Attack direction determination method and device, electronic equipment and storage medium

By obtaining the adjacency table when a network attack occurs, determining the first and second attack directions of the network attack, the problem of false alarms in the prior art is solved, and the accuracy of the attack direction and the effectiveness of network security processing are improved.

CN119945747APending Publication Date: 2025-05-06SANGFOR TECH INC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411991926.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-31
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

The prior art is prone to false alarms when determining the attack direction of a network attack, and it is difficult to accurately judge the risk level and impact range of the attack traffic.

Method used

By obtaining the adjacency table, the location of the external network equipment, proxy server and probe are determined, and the first attack direction of the network attack is determined based on the IP address, source IP address and destination IP address of the proxy server. At the same time, by comparing the similarity between the data packets captured by the probe and the data packets of the intranet device, the second attack direction of the network attack is determined.

Benefits of technology

It improves the accuracy of the direction of network attacks, reduces the false alarm rate, and can more accurately judge the risk level and impact range of attack traffic.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119945747A_ABST
    Figure CN119945747A_ABST
Patent Text Reader

Abstract

The invention provides an attack direction determination method and device, electronic equipment and a storage medium, and the method comprises the steps: obtaining an adjacency list if a network attack is detected, and enabling the adjacency list to comprise external network equipment, a proxy server located at an Internet exit, and a first probe located between the external network equipment and the proxy server; determining an IP address of the proxy server and a source IP address and a destination IP address in a first data packet corresponding to the first probe; and determining a first attack direction of the network attack between the external network equipment and the proxy server according to the IP address of the proxy server, the source IP address and the destination IP address. According to the scheme, the accuracy of determining the attack direction can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of network security technology, and more specifically, to a method, device, electronic device and storage medium for determining an attack direction. Background Art

[0002] With the rapid development of science and technology, network security has become a vital part of ensuring personal privacy security. When there is a network attack, timely determining the attack direction of the network attack helps security administrators judge the risk level and impact range of the attack traffic, and then perform network security processing based on the risk level and impact range of the attack traffic. However, when determining the attack direction of a network attack, there are often false alarms of the attack direction. Therefore, how to accurately determine the attack direction of a network attack has become an urgent problem to be solved. Summary of the invention

[0003] In view of the above problems, the embodiments of the present application propose a method, device, electronic device and storage medium for determining an attack direction to improve the above problems.

[0004] According to one aspect of an embodiment of the present application, a method for determining an attack direction is provided, comprising: if a network attack is detected, obtaining an adjacency list, wherein the adjacency list includes an external network device, a proxy server located at an Internet exit, and a first probe located between the external network device and the proxy server; determining the IP address of the proxy server and the source IP address and the destination IP address in a first data packet corresponding to the first probe; determining a first attack direction of the network attack between the external network device and the proxy server based on the IP address of the proxy server, the source IP address, and the destination IP address.

[0005] In some embodiments, the adjacency table also includes an intranet device and at least one second probe, wherein at least one second probe is located between the proxy server and the intranet device. After determining the attack direction of the target link according to the target IP address, the source IP address and the destination IP address, the method also includes: determining the similarity between a second data packet corresponding to at least one second probe and the first data packet; determining a second data packet whose corresponding similarity in at least one second data packet is greater than a similarity threshold as a target data packet; and determining a second attack direction of the network attack between the proxy server and the intranet device based on the target data packet and the first data packet.

[0006] In some embodiments, before determining the similarity between the second data packet corresponding to at least one second probe and the first data packet, it also includes: determining the response duration corresponding to the first data packet, the request duration corresponding to the first data packet and the timestamp corresponding to the first data packet; if the IP address of the proxy server is the same as the source IP address, determining a first duration range based on the response duration, the request duration and the timestamp, and obtaining a second data packet of at least one second probe within the first duration range; or if the IP address of the proxy server is the same as the destination IP address, determining a second duration range based on the number of at least one second probe, the response duration, the request duration and the timestamp, and obtaining a second data packet of at least one second probe within the second duration range.

[0007] In some embodiments, determining the second attack direction of the network attack between the proxy server and the intranet device based on the target data packet and the first data packet includes: if the number of the target data packets is the same as the number of the second probes, and the first attack direction is from the external network to the internal network, then determining the second attack direction is from the external network to the internal network; or if the number of the target data packets is the same as the number of at least one of the second probes, and the first attack direction is from the internal network to the external network, then determining the second attack direction is from the internal network to the external network; or if the number of the target data packets is different from the number of at least one of the second probes, and the If the first attack direction is from the external network to the internal network, then it is determined that the second attack direction between the second probe corresponding to the target data packet and the proxy server is from the external network to the internal network, and the second attack direction of the network attack between the remaining second probes and the internal network devices is from the internal network to the internal network; or if the number of the target data packets is different from the number of at least one second probe, and the first attack direction is from the internal network to the external network, then it is determined that the second attack direction between the second probe corresponding to the target data packet and the proxy server is from the internal network to the external network, and the second attack direction between the remaining second probes and the internal network devices is from the internal network to the internal network.

[0008] In some embodiments, determining the first attack direction of the network attack between the external network device and the proxy server based on the IP address of the proxy server, the source IP address and the destination IP address includes: if the IP address of the proxy server is the same as the destination IP address, determining that the first attack direction is from the external network to the internal network; or if the IP address of the proxy server is the same as the source IP address, determining that the first attack direction is from the internal network to the external network.

[0009] In some embodiments, the method further includes: if the IP address of the proxy server is different from the source IP address and the destination IP address, determining the first attack direction according to first network information corresponding to the source IP address and second network information corresponding to the destination IP address.

[0010] In some embodiments, the method also includes: if it is determined in the database that the data corresponding to the first network information belongs to the target internal asset or the data corresponding to the first network information meets the internal asset characteristics, then the first network information is determined to be an intranet; or if it is determined in the database that the data corresponding to the first network information does not belong to the target internal asset, and the data corresponding to the first network information does not meet the internal asset characteristics, then the network information corresponding to the first network information is determined to be an external network; or if it is determined in the database that the data corresponding to the second network information belongs to the target internal asset or the data corresponding to the second network information meets the internal asset characteristics, then the network information corresponding to the second network information is determined to be an intranet; or if it is determined in the database that the data corresponding to the second network information does not belong to the target internal asset, and the data corresponding to the second network information does not meet the internal asset characteristics, then the network information corresponding to the second network information is determined to be an external network.

[0011] In some embodiments, the determining of the first attack direction based on the first network information corresponding to the source IP address and the second network information corresponding to the destination IP address includes: if the first network information is an external network and the second network information is an intranet, then the first attack direction is from the intranet to the external network; or if the first network information is an intranet and the second network information is an external network, then the first attack direction is from the external network to the intranet; or if the first network information is an intranet and the second network information is an intranet, then the first attack direction is from the intranet to the intranet.

[0012] According to one aspect of an embodiment of the present application, a device for determining an attack direction is provided, the device comprising: an adjacency table acquisition module, for acquiring an adjacency table if a network attack is detected, wherein the adjacency table includes an external network device, a proxy server located at an Internet exit, and a first probe located between the external network device and the proxy server; a determination module, for determining the IP address of the proxy server and the source IP address and the destination IP address in a first data packet corresponding to the first probe; a first attack direction determination module, for determining the first attack direction of the network attack between the external network device and the proxy server based on the IP address of the proxy server, the source IP address, and the destination IP address.

[0013] According to one aspect of an embodiment of the present application, an electronic device is provided, including: a processor; a memory, wherein the memory stores computer-readable instructions, and when the computer-readable instructions are executed by the processor, the method for determining the attack direction as described above is implemented.

[0014] According to one aspect of an embodiment of the present application, a computer-readable storage medium is provided, on which computer-readable instructions are stored. When the computer-readable instructions are executed by a processor, the method for determining the attack direction as described above is implemented.

[0015] According to one aspect of an embodiment of the present application, a computer program product is provided, including computer instructions, and when the computer instructions are executed by the processor, the method for determining the attack direction as described above is implemented.

[0016] In the present application, when a network attack is detected, the external network device, the proxy server located at the Internet exit, and the first probe located between the external network device and the proxy server are determined by obtaining an adjacency table, so that the IP address of the proxy server and the source IP address and the destination IP address in the first data packet corresponding to the first probe can be determined, and then the first attack direction of the network attack between the external network device and the proxy server can be determined based on the proxy server address, the source IP address, and the destination IP address. The present application improves the accuracy of the attack direction of the network attack by determining the attack direction of the network attack based on the location of the probe, the IP address corresponding to the proxy server, and the data packet corresponding to the probe.

[0017] It is to be understood that both the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the invention. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] The drawings herein are incorporated into the specification and constitute a part of the specification, illustrate embodiments consistent with the present application, and together with the specification are used to explain the principles of the present application. Obviously, the drawings described below are only some embodiments of the present application, and for ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0019] Figure 1 is a flow chart of a method for determining an attack direction according to an embodiment of the present application;

[0020] Figure 2 is a flow chart of a method for determining an attack direction according to another embodiment of the present application;

[0021] Figure 3 is a simplified topological diagram according to an embodiment of the present application;

[0022] Figure 4 is a flowchart of specific steps after step 250 according to an embodiment of the present application;

[0023] Figure 5 is a flow chart of a method for determining an attack direction according to another embodiment of the present application;

[0024] Figure 6 is a flow chart of a method for determining an attack direction according to another embodiment of the present application;

[0025] Figure 7 It is a schematic diagram of a flow chart of making a judgment based on a data packet reported by a probe according to an embodiment of the present application;

[0026] Figure 8 It is a schematic diagram of a process of sequentially judging the network information corresponding to the source IP address and the destination IP address according to an embodiment of the present application;

[0027] Fig. 9 is a block diagram of a device for determining an attack direction according to an embodiment of the present application;

[0028] Fig.10 A block diagram of an electronic device according to an embodiment of the present application for executing a method for determining an attack direction according to an embodiment of the present application is shown;

[0029] Fig.11 A storage unit for storing or carrying a program code for implementing a scrambling method for a model according to an embodiment of the present application is shown. DETAILED DESCRIPTION

[0030] Example embodiments will now be described more fully with reference to the accompanying drawings. However, example embodiments can be implemented in a variety of forms and should not be construed as limited to the examples set forth herein; rather, these embodiments are provided so that this application will be more comprehensive and complete and fully convey the concept of the example embodiments to those skilled in the art.

[0031] In addition, described feature, structure or characteristic can be combined in one or more embodiments in any suitable manner. In the following description, many specific details are provided to provide a full understanding of the embodiments of the present application. However, those skilled in the art will appreciate that the technical scheme of the present application can be put into practice without one or more of the specific details, or other methods, components, devices, steps, etc. can be adopted. In other cases, known methods, devices, realizations or operations are not shown or described in detail to avoid blurring the various aspects of the application.

[0032] The block diagrams shown in the accompanying drawings are merely functional entities and do not necessarily correspond to physically independent entities. That is, these functional entities may be implemented in software form, or in one or more hardware modules or integrated circuits, or in different networks and / or processor devices and / or microcontroller devices.

[0033] The flowcharts shown in the accompanying drawings are only exemplary and do not necessarily include all the contents and operations / steps, nor must they be executed in the order described. For example, some operations / steps can be decomposed, and some operations / steps can be combined or partially combined, so the actual execution order may change according to actual conditions.

[0034] At present, the commonly used method to determine the attack direction is generally based on the internal and external attributes of the IP address. For example, if the source IP is an intranet address and the destination IP is an external address, the attack direction is from inside to outside. However, this approach cannot solve the scenario where the external address is used internally, so false positives may occur.

[0035] In a multi-layer proxy scenario, if the source IP and destination IP are directly obtained, it is very likely that the external-to-inside traffic will be identified as internal-to-inside (the source IP address is modified by the proxy service to the IP address of the proxy server). In order to solve the proxy problem, the current main idea is to make a judgment in combination with X-Forwarded-For (XFF for short). In combination with the judgment idea of ​​XFF, the user's proxy server must be configured with XFF, so that the user's original IP will be recorded in the XFF field, and the system obtains the real client IP by extracting XFF. The following scenarios may have false positives in this solution: 1. If the proxy server does not have XFF turned on, the real client IP will not be identified; 2. When the proxy server with XFF turned on is not at the Internet exit, the external real client IP will not be identified; 3. In the scenario of forged XFF, the extracted client IP may be forged, which affects the identification of the attack direction.

[0036] In response to the above problems, the inventors have discovered after long-term research and proposed a method, device, electronic device and storage medium for determining the attack direction provided in the embodiments of the present application. When a network attack is detected, the external network device, the proxy server located at the Internet exit and the first probe located between the external network device and the proxy server are determined by using the acquired adjacency table. In this way, the IP address of the proxy server and the source IP address and destination IP address in the first data packet corresponding to the first probe can be determined. Furthermore, the first attack direction of the network attack between the external network device and the proxy server can be determined based on the proxy server address, the source IP address and the destination IP address, thereby improving the accuracy of the attack direction of the network attack.

[0037] In order to better understand the solutions of the embodiments of the present application, the technical terms used in the embodiments of the present application are explained below.

[0038] Source IP: refers to the IP address of the sender of a data packet in network communication. It identifies the starting location of the data packet, that is, which device or host sent the data packet. In network communication, the IP address is a unique identifier used to identify the device in the network. After passing through the proxy, it may be modified to the IP address of the proxy server.

[0039] Destination IP: refers to the IP address of the recipient of a data packet in network communications. It identifies the destination of the data packet, that is, which device or host is the intended recipient of the data packet. In network communications, the IP address is used to uniquely identify devices in the network. When internal assets return packets to the proxy server, it may be modified to the IP address of the proxy server.

[0040] Internet Gateway Proxy: A proxy server located between the local network and the Internet, acting as an intermediary to help users on the internal network access external Internet resources.

[0041] Load Balancer: A device or software system used to distribute network traffic or computing tasks. Its main function is to evenly distribute incoming requests or loads to multiple servers or resources to optimize resource usage and improve system response speed and reliability. Load balancers play an important role in modern network architecture, especially in high availability and high performance application scenarios.

[0042] Adjacency List: It is a common method for representing graph data structures, especially for sparse graphs. A graph consists of a set of vertices (nodes) and edges connecting these vertices. The adjacency list effectively represents the connection relationship of the graph by maintaining a list for each vertex to record the vertices directly connected to it.

[0043] Internal assets: usually refers to the resources and property owned and controlled by an organization or enterprise. These assets are usually used to support the operation, production and strategic goals of the enterprise. The management and optimization of internal assets is one of the key factors for the success of an enterprise.

[0044] External Assets: In contrast to internal assets, external assets refer to assets that are not managed internally by the enterprise.

[0045] The embodiments of the present application will be described below in conjunction with the accompanying drawings.

[0046] See also Figure 1 , Figure 1 A flow chart of a method for determining an attack direction provided in an embodiment of the present application is shown. The method for determining the attack direction determines the external network device, the proxy server located at the Internet exit, and the first probe located between the external network device and the proxy server through the acquired adjacency table when a network attack is detected, thereby being able to determine the IP address of the proxy server and the source IP address and destination IP address in the first data packet corresponding to the first probe, and then being able to determine the first attack direction of the network attack between the external network device and the proxy server based on the proxy server address, source IP address, and destination IP address, thereby improving the accuracy of the attack direction of the network attack. In a specific embodiment, the method for determining the attack direction can be applied to, for example, Fig.10 The attack direction determination device 100 and the electronic device 200 equipped with the attack direction determination device 100 are shown in FIG. Fig.11 ). Figure 1 The process shown is described in detail, and the method for determining the attack direction may specifically include the following steps:

[0047] Step S110: if a network attack is detected, an adjacency table is obtained, wherein the adjacency table includes an external network device, a proxy server located at an Internet exit, and a first probe located between the external network device and the proxy server.

[0048] As a way, in the network security incident detection and response, the current network attacks are mainly carried out through traffic to the internal network. In order to deal with the network attack, the attack direction of the network attack based on the traffic can be determined first. In this way, the security administrator can judge the risk level and impact range of the attack traffic based on the attack direction of the network attack based on the traffic, so as to protect and deal with the network attack. Optionally, methods such as network sniffing, network firewalls, and attack analysis tools can be used to determine whether the user network is under network attack.

[0049] Optionally, the external network device refers to an Internet device that exchanges data with the internal network device where the user network is located through a proxy server, and the probe refers to a tool for monitoring and analyzing network traffic to capture and analyze network data packets. The probe is placed at different nodes in the link through which the external network device and the internal network device communicate. The external network device transmits the data or traffic of the external device to the internal network device through the Internet exit and the proxy server connected to the Internet exit, or transmits the data or traffic in the internal network device to the external network device through the proxy server. Therefore, a first probe can be set between the external network device and the proxy server to obtain the corresponding data packets when the external network device and the proxy server transmit data or traffic based on the first probe.

[0050] Step S120: Determine the IP address of the proxy server and the source IP address and the destination IP address in the first data packet corresponding to the first probe.

[0051] As a method, since the probe can be used to capture and analyze network data packets, the data packets acquired within a period of time can be included in the adjacency table, so as to determine the IP address of the proxy server and the first data packet captured by the first probe by analyzing the first data packet captured by the first probe, wherein the IP address of the proxy server is used to indicate the address of the recipient corresponding to the data or traffic sent by the proxy server. Optionally, the first data packet includes the source IP address and destination IP address of the data packet at the intersection. The source IP address is used to indicate the address of the sender of the data or traffic in the first data packet, and the destination IP address is used to indicate the address of the recipient of the data or traffic in the first data packet.

[0052] Optionally, in the adjacency table, the external network device and the proxy server are both regarded as vertices, and the relationship between each vertex and other vertices exists in the adjacency table. The adjacency table can be queried to determine whether the external network device and the probe are connected, whether the external network device and the proxy server are connected, etc., so that the target link where the external network device, the proxy server, and the first probe are located can be determined by directly obtaining the adjacency table.

[0053] Step S130: determining a first attack direction of the network attack between the external network device and the proxy server according to the IP address of the proxy server, the source IP address and the destination IP address.

[0054] As a method, since the IP address of the proxy server indicates the address of the recipient of the data or traffic, the source IP address indicates the address of the sender of the data or traffic in the first data packet, and the destination IP indicates the address of the recipient of the data or traffic in the first data packet, the first attack direction of the network attack between the external network device and the proxy server can be determined by determining whether the IP address of the proxy server is the same as the source IP address or the destination IP address. Optionally, the first attack direction may include from the external network to the internal network, from the internal network to the external network, and from the internal network to the internal network, etc., wherein, when it is determined that the first attack direction is from the internal network to the internal network, it can be determined that the internal network device is likely to have been compromised and has moved horizontally, so that an alarm can be issued when it is determined that the first attack direction is from the internal network to the internal network.

[0055] In an embodiment of the present application, when a network attack is detected, the external network device, the proxy server located at the Internet exit, and the first probe located between the external network device and the proxy server are determined by the acquired adjacency table, so that the IP address of the proxy server and the source IP address and the destination IP address in the first data packet corresponding to the first probe can be determined, and then the first attack direction of the network attack between the external network device and the proxy server can be determined based on the proxy server address, the source IP address, and the destination IP address. The present application improves the accuracy of the attack direction of the network attack by determining the attack direction of the network attack based on the location of the probe, the IP address corresponding to the proxy server, and the data packet corresponding to the probe.

[0056] As a method, since there are multiple network data exchange nodes in the target link, in order to determine the attack direction of the network attack on the target link, it is possible to obtain the network data packets corresponding to all network data exchange nodes on the target link, that is, obtain the first data packet of the first probe and the second data packet of the second probe.

[0057] Optionally, due to the influence of the data transmission direction on the target link, the duration range corresponding to the data packet corresponding to the second probe is obtained. Therefore, the duration range can be first determined based on the data transmission direction to obtain the second data packet corresponding to the duration range.

[0058] As a method, after determining the first data packet and the second data packet, since the first data packet is a network data packet captured by the first probe, and the direction of the network attack between the Internet and the proxy server can be determined based on the first data packet, but the attack direction of the network attack between the network data exchange nodes behind the proxy server needs to be determined by the first data packet and the second data packet, and then the attack direction on the target link is determined by combining the attack direction between the Internet and the proxy server and the attack direction of the network attack between the network data exchange nodes behind the proxy server.

[0059] Optionally, the attack direction of the network attack between the network data exchange nodes behind the proxy server can be determined by determining the similarity between each second data packet in the second data packet corresponding to at least one second probe and the first data packet. Optionally, if the similarity between the second data packet and the first data packet indicates that the second data packet is exactly the same as the first data packet or the similarity is greater than or equal to a threshold, it can be determined that the attack direction of the network attack between the second probe corresponding to the second data packet and the proxy server is the same as the network attack direction between the Internet and the proxy server.

[0060] Optionally, if there is a similarity between the second data packet and the first data packet indicating that the second data packet is completely different from the first data packet or the similarity is less than a threshold, it is determined that the attack direction of the network attack between the second probe and the proxy server corresponding to the second data packet is different from the network attack direction between the Internet and the proxy server, thereby determining that the attack direction corresponding to the second data packet is from intranet to intranet. Optionally, when the attack direction is determined to be from intranet to intranet, it can be determined that the user network is likely to have been compromised and lateral movement has occurred, thereby providing an alarm prompt when the attack direction is determined to be from intranet to intranet.

[0061] In an embodiment of the present application, when a network attack is detected, the target link where the external network, the proxy server, the first probe, the internal network and at least one second probe are located is determined by the acquired adjacency table, and the first IP attribute of the proxy server and the second IP attribute of the export load corresponding to the target link are determined, so that the data transmission direction of the target link can be determined based on the first IP attribute and the second IP attribute, and then the second data packet of at least one second probe is obtained based on the data transmission direction, and finally the attack direction of the network attack on the target link can be determined based on the first data packet and the second data packet of the first probe. The scheme of the present application improves the accuracy of the attack direction of the network attack by determining the attack direction of the network attack based on the data packets corresponding to the probes at different positions in the target link.

[0062] See also Figure 2 , Figure 2 The following is a flow chart of a method for determining an attack direction provided by an embodiment of the present application. Figure 2 The process shown is described in detail, the adjacency table also includes an intranet device and at least one second probe, wherein at least one second probe is located between the proxy server and the intranet device, and the method for determining the attack direction can specifically include the following steps:

[0063] Step S210: If a network attack is detected, an adjacency table is obtained, wherein the adjacency table includes an external network device, a proxy server located at an Internet exit, and a first probe located between the external network device and the proxy server.

[0064] Step S220: Determine the IP address of the proxy server and the source IP address and the destination IP address in the first data packet corresponding to the first probe.

[0065] Step S230: determining a first attack direction of the network attack between the external network device and the proxy server according to the IP address of the proxy server, the source IP address and the destination IP address.

[0066] Step S240: Determine the similarity between the first data packet and a second data packet corresponding to at least one of the second probes.

[0067] As a method, when an external network device and an internal network device transmit data or traffic, at least one second probe can be placed between the internal network device and the proxy server, so that at least one data exchange node between the internal network device and the proxy server can be monitored by at least one second probe, so as to determine the second attack direction between the network attack proxy server and the internal network device based on at least the second probe.

[0068] Optionally, a corresponding second probe may be set between the intranet device and the proxy server according to the data exchange nodes of the network, that is, a corresponding second probe is set in each data exchange node, and the number of the second probes is the same as the number of the data exchange nodes.

[0069] Optionally, a topology diagram between the intranet device and the extranet device, the proxy server, and the corresponding probes in each data exchange node may be drawn in advance, such as Figure 3 As shown, in the simplified topology diagram, different external network devices and internal network devices are connected by different links. In the first link, the Internet 1 is connected to the proxy server, and there is a probe 1 between the Internet 1 and the proxy server, and there is a probe 2 behind the proxy server. After probe 2, the intranet is connected through probes 3 and 4, and through probes 5 and 6, respectively, wherein probe 1 is the first probe, and probes 2-probe 6 are the second probes; in another link, the Internet 1 is connected to the proxy server, and there is a probe 7 between the Internet 2 and the proxy server, and the intranet is connected through probes 8, 9 and 10 in sequence after the proxy server, wherein probe 7 is the first probe, and probes 8-probe 10 are the second probes. Optionally, the topology diagram can be stored in the form of an adjacency table data structure, so that the adjacency table can be directly obtained in the server corresponding to the intranet device, so as to determine at least one second probe between the intranet device and the proxy server based on the adjacency table.

[0070] Optionally, since the first data packet is a network data packet captured by the first probe, and the first attack direction between the external network device and the proxy server can be determined based on the first data packet, and the second attack direction of the network attack between the data exchange nodes behind the proxy server needs to be determined by the first data packet and the second data packet, and then the network attack direction between the Internet and the proxy server and the attack direction of the network attack between the network data exchange nodes behind the proxy server are combined to determine the attack direction on the target link.

[0071] Optionally, the attack direction of the network attack between the network data exchange nodes behind the proxy server may be determined by determining the similarity between each second data packet in the second data packets corresponding to at least one second probe and the first data packet.

[0072] Optionally, when there are multiple second probes, the similarity between each second data packet and the first data packet can be determined. Optionally, the similarity between the first data packet and the second data packet can be determined by first determining the unique identifiers corresponding to each of the first data packet and the second data packet. If the unique identifier corresponding to the first data packet is the same as the unique identifier corresponding to the second data packet, it is determined that the first data packet and the second data packet are exactly the same, so that the similarity between the first data packet and the second data packet can be determined to be 100%.

[0073] Optionally, the unique identifier of the first data packet or the second data packet may be a unique identifier in the request header of the data packet, such as uuid or fields such as cookie, sessionID, etc., which is used as the unique identifier to determine the similarity between the first data packet and the second data packet. Optionally, the request body and response body of the first data packet and the second data packet may be determined, and the request body and response body may be used as identifiers, so as to determine that the first data packet and the second data packet are exactly the same when the request body and response body of the first data packet and the second data packet are exactly the same. Optionally, it may also be determined whether the TCP sequence numbers corresponding to the first data packet and the second data packet are the same, so as to determine that the first data packet and the second data packet are exactly the same when the TCP sequence numbers corresponding to the first data packet and the second data packet are the same.

[0074] Optionally, when it is determined that the identifiers corresponding to the first data packet and the second data packet are different, the context similarity between the first data packet and the second data packet can be determined, and the context similarity can be used as the similarity between the first data packet and the second data packet. Optionally, the context similarity between the first data packet and the second data packet can be determined by calculating a hash value between the first data packet and the second data packet.

[0075] Step S250: Determine at least one second data packet in the second data packets whose corresponding similarity is greater than a similarity threshold as a target data packet.

[0076] As a method, since the traffic or data is transmitted through a data exchange node corresponding to at least one second probe, when it is determined that there is a second data packet with a corresponding similarity greater than a similarity threshold, it can be determined that the second data packet is a data packet corresponding to the traffic forwarded by the first probe forwarded by the node, so that the second data packet is determined as a target data packet, and then, the attack direction corresponding to the network attack in the target data packet is the same as the attack direction corresponding to the network attack in the first data packet, and then, it can be determined that on the target link, the attack direction from the external network to the first probe, the proxy server and the second probe corresponding to the target data packet is the same as the attack direction from the external network to the first probe. Optionally, the attack direction may include from the external network to the internal network, from the internal network to the external network, and from the internal network to the internal network.

[0077] Optionally, since there may be multiple attack directions on the target link, in order to accurately determine all attack directions of the network attack on the external network device and the internal network device, the number of second probes corresponding to the target data packet and the number of all second probes on the target link can be determined first, so as to determine whether there are multiple attack directions between the internal network device and the proxy server, so as to accurately determine all attack directions on the external network device and the internal network device.

[0078] Step S260: determining a second attack direction of the network attack between the proxy server and the intranet device based on the target data packet and the first data packet.

[0079] As a method, since the target data packet is a data packet in the second data packet whose similarity with the first data packet is greater than a threshold, it can be determined that the data in the target data packet is approximately the same as the data in the first data packet, and further, it can be determined that the second attack direction between the probe corresponding to the target data packet and the proxy server or the intranet device is the same as the first attack direction between the external network device and the proxy server.

[0080] Optionally, when there are target data packets and non-target data packets among multiple second data packets, the link in which the second attack direction is the same as the first attack direction between the external network device and the proxy server can be determined based on the position of the second probe corresponding to the target data packet, and the link in which the second attack direction corresponding to the non-target data packet in the second data packet is different from the first attack direction between the external network device and the proxy server.

[0081] In some embodiments, the step S250 includes: if the number of the target data packets is the same as the number of the second probes, and the first attack direction is from the external network to the internal network, then determining that the second attack direction is from the external network to the internal network.

[0082] As a method, since there may be multiple attack directions on the link from the proxy server to the intranet device, in order to accurately determine all attack directions of the network attack on the link from the proxy server to the intranet device, the number of second probes corresponding to the target data packet and the number of all second probes on the link from the proxy server to the intranet device can be determined first, so as to determine whether there are multiple attack directions on the link from the proxy server to the intranet device, so as to accurately determine the attack direction on the link from the proxy server to the intranet device.

[0083] As a method, when it is determined that the number of target data packets is the same as the number of second probes, it can be determined that all attack directions on the target link are the same as the first attack direction. Therefore, when the first attack direction is determined to be from the external network to the internal network, the second attack direction of the network attack on the entire path of the link from the proxy server to the internal network device is determined to be from the external network to the internal network.

[0084] If the number of the target data packets is the same as the number of at least one of the second probes, and the first attack direction is from the intranet to the extranet, then it is determined that the second attack direction is from the intranet to the extranet.

[0085] As a method, when it is determined that the number of target data packets is the same as the number of second probes, it can be determined that all attack directions on the target link are the same as the first attack direction. Therefore, when the first attack direction is determined to be from the intranet to the extranet, the second attack direction of the network attack on the entire path of the link from the proxy server to the intranet device is determined to be from the intranet to the extranet.

[0086] If the number of the target data packets is different from the number of at least one of the second probes, and the first attack direction is from the external network to the internal network, then it is determined that the second attack direction between the second probe corresponding to the target data packet and the proxy server is from the external network to the internal network, and the second attack direction of the network attack between the remaining second probes and the internal network devices is from internal network to internal network.

[0087] As a method, when it is determined that the number of target data packets is different from the number of second probes, it can be determined that there are multiple attack directions of the network attack on the link from the proxy server to the intranet device. In this way, it can be determined that the attack direction of the path between the second probe corresponding to the target data packet and the proxy server or the intranet is the same as the first attack direction. In this way, when the first attack direction is determined to be from the external network to the intranet, it can be determined that the second attack direction of the network attack on the path between the second probe corresponding to the target data packet and the proxy server is from the external network to the intranet.

[0088] Optionally, on the link from the proxy server to the intranet device, in addition to the path between the second probe corresponding to the target data packet and the proxy server, it also includes the path between the second probe corresponding to the non-target data packet and the intranet device. Since the similarity between the second data packet corresponding to the non-target data packet and the first data packet is less than the similarity threshold, it can be determined that the second attack direction of the network attack between the remaining second probe and the intranet device is from intranet to intranet.

[0089] If the number of the target data packets is different from the number of at least one of the second probes, and the first attack direction is from the intranet to the extranet, then it is determined that the second attack direction between the second probe corresponding to the target data packet and the proxy server is from the intranet to the extranet, and the second attack direction between the remaining second probes and the intranet device is from the intranet to the intranet.

[0090] As a method, when it is determined that the number of target data packets is different from the number of second probes, it can be determined that there are multiple attack directions of the network attack on the link from the proxy server to the intranet device. In this way, it can be determined that the attack direction of the path between the second probe corresponding to the target data packet and the proxy server or the intranet is the same as the first attack direction. In this way, when it is determined that the first attack direction is from the intranet to the extranet, it can be determined that the second attack direction of the network attack on the path between the second probe corresponding to the target data packet and the intranet device is from the intranet to the extranet.

[0091] Optionally, on the link from the proxy server to the intranet device, in addition to the path between the second probe corresponding to the target data packet and the intranet device, the link also includes the path between the second probe corresponding to the non-target data packet and the proxy server. Since the similarity between the second data packet corresponding to the non-target data packet and the first data packet is less than the similarity threshold, it can be determined that the second attack direction of the network attack between the remaining second probe and the proxy server is from intranet to intranet.

[0092] Among them, the specific step descriptions of step S210 to step S230 and step S270 can refer to step S110 to step S130 and step S150, which will not be repeated here.

[0093] In some embodiments, before step S250, Figure 4 As shown, the method also includes:

[0094] Step S310: determine a response duration corresponding to the first data packet, a request duration corresponding to the first data packet, and a timestamp corresponding to the first data packet.

[0095] As a method, in order to accurately determine the second attack direction of the network attack on the proxy server and the intranet device, it is necessary to obtain an accurate second data packet. In order to accurately obtain the second data packet, a time range can be determined first, and then the corresponding second data packet can be obtained based on the time range, thereby ensuring the accuracy of the second data packet and improving the attack direction of the network attack on the target link.

[0096] Optionally, the first data packet may be analyzed to determine from the data of the first data packet the response time corresponding to the instruction to obtain the first data packet and the request time between sending the request to obtain the first data packet and starting to respond to the request. Optionally, the timestamp corresponding to the first data packet may be directly determined from the obtained first data packet.

[0097] Step S320: If the IP address of the proxy server is the same as the source IP address, determine a first duration range based on the response duration, the request duration and the timestamp, and obtain at least one second data packet of the second probe within the first duration range.

[0098] As a method, if the IP address of the proxy server is the same as the source IP address, the data transmission direction in the proxy server is determined to be from the intranet to the extranet, so that the first probe can be determined to be the first probe through which the data or traffic passes, and this can be determined based on the response time of the first data packet, the request time of the first data packet and the timestamp of the first data packet, wherein the request time and the response time can be added to the timestamp corresponding to the first data packet to obtain a new timestamp, and the first time range is determined based on the new timestamp and the timestamp of the first data packet, so as to obtain the second data packet whose timestamp is within the first time range, thereby ensuring the accuracy of the second data packet of the second probe obtained, and thereby ensuring the accuracy of the second attack direction determined based on the first data and the second data packet.

[0099] Step S330, if the IP address of the proxy server is the same as the destination IP address, determine the second duration range based on the number of at least one second probe, the response duration, the request duration and the timestamp, and obtain a second data packet of at least one second probe in the second duration range.

[0100] As a method, if the IP address of the proxy server is the same as the destination IP address, the data transmission direction in the proxy server is determined to be from the external network to the internal network, so as to determine that the first probe is the last probe through which the traffic passes, and then it can be determined based on the response time of the first data packet, the request time of the first data packet and the timestamp of the first data packet, wherein it can be based on the timestamp corresponding to the first data packet plus the request time and response time based on the number of second probes minus the corresponding number in sequence, and add one second to the request time and the response time to obtain a new timestamp, and then determine the second time range based on the new timestamp and the timestamp of the first data packet, so as to obtain the second data packet whose timestamp is within the second time range, thereby ensuring the accuracy of the second data packet of the second probe obtained, thereby ensuring the accuracy of the second attack direction determined based on the first data and the second data packet.

[0101] In this embodiment, in order to determine the second attack direction between the proxy server and the intranet device, the similarity between the second data packet captured by the second probe and the first data packet captured by the first probe can be determined first, and then a target data packet with a similarity greater than a similarity threshold can be determined based on the similarity. In this way, the second attack direction of the network attack between the proxy server and the intranet device can be determined based on the target data packet and the first data packet, thereby ensuring the accuracy of the determined second attack direction.

[0102] See also Figure 5 , Figure 5 The following is a flow chart of a method for determining an attack direction provided by an embodiment of the present application. Figure 5 The process shown is described in detail, and the method for determining the attack direction may specifically include the following steps:

[0103] Step S410: If a network attack is detected, an adjacency table is obtained, wherein the adjacency table includes an external network device, a proxy server located at an Internet exit, and a first probe located between the external network device and the proxy server.

[0104] Step S420: Determine the IP address of the proxy server and the source IP address and the destination IP address in the first data packet corresponding to the first probe.

[0105] Step S430: If the IP address of the proxy server is the same as the destination IP address, it is determined that the first attack direction is from the external network to the internal network.

[0106] As a method, when it is determined that the IP address of the proxy server is the same as the destination IP address, it can be determined that the data flow direction between the external network device and the proxy server is that the proxy server sends the data or traffic received from the external network device, and forwards the data or traffic through the import proxy server so that the traffic or data can be forwarded to the internal network device. In this way, network attacks can be carried out based on this direction, and the first attack direction is determined to be from the external network to the internal network.

[0107] Step S440: If the IP address of the proxy server is the same as the source IP address, it is determined that the first attack direction is from the intranet to the extranet.

[0108] As a method, when it is determined that the IP address of the proxy server is the same as the source IP address, it can be determined that the data flow direction between the external network device and the proxy server is the proxy server sending the data or traffic received from the internal network device, and forwarding the data or traffic through the import proxy server so that the traffic or data can be forwarded to the external network device. In this way, the network attack can be carried out based on this direction, and the first attack direction is determined to be from the internal network to the external network.

[0109] In some embodiments, after step S420, the method further includes:

[0110] If the IP address of the proxy server is different from the source IP address and the destination IP address, the first attack direction is determined according to first network information corresponding to the source IP address and second network information corresponding to the destination IP address.

[0111] As a method, when it is determined that the IP address of the proxy server is different from the source IP address or the destination IP address, it can be determined that at this time, the source IP address can be determined to belong to an intranet device or an extranet device through the first network information corresponding to the source IP address and the second network information corresponding to the destination IP address, and the destination IP address can be determined to belong to an intranet device or an extranet device, and the second attack direction can be determined based on the first network information of the source IP address and the second network information of the destination IP address.

[0112] In some embodiments, if it is determined in the database that the data corresponding to the first network information belongs to the target internal asset or the data corresponding to the first network information meets the internal asset characteristics, the first network information is determined to be an intranet.

[0113] As a method, network assets exist in the database, and network assets may include network equipment, servers, and software, etc., which can be managed through network asset ledgers. Among them, network asset ledgers can be used to monitor and track network assets in real time, and network asset ledgers can be established through methods such as third-party system or product data import, system built-in network asset scanning, and manual investigation by network security personnel.

[0114] Optionally, it is possible to determine in the network asset ledger in the database whether the data corresponding to the source IP address belongs to the target internal asset, wherein the target internal asset may be an existing asset in the ledger, that is, a network asset existing in the network asset ledger. Therefore, when determining that it belongs to the target internal asset, it can be determined that the data corresponding to the source IP attribute is an existing asset in the ledger, and further it can be determined that the first network information corresponding to the source IP address is an intranet.

[0115] As a method, the data corresponding to the source IP address in the database does not belong to the target internal assets. In order to accurately determine the first network information corresponding to the source IP address, it is possible to check whether the data corresponding to the source IP address meets the internal asset characteristics to determine the first network information corresponding to the source IP address.

[0116] Optionally, whether the internal asset characteristics are met may be by determining whether a server address range or domain name range corresponding to the source IP exists in the data corresponding to the source IP address, wherein the server address range or domain name range may be commonly accessible applications corresponding to the terminal device (such as office software, etc.).

[0117] Optionally, whether the internal asset characteristics are met may also include whether the data corresponding to the source IP address contains data packets for accessing the consent authentication application, whether there are data packets for calling the device system automatic update program, whether there are data packets for calling commonly used internal business domain names or IPs, whether there is data with normal traffic exchanges with known internal assets (meeting a predetermined request frequency threshold), and whether there are other surviving internal assets in the same network segment.

[0118] Optionally, when it is determined that the data corresponding to the source IP address meets the internal asset characteristics, it can be determined that the data corresponding to the source IP address can be added to the network asset ledger, so that the first network information corresponding to the source IP address can be determined to be an intranet.

[0119] If it is determined in the database that the data corresponding to the first network information does not belong to the target internal asset, and the data corresponding to the first network information does not meet the characteristics of the internal asset, then it is determined that the network information corresponding to the first network information is an external network.

[0120] As a method, when it is determined in the database that the source IP address does not belong to the target internal asset and the data corresponding to the source IP address does not meet the internal asset characteristics, it can be determined that the data corresponding to the source IP address is data forwarded from the external network to the internal network via a proxy server, and therefore it can be determined that the first network information corresponding to the source IP address is from the external network.

[0121] If it is determined in the database that the data corresponding to the second network information belongs to the target internal asset or the data corresponding to the second network information meets the internal asset characteristics, the network information corresponding to the second network information is determined to be an intranet.

[0122] As one method, it is possible to determine whether the data corresponding to the destination IP address belongs to the target internal assets in the network asset ledger in the database, wherein the target internal assets may be existing assets in the ledger, that is, network assets existing in the network asset ledger. Therefore, when determining that it belongs to the target internal assets, it can be determined that the data corresponding to the destination IP attributes is an existing asset in the ledger, and then it can be determined that the second network information corresponding to the destination IP address is an intranet.

[0123] As a method, the data corresponding to the destination IP address in the database does not belong to the target internal assets. In order to accurately determine the second network information corresponding to the destination IP address, it is possible to check whether the data corresponding to the destination IP address meets the internal asset characteristics to determine the second network information corresponding to the destination IP address.

[0124] Optionally, whether the internal asset characteristics are met may be by determining whether a server address range or domain name range corresponding to the destination IP exists in the data corresponding to the destination IP address, wherein the server address range or domain name range may be commonly accessible applications (such as office software, etc.) corresponding to the terminal device.

[0125] Optionally, whether the internal asset characteristics are met may also include whether the data corresponding to the destination IP address contains data packets for accessing the consent authentication application, whether data packets for calling the device system automatic update program, whether data packets for calling commonly used internal business domain names or IPs, whether data has normal traffic exchanges with known internal assets (meeting a predetermined request frequency threshold), and whether there are other surviving internal assets in the same network segment.

[0126] Optionally, when it is determined that the data corresponding to the destination IP address meets the internal asset characteristics, it can be determined that the data corresponding to the destination IP address can be added to the network asset ledger, so that the second network information corresponding to the destination IP address can be determined to be an intranet.

[0127] If it is determined in the database that the data corresponding to the second network information does not belong to the target internal asset, and the data corresponding to the second network information does not meet the internal asset characteristics, then it is determined that the network information corresponding to the second network information is an external network.

[0128] As a method, when it is determined in the database that the destination IP address does not belong to the target internal asset and the data corresponding to the destination IP address does not meet the internal asset characteristics, it can be determined that the data corresponding to the destination IP address is data forwarded from the external network to the internal network via a proxy server, and therefore it can be determined that the second network information corresponding to the destination IP address is from the external network.

[0129] In some embodiments, determining the first attack direction according to the first network information corresponding to the source IP address and the second network information corresponding to the destination IP address includes:

[0130] If the first network information is an external network and the second network information is an internal network, the first attack direction is from the internal network to the external network.

[0131] As a method, when the first network information is an external network and the second network information is an internal network, it can be determined that the source IP address in the first data packet is an internal network device and the destination IP address is an external network device, thereby determining that the first attack direction is from the internal network to the external network.

[0132] If the first network information is an intranet and the second network information is an extranet, then the first attack direction is from the extranet to the intranet.

[0133] As a method, when the first network information is an intranet and the second network information is an extranet, it can be determined that the source IP address in the first data packet is an extranet device and the destination IP address is an intranet device, thereby determining that the first attack direction is from the extranet to the intranet.

[0134] If the first network information is an intranet and the second network information is an intranet, then the first attack direction is from the intranet to the intranet.

[0135] As a method, when the first network information is an intranet and the second network information is an intranet, it can be determined that the source IP address in the first data packet is an intranet device and the destination IP address is also an intranet device, thereby determining that the first attack direction is from intranet to intranet.

[0136] The specific step description of step S410 to step S420 can refer to step S110 to step S120, which will not be repeated here.

[0137] In this embodiment, the first attack direction is determined by determining whether the IP address of the proxy server is the same as the source IP address or the destination IP address, and when it is determined that the IP address of the proxy server is different from the source IP address or the destination IP address, the first attack direction is determined by determining first network information corresponding to the source IP address and second network information of the destination IP address, thereby determining the first attack direction in a comprehensive manner and improving the accuracy of the determined first attack direction.

[0138] Figure 6 According to the method for determining the attack direction shown in an embodiment of the present application, Figure 6 As shown, an adjacency table may be obtained first, so as to determine the target link in the adjacency table, and then determine whether there is a probe between the Internet and the export proxy server in the target link. When it is determined that there is a probe between the Internet and the export proxy server, the data packets reported by the probe between the Internet and the export proxy server are judged, and based on the response time and request time of the data packets reported by the probe between the Internet and the export proxy server, the data packets reported by other probes on the target link within a specified time range are determined to be judged, so as to determine the attack direction of the network attack in the target link; when it is determined that there is no probe between the Internet and the export proxy server, determine whether there is a probe between the proxy server and the intranet, so as to determine whether there is a probe between the proxy server and the intranet, the data packets reported by the probe between the proxy server and the intranet are judged, and based on the response time and request time of the data packets reported by the probe between the proxy server and the intranet, the data packets reported by other probes on the target link within a specified time range are determined to be judged, so as to determine the attack direction of the network attack in the target link; when it is determined that there is no probe between the proxy server and the intranet, the data packets reported by other probes on the target link are judged, so as to determine the attack direction of the network attack in the target link.

[0139] Figure 7 FIG. 1 is a flow chart of judging based on a data packet reported by a probe according to an embodiment of the present application, as shown in FIG. Figure 7As shown, first determine the IP attribute corresponding to the source IP or destination IP in the data packet reported by the probe, and then determine whether the source IP or destination IP in the data packet is the export load IP based on the IP attribute corresponding to the source IP or destination IP. When the source IP is determined to be the export load IP, if the probe is a probe between the proxy server and the intranet, the proxy server is parsed to determine that there are valid data packets before and after the proxy server performs data or traffic proxying. When it is determined that there are valid data packets or the probe is a probe between the Internet and the proxy server, the attack direction of the network attack between the probes is from the external network to the intranet; if it is determined that there is no valid data packet, the attack direction of the network attack between the probes is determined to be from the intranet to the intranet, and continue to determine the similarity between other data packets on the target link and the valid data packet. When the similarity is greater than a threshold, it is determined that the attack direction is the same as the valid data packet, and the attack directions corresponding to the data packets on the same path are aggregated to determine the attack direction of the network attack on the target link.

[0140] If it is determined that the source IP is the export load IP, and if the probe is a probe between the proxy server and the intranet, the proxy server is parsed to determine that there are valid data packets before and after the proxy server performs data or traffic proxying. When it is determined that there are valid data packets or the probe is a probe between the Internet and the proxy server, the attack direction of the network attack between the probes is determined to be from the intranet to the extranet. If it is determined that there are no valid data packets, the attack direction of the network attack between the probes is determined to be from the intranet to the intranet, and the similarity between other data packets on the target link and the valid data packets is continued to be determined. When the similarity is greater than a threshold, it is determined that the attack direction is the same as the valid data packet, and the attack directions corresponding to the data packets on the same path are aggregated to determine the attack direction of the network attack on the target link.

[0141] If it is determined that the IP attributes corresponding to the source IP and the destination IP are not the export load IP, the network information of the source IP attributes and the network information corresponding to the destination IP attributes are judged in turn. After determining the network information of the IP attributes corresponding to the source IP and the destination IP, the attack direction of the network attack on the target link is determined. Among them, if the network information of the IP attributes corresponding to the source IP indicates an external network and the network information of the IP attributes corresponding to the destination IP indicates an internal network, the attack direction is determined to be from the internal network to the external network; if the network information of the IP attributes corresponding to the source IP indicates an internal network and the network information of the IP attributes corresponding to the destination IP indicates an external network, the attack direction is determined to be from the external network to the internal network.

[0142] Figure 8 FIG. 1 is a flow chart showing a process of sequentially judging the network information corresponding to the source IP attribute and the destination IP attribute according to an embodiment of the present application, such as Figure 8 As shown, it can be determined whether the data corresponding to the source IP attribute or the destination IP attribute in the database belongs to a clear internal asset. When it is determined that it belongs to a clear internal asset, it is determined that the data corresponding to the source IP attribute or the destination IP attribute belongs to the internal asset. In this way, it is determined that the network information corresponding to the source IP attribute or the destination IP attribute is an intranet, wherein the clear internal asset refers to the data existing in the internal asset ledger of the database; if it is determined that it does not belong to a clear internal asset, it is determined whether the data corresponding to the source IP attribute or the destination IP attribute in the database meets the internal asset characteristics. When it is determined that it meets the internal asset characteristics, it is determined that the data corresponding to the source IP attribute or the destination IP attribute belongs to the internal asset. In this way, the source IP The network information corresponding to the source IP attribute or the destination IP attribute is the intranet; if it is determined that it does not meet the internal asset characteristics, the data corresponding to the source IP attribute or the destination IP attribute is determined to belong to the external asset, and the network information corresponding to the source IP attribute or the destination IP attribute is determined to be the extranet, where the internal asset characteristics can be the server address range or domain name range of commonly used applications in the device corresponding to the internal network, whether there are data packets for accessing the consent authentication application, whether there are data packets for calling the device system automatic update program, whether there are data packets for calling commonly used internal business domain names or IPs, whether there is data with normal traffic exchanges with known internal assets (meeting the established request frequency threshold), and whether there are other surviving internal assets in the same network segment, etc.

[0143] Fig. 9 A device for determining an attack direction according to an embodiment of the present application is shown. Fig. 9 As shown, the attack direction determination device 100 includes: an adjacency table acquisition module 110 , a determination module 120 and a first attack direction determination module 130 .

[0144] The adjacency table acquisition module 110 is used to obtain an adjacency table if a network attack is detected, wherein the adjacency table includes an external network device, a proxy server located at an Internet exit, and a first probe located between the external network device and the proxy server; the determination module 120 is used to determine the IP address of the proxy server and the source IP address and the destination IP address in the first data packet corresponding to the first probe; the first attack direction determination module 130 is used to determine the first attack direction of the network attack between the external network device and the proxy server based on the IP address of the proxy server, the source IP address and the destination IP address.

[0145] In some embodiments, the adjacency table also includes an intranet device and at least one second probe, wherein at least one second probe is located between the proxy server and the intranet device, and the attack direction determination device 100 also includes: a similarity determination module, used to determine the similarity between a second data packet corresponding to at least one second probe and the first data packet; a target data packet determination module, used to determine a second data packet corresponding to at least one second data packet whose similarity is greater than a similarity threshold as a target data packet; a second attack direction determination module, used to determine the second attack direction of the network attack between the proxy server and the intranet device based on the target data packet and the first data packet.

[0146] In some embodiments, the attack direction determination device 100 includes: a timestamp determination module, which is used to determine the response duration corresponding to the first data packet, the request duration corresponding to the first data packet and the timestamp corresponding to the first data packet; a second data packet acquisition first module, which is used to determine a first duration range based on the response duration, the request duration and the timestamp if the IP address of the proxy server is the same as the source IP address, and obtain at least one second data packet of the second probe within the first duration range; or a second data packet acquisition second module, which is used to determine a second duration range based on the number of at least one second probe, the response duration, the request duration and the timestamp if the IP address of the proxy server is the same as the destination IP address, and obtain at least one second data packet of the second probe within the second duration range.

[0147] In some embodiments, the second attack direction determination module includes: a first determination submodule, which is used to determine that the second attack direction is from the external network to the internal network if the number of the target data packets is the same as the number of the second probes and the first attack direction is from the external network to the internal network; or a second determination submodule, which is used to determine that the second attack direction is from the internal network to the external network if the number of the target data packets is the same as the number of at least one of the second probes and the first attack direction is from the internal network to the external network; or a third determination submodule, which is used to determine that the second attack direction is from the internal network to the external network if the number of the target data packets is different from the number of at least one of the second probes and the first attack direction is from the external network. to the intranet, then determine that the second attack direction between the second probe corresponding to the target data packet and the proxy server is from the external network to the intranet, and the second attack direction of the network attack between the remaining second probes and the intranet devices is from the intranet to the intranet; or a fourth determination submodule is used for, if the number of the target data packets is different from the number of at least one of the second probes, and the first attack direction is from the intranet to the external network, then determine that the second attack direction between the second probe corresponding to the target data packet and the proxy server is from the intranet to the external network, and the second attack direction between the remaining second probes and the intranet devices is from the intranet to the intranet.

[0148] In some embodiments, the first attack direction determination module 130 includes: a fifth determination submodule, used to determine that the first attack direction is from the external network to the internal network if the IP address of the proxy server is the same as the destination IP address; or a sixth determination submodule, used to determine that the first attack direction is from the internal network to the external network if the IP address of the proxy server is the same as the source IP address.

[0149] In some embodiments, the first attack direction determination module 130 also includes: a seventh determination submodule, which is used to determine the first attack direction according to the first network information corresponding to the source IP address and the second network information corresponding to the destination IP address if the IP address of the proxy server is different from the source IP address and the destination IP address.

[0150] In some embodiments, the first attack direction determination module 130 also includes: an intranet first determination submodule, which is used to determine that the first network information is an intranet if it is determined in the database that the data corresponding to the first network information belongs to the target internal asset or the data corresponding to the first network information meets the internal asset characteristics; or an external network first determination submodule, which is used to determine that the network information corresponding to the first network information is an external network if it is determined in the database that the data corresponding to the first network information does not belong to the target internal asset and the data corresponding to the first network information does not meet the internal asset characteristics; or an intranet second determination submodule, which is used to determine that the network information corresponding to the second network information is an intranet if it is determined in the database that the data corresponding to the second network information belongs to the target internal asset or the data corresponding to the second network information meets the internal asset characteristics; or an external network second determination submodule, which is used to determine that the network information corresponding to the second network information is an external network if it is determined in the database that the data corresponding to the second network information does not belong to the target internal asset and the data corresponding to the second network information does not meet the internal asset characteristics.

[0151] In some embodiments, the first attack direction determination module 130 includes: a first attack direction first determination submodule, used for if the first network information is an external network and the second network information is an intranet, then the first attack direction is from the intranet to the external network; or a first attack direction second determination submodule, used for if the first network information is an intranet and the second network information is an external network, then the first attack direction is from the external network to the intranet; or a first attack direction third determination submodule, used for if the first network information is an intranet and the second network information is an intranet, then the first attack direction is from the intranet to the intranet.

[0152] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the above-described devices and modules can refer to the corresponding processes in the aforementioned method embodiments, and will not be repeated here.

[0153] In several embodiments provided in the present application, the coupling between modules may be electrical, mechanical or other forms of coupling.

[0154] In addition, each functional module in each embodiment of the present application can be integrated into a processing module, or each module can exist physically separately, or two or more modules can be integrated into one module. The above integrated modules can be implemented in the form of hardware or software functional modules.

[0155] See also Fig.10, which shows a structural block diagram of an electronic device provided in an embodiment of the present application. The electronic device 200 may be an electronic device capable of running applications, such as a smart phone, a tablet computer, an e-book, etc. The electronic device 200 in the present application may include one or more of the following components: a processor 210, a processor 220, and one or more applications, wherein one or more applications may be stored in the processor 220 and configured to be executed by one or more processors 210, and one or more programs are configured to execute the method described in the aforementioned method embodiment.

[0156] The processor 210 may include one or more processing cores. The processor 210 uses various interfaces and lines to connect the various parts of the entire electronic device 200, and executes various functions and processes data of the electronic device 200 by running or executing instructions, programs, code sets or instruction sets stored in the processor 220, and calling data stored in the processor 220. Optionally, the processor 210 can be implemented in at least one hardware form of digital signal processing (Digital Signal Processing, DSP), field programmable gate array (Field-Programmable Gate Array, FPGA), and programmable logic array (Programmable Logic Array, PLA). The processor 210 can integrate one or a combination of a central processing unit (Central Processing Unit, CPU), a graphics processing unit (Graphics Processing Unit, GPU) and a modem. Among them, the CPU mainly processes the operating system, user interface and application programs; the GPU is responsible for rendering and drawing the content to be displayed; and the modem is used to process wireless communications. It can be understood that the above-mentioned modem may not be integrated into the processor 210, but may be implemented separately through a communication chip.

[0157] The processor 220 may include a random access memory (RAM) or a read-only memory (ROM). The processor 220 may be used to store instructions, programs, codes, code sets or instruction sets. The processor 220 may include a program storage area and a data storage area, wherein the program storage area may store instructions for implementing an operating system, instructions for implementing at least one function (such as a touch function, a sound playback function, an image playback function, etc.), instructions for implementing the following various method embodiments, etc. The data storage area may also store data (such as a phone book, audio and video data, chat record data) created by the electronic device 200 during use.

[0158] See also Fig.11, which shows a structural block diagram of a computer-readable storage medium provided in an embodiment of the present application. The computer-readable medium 300 stores program codes, which can be called by a processor to execute the method described in the above method embodiment.

[0159] The computer readable storage medium 300 can be an electronic memory such as a flash memory, an EEPROM (electrically erasable programmable read-only memory), an EPROM, a hard disk, or a ROM. Optionally, the computer readable storage medium 300 includes a non-transitory computer-readable storage medium. The computer readable storage medium 300 has storage space for program code 310 that performs any method steps in the above method. These program codes can be read from or written to one or more computer program products. The program code 310 can be compressed, for example, in an appropriate form.

[0160] In some implementations, an embodiment of the present application provides a computer program product, which includes a computer program. When the computer program is executed by a processor, the method for determining the attack direction in the embodiment of the present application is implemented.

[0161] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit it. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present application.

Claims

1. A method for determining an attack direction, characterized in that: The method comprises: If a network attack is detected, an adjacency table is obtained, wherein the adjacency table includes an external network device, a proxy server located at an Internet exit, and a first probe located between the external network device and the proxy server; Determine the IP address of the proxy server and the source IP address and the destination IP address in the first data packet corresponding to the first probe; A first attack direction of the network attack between the external network device and the proxy server is determined according to the IP address of the proxy server, the source IP address and the destination IP address.

2. The method according to claim 1, characterized in that: The adjacency table also includes an intranet device and at least one second probe, wherein at least one second probe is located between the proxy server and the intranet device. After determining the attack direction of the target link according to the target IP address, the source IP address and the destination IP address, the method further includes: Determine a similarity between a second data packet corresponding to at least one of the second probes and the first data packet; Determine at least one second data packet in the second data packets whose corresponding similarity is greater than a similarity threshold as a target data packet; A second attack direction of the network attack between the proxy server and the intranet device is determined based on the target data packet and the first data packet.

3. The method according to claim 2, characterized in that Before determining the similarity between the second data packet corresponding to at least one of the second probes and the first data packet, the method further includes: Determine a response duration corresponding to the first data packet, a request duration corresponding to the first data packet, and a timestamp corresponding to the first data packet; If the IP address of the proxy server is the same as the source IP address, determining a first duration range based on the response duration, the request duration and the timestamp, and obtaining at least one second data packet of the second probe within the first duration range; or If the IP address of the proxy server is the same as the destination IP address, the second duration range is determined based on the number of at least one second probe, the response duration, the request duration and the timestamp, and a second data packet of at least one second probe in the second duration range is obtained.

4. The method according to claim 2, characterized in that: The determining, based on the target data packet and the first data packet, a second attack direction of the network attack between the proxy server and the intranet device comprises: If the number of the target data packets is the same as the number of the second probes, and the first attack direction is from the external network to the internal network, then it is determined that the second attack direction is from the external network to the internal network; or If the number of the target data packets is the same as the number of at least one of the second probes, and the first attack direction is from the intranet to the extranet, then determining that the second attack direction is from the intranet to the extranet; or If the number of the target data packets is different from the number of at least one of the second probes, and the first attack direction is from the external network to the internal network, then determine that the second attack direction between the second probe corresponding to the target data packet and the proxy server is from the external network to the internal network, and the second attack direction of the network attack between the remaining second probes and the internal network device is from the internal network to the internal network; or If the number of the target data packets is different from the number of at least one of the second probes, and the first attack direction is from the intranet to the extranet, then it is determined that the second attack direction between the second probe corresponding to the target data packet and the proxy server is from the intranet to the extranet, and the second attack direction between the remaining second probes and the intranet device is from the intranet to the intranet.

5. The method according to any one of claims 1 to 4, characterized in that: The determining, according to the IP address of the proxy server, the source IP address, and the destination IP address, of a first attack direction of the network attack between the external network device and the proxy server comprises: If the IP address of the proxy server is the same as the destination IP address, then determining that the first attack direction is from the external network to the internal network; or If the IP address of the proxy server is the same as the source IP address, it is determined that the first attack direction is from the intranet to the extranet.

6. The method according to claim 5, characterized in that: The method further comprises: If the IP address of the proxy server is different from the source IP address and the destination IP address, the first attack direction is determined according to first network information corresponding to the source IP address and second network information corresponding to the destination IP address.

7. The method according to claim 6, characterized in that The method further comprises: If it is determined in the database that the data corresponding to the first network information belongs to the target internal asset or the data corresponding to the first network information meets the internal asset characteristics, then the first network information is determined to be an intranet; or If it is determined in the database that the data corresponding to the first network information does not belong to the target internal asset, and the data corresponding to the first network information does not meet the internal asset characteristics, then the network information corresponding to the first network information is determined to be an external network; or If it is determined in the database that the data corresponding to the second network information belongs to the target internal asset or the data corresponding to the second network information meets the internal asset characteristics, then the network information corresponding to the second network information is determined to be an intranet; or If it is determined in the database that the data corresponding to the second network information does not belong to the target internal asset, and the data corresponding to the second network information does not meet the internal asset characteristics, then it is determined that the network information corresponding to the second network information is an external network.

8. The method according to claim 6, characterized in that The determining the first attack direction according to the first network information corresponding to the source IP address and the second network information corresponding to the destination IP address includes: If the first network information is an external network and the second network information is an internal network, then the first attack direction is from the internal network to the external network; or If the first network information is an intranet and the second network information is an extranet, then the first attack direction is from the extranet to the intranet; or If the first network information is an intranet and the second network information is an intranet, then the first attack direction is from the intranet to the intranet.

9. A device for determining an attack direction, characterized in that: The device comprises: An adjacency table acquisition module, used to acquire an adjacency table if a network attack is detected, wherein the adjacency table includes an external network device, a proxy server located at an Internet exit, and a first probe located between the external network device and the proxy server; A determination module, used to determine the IP address of the proxy server and the source IP address and the destination IP address in the first data packet corresponding to the first probe; The first attack direction determination module is used to determine the first attack direction of the network attack between the external network device and the proxy server according to the IP address of the proxy server, the source IP address and the destination IP address.

10. An electronic device, characterized in that: The electronic device comprises: one or more processors; a memory, electrically connected to the one or more processors; One or more applications, wherein the one or more applications are stored in the memory and configured to be executed by the one or more processors, and the one or more applications are configured to execute the method according to any one of claims 1 to 8.

11. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores program codes, which can be called by a processor to execute the method according to any one of claims 1 to 8.

12. A computer program product comprising computer instructions, characterized in that: When the computer instructions are executed by a processor, the method according to any one of claims 1 to 8 is implemented.