Public network protection method and device, equipment and storage medium

By leveraging the collaborative efforts of WAF and ACC, and utilizing blockchain data for fine-grained verification and transmission mode adjustment, the problem of coarse-grained public network protection has been solved, achieving efficient and secure protection for the public network.

CN119966597BActive Publication Date: 2025-11-04CHINA UNITED NETWORK COMM GRP CO LTD +2
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202311489629.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-11-09
Publication Date
2025-11-04
Estimated Expiration
2043-11-09

AI Technical Summary

Technical Problem

Current technologies offer coarse-grained public network protection, failing to provide fine-grained security protection for public networks and posing significant cybersecurity risks.

Method used

By working together with WAF and ACC, the system utilizes synchronously updated data on the blockchain to perform anomaly checks on IP addresses, configures the SNI identifier for TLS and custom fields in the HTTP request header, and enables fine-grained verification of access requests and dynamic adjustment of transmission modes.

Benefits of technology

It achieves fine-grained point-to-point system protection for the public network, improves network security protection capabilities, and reduces network security risks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119966597B_ABST
    Figure CN119966597B_ABST
Patent Text Reader

Abstract

The application provides a public network protection method and device, equipment and a storage medium. The method comprises the following steps: acquiring synchronization update data on a block chain; receiving an access request sent by any user end, wherein the access request comprises an Internet Protocol (IP) address of the user end; performing abnormality checking on the IP address according to the synchronization update data to obtain a first checking result; if it is determined that the first checking result is passed, configuring a Transport Layer Security (TLS) Server Name Indication (SNI) identifier and a HyperText Transfer Protocol (HTTP) request header custom domain in the access request; and sending the access request to a corresponding Access Control Component (ACC) according to a local routing table, wherein the access request comprises the SNI identifier of the TLS, the HTTP request header custom domain and the IP address, the access entry is unified, and fine-grained point-to-point system protection for the public network is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security, and in particular to a public network protection method, apparatus, device, and storage medium. Background Technology

[0002] Due to limitations in resource distribution and deployment architecture, multiple subsystems of the network platform are deployed across multiple data centers or cloud pools in different regions, communicating and accessing each other via the public internet. As the number of subsystems continues to increase, the network security risks to the public internet also rise, making effective public internet protection a pressing issue that needs to be addressed.

[0003] In existing technologies, security groups are often used in data centers or cloud hosts to control access to clusters consisting of multiple hosts.

[0004] However, existing technologies only apply to access protection for clusters consisting of multiple hosts, which is coarse-grained and cannot provide fine-grained security protection for the public network, thus still posing significant network security risks. Summary of the Invention

[0005] This application provides a public network protection method, device, equipment, and storage medium to solve the technical problem that existing technologies only apply to access protection of clusters composed of multiple hosts, which is coarse-grained and cannot provide fine-grained security protection for the public network, thus still posing considerable network security risks.

[0006] Firstly, this application provides a public network protection method for use in a World Wide Web Application Firewall (WAF), comprising:

[0007] Obtain synchronized updated data on the blockchain;

[0008] Receive an access request sent by any user terminal, wherein the access request includes the Internet Protocol (IP) address of the user terminal;

[0009] An anomaly check is performed on the IP address based on the synchronously updated data to obtain a first check result;

[0010] If the first verification result is determined to be successful, then the Server Name Indicator (SNI) identifier for Transport Layer Security (TLS) and a custom field in the Hypertext Transfer Protocol (HTTP) request header are configured in the access request.

[0011] sending the access request to a corresponding request control component ACC according to a local routing table, wherein the access request comprises the SNI identifier of the TLS, the custom domain of the HTTP request header, and the IP address, so that the ACC obtains corresponding target synchronization update data on the blockchain, wherein the target synchronization update data belongs to the synchronization update data, and determines a target transmission mode according to the SNI identifier of the TLS, judges whether the request source of the access request is a secure source according to the custom domain of the HTTP request header, if it is judged that the request source is a secure source, performs abnormality check on the IP address according to the target synchronization update data to obtain a second check result, and if it is judged that the second check result is a check pass, sends the access request to a target system to be accessed according to the target transmission mode according to a target routing table.

[0012] Optionally, the method as described above, the synchronization update data comprises: an IP whitelist list, user authentication data, and an Open Web Application Security Project (OWASP) Core Rule Set rule, wherein the synchronization update data is uploaded to the blockchain by an operation and maintenance personnel terminal corresponding to an operation and maintenance personnel; accordingly, the abnormality check on the IP address according to the synchronization update data to obtain a first check result comprises: performing a soft anti-distributed denial of service (DDoS) check on the IP address to obtain a first soft anti-check result; performing an IP whitelist and user authentication combined authentication check on the IP address according to the IP whitelist list and the user authentication data to obtain a first authentication check result; performing an abnormal attack check on the IP address according to the OWASP Core Rule Set rule to obtain a first attack check result; and generating the first check result according to the first soft anti-check result, the first authentication check result, and the first attack check result.

[0013] Optionally, the method as described above, the configuration of a server name indication (SNI) identifier of a transport layer security (TLS) and a custom domain of a hypertext transfer protocol (HTTP) request header in the access request comprises: obtaining a target system to be accessed of the access request; configuring the SNI identifier of the TLS of the access request according to the target system to be accessed; obtaining a preset custom domain according to the target system to be accessed, and setting the custom domain of the HTTP request header of the access request according to the custom domain.

[0014] Optionally, the method as described above, the sending of the access request to a corresponding request control component ACC according to a local routing table comprises: obtaining a request control component ACC corresponding to the target system to be accessed according to the target system to be accessed and a local routing table; and sending the access request to the ACC.

[0015] In a second aspect, the present application provides a public network protection method applied to an application control component (ACC), comprising:

[0016] receiving an access request sent by a WAF, wherein the access request comprises a TLS SNI identifier, an HTTP request header custom domain, and an IP address, wherein the TLS SNI identifier and the HTTP request header custom domain are configured in the access request by the WAF after determining that a first check result is passed, wherein the first check result is obtained by the WAF after performing an exception check on the IP address according to synchronization update data, wherein the IP address is any client that sends the access request to the WAF, and wherein the synchronization update data is obtained by the WAF from a blockchain;

[0017] obtaining corresponding target synchronization update data on the blockchain, wherein the target synchronization update data belongs to the synchronization update data;

[0018] determining a target transmission mode according to the TLS SNI identifier;

[0019] determining whether a request source of the access request is a secure source according to the HTTP request header custom domain;

[0020] if it is determined that the request source is a secure source, performing an exception check on the IP address according to the target synchronization update data to obtain a second check result;

[0021] if it is determined that the second check result is passed, sending the access request to a target system to be accessed in the target transmission mode according to a target routing table.

[0022] Optionally, in the method described above, the target synchronization update data comprises target IP whitelist list and target user authentication data; accordingly, the performing an exception check on the IP address according to the target synchronization update data to obtain a second check result comprises performing a soft anti-distributed denial of service (DDoS) check on the IP address to obtain a second soft anti-check result, performing IP whitelist and user authentication combined authentication check on the IP address according to the target IP whitelist list and the target user authentication data to obtain a second authentication check result, and generating the second check result according to the second soft anti-check result and the second authentication check result.

[0023] Optionally, in the method described above, the determining a target transmission mode according to the TLS SNI identifier comprises obtaining the TLS SNI identifier, obtaining a preset transmission requirement according to the TLS SNI identifier, and determining the target transmission mode according to the transmission requirement.

[0024] Optionally, the method as described above, the determining whether the request source of the access request is a secure source according to the custom domain of the HTTP request header comprises: obtaining the custom domain of the HTTP request header; matching the custom domain of the HTTP request header according to a preset custom domain library to obtain a matching result; and determining that the request source of the access request is a secure source if it is determined that the matching result is a matching success.

[0025] In a third aspect, the present application provides a public network protection device applied to a Web Application Firewall (WAF), comprising:

[0026] The obtaining module is configured to obtain synchronization update data on a blockchain.

[0027] The receiving module is configured to receive an access request sent by any user end, wherein the access request comprises an Internet Protocol (IP) address of the user end.

[0028] The checking module is configured to perform abnormality checking on the IP address according to the synchronization update data to obtain a first checking result.

[0029] The configuration module is configured to configure a Server Name Indication (SNI) identifier of Transport Layer Security (TLS) and a custom domain of a HyperText Transfer Protocol (HTTP) request header in the access request if it is determined that the first checking result is a checking success.

[0030] The sending module is configured to send the access request to a corresponding Access Control Component (ACC) according to a local routing table, wherein the access request comprises the SNI identifier of the TLS, the custom domain of the HTTP request header and the IP address, so that the ACC obtains corresponding target synchronization update data on the blockchain, wherein the target synchronization update data belongs to the synchronization update data, determines a target transmission mode according to the SNI identifier of the TLS, determines whether the request source of the access request is a secure source according to the custom domain of the HTTP request header, performs abnormality checking on the IP address according to the target synchronization update data if it is determined that the request source is a secure source to obtain a second checking result, and sends the access request to a target system to be accessed in the target transmission mode according to a target routing table if it is determined that the second checking result is a checking success.

[0031] In a fourth aspect, the present application provides a public network protection device applied to an Access Control Component (ACC), comprising:

[0032] The receiving module is configured to receive an access request sent by a WAF, wherein the access request comprises a SNI identifier of TLS, a HTTP request header custom domain and an IP address, wherein the SNI identifier of TLS and the HTTP request header custom domain are configured in the access request by the WAF after determining that a first check result is passed, wherein the first check result is obtained by the WAF after performing an exception check on the IP address according to synchronization update data, wherein the IP address is any client sending the access request to the WAF, and wherein the synchronization update data is obtained by the WAF from a blockchain;

[0033] The obtaining module is configured to obtain corresponding target synchronization update data on the blockchain, wherein the target synchronization update data belongs to the synchronization update data.

[0034] The determining module is configured to determine a target transmission mode according to the SNI identifier of TLS.

[0035] The judging module is configured to determine whether a request source of the access request is a secure source according to the HTTP request header custom domain.

[0036] The checking module is configured to perform an exception check on the IP address according to the target synchronization update data to obtain a second check result if it is determined that the request source is a secure source.

[0037] The sending module is configured to send the access request to a target system to be accessed in the target transmission mode according to a target routing table if it is determined that the second check result is passed.

[0038] In a fifth aspect, the present application provides a network device, comprising a processor and a memory connected with the processor in communication;

[0039] The memory stores computer execution instructions.

[0040] The at least one processor executes the computer execution instructions stored in the memory, so that the at least one processor executes the public network protection method as described in the above first aspect or second aspect and various possible designs of the first aspect or second aspect.

[0041] In a sixth aspect, the present application provides a computer readable storage medium, wherein the computer readable storage medium stores computer execution instructions, and the computer execution instructions are executed by a processor to implement the method as described in the above first aspect or second aspect and various possible designs of the first aspect or second aspect.

[0042] The public network protection method, device, equipment and storage medium provided by the application, through the WAF, the IP address of any user terminal sending an access request is abnormally checked, the SNI identifier of the TLS and the HTTP request header custom domain are configured in the access request after the check is passed, and the access request including the SNI identifier of the TLS, the HTTP request header custom domain and the IP address is sent to the ACC; the access entrance is unified, and the fine-grained point-to-point system protection of the public network is realized. BRIEF DESCRIPTION OF DRAWINGS

[0043] The accompanying drawings, which are incorporated herein and constitute part of the specification, illustrate embodiments consistent with the application and, together with the description, serve to explain the principles of the application.

[0044] Figure 1 The scene schematic diagram of the public network protection method provided by the embodiment of the application;

[0045] Figure 2 The flowchart of the public network protection method provided by the embodiment of the application;

[0046] Figure 3 The flowchart of the public network protection method provided by another embodiment of the application;

[0047] Figure 4 The structure schematic diagram of the public network protection device provided by the embodiment of the application;

[0048] Figure 5 The structure schematic diagram of another public network protection device provided by the embodiment of the application;

[0049] Figure 6 The hardware structure schematic diagram of the network equipment provided by the embodiment of the application.

[0050] Through the above-mentioned drawings, the specific embodiments of the application have been shown, and more detailed descriptions will be given hereinafter. These drawings and textual descriptions are not intended to limit the scope of the concept of the application by any means, but to illustrate the concept of the application to those skilled in the art by referring to specific embodiments. DETAILED DESCRIPTION

[0051] The exemplary embodiments will be described in detail herein with reference to the attached drawings. The following description is only one of the embodiments consistent with the application, and is not intended to limit the scope of the application. On the contrary, they are only examples of devices and methods consistent with some aspects of the application as detailed in the appended claims.

[0052] It should be noted that the user information (including but not limited to user equipment information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in the present application are all information and data authorized by the user or authorized by all parties, and the collection, use and processing of related data need to comply with relevant laws, regulations and standards, and provide corresponding operation portal for user to choose authorization or refusal.

[0053] The technical solutions of the present application and how the technical solutions of the present application solve the above technical problems will be described in detail below with specific examples. The following specific examples can be combined with each other, and the same or similar concepts or processes may not be described again in some examples. The embodiments of the present application will be described below with reference to the drawings.

[0054] Figure 1 The scene schematic diagram of the public network protection method provided by the embodiment of the present application is shown in the figure. Figure 1 As shown in the figure, the system provided by the embodiment of the present application includes a user terminal 101, a WAF (Web Application Firewall, Web Application Firewall) 102, a blockchain 103, an ACC (Adaptive Control Component, Request Control Component) 104 and a target system to be accessed 105.

[0055] The user terminal 101 can be a mobile phone or a computer.

[0056] The target system to be accessed 105 can be a mobile phone or a computer.

[0057] Specifically, any user terminal 101 sends an access request to the WAF 102; the WAF 102 sends a data request to the blockchain 103, the blockchain 103 sends the synchronization update data to the WAF 102 according to the data request, and the WAF 102 performs abnormality check on the access request according to the synchronization update data; after the check is passed, the access request is sent to the ACC 104; the ACC 104 sends a data request to the blockchain 103, the blockchain 103 sends the target synchronization update data to the ACC 104 according to the data request, and the ACC 104 performs abnormality check on the access request according to the target synchronization update data; after the check is passed, the access request is sent to the target system to be accessed 105.

[0058] Figure 2 The flowchart of the public network protection method provided by an embodiment of the present application is shown in the figure. The execution subject of the embodiment of the present application can be the WAF 102 shown in the figure. Figure 1 The execution subject of the embodiment of the present application can also be other computer devices, which is not particularly limited here. As shown in the figure, Figure 2 The method comprises:

[0059] S201: Obtain synchronization update data on the blockchain.

[0060] Specifically, a complete node is run by a node running code to synchronize the blockchain, and after synchronization is successful, synchronization update data on the blockchain is listened to and obtained.

[0061] S202: Receive an access request sent by any user terminal, wherein the access request includes an IP (Internet Protocol) address of the user terminal.

[0062] S203: Perform abnormality checking on the IP address according to the synchronization update data to obtain a first checking result.

[0063] The synchronization update data includes an IP whitelist list, user authentication data, and an OWASP (Open Web Application Security Project) core rule base rule.

[0064] The synchronization update data is uploaded to the blockchain by an operation and maintenance personnel terminal corresponding to an operation and maintenance personnel.

[0065] Specifically, S203 specifically includes S2031-S2034:

[0066] S2031: Perform soft anti-DDoS (Distributed Denial of Service) checking on the IP address to obtain a first soft anti-checking result.

[0067] The soft anti-DDoS checking includes at least one of the following: traffic analysis and behavior detection, black and white list filtering, geographic location filtering, and slow attack detection.

[0068] Specifically, traffic analysis and behavior detection are performed on the IP address to obtain the first soft anti-checking result.

[0069] S2032: Perform IP whitelist and user authentication combined authentication checking on the IP address according to the IP whitelist list and the user authentication data to obtain a first authentication checking result.

[0070] The IP whitelist and user authentication combined authentication checking mode includes: IP whitelist authentication is valid, user authentication is valid, IP whitelist authentication and user authentication dual authentication are valid, and IP whitelist authentication and user authentication any authentication is valid.

[0071] Specifically, the IP address is authenticated in any authentication valid mode of the IP whitelist list and the user authentication data to obtain the first authentication checking result.

[0072] Exemplarily, the IP address is subjected to IP whitelist checking according to an IP whitelist list; if the checking succeeds, the first authentication checking result is that the checking passes; if the checking fails, the IP address is subjected to authentication checking according to user authentication data; if the checking succeeds, the first authentication checking result is that the checking passes.

[0073] S2033: Subjecting the IP address to abnormal attack checking according to an OWASP core rule library rule, to obtain a first attack checking result.

[0074] The abnormal attack checking includes at least one of abnormal access frequency detection, abnormal request behavior detection, abnormal geographic location detection, and abnormal traffic detection.

[0075] S2034: Generating a first checking result according to the first soft anti-checking result, the first authentication checking result, and the first attack checking result.

[0076] Specifically, the first soft anti-checking result, the first authentication checking result, and the first attack checking result are combined into the first checking result.

[0077] S204: If it is determined that the first checking result passes the checking, configuring a SNI (Server Name Indication) identity of TLS (Transport Layer Security) and a custom domain of an HTTP (Hypertext Transfer Protocol) request header in the access request.

[0078] Specifically, S204 specifically includes S2041-S2043:

[0079] S2041: Obtaining a to-be-accessed target system of an access request.

[0080] Specifically, the to-be-accessed target system of the access request is obtained by parsing the access request.

[0081] S2042: Configuring a SNI identity of TLS of the access request according to the to-be-accessed target system.

[0082] Specifically, a domain name of the to-be-accessed target system is obtained, and the domain name of the to-be-accessed target system is configured as the SNI identity of TLS of the access request.

[0083] S2043: Obtaining a preset custom domain according to the to-be-accessed target system, and setting a custom domain of an HTTP request header of the access request according to the custom domain.

[0084] Specifically, the to-be-accessed target system is matched with a preset custom domain library to obtain the preset custom domain.

[0085] S205: sending the access request to the corresponding ACC according to the local routing table, wherein the access request comprises a SNI identifier of the TLS, a HTTP request header custom domain and an IP address, so that the ACC obtains corresponding target synchronization update data on the blockchain, wherein the target synchronization update data belongs to the synchronization update data, and determines a target transmission mode according to the SNI identifier of the TLS, judges whether the request source of the access request is a secure source according to the HTTP request header custom domain, if it is judged that the request source is a secure source, performs abnormality check on the IP address according to the target synchronization update data to obtain a second check result, and if it is judged that the second check result is a check pass, sends the access request to the target system to be accessed according to the target routing table and the target transmission mode.

[0086] Specifically, S205 specifically comprises S2051-S2052:

[0087] S2051: obtaining the ACC corresponding to the target system to be accessed according to the target system to be accessed and the local routing table.

[0088] Specifically, the IP address of the target system to be accessed is obtained, the local routing table is searched according to the IP address of the target system to be accessed, and the ACC corresponding to the target system to be accessed is obtained.

[0089] S2052: sending the access request to the ACC.

[0090] As can be known from the above description, the present application performs abnormality check on the IP address of any user terminal sending an access request through the WAF, configures the SNI identifier of the TLS and the HTTP request header custom domain in the access request after the check pass, and sends the access request comprising the SNI identifier of the TLS, the HTTP request header custom domain and the IP address to the ACC; the access entry is unified, and fine-grained point-to-point system protection for the public network is realized.

[0091] Figure 3 A flowchart of a public network protection method provided by another embodiment of the present application is shown. The execution subject of the present embodiment can be the ACC 104 shown in Figure 1 , or other computer devices, and the present embodiment does not make special limitations hereon. As shown in Figure 3 , the method comprises:

[0092] S301: receiving an access request sent by a WAF, wherein the access request comprises an SNI identifier of TLS, an HTTP request header custom domain, and an IP address, wherein the SNI identifier of TLS and the HTTP request header custom domain are configured in the access request by the WAF after determining that a first check result is a check pass, wherein the first check result is obtained by the WAF after performing an exception check on the IP address according to synchronization update data, wherein the IP address is any client sending an access request to the WAF, and wherein the synchronization update data is obtained by the WAF from a blockchain.

[0093] S302: obtaining corresponding target synchronization update data on the blockchain, wherein the target synchronization update data belongs to the synchronization update data.

[0094] Specifically, a lightweight node connected to the blockchain network obtains corresponding target synchronization update data on the blockchain.

[0095] S303: determining a target transmission mode according to the SNI identifier of TLS.

[0096] Specifically, S303 specifically comprises S3031-S3033:

[0097] S3031: obtaining the SNI identifier of TLS.

[0098] Specifically, the access request is parsed to obtain the SNI identifier of TLS.

[0099] S3032: obtaining a preset transmission requirement according to the SNI identifier of TLS.

[0100] Specifically, the SNI identifier of TLS is parsed to obtain the domain name of the target system to be accessed, the preset transmission requirement library is searched according to the domain name of the target system to be accessed, and the preset transmission requirement is obtained.

[0101] S3033: determining a target transmission mode according to the transmission requirement.

[0102] Specifically, the transmission requirement is matched with a preset transmission mode to determine the target transmission mode.

[0103] The preset transmission mode comprises: plaintext transmission and ciphertext transmission.

[0104] S304: determining whether the request source of the access request is a secure source according to the HTTP request header custom domain.

[0105] Specifically, S304 specifically comprises S3041-S3043:

[0106] S3041: obtaining the HTTP request header custom domain.

[0107] Specifically, the access request is parsed to obtain the HTTP request header custom domain.

[0108] S3042: The HTTP request header custom domain is matched according to the preset custom domain library to obtain a matching result.

[0109] Specifically, the HTTP request header custom domain is parsed to obtain the custom domain, and the custom domain is matched according to the preset custom domain library to obtain a matching result.

[0110] S3043: If it is determined that the matching result is a matching success, it is determined that the request source of the access request is a secure source.

[0111] S305: If it is determined that the request source is a secure source, the IP address is abnormally checked according to the target synchronization update data to obtain a second checking result.

[0112] The target synchronization update data includes a target IP whitelist list and target user authentication data.

[0113] Specifically, S305 specifically includes S3051-S3053:

[0114] S3051: The IP address is soft anti-DDoS checked to obtain a second soft anti-checking result.

[0115] The soft anti-DDoS checking includes at least one of the following: traffic analysis and behavior detection, black and white list filtering, geographic location filtering, and slow attack detection.

[0116] Specifically, the IP address is traffic analyzed and behavior detected to obtain the second soft anti-checking result.

[0117] S3052: The IP address is checked by IP whitelist and user authentication combined authentication according to the target IP whitelist list and the target user authentication data to obtain a second authentication checking result.

[0118] The IP whitelist and user authentication combined authentication checking mode includes: IP whitelist authentication is valid, user authentication is valid, IP whitelist authentication and user authentication dual authentication are valid, and IP whitelist authentication and user authentication any authentication is valid.

[0119] Specifically, the IP address is authenticated in the IP whitelist authentication and user authentication dual authentication effective mode to obtain the second authentication checking result.

[0120] Illustratively, the IP address is checked by IP whitelist according to the IP whitelist list; if the checking is successful, the IP address is authenticated according to the user authentication data, if the checking is successful, the second authentication checking result is checking passed; if the checking fails, the second authentication checking result is checking failed.

[0121] S3053: generating a second check result according to the second soft anti-check result and the second authentication check result.

[0122] Specifically, the second soft anti-check result and the second authentication check result are combined into the second check result.

[0123] S306: if it is determined that the second check result is passed, sending the access request to the target system to be accessed according to a target transmission mode based on a target routing table.

[0124] Specifically, the IP address of the target system to be accessed is obtained according to the domain name of the target system to be accessed, the target routing table is searched according to the IP address of the target system to be accessed, and the access request is sent to the target system to be accessed according to the target transmission mode.

[0125] From the above description, in the present application, the ACC determines the target transmission mode according to the SNI identifier of the TLS, and judges whether the request source of the access request is a secure source according to the custom domain of the HTTP request header; if it is determined that the request source of the access request is a secure source, the access request is subjected to an abnormal check, and after the check is passed, the access request is sent to the target system to be accessed according to the target transmission mode, thereby realizing fine-grained point-to-point system protection for the public network.

[0126] Figure 4 The structure diagram of the public network protection device provided by the embodiment of the present application is shown in FIG. 1. Figure 4 As shown in the figure, the public network protection device 40 includes an acquisition module 401, a receiving module 402, a check module 403, a configuration module 404 and a sending module 405.

[0127] The acquisition module 401 is configured to acquire synchronization update data on a block chain.

[0128] The receiving module 402 is configured to receive an access request sent by any user end, wherein the access request includes an Internet Protocol (IP) address of the user end.

[0129] The check module 403 is configured to perform an abnormal check on the IP address according to the synchronization update data, and obtain a first check result.

[0130] The configuration module 404 is configured to configure a Server Name Indication (SNI) identifier of a Transport Layer Security (TLS) and a custom domain of a HyperText Transfer Protocol (HTTP) request header in the access request if it is determined that the first check result is passed.

[0131] The sending module 405 is configured to send the access request to a corresponding request control component ACC according to a local routing table, wherein the access request comprises the SNI identifier of the TLS, the HTTP request header custom domain, and the IP address, so that the ACC acquires corresponding target synchronization update data on the blockchain, wherein the target synchronization update data belongs to the synchronization update data, and determines a target transmission mode according to the SNI identifier of the TLS, judges whether the request source of the access request is a secure source according to the HTTP request header custom domain, if it is judged that the request source is a secure source, performs abnormality check on the IP address according to the target synchronization update data to obtain a second check result, if it is judged that the second check result is a check pass, sends the access request to a target system to be accessed in the target transmission mode according to a target routing table.

[0132] In a possible design, the synchronization update data comprises an IP white list, user authentication data, and an Open Web Application Security Project (OWASP) core rule set rule, wherein the synchronization update data is uploaded to the blockchain by an operation and maintenance personnel terminal corresponding to an operation and maintenance personnel; accordingly, the checking module 403 is specifically configured to perform soft anti-distributed denial of service (DDoS) check on the IP address to obtain a first soft anti-check result, perform IP white list and user authentication combined authentication check on the IP address according to the IP white list and the user authentication data to obtain a first authentication check result, perform abnormality attack check on the IP address according to the OWASP core rule set rule to obtain a first attack check result, and generate a first check result according to the first soft anti-check result, the first authentication check result, and the first attack check result.

[0133] In a possible design, the configuration module 404 is specifically configured to acquire a target system to be accessed of the access request, configure the SNI identifier of the TLS of the access request according to the target system to be accessed, acquire a preset custom domain according to the target system to be accessed, and set the HTTP request header custom domain of the access request according to the custom domain.

[0134] In a possible design, the sending module 405 is specifically configured to acquire a request control component ACC corresponding to the target system to be accessed according to the target system to be accessed and a local routing table, and send the access request to the ACC.

[0135] The apparatus provided in this embodiment can be used to execute the technical solutions of the method embodiments, and has similar implementation principles and technical effects, which will not be described here in detail.

[0136] Figure 5Another structural schematic diagram of a public network protection device provided by an embodiment of the present application is provided. As shown in Figure 5 The public network protection device 50 includes a receiving module 501, an obtaining module 502, a determining module 503, a judging module 504, a verifying module 505, and a sending module 506.

[0137] The receiving module 501 is configured to receive an access request sent by a WAF, wherein the access request includes a SNI identifier of TLS, a HTTP request header custom domain, and an IP address, wherein the SNI identifier of TLS and the HTTP request header custom domain are configured in the access request by the WAF after determining that a first verification result is verified, wherein the first verification result is obtained by the WAF after performing abnormal verification on the IP address according to synchronization update data, wherein the IP address is any client that sends the access request to the WAF, and wherein the synchronization update data is obtained by the WAF from a blockchain;

[0138] The obtaining module 502 is configured to obtain corresponding target synchronization update data on the blockchain, wherein the target synchronization update data belongs to the synchronization update data.

[0139] The determining module 503 is configured to determine a target transmission mode according to the SNI identifier of TLS.

[0140] The judging module 504 is configured to determine whether a request source of the access request is a secure source according to the HTTP request header custom domain.

[0141] The verifying module 505 is configured to perform abnormal verification on the IP address according to the target synchronization update data to obtain a second verification result if it is determined that the request source is a secure source.

[0142] The sending module 506 is configured to send the access request to a target system to be accessed in the target transmission mode according to a target routing table if it is determined that the second verification result is verified.

[0143] In a possible design, the target synchronization update data includes a target IP white list and target user authentication data; accordingly, the verifying module 505 is specifically configured to perform soft anti-distributed denial of service (DDoS) verification on the IP address to obtain a second soft anti-verification result, perform IP white list and user authentication combined authentication verification on the IP address according to the target IP white list and the target user authentication data to obtain a second authentication verification result, and generate the second verification result according to the second soft anti-verification result and the second authentication verification result.

[0144] In a possible design, the determining module 503 is specifically configured to: obtain the SNI identifier of the TLS; obtain a preset transmission requirement according to the SNI identifier of the TLS; and determine a target transmission mode according to the transmission requirement.

[0145] In a possible design, the determining module 504 is specifically configured to: obtain the HTTP request header custom domain; match the HTTP request header custom domain according to a preset custom domain library to obtain a matching result; and determine that the request source of the access request is a secure source if it is determined that the matching result is a matching success.

[0146] The apparatus provided in this embodiment can be used to execute the technical solutions of the method embodiments, and has similar implementation principles and technical effects, which will not be described here again in this embodiment.

[0147] Figure 6 A hardware structure schematic diagram of a network device provided in this embodiment is shown in FIG. 6. As shown in FIG. 6, the network device 60 in this embodiment includes at least one processor 601 and a memory 602; the memory stores computer execution instructions; the at least one processor executes the computer execution instructions stored in the memory, so that the at least one processor executes the public network protection method as described above. Figure 6

[0148] Optionally, the memory 602 can be independent or integrated with the processor 601.

[0149] When the memory 602 is independently arranged, the network device further includes a bus 603, configured to connect the memory 602 and the processor 601.

[0150] The embodiment of the present application further provides a computer readable storage medium, which stores computer execution instructions, and when the processor executes the computer execution instructions, the public network protection method as described above is implemented.

[0151] The embodiment of the present application further provides a computer program product, which includes a computer program, and when the processor executes the computer program, the public network protection method as described above is implemented.

[0152] It should be noted that, for each of the foregoing method embodiments, in order to simply describe, each is described as a series of action combinations, but those skilled in the art should know that the present application is not limited to the action order described, because according to the present application, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should know that the embodiments described in the specification are all optional embodiments, and the actions and modules involved are not necessarily required by the present application.

[0153] ​It should be further noted that although the steps in the flowchart are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowchart may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these sub-steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the sub-steps or stages of other steps.

[0154] It should be understood that the above-described device embodiments are merely illustrative, and the device of this application can also be implemented in other ways. For example, the division of units / modules in the above embodiments is only a logical functional division, and there may be other division methods in actual implementation. For example, multiple units, modules, or components may be combined, or integrated into another system, or some features may be ignored or not executed.

[0155] Furthermore, unless otherwise specified, the functional units / modules in the various embodiments of this application can be integrated into one unit / module, or each unit / module can exist physically separately, or two or more units / modules can be integrated together. The integrated units / modules described above can be implemented in hardware or as software program modules.

[0156] When integrated units / modules are implemented in hardware, the hardware can be digital circuits, analog circuits, etc. The physical implementation of the hardware structure includes, but is not limited to, transistors, memristors, etc. Unless otherwise specified, the processor can be any suitable hardware processor, such as a CPU, GPU, FPGA, DSP, and ASIC, etc. Unless otherwise specified, the storage unit can be any suitable magnetic or magneto-optical storage medium, such as Resistive Random Access Memory (RRAM), Dynamic Random Access Memory (DRAM), Static Random Access Memory (SRAM), Enhanced Dynamic Random Access Memory (EDRAM), High-Bandwidth Memory (HBM), Hybrid Memory Cube (HMC), etc.

[0157] If the integrated units / modules are implemented in the form of software program modules and sold or used as independent products, they can be stored in a computer readable memory. Based on such understanding, the technical solutions of the present application essentially or the part that contributes to the prior art or the whole or part of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a memory and includes a number of instructions for causing a computer device (which can be a personal computer, a server or a network device, etc.) to execute all or part of the steps of the embodiments of the method of the present application. The aforementioned memory includes: a U disk, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), a mobile hard disk, a magnetic disk or an optical disk, and various media that can store program codes.

[0158] In the above embodiments, the description of each embodiment has its own focus, and the parts not described in detail in a certain embodiment can be referred to the related description of other embodiments. The technical features of the above embodiments can be combined arbitrarily. In order to make the description concise, not all possible combinations of the technical features in the above embodiments are described, however, as long as the combinations of the technical features do not exist contradictory, they should be considered as the scope of the present application.

[0159] Other embodiments of the application will be apparent to those skilled in the art from consideration of the specification and practice of the application disclosed herein. The application is intended to cover any variations, uses or adaptations of the application following, in general, the principles of the application and including such departures from the present disclosure as come within known or customary practice in the art to which the application pertains or can relate. The specification and examples are to be regarded as exemplary only, and the true scope and spirit of the application are indicated by the following claims.

[0160] It should be understood that the application is not limited to the precise construction that has been described above and illustrated in the accompanying drawings, and that various modifications and changes can be made without departing from the scope thereof. The scope of the application is limited only by the claims that follow.

Claims

1. A public network protection method, characterized by, Applied to a web application firewall (WAF), comprising: Obtaining synchronization update data on a blockchain; Receiving an access request sent by any user end, wherein the access request includes an Internet Protocol (IP) address of the user end; According to the synchronization update data, the IP address is checked for abnormalities to obtain a first check result; If it is determined that the first check result is passed, a server name indication (SNI) identifier of transport layer security (TLS) and a custom domain of a hypertext transfer protocol (HTTP) request header are configured in the access request; According to a local routing table, the access request is sent to a corresponding request control component (ACC), wherein the access request includes the SNI identifier of the TLS, the custom domain of the HTTP request header, and the IP address, so that the ACC obtains corresponding target synchronization update data on the blockchain, determines a target transmission mode according to the SNI identifier of the TLS, judges whether the request source of the access request is a secure source according to the custom domain of the HTTP request header, if it is determined that the request source is a secure source, checks the IP address for abnormalities according to the target synchronization update data to obtain a second check result, and if it is determined that the second check result is passed, the access request is sent to a target system to be accessed in the target transmission mode according to a target routing table.

2. The method of claim 1, wherein, The synchronization update data includes an IP whitelist list, user authentication data, and an open web application security project (OWASP) core rule library rule, wherein the synchronization update data is uploaded to the blockchain by an operation and maintenance personnel terminal corresponding to an operation and maintenance personnel; Accordingly, the first check result is obtained by checking the IP address for abnormalities according to the synchronization update data, comprising: A first soft-anti-distributed denial of service (DDoS) check result is obtained by checking the IP address for soft-anti-DDoS; A first authentication check result is obtained by combining IP whitelist and user authentication to check the IP address according to the IP whitelist list and user authentication data; A first attack check result is obtained by checking the IP address for abnormal attacks according to the OWASP core rule library rule; The first check result is generated according to the first soft-anti-check result, the first authentication check result, and the first attack check result.

3. The method of claim 1, wherein, The SNI identifier of the TLS and the custom domain of the HTTP request header are configured in the access request, comprising: Obtaining a target system to be accessed of the access request; The SNI identifier of the TLS of the access request is configured according to the target system to be accessed; A preset custom domain is obtained according to the target system to be accessed, and the custom domain of the HTTP request header of the access request is set according to the custom domain.

4. The method of claim 3, wherein, According to the local routing table, the access request is sent to the corresponding ACC, comprising: According to the target system to be accessed and the local routing table, the ACC corresponding to the target system to be accessed is obtained; sending the access request to the ACC.

5. A public network protection method characterized by comprising: The application is applied to a request control component ACC, and comprises: receiving an access request sent by a WAF, wherein the access request comprises a SNI identifier of TLS, a custom domain of an HTTP request header, and an IP address, wherein the SNI identifier of TLS and the custom domain of the HTTP request header are configured in the access request by the WAF after determining that a first check result is passed, wherein the first check result is obtained by the WAF after performing abnormal check on the IP address according to synchronization update data, wherein the IP address is any client sending the access request to the WAF, and wherein the synchronization update data is obtained by the WAF from a blockchain; obtaining corresponding target synchronization update data on the blockchain, wherein the target synchronization update data belongs to the synchronization update data; determining a target transmission mode according to the SNI identifier of TLS; determining whether a request source of the access request is a safe source according to the custom domain of the HTTP request header; if it is determined that the request source is a safe source, performing abnormal check on the IP address according to the target synchronization update data to obtain a second check result; if it is determined that the second check result is passed, sending the access request to a target system to be accessed in the target transmission mode according to a target routing table.

6. The method of claim 5, wherein, The target synchronization update data comprises a target IP whitelist and target user authentication data. Correspondingly, the abnormal check on the IP address according to the target synchronization update data to obtain a second check result comprises: performing soft anti-distributed denial of service (DDoS) check on the IP address to obtain a second soft anti-check result; performing IP whitelist and user authentication combined authentication check on the IP address according to the target IP whitelist and the target user authentication data to obtain a second authentication check result; and generating the second check result according to the second soft anti-check result and the second authentication check result.

7. The method of claim 5, wherein, The determination of the target transmission mode according to the SNI identifier of TLS comprises: obtaining the SNI identifier of TLS; obtaining a preset transmission requirement according to the SNI identifier of TLS; and determining the target transmission mode according to the transmission requirement.

8. The method according to any one of claims 5 to 7, characterized in that, The determination of whether the request source of the access request is a safe source according to the custom domain of the HTTP request header comprises: obtaining the custom domain of the HTTP request header; matching the custom domain of the HTTP request header according to a preset custom domain library to obtain a matching result; and if it is determined that the matching result is matched successfully, determining that the request source of the access request is a safe source.

9. A public network protection device, characterized by comprising: The application is applied to a web application firewall (WAF), and comprises: an obtaining module, configured to obtain synchronization update data on a blockchain; a receiving module, configured to receive an access request sent by any user terminal, wherein the access request comprises an Internet Protocol (IP) address of the user terminal; a check module, configured to perform abnormal check on the IP address according to the synchronization update data to obtain a first check result; and a sending module, configured to send the access request to an ACC. The configuration module is configured to configure a server name indication (SNI) identity of a transport layer security (TLS) and a hypertext transfer protocol (HTTP) request header custom domain in the access request if the first check result is determined to be a check pass. The sending module is configured to send the access request to a corresponding ACC according to a local routing table, where the access request includes the SNI identity of the TLS, the HTTP request header custom domain, and the IP address, so that the ACC acquires corresponding target synchronization update data on the blockchain, where the target synchronization update data belongs to the synchronization update data, determines a target transmission mode according to the SNI identity of the TLS, determines whether a request source of the access request is a secure source according to the HTTP request header custom domain, performs abnormality check on the IP address according to the target synchronization update data if the request source is determined to be the secure source, obtains a second check result, and sends the access request to a target system to be accessed in the target transmission mode according to a target routing table if the second check result is determined to be a check pass.

10. A public network protection device, characterized by comprising: The application is applied to an ACC and includes: The receiving module is configured to receive an access request sent by a WAF, where the access request includes an SNI identity of a TLS, an HTTP request header custom domain, and an IP address, the SNI identity of the TLS and the HTTP request header custom domain are configured in the access request by the WAF after a first check result is determined to be a check pass, the first check result is obtained by the WAF after performing abnormality check on the IP address according to synchronization update data, the IP address is any client that sends the access request to the WAF, and the synchronization update data is acquired by the WAF on a blockchain; The acquiring module is configured to acquire corresponding target synchronization update data on the blockchain, where the target synchronization update data belongs to the synchronization update data. The determining module is configured to determine a target transmission mode according to the SNI identity of the TLS. The judging module is configured to determine whether a request source of the access request is a secure source according to the HTTP request header custom domain. The checking module is configured to perform abnormality check on the IP address according to the target synchronization update data if the request source is determined to be the secure source, and obtain a second check result. The sending module is configured to send the access request to a target system to be accessed in the target transmission mode according to a target routing table if the second check result is determined to be a check pass.

11. A network device, comprising: include: a processor and a memory connected with the processor in communication; the memory stores computer execution instructions; the processor executes the computer execution instructions stored in the memory to implement the public network protection method in any one of claims 1 to 4 or any one of claims 5 to 8.

12. A computer-readable storage medium, characterized in that, The computer readable storage medium stores computer execution instructions, and the computer execution instructions are used for implementing the public network protection method in any one of claims 1 to 4 or any one of claims 5 to 8 when executed by the processor.

Citation Information

Patent Citations

  • Method and device for network configuration of subscriber terminal

    CN101197721A

  • Secure access method and gathering device

    CN102255874A