner of step S31 is the same as that of the foregoing step S21. For relevant descriptions, refer to the foregoing step S21 and will not be elaborated here.

[0061] S32: Obtain the identifier at the preset position in the mirror message.

[0062] Here, the preset position may be the RST flag bit in the mirror message, or it may be a position preset in the mirror message for configuring the corresponding identifier when it is a blocking message. When the preset position is the RST flag bit, if it indicates blocking, the identifier on it is 1. When the preset position is a preset position, if it indicates blocking, the identifier on it is a pre-agreed identifier. Of course, the identifier at the preset position in the mirror message may also be the message content at the specified position in the mirror message.

[0063] S33: Determine whether the identifier exists in the preset list. If so, execute S34; if not, execute S35.

[0064] Among them, the preset list records the identifiers at the preset positions in the sent blocking messages.

[0065] In the preset list, the blocking message itself can be directly recorded. In order to reduce the occupation of preset list resources, the identifiers at the preset positions in the sent blocking messages can be recorded.

[0066] It should be noted here that if the identifier indicating blocking is fixed, for example: the RST flag bit is 1, the preset identifier, then it can be recorded in the preset list before the blocking message is sent. If the identifier indicating blocking varies based on the message, then after the blocking message is sent, the preset list can record the identifier at the preset position in it according to the sent blocking message.

[0067] To improve the accuracy of judgment, two preset positions can be used. That is, the preset positions include the first position and the second position, and the preset list includes the identifiers at the first position and the second position in the blocking message.

[0068] The above step S33 may include:

[0069] Step A1: Determine whether the identifiers at the first position and the second position in the mirror message both exist in the preset list. If so, execute A2; if not, execute A3.

[0070] Step A2: Determine that the identifier exists in the preset list.

[0071] Step A3: Determine that the identifier does not exist in the preset list.

[0072] In the first position of the mirror message, there is an identifier. In the second position of the mirror message, there is also an identifier. If the target network message corresponding to the mirror message is sent by the bypass blocking device, then the target network message is a blocking message. After the blocking message is sent, the identifiers at the first position and the second position in the blocking message will be recorded in the preset list. Compare the two identifiers obtained from the mirror message with the identifiers in the preset list. If both identifiers match successfully with the preset list, it is determined that the identifiers of the mirror message at the preset position exist in the preset list. If one of the two identifiers fails to match the preset list, it is determined that the identifiers of the mirror message at the preset position do not exist in the preset list.

[0073] For example, assume that the identifier a exists in the first position of the mirror message, and the identifier b exists in the second position. The preset list records the identifiers a, b, and c. Since the identifiers of the mirror message at both positions can match the identifiers in the preset list, it is determined that the identifiers of the mirror message at the preset position exist in the preset list.

[0074] For another example, assume that the identifier a exists in the first position of the mirror message, and the identifier d exists in the second position. The preset list records the identifiers a, b, and c. Since one of the identifiers in the mirror message does not match the identifiers in the preset list, it is determined that the identifiers of the mirror message at the preset position do not exist in the preset list.

[0075] The first position and the second position here can be any two positions in the message. Preferably, positions in different types of structures can be selected. In this way, the difference between the identifiers at the two positions can be maximized, and it can be avoided from being easily tampered with, improving the accuracy of judgment.

[0076] To improve the efficiency of judgment, the value obtained after calculating the message content can be used. That is, the identifier at the preset position in the mirror message is the first value obtained by processing the message content at the preset position in the mirror message using a preset algorithm, and the preset list includes the value obtained by processing the message content at the preset position in the blocking message using the preset algorithm.

[0077] For the message content at the preset position in the mirrored message, if the data volume is large, a preset algorithm can be used for calculation to obtain a value with a smaller data volume, that is, the first value. For example, the message content at the preset position in the mirrored message is "abcdef", and after calculation using the preset algorithm, the value "2" is obtained. In this way, the data volume for subsequent comparison with the preset list can be reduced, the comparison efficiency can be improved, and thus the judgment efficiency can be improved.

[0078] The preset algorithm here can be any algorithm used to reduce the data volume. For example, the Hash algorithm, the Message Digest 5 (MD5) algorithm.

[0079] In the preset list, after the bypass blocking device sends a blocking message during the historical process, the message content at the preset position in the blocking message will be calculated using a preset algorithm to obtain a value. Thereafter, the mirrored message of the target network message is obtained from the network, and the message content is obtained from the preset position of the mirrored message. The obtained identifier is also calculated using this preset algorithm, and then the calculated first value is matched with the value in the preset list. If the match is successful, it is determined that the mirrored message is the blocking message previously sent by the bypass blocking device itself. If the match fails, it is determined that the mirrored message is the mirror of the message for normal communication between the two parties of the message, and security detection needs to be performed.

[0080] The above step S33 may include:

[0081] Step B1 of obtaining the first value: Determine whether the first value is the same as the value in the preset list. If so, execute step B2; if not, execute step B3.

[0082] Step B2: Determine that the identifier exists in the preset list.

[0083] Step B3: Determine that the identifier does not exist in the preset list.

[0084] To improve both the accuracy and efficiency of judgment simultaneously, two preset positions can be used, and the values obtained after calculating the message content are compared. That is, the preset positions include the first position and the second position. The identifier at the preset position in the mirrored message is the total content composed of the message content at the first position and the message content at the second position in the mirrored message, and the second value obtained after processing using the preset algorithm. The preset list includes the total content composed of the message content at the first position and the message content at the second position in the blocking message, and the value obtained after processing using the preset algorithm.

[0085] For the message content formed by the first position and the second position in the mirrored message, if the data volume is large, a preset algorithm can be used for calculation to obtain a value with a smaller data volume, that is, the second value. For example: the message content at the first position in the mirrored message is "abcdef", and the message content at the second position in the mirrored message is "qwertyu". Calculate "abcdefqwertyu" using the preset algorithm to obtain the value "5". In this way, the data volume for subsequent comparison with the preset list can be reduced, the comparison efficiency can be improved, and thus the judgment efficiency can be improved.

[0086] In the preset list, after the bypass blocking device sends a blocking message during the historical process, the message content formed by the first position and the second position in the blocking message is calculated using a preset algorithm to obtain a value. Thereafter, obtain the mirrored message of the target network message from the network, and obtain the message content from the first position and the second position of the mirrored message, and also calculate this message content using the preset algorithm, and then match the calculated second value with the preset list. If the match is successful, it is determined that the mirrored message is the blocking message previously sent by the bypass blocking device itself. If the match fails, it is determined that the mirrored message is the mirror of the message for normal communication between the two parties, and security detection is required.

[0087] The above step S33 may include:

[0088] Step C1: Determine whether the second value is the same as the value in the preset list. If so, execute step C3; if not, execute step C3.

[0089] Step C2: Determine that the identifier exists in the preset list.

[0090] Step C3: Determine that the identifier does not exist in the preset list.

[0091] When it is determined in S33 that the identifier exists in the preset list, then execute S34; when it is determined in S33 that the identifier does not exist in the preset list, then execute S35.

[0092] S34: Determine that the mirrored message is the blocking message sent by the bypass blocking device itself.

[0093] When the identifier at the preset position in the mirrored message exists in the preset list, it indicates that the corresponding target network message is sent by the bypass blocking device. At this time, it can be determined that the mirrored message, that is, the target network message, is the blocking message sent by the bypass blocking device itself.

[0094] S35: Determine that the blocking message is not the blocking message sent by the bypass blocking device itself.

[0095] When the identifier at the preset position in the mirrored message does not exist in the preset list, it indicates that the corresponding target network message is not sent by the bypass blocking device. At this time, it can be determined that the mirrored message, that is, the target network message, is not a blocking message sent by the bypass blocking device itself, but a message sent between the two communication parties.

[0096] After determining that the mirrored message is a blocking message sent by the bypass blocking device itself, the mirrored message at this time does not need to be subjected to security detection, and S36 is executed.

[0097] S36: Skip the security detection of the mirrored message and discard the mirrored message.

[0098] The specific implementation method of step S36 is the same as that of the foregoing step S23. For the relevant description, refer to the foregoing step S23 and will not be elaborated here.

[0099] After determining that the mirrored message is not a blocking message sent by the bypass blocking device itself, it indicates that the target network message corresponding to the mirrored message is a message sent between the two communication parties. The role of the bypass blocking device is precisely for the security detection of the messages transmitted between the two communication parties. Therefore, the mirrored message at this time needs to be subjected to security detection, and S37 is executed.

[0100] S37: Perform security detection on the mirrored message.

[0101] The specific implementation method of step S37 is the same as that of the foregoing step S24. For the relevant description, refer to the foregoing step S24 and will not be elaborated here.

[0102] After performing security detection on the mirrored message using the preset security protection rules, two results will be obtained. One result is that the mirrored message fails to match the preset security protection rules. The other result is that the mirrored message matches the preset security protection rules successfully. For the former, it indicates that there is no security problem with the mirrored message, and its corresponding target network message can flow normally. For the latter, it indicates that there is a security problem with the mirrored message and further processing is required.

[0103] S38: When there is a security problem with the mirrored message, generate a blocking message corresponding to the mirrored message.

[0104] If there is a security problem with the mirrored message, it indicates that there is a security problem with the target network message it mirrors, and further indicates that there is a security problem between the two communication parties of the target network message. It is necessary to generate a corresponding blocking message based on this mirrored message to block the communication between the two communication parties.

[0105] When generating a blocking message corresponding to a mirrored message, the source IP address in the mirrored message can be used as the destination IP address, the source port as the destination port, the destination IP address as the source IP address, the destination port as the source port, the sequence number incremented by 1, the value corresponding to the Identification flag field in the IP header structure incremented by 1, and a random value generated for the 16-bit window size field in the TCP header to obtain a blocking message. Then, this blocking message is sent to the sender of the target network message, and the source IP address, source port, destination IP address, and destination port in the mirrored message remain unchanged, the sequence number is incremented by 1, the value corresponding to the Identification flag field in the IP header structure is incremented by 1, and a random value generated using the above random value is used for the 16-bit window size field in the TCP header to obtain a blocking message. Then, this blocking message is sent to the receiver of the target network message.

[0106] S39: Send the blocking message corresponding to the mirrored message to both communication parties of the target network message.

[0107] S310: Record the blocking message corresponding to the mirrored message in a preset list.

[0108] After the bypass blocking device successfully sends the blocking message corresponding to the mirrored message to both communication parties, it is also necessary to record the blocking message corresponding to the mirrored message in the preset list so that when the blocking message sent is mirrored by the bypass blocking device again, the mirrored message can be identified as the blocking message sent by itself previously through the preset list.

[0109] When recording the blocking message in the preset list, it does not record the blocking message itself, but records the value obtained after calculating the message contents at two different positions in the blocking message.

[0110] Specifically, the above step S310 may include:

[0111] Step E1: Obtain the first message content from the first position of the blocking message corresponding to the mirrored message.

[0112] Among them, the content corresponding to the first position can uniquely represent the corresponding message. In practical applications, the first position can be the Identification flag field in the IP header structure.

[0113] Step E2: Obtain the second message content from the second position of the blocking message corresponding to the mirrored message.

[0114] Among them, the content corresponding to the second position can uniquely represent the corresponding message, and the second position is different from the first position. In practical applications, the second position can be the 16-bit window size field in the TCP header.

[0115] Step E3: Process the total content composed of the first message content and the second message content using a preset algorithm to obtain a blocking value.

[0116] Step E4: Record the blocking value in a preset list.

[0117] After determining that the blocking message has been successfully sent, extract the message content from two positions in the blocking message that can uniquely represent the message, and merge the extracted message content together and calculate it using a preset algorithm. Then, store the calculated blocking value in a preset list. In this way, if the bypass blocking device mirrors the blocking message from the network, and the value obtained by calculating the merged message content at the first position and the second position of the mirrored message using a preset algorithm is the same as a certain value stored in the preset list, it is determined that the mirrored message is the blocking message it sent before, and no further security detection is performed, avoiding the generation of a duplicate blocking message due to the discovery of security issues during repeated security detection, thus avoiding a message storm.

[0118] Finally, taking TCP transmission as an example, the processing of network messages provided in the embodiments of the present application will be described again.

[0119] The bypass blocking device mirrors the TCP message transmitted in the network to obtain a mirrored message, and then matches the mirrored message with a preset security protection rule. If the match is successful, a blocking message is generated based on the mirrored message, and the blocking message is sent to both communication parties of the TCP message through the network.

[0120] Figure 4 This is a partial structural schematic of the blocking message in the embodiments of the present application Figure 1 , see Figure 4 As shown, when generating the blocking message, add 1 to the Identification flag field in the IP header structure of the mirrored message to obtain a new value A, and assign it to the Identification flag field in the IP header of the RST packet.

[0121] Figure 5 This is a partial structural schematic of the blocking message in the embodiments of the present application Figure 2 , see Figure 5 As shown, when generating the blocking message, generate a random value B and assign it to the 16-bit window size field in the TCP header of the RST packet.

[0122] For values A and B, use a hash algorithm (such as CRC32, SHA256, etc.) to process, C = hash(A, B), and then store C in the flow table of the blocked object.

[0123] The bypass blocking device continues to mirror the TCP messages transmitted in the network to obtain mirrored messages, and then extracts identifier E from the Identification identifier field in the IP header of the mirrored messages, and extracts identifier F from the 16-bit window size field in the TCP header. Using the same hash algorithm, C1 = hash(E,F). If the value of C1 is the same as the value of C recorded in the flow table of the blocked object, that is, the RST packet sent by the bypass blocking device itself before, no security detection is performed on this mirrored message, that is, no new RST packet is sent. If the value of C1 is different from the value of C recorded in the flow table of the blocked object, it is not the RST packet sent by the bypass blocking device itself before, and security detection needs to be performed on this mirrored message.

[0124] So far, the method for processing network messages provided by the embodiments of this application has been fully described.

[0125] Based on the same inventive concept, as an implementation of the above method, the embodiments of this application also provide a device for processing network messages.

[0126] Figure 6 The structural schematic of the device for processing network messages in the embodiments of this application Figure 1 , see Figure 6 As shown, the device may include: an acquisition module 61, a judgment module 62, and a processing module 63. Among them, the acquisition module 61, the judgment module 62, and the processing module 63 are connected in sequence.

[0127] The acquisition module 61 is used to acquire the mirrored message of the target network message.

[0128] The judgment module 62 is used to judge whether the mirrored message is a blocking message sent by the bypass blocking device itself; if so, it enters the processing module.

[0129] The processing module 63 is used to skip the security detection of the mirrored message and discard the mirrored message.

[0130] Furthermore, as a refinement and extension of the Figure 6 device shown, the embodiments of this application also provide a device for processing network messages.

[0131] Figure 7 The structural schematic of the device for processing network messages in the embodiments of this application Figure 2 , see Figure 7 As shown, the device may include: an acquisition module 71, a judgment module 72, a processing module 73, a detection module 74, a generation module 75, a blocking module 76, and a storage module 77. Among them, the acquisition module 71, the judgment module 72, the processing module 73, the generation module 75, the blocking module 76, and the storage module 77 are connected in sequence. The detection module 74 is connected to the judgment module 72.

[0132] An obtaining module 71, configured to obtain a mirror message of a target network message.

[0133] A judging module 72, including: an obtaining unit 721, a judging unit 722, a first determining unit 723 and a second determining unit 724. Among them, the obtaining unit 721, the judging unit 722, and the first determining unit 723 are connected in sequence. The second determining unit 724 is connected to the judging unit 722.

[0134] The obtaining unit 721 is configured to obtain an identifier at a preset position in the mirror message.

[0135] The judging unit 722 is configured to judge whether the identifier exists in a preset list, and the preset list records identifiers at preset positions in the sent blocking messages. If so, it enters the first determining unit 723; if not, it enters the second determining unit 724.

[0136] The first determining unit 723 is configured to determine that the mirror message is a blocking message sent by the bypass blocking device itself.

[0137] The second determining unit 724 is configured to determine that the blocking message is not a blocking message sent by the bypass blocking device itself.

[0138] When the preset positions include a first position and a second position, and the preset list includes the identifiers at the first position and the second position in the blocking message, the judging unit 722 is specifically configured to judge whether both the identifier at the first position and the identifier at the second position in the mirror message exist in the preset list; if so, it determines that the identifier exists in the preset list; if not, it determines that the identifier does not exist in the preset list.

[0139] When the identifier at the preset position in the mirror message is a first value obtained by processing the message content at the preset position in the mirror message using a preset algorithm, and the preset list includes the value obtained by processing the message content at the preset position in the blocking message using the preset algorithm, the judging unit 722 is specifically configured to judge whether the first value is the same as the value in the preset list using the obtained first value; if so, it determines that the identifier exists in the preset list; if not, it determines that the identifier does not exist in the preset list.

[0140] When the preset position includes a first position and a second position, and the identifier of the preset position in the mirror message is the total content formed by the message content of the first position and the message content of the second position in the mirror message, and is a second value obtained after being processed by a preset algorithm, and the preset list includes the value obtained after the total content formed by the message content of the first position and the message content of the second position in the blocking message is processed by the preset algorithm, the determination unit 722 is specifically configured to determine whether the second value is the same as the value in the preset list; if so, it is determined that the identifier exists in the preset list; if not, it is determined that the identifier does not exist in the preset list.

[0141] The processing module 73 is configured to skip the security detection of the mirror message and discard the mirror message.

[0142] The detection module 74 is configured to perform a security detection on the mirror message.

[0143] The generation module 75 is configured to generate a blocking message corresponding to the mirror message when there is a security problem with the mirror message.

[0144] The blocking module 76 is configured to send the blocking message corresponding to the mirror message to both communication parties of the target network message.

[0145] The storage module 77 is configured to record the blocking message corresponding to the mirror message in the preset list.

[0146] The storage module 77 includes: a first acquisition unit 771, a second acquisition unit 772, a processing unit 773, and a storage unit 774. Among them, the first acquisition unit 771, the second acquisition unit 772, the processing unit 773, and the storage unit 774 are connected in sequence.

[0147] The first acquisition unit 771 acquires first message content from the first position of the blocking message corresponding to the mirror message, and the content corresponding to the first position can uniquely represent the corresponding message.

[0148] The second acquisition unit 772 is configured to acquire second message content from the second position of the blocking message corresponding to the mirror message, the content corresponding to the second position can uniquely represent the corresponding message, and the second position is different from the first position.

[0149] The processing unit 773 is configured to process the total content formed by the first message content and the second message content by a preset algorithm to obtain a blocking value.

[0150] The storage unit 774 is configured to record the blocking value in the preset list.

[0151] It should be noted here that the description of the above device embodiments is similar to that of the above method embodiments and has similar beneficial effects to those of the method embodiments. For the technical details not disclosed in the device embodiments of the present application, please refer to the description of the method embodiments of the present application for understanding.

[0152] Based on the same inventive concept, an embodiment of the present application further provides an electronic device. Figure 8 For the structural schematic diagram of the electronic device in the embodiment of the present application, see Figure 8 As shown, the electronic device may include: a processor 81, a memory 82, and a bus 83; wherein, the processor 81 and the memory 82 communicate with each other through the bus 83; the processor 81 is used to call program instructions in the memory 82 to execute the method in the above one or more embodiments.

[0153] It should be noted here that the description of the above electronic device embodiments is similar to that of the above method embodiments and has similar beneficial effects to those of the method embodiments. For the technical details not disclosed in the electronic device embodiments of the present application, please refer to the description of the method embodiments of the present application for understanding.

[0154] Based on the same inventive concept, an embodiment of the present application further provides a computer-readable storage medium, which may include: a stored program; wherein, when the program runs, it controls the device where the storage medium is located to execute the method in the above one or more embodiments.

[0155] It should be noted here that the description of the above storage medium embodiments is similar to that of the above method embodiments and has similar beneficial effects to those of the method embodiments. For the technical details not disclosed in the storage medium embodiments of the present application, please refer to the description of the method embodiments of the present application for understanding.

[0156] As described above, the above are only the specific implementation manners of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of changes or substitutions within the technical scope disclosed by the present application, and all should be covered by the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claimed rights.

Claims

1. A method for processing network messages, characterized in that, The method is applied to a bypass blocking device, and the method includes: Obtaining a mirror message of a target network message; Determining whether the mirror message is a blocking message sent by the bypass blocking device itself; If so, skipping the security detection of the mirror message and discarding the mirror message; Wherein, after determining whether the mirror message is a blocking message sent by the bypass blocking device itself, the method further includes: If not, performing a security detection on the mirror message; When there is a security problem with the mirror message, generating a blocking message corresponding to the mirror message; Sending the blocking message corresponding to the mirror message to both communication parties of the target network message; Recording the blocking message corresponding to the mirror message in a preset list; Wherein, recording the blocking message corresponding to the mirror message in the preset list includes: Obtaining a first message content from a first position of the blocking message corresponding to the mirror message, and the content corresponding to the first position can uniquely represent the corresponding message; Obtaining a second message content from a second position of the blocking message corresponding to the mirror message, and the content corresponding to the second position can uniquely represent the corresponding message, and the second position is different from the first position; Processing the total content composed of the first message content and the second message content by a preset algorithm to obtain a blocking value; Recording the blocking value in the preset list.

2. The method according to claim 1, characterized in that, Determining whether the mirror message is a blocking message sent by the bypass blocking device itself includes: Obtaining an identifier at a preset position in the mirror message; Determining whether the identifier exists in a preset list, and the preset list records the identifiers at the preset positions in the already sent blocking messages; If so, determining that the mirror message is a blocking message sent by the bypass blocking device itself; If not, determining that the blocking message is not a blocking message sent by the bypass blocking device itself.

3. The method according to claim 2, wherein The preset position includes a first position and a second position, and the preset list includes the identifier at the first position and the identifier at the second position in the blocking message; Determining whether the identifier exists in the preset list includes: Determining whether both the identifier at the first position and the identifier at the second position in the mirror message exist in the preset list; If so, determining that the identifier exists in the preset list; If not, determining that the identifier does not exist in the preset list.

4. The method according to claim 2, wherein The identifier at the preset position in the mirror message is a first value obtained by processing the message content at the preset position in the mirror message by a preset algorithm, and the preset list includes the value obtained by processing the message content at the preset position in the blocking message by a preset algorithm; Determining whether the identifier exists in the preset list includes: Determining whether the first value is the same as the value in the preset list; If so, determining that the identifier exists in the preset list; If not, determining that the identifier does not exist in the preset list.

5. The method according to claim 2, characterized in that, The preset positions include a first position and a second position. The identifier of the preset position in the mirror message is the second value obtained after processing the total content composed of the message content of the first position and the message content of the second position in the mirror message using a preset algorithm. The preset list includes the value obtained after processing the total content composed of the message content of the first position and the message content of the second position in the blocking message using a preset algorithm; The judging whether the identifier exists in the preset list includes: Judging whether the second value is the same as the value in the preset list; If so, it is determined that the identifier exists in the preset list; If not, it is determined that the identifier does not exist in the preset list.

6. A processing device for network messages, characterized in that, The processing device is applied to a bypass blocking device, and the device includes: An obtaining module, configured to obtain a mirror message of a target network message; A judging module, configured to judge whether the mirror message is a blocking message sent by the bypass blocking device itself; if so, enter the processing module; if not, enter the detection module; A processing module, configured to skip the security detection of the mirror message and discard the mirror message; A detection module, configured to perform a security detection on the mirror message; A generating module, configured to generate a blocking message corresponding to the mirror message when the mirror message has a security problem; A blocking module, configured to send the blocking message corresponding to the mirror message to both communication parties of the target network message; A storage module, configured to record the blocking message corresponding to the mirror message in a preset list; The storage module includes: a first obtaining unit, a second obtaining unit, a processing unit, and a storage unit; The first obtaining unit obtains first message content from the first position of the blocking message corresponding to the mirror message, and the content corresponding to the first position can uniquely represent the corresponding message; The second obtaining unit is configured to obtain second message content from the second position of the blocking message corresponding to the mirror message, and the content corresponding to the second position can uniquely represent the corresponding message, and the second position is different from the first position; The processing unit is configured to process the total content composed of the first message content and the second message content using a preset algorithm to obtain a blocking value; The storage unit is configured to record the blocking value in the preset list.

7. An electronic device, characterized in that, The electronic device includes: a processor, a memory, and a bus; wherein, the processor and the memory complete communication with each other through the bus; the processor is configured to call program instructions in the memory to execute the method according to any one of claims 1 to 5.

8. A computer-readable storage medium, characterized in that, The storage medium includes: a stored program; wherein, when the program runs, it controls the device where the storage medium is located to execute the method according to any one of claims 1 to 5.

Citation Information

Patent Citations

  • Bypass blocking method and device, electronic equipment and storage medium

    CN112738110A