Network access control method, system and equipment based on zero trust and medium
By using a zero-trust mechanism to continuously evaluate and monitor the security of the user terminal after entering the network, and disconnecting the connection when abnormalities are found, the problem of low network security caused by neglecting the security problems after accessing the network is solved in the prior art, and higher network security is achieved.
Patent Information
- Application Number
- CN202510103195.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-22
- Publication Date
- 2025-05-09
AI Technical Summary
The existing network access control methods only focus on the authentication and network access issues of user terminals, ignore the security issues after network access, and it is difficult to detect and block abnormal terminals in a timely manner, resulting in low network security.
Using a zero-trust-based network access control method, after the user terminal obtains network access permissions and resource access permissions through a zero-trust server, the user terminal's network access security index value is evaluated, and the connection is disconnected when the preset conditions are not met, and abnormal terminals are continuously monitored and blocked.
It realizes continuous monitoring of user terminals after they enter the network, timely discover and block abnormal terminals, effectively improving network security.
Smart Images

Figure CN119966703A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of network security technology, and more specifically, to a zero-trust based network access control method, system, device and medium. Background Art
[0002] Illegal user terminals can access the network at will, which will threaten the information security within the network. Considering the network security issues, the network access control method is mainly used to allow only legal user terminals to access the network. However, the existing network access control method only focuses on solving the authentication and network access problems of user terminals, ignoring the security issues after the user terminals access the network, and it is difficult to detect and block abnormal terminals in time, resulting in low network security. Summary of the invention
[0003] The purpose of the embodiments of the present application is to provide a zero-trust based network access control method, system, device and medium to achieve the technical effect of effectively improving network security.
[0004] In a first aspect, an embodiment of the present application provides a zero-trust based network access control method, applicable to a zero-trust server, the method comprising:
[0005] After the user terminal obtains the network access authority and resource access authority of the target network, evaluating the network access security index value of the user terminal;
[0006] When the network access security index value does not meet a preset value condition, the user terminal is controlled to disconnect from the target network.
[0007] In the above implementation process, after the zero-trust server obtains the network access rights and resource access rights of the target network from the user terminal, it evaluates the network access security index value of the user terminal, and controls the user terminal to disconnect from the target network when the network access security index value does not meet the preset value conditions. Based on the zero-trust mechanism, it can continue to monitor the network access security of the user terminal after the user terminal accesses the network, thereby ensuring timely detection and blocking of abnormal terminals, effectively improving network security.
[0008] Furthermore, the network access right is granted to the user terminal by the network access control device after the user terminal passes the authentication once after the network access request information of the user terminal is authenticated once; the network access request information is sent by the network access device to the network access control device;
[0009] After the user terminal obtains the network access authority and resource access authority of the target network, before evaluating the network access security index value of the user terminal, the method further includes:
[0010] After the user terminal obtains the network access authority, a secondary authentication is performed on the user terminal, and after the user terminal passes the secondary authentication, the resource access authority is granted to the user terminal.
[0011] In the above implementation process, the network access control device authenticates the user terminal once, and grants the user terminal network access rights to the target network after the user terminal passes the primary authentication. The zero-trust server performs a secondary authentication on the user terminal after the user terminal obtains the network access rights to the target network, and grants the user terminal resource access rights to the target network after the user terminal passes the secondary authentication. Based on the zero-trust mechanism, the user terminal can continue to be authenticated and authorized after the user terminal obtains the network access rights to the target network, thereby ensuring accurate restriction of the resource access rights of the user terminal and effectively improving network security.
[0012] Further, the evaluating the network access security index value of the user terminal includes:
[0013] Performing a health check on the user terminal to obtain a health score of the user terminal; wherein the health check includes one or more of checking whether the open port is compliant, checking whether the terminal has joined a compliant AD domain, checking whether the installation and operation of the software program is compliant, checking whether the guest account is enabled, checking whether the file sharing function is enabled, checking whether the display interface protection function is enabled, and checking whether there are vulnerability patches;
[0014] The health score is used as the network access security index value.
[0015] In the above implementation process, the zero-trust server evaluates the network access security index value of the user terminal by performing a health check on the user terminal, which can comprehensively consider the impact of changes in configuration items such as user terminal hardware, software, and system on network security and accurately evaluate the network access security index value of the user terminal.
[0016] Furthermore, the preset value condition includes that the health score is greater than a preset score threshold.
[0017] In the above implementation process, the zero-trust server selects the health score of the user terminal as the network access security index value of the user terminal, and uses the preset value conditions including the health score being greater than the preset score threshold to monitor the network access security of the user terminal. It can quickly and accurately determine whether the user terminal is an abnormal terminal, thereby ensuring timely discovery and blocking of abnormal terminals, effectively improving network security.
[0018] Further, the evaluating the network access security index value of the user terminal includes:
[0019] Determine resource access statistics of the user terminal; wherein the resource access statistics include one or more of the number of resource accesses and the frequency of resource accesses;
[0020] The resource access statistics are used as the network access security index value.
[0021] In the above implementation process, the zero-trust server evaluates the network access security index value of the user terminal by determining the resource access statistics of the user terminal, which can take into account the impact of the resource access behavior of the user terminal on network security and accurately evaluate the network access security index value of the user terminal.
[0022] Furthermore, the preset value condition includes that the resource access statistic is less than a preset statistic threshold.
[0023] In the above implementation process, the zero-trust server selects the resource access statistics of the user terminal as the network access security index value of the user terminal, and uses the preset value conditions including the resource access statistics being less than the preset statistical threshold to monitor the network access security of the user terminal. It can quickly and accurately determine whether the user terminal is an abnormal terminal, thereby ensuring timely discovery and blocking of abnormal terminals, effectively improving network security.
[0024] Furthermore, the user terminal includes a dumb terminal.
[0025] In the above implementation process, by performing network access control on dumb terminals, it is possible to support refined network access control on dumb terminals, thereby effectively improving network security.
[0026] In a second aspect, an embodiment of the present application provides a zero-trust-based network access control system, including a zero-trust server;
[0027] The zero trust server is used to:
[0028] After the user terminal obtains the network access authority and resource access authority of the target network, evaluating the network access security index value of the user terminal;
[0029] When the network access security index value does not meet a preset value condition, the user terminal is controlled to disconnect from the target network.
[0030] Furthermore, the system also includes a network access device and a network admission control device;
[0031] The network access device is used to send the network access request information of the user terminal to the network admission control device;
[0032] The network access control device is used to authenticate the user terminal once according to the network access request information, and grant the network access authority to the user terminal after the user terminal passes the authentication once;
[0033] The zero-trust server is also used to perform secondary authentication on the user terminal after the user terminal obtains the network access authority, and grant the resource access authority to the user terminal after the user terminal passes the secondary authentication.
[0034] In a third aspect, an embodiment of the present application provides an electronic device, comprising a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor; when the processor executes the computer program, the method as described above is implemented.
[0035] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, wherein the computer-readable storage medium includes a stored computer program; wherein, when the computer program is running, the device where the computer-readable storage medium is located is controlled to execute the method described above. BRIEF DESCRIPTION OF THE DRAWINGS
[0036] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required for use in the embodiments of the present application will be briefly introduced below. It should be understood that the following drawings only show certain embodiments of the present application and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other related drawings can be obtained based on these drawings without paying creative work.
[0037] Figure 1 A flowchart of a zero-trust based network access control method provided in the first embodiment of the present application;
[0038] Figure 2 A schematic diagram of the structure of a zero-trust based network access control system provided in the second embodiment of the present application;
[0039] Figure 3 A schematic diagram of the structure of a zero-trust based network access control system provided for an optional embodiment in the second embodiment of the present application;
[0040] Figure 4 A schematic diagram of the structure of an electronic device provided in the third embodiment of the present application. DETAILED DESCRIPTION
[0041] The technical solutions in the embodiments of the present application will be described below in conjunction with the drawings in the embodiments of the present application.
[0042] It should be noted that in the description of this application, the terms "first", "second", etc. are only used to distinguish descriptions and cannot be understood as indicating or implying relative importance. At the same time, the step numbers in the text are only for the convenience of explaining the embodiments of this application and do not serve to limit the order of execution of the steps.
[0043] Illegal user terminals can access the network at will, which will threaten the information security inside the network. Considering the network security problem, the network access control method is mainly used to allow only legal user terminals to access the network.
[0044] In the related technology, based on the 802.1x network access control protocol, when a user terminal requests to access the network, the user terminal first interacts with the network access device and sends the terminal information of the user terminal itself to the network access device. Then the network access device sends the terminal information to the network access control device, so that the network access control device checks the user terminal and the user according to the terminal information. If it is determined that the user terminal and the user meet the access policy defined by the network access control device, the network access control device notifies the network access device to release the user terminal, otherwise the user terminal is prohibited from accessing the network.
[0045] It can be seen that the existing network access control method only focuses on solving the authentication and network access problems of user terminals, ignoring the security issues after the user terminals enter the network. It is difficult to detect and block abnormal terminals in time, resulting in low network security.
[0046] To this end, the present application proposes a network access control method based on zero trust. After the user terminal obtains the network access permission and resource access permission of the target network, the zero trust server evaluates the network access security index value of the user terminal, and controls the user terminal to disconnect from the target network when the network access security index value does not meet the preset value condition. Based on the zero trust mechanism, the network access security of the user terminal can continue to be monitored after the user terminal accesses the network, thereby ensuring timely detection and blocking of abnormal terminals, effectively improving network security.
[0047] The technical solutions in the embodiments of the present application will be described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all of the embodiments.
[0048] The method provided in the embodiment of the present application can be executed by a relevant terminal device, and the following description will be given using a zero-trust server as an example of the execution entity.
[0049] Please see Figure 1 , Figure 1A flowchart of a zero-trust based network access control method provided in the first embodiment of the present application. The first embodiment of the present application provides a zero-trust based network access control method, which is applicable to a zero-trust server, and the method includes steps S101 to S102:
[0050] S101. After the user terminal obtains network access rights and resource access rights of the target network, the network access security index value of the user terminal is evaluated.
[0051] As an example, when the user terminal needs to access the target network to access corresponding resources of the target network, such as accessing an enterprise network to access a database of the enterprise network, the user terminal requests to obtain the network access permission of the target network and the resource access permission of corresponding resources.
[0052] It should be noted that the user terminal includes terminal devices such as mobile phones, tablets or computers held by users that can communicate over the Internet.
[0053] Zero trust represents a new generation of network security protection concept. Its key lies in breaking the default "trust". In simple terms, it is "continuous verification, never trust". By default, any user, device and system inside or outside the enterprise network is not trusted. The trust foundation of access control is rebuilt based on identity authentication and authorization, thus ensuring that the identity, device, application and link are trustworthy. Based on the principle of zero trust, the three "security" of the office system can be guaranteed: terminal security, link security and access control security.
[0054] After the user terminal obtains the network access rights of the target network and the resource access rights of the corresponding resources, the zero-trust server evaluates the network access security index value of the user terminal. Among them, the network access security index value of the user terminal is used to indicate the security of the user terminal after network access.
[0055] S102: When the network access security index value does not meet the preset value condition, control the user terminal to disconnect from the target network.
[0056] As an exemplary example, according to actual network security requirements, the value conditions of the network access security indicators are preset, that is, the preset value conditions.
[0057] After obtaining the network access security index value of the user terminal, the zero-trust server determines whether the network access security index value of the user terminal meets the preset value conditions. If the network access security index value of the user terminal does not meet the preset value conditions, it is considered that an abnormality has occurred after the user terminal has accessed the network, affecting the security of the target network. At this time, the user terminal is controlled to disconnect from the target network to prohibit the user terminal from continuing to access the target network and access the corresponding resources of the target network; if the network access security index value of the user terminal meets the preset value conditions, it is considered that no abnormality has occurred after the user terminal has accessed the network. At this time, no processing is performed to allow the user terminal to continue to access the target network and access the corresponding resources of the target network.
[0058] In the embodiment of the present application, after the user terminal obtains the network access permission and resource access permission of the target network, the zero-trust server evaluates the network access security index value of the user terminal, and controls the user terminal to disconnect from the target network when the network access security index value does not meet the preset value condition. Based on the zero-trust mechanism, the network access security of the user terminal can continue to be monitored after the user terminal has accessed the network, thereby ensuring timely discovery and blocking of abnormal terminals, effectively improving network security.
[0059] In an optional embodiment, the network access right is that the network access control device authenticates the user terminal once according to the network access request information of the user terminal, and grants the user terminal after the user terminal passes the single authentication; the network access request information is sent by the network access device to the network access control device; after the user terminal obtains the network access right and resource access right of the target network, and before evaluating the network access security index value of the user terminal, it also includes: after the user terminal obtains the network access right, the user terminal is authenticated twice, and after the user terminal passes the secondary authentication, the user terminal is granted resource access right.
[0060] As an example, when a user terminal needs to access a target network to access corresponding resources of the target network, such as accessing an enterprise network to access a database of the enterprise network, the user terminal can interact with a network access device and send the user terminal's own network access request information to the network access device, wherein the network access device includes a switch or a wireless access point.
[0061] After receiving the network access request information from the user terminal, the network access device sends the network access request information from the user terminal to the network admission control device.
[0062] The network access control device authenticates the user terminal once based on the network access request information of the user terminal based on the network access control protocol. After the user terminal passes the authentication once, the network access permission of the target network is granted to the user terminal; if the user terminal fails the authentication once, a network access rejection response is returned to the user terminal.
[0063] In actual applications, the network access control device can select the 802.1x network access control protocol, the EAPoL authentication protocol (Extensible authentication protocol over LAN) is used between the user terminal and the network access device, and the RADIUS authentication protocol (Remote Authentication Dial In User Service) is used between the network access device and the network access control device. The user terminal sends an EAPoL message to the network access device. The EAPoL message carries the user terminal's own login account, login password, IP address (Internet Protocol Address) and MAC address (Media Access Control Address) and other network access request information. After receiving the EAPoL message, the network access device encapsulates the EAPoL message into a RADIUS message and sends it to the network access control device. Based on the 802.1x network access control protocol, the network access control device authenticates the user terminal once according to the RADIUS message, including the verification of the login account and login password, as well as the verification of the IP address and MAC address. After the user terminal passes the authentication once, the network access device is notified to open the data port of the user terminal so that the user terminal can access the target network, and the access traffic of the user terminal's Layer 2 network is taken over according to the ACL (Access Control List) issued by the network access control device or configured by the network access device. It can be understood that the one-time authentication is the 802.1x authentication.
[0064] After the user terminal obtains network access permissions to the target network, the zero-trust server performs secondary authentication on the user terminal based on the zero-trust mechanism. After the user terminal passes the secondary authentication, the zero-trust server grants the user terminal resource access permissions to the corresponding resources of the target network. If the user terminal fails the secondary authentication, a network access rejection response is returned to the user terminal.
[0065] In actual applications, secondary authentication includes identity authentication, such as verification of login account and login password. It can be understood that secondary authentication is zero-trust authentication.
[0066] Zero-trust servers can use single-packet authorization and network proxy technology to authenticate and authorize user terminals. The authentication and authorization process involves the collaborative work of three major components in the zero-trust server: zero-trust client, zero-trust controller, and zero-trust gateway.
[0067] Single Packet Authorization (SPA) is a network authentication technology that performs a "knock on the door" operation by sending a single data packet containing the terminal's identity information to the SPA port of the zero-trust gateway. After the zero-trust gateway verifies the identity, it "opens the door" to the whitelist of terminal IP addresses, allowing them to access the TCP port of the zero-trust gateway, and no longer discards data packets from the IP address, thus achieving user identity authentication and authorization, simplifying the authentication process, and improving security and efficiency.
[0068] A network proxy refers to a collection of information used to describe the initiator of a network request, which generally includes three types of entity information: user, application, and device. In a zero-trust network, policies are formulated based on the combination of these three types of entity information to achieve fine-grained access control.
[0069] During the authentication and authorization process, the operations performed by the zero-trust client, zero-trust controller, and zero-trust gateway are as follows: the zero-trust client is used to obtain the unique identifier of the user terminal and initiate an authentication request for the user terminal and user to the zero-trust controller. The zero-trust client performs single-packet authorization by separating the control plane and the business plane, so that the user terminal and user are verified first, and the application is visible and accessible only after the verification is passed; the zero-trust controller is used to perform unified management of the zero-trust client and zero-trust gateway, including authentication and permission management of user terminals and users, as well as unified scheduling and management of subject and object access, that is, which users can access which resources. The zero-trust controller is also responsible for dynamically generating a minimized permission access policy and sending it to the zero-trust client and zero-trust gateway; the zero-trust gateway is used to hide the network and back-end business. Before the zero-trust client initiates single-packet authorization and verification, no TCP port is opened and no response is given. The zero-trust gateway is also responsible for establishing a secure tunnel with the zero-trust client to implement dynamic permission access control to ensure that only traffic that has passed single-packet authorization and verification can reach the target service.
[0070] It should be noted that the resource access rights assigned by the zero-trust server are different from the ACL mentioned above. The resource access rights here refer to the rights used to control user terminals' access to resources, while the ACL mentioned above refers to the rights used to control user terminals' access to the Internet.
[0071] In the embodiment of the present application, a network access control device performs a one-time authentication on the user terminal, and grants the user terminal network access rights to the target network after the user terminal passes the one-time authentication; and a zero-trust server performs a second authentication on the user terminal after the user terminal obtains the network access rights to the target network, and grants the user terminal resource access rights to the target network after the user terminal passes the second authentication. Based on the zero-trust mechanism, the user terminal can continue to be authenticated and authorized after the user terminal obtains the network access rights to the target network, thereby ensuring accurate restriction of the resource access rights of the user terminal and effectively improving network security.
[0072] In an optional embodiment, the evaluation of the network access security index value of the user terminal includes: performing a health check on the user terminal to obtain a health score of the user terminal; wherein the health check includes checking whether open ports are compliant, checking whether the terminal has joined a compliant AD domain, checking whether the installation and operation of software programs are compliant, checking whether a guest account is enabled, checking whether a file sharing function is enabled, checking whether a display interface protection function is enabled, and checking whether there are one or more of vulnerability patches; and using the health score as the network access security index value.
[0073] As an example, considering that in the process of the user terminal accessing the target network and accessing the corresponding resources of the target network, the configuration items such as the hardware, software and system of the user terminal may change, which may affect the security of the network, so the zero-trust server can evaluate the network security index value of the user terminal by performing a health check on the user terminal. Among them, the health check includes checking whether the open port is compliant, checking whether the terminal joins a compliant AD domain (Active Directory Domain, a directory service), checking whether the installation and operation of the software program is compliant, checking whether the Guest account is enabled, checking whether the file sharing function is enabled, checking whether the display interface protection function is enabled, and checking whether there are one or more of the vulnerability patches.
[0074] After the user terminal obtains the network access rights of the target network and the resource access rights of the corresponding resources, the zero-trust server performs a health check on the user terminal, such as checking whether the open ports are compliant, checking whether the terminal is joined to a compliant AD domain, checking whether the installation and operation of the software program are compliant, checking whether the guest account is enabled, checking whether the file sharing function is turned on, checking whether the display interface protection function is turned on, and checking whether there are vulnerability patches, to obtain the health score of the user terminal and use the health score of the user terminal as the network access security index value of the user terminal.
[0075] It should be noted that the item of checking whether the open port is normal mainly checks whether the service port opened by the user terminal meets the compliance requirements. If the service port opened by the user terminal does not meet the compliance requirements, it is determined that the user terminal has not passed this check and cannot get the score corresponding to this check. Otherwise, it is determined that the user terminal has passed this check and can get the score corresponding to this check. The item of checking whether the terminal has joined a compliant AD domain mainly checks whether the AD domain joined by the user terminal is consistent with the preset AD domain. If the AD domain joined by the user terminal is inconsistent with the preset AD domain, it is determined that the user terminal has not passed this check and cannot get the score corresponding to this check. points, otherwise it is determined that the user terminal has passed this inspection and the score corresponding to this inspection can be obtained; Check whether the installation and operation of software programs are compliant. This item mainly checks whether the user terminal has the necessary software, services and processes installed and run, whether the software, services and processes that are prohibited from being installed and run are installed and run, and whether the installed operating system is consistent with the preset operating system, whether the configuration items of the operating system are consistent with the preset configuration items, etc. If the software program installed and run by the user terminal is not compliant, it is determined that the user terminal has not passed this inspection and the score corresponding to this inspection cannot be obtained. Otherwise, it is determined that the user terminal has passed this inspection and the score corresponding to this inspection can be obtained; Check whether the software program installed and run by the user terminal is not compliant, then it is determined that the user terminal has not passed this inspection and the score corresponding to this inspection can be obtained. Whether to enable the guest account is mainly to check whether the user terminal has enabled the guest account. If the user terminal has enabled the guest account, it is determined that the user terminal has not passed this check and cannot get the score corresponding to this check. Otherwise, it is determined that the user terminal has passed this check and can get the score corresponding to this check. Check whether the file sharing function is turned on. Mainly check whether the user terminal has turned on the file sharing function. If the user terminal has turned on the file sharing function, it is determined that the user terminal has not passed this check and cannot get the score corresponding to this check. Otherwise, it is determined that the user terminal has passed this check and can get the score corresponding to this check. Check whether the display function is turned on. The display interface protection function mainly checks whether the user terminal has the display interface protection function turned on. If the user terminal has the display interface protection function turned on, it is determined that the user terminal has not passed this check and cannot get the score corresponding to this check. Otherwise, it is determined that the user terminal has passed this check and can get the score corresponding to this check. The check for vulnerability patches mainly checks whether the user terminal has security vulnerabilities and patches. If the user terminal has security vulnerabilities or patches, it is determined that the user terminal has not passed this check and cannot get the score corresponding to this check. Otherwise, it is determined that the user terminal has passed this check and can get the score corresponding to this check. The scores corresponding to each check are set by the management user.
[0076] In actual applications, if the health check performed by the zero-trust server on the user terminal includes checking whether the open ports are compliant, checking whether the terminal is joined to a compliant AD domain, checking whether the installation and operation of the software program is compliant, checking whether the guest account is enabled, checking whether the file sharing function is turned on, checking whether the display interface protection function is turned on, and checking whether there are multiple vulnerability patches, then the zero-trust server can perform a simple sum calculation or a weighted sum calculation on the scores corresponding to the various checks passed by the user terminal to obtain the health score of the user terminal, and use the health score of the user terminal as the network access security index value of the user terminal.
[0077] In actual applications, the zero-trust server can perform health checks on the user terminal regularly or irregularly after the user terminal obtains network access permissions and resource access permissions of the target network. It can also trigger a health check on the user terminal when the user terminal obtains network access permissions or resource access permissions of the target network.
[0078] In the embodiment of the present application, a zero-trust server is used to evaluate the network access security index value of the user terminal by performing a health check on the user terminal. This can comprehensively consider the impact of changes in configuration items such as the user terminal's hardware, software, and system on network security, and accurately evaluate the network access security index value of the user terminal.
[0079] In an optional embodiment, the preset value condition includes the health score being greater than a preset score threshold.
[0080] As an example, according to actual network security requirements, the health score value conditions are preset, that is, the preset value conditions include that the health score is greater than a preset score threshold.
[0081] After obtaining the health score of the user terminal, the zero trust server compares the health score of the user terminal with the preset score threshold. If the health score of the user terminal is less than or equal to the preset score threshold, that is, it does not meet the preset value conditions, it is considered that an abnormality has occurred after the user terminal has accessed the network, affecting the security of the target network. At this time, the user terminal is controlled to disconnect from the target network to prohibit the user terminal from continuing to access the target network and accessing the corresponding resources of the target network; if the health score of the user terminal is greater than the preset score threshold, that is, it meets the preset value conditions, it is considered that no abnormality has occurred after the user terminal has accessed the network. At this time, no processing is performed to allow the user terminal to continue to access the target network and access the corresponding resources of the target network.
[0082] In the embodiment of the present application, a zero-trust server selects the health score of the user terminal as the network access security index value of the user terminal, and uses a preset value condition including a health score greater than a preset score threshold to monitor the network access security of the user terminal. It can quickly and accurately determine whether the user terminal is an abnormal terminal, thereby ensuring timely discovery and blocking of abnormal terminals, and effectively improving network security.
[0083] In an optional embodiment, the evaluation of the network access security index value of the user terminal includes: determining the resource access statistics of the user terminal; wherein the resource access statistics include one or more of the number of resource accesses and the frequency of resource access; and using the resource access statistics as the network access security index value.
[0084] As an example, considering that in the process of the user terminal accessing the target network and accessing the corresponding resources of the target network, the user terminal frequently accesses the corresponding resources of the target network, which is easy to introduce various security threats such as viruses, Trojans and network attacks, and affect the security of the network, the zero trust server can evaluate the network access security index value of the user terminal by determining the resource access statistics of the user terminal. Among them, the resource access statistics include one or more of the number of resource accesses and the frequency of resource access.
[0085] After the user terminal obtains the network access permission of the target network and the resource access permission of the corresponding resources, the zero-trust server determines the resource access statistics of the user terminal, such as the number of resource accesses and the frequency of resource access, and uses the resource access statistics of the user terminal as the network access security index value of the user terminal.
[0086] In actual applications, the zero-trust server can determine the resource access statistics of the user terminal at regular or irregular intervals after the user terminal obtains the network access rights and resource access rights of the target network. It can also trigger the determination of the resource access statistics of the user terminal when the user terminal obtains the network access rights or resource access rights of the target network.
[0087] In the embodiment of the present application, a zero-trust server is used to evaluate the network access security index value of a user terminal by determining the resource access statistics of the user terminal. This can take into account the impact of the resource access behavior of the user terminal on network security and accurately evaluate the network access security index value of the user terminal.
[0088] In an optional embodiment, the preset value condition includes that the resource access statistic is less than a preset statistic threshold.
[0089] As an exemplary embodiment, according to actual network security requirements, a value condition of the resource access statistic is preset, that is, the preset value condition includes that the resource access statistic is less than a preset statistic threshold.
[0090] After obtaining the resource access statistics of the user terminal, the zero-trust server compares the resource access statistics of the user terminal with the preset statistical threshold. If the resource access statistics of the user terminal is greater than or equal to the preset statistical threshold, that is, it does not meet the preset value conditions, it is considered that an abnormality has occurred after the user terminal has accessed the network, affecting the security of the target network. At this time, the user terminal is controlled to disconnect from the target network to prohibit the user terminal from continuing to access the target network and access the corresponding resources of the target network; if the resource access statistics of the user terminal is less than the preset statistical threshold, that is, it meets the preset value conditions, it is considered that no abnormality has occurred after the user terminal has accessed the network. At this time, no processing is performed to allow the user terminal to continue to access the target network and access the corresponding resources of the target network.
[0091] In the embodiment of the present application, a zero-trust server selects the resource access statistics of the user terminal as the network access security index value of the user terminal, and uses preset value conditions including that the resource access statistics are less than a preset statistical threshold to monitor the network access security of the user terminal. It can quickly and accurately determine whether the user terminal is an abnormal terminal, thereby ensuring timely discovery and blocking of abnormal terminals, and effectively improving network security.
[0092] In an optional embodiment, the user terminal includes a dumb terminal.
[0093] As an example, a dumb terminal only has the function of inputting and outputting characters, has no processor or hard disk, is connected to a host through a serial interface, and all work is done by the host.
[0094] The embodiment of the present application can support refined network access control for dumb terminals by performing network access control on dumb terminals, thereby effectively improving network security.
[0095] In order to more clearly illustrate a zero-trust-based network admission control method provided in the first embodiment of the present application, the zero-trust-based network admission control method is applied to perform network admission control on the user terminal and the dumb terminal b. The specific process is as follows:
[0096] 1. The user terminal sends an EAPoL message to the network access device. The EAPoL message carries the user terminal's own login account, login password, IP address, MAC address and other network access request information.
[0097] 2. The network access device receives the EAPoL message, encapsulates the EAPoL message into a RADIUS message and sends it to the network access control device.
[0098] 3. Based on the 802.1x network access control protocol, the network access control device authenticates the user terminal once according to the RADIUS message, including the verification of the login account and login password, as well as the verification of the IP address and MAC address. After the user terminal passes the authentication once, the network access control device is notified to open the data port of the user terminal so that the user terminal can access the target network, and take over the access traffic of the user terminal's Layer 2 network according to the ACL issued by the network access control device or configured by the network access device. For example, if the user terminal is a dumb terminal, the dumb terminal can take over the access traffic of the dumb terminal's Layer 2 network according to the ACL issued by the network access control device that the dumb terminal can only access port 514 of terminal a in its Layer 2 network.
[0099] 4. User terminals that have successfully passed 802.1x authentication need to be authenticated and authorized by the zero-trust server to access the office system, database and other corresponding resources of the target network. After passing the authentication and authorization, the user terminal can access the corresponding office system, database and other resources. Access to unauthorized resources is prohibited.
[0100] 5. The zero-trust server performs continuous health checks on user terminals to obtain the health score of the user terminals. If the health score of the user terminal is less than or equal to the preset score threshold, the user terminal is determined to be an abnormal terminal, and the user terminal offline policy is sent to the network access control device. After receiving the user terminal offline policy, the network access control device triggers the network access device to offline the user terminal. At this time, the data port of the user terminal is closed, and only the EAPoL protocol is passed, and the user terminal is disconnected from the target network.
[0101] 6. The zero-trust server determines the resource access statistics of the user terminal in a preset time period, such as accessing various resources such as office systems or databases in the last hour. If the resource access statistics of the user terminal to any resource are greater than or equal to the preset statistical threshold corresponding to the resource, the user terminal is determined to be an abnormal terminal, and the user terminal offline policy is sent to the network access control device. After receiving the user terminal offline policy, the network access control device triggers the network access device to offline the user terminal. At this time, the data port of the user terminal is closed, and only the EAPoL protocol is passed, and the user terminal is disconnected from the target network.
[0102] Please see Figure 2 , Figure 2A schematic diagram of the structure of a zero-trust network access control system provided for the second embodiment of the present application. The second embodiment of the present application provides a zero-trust network access control system, including a zero-trust server 201; the zero-trust server 201 is used to: evaluate the network access security index value of the user terminal after the user terminal obtains the network access authority and resource access authority of the target network; and control the user terminal to disconnect from the target network when the network access security index value does not meet the preset value conditions.
[0103] Please see Figure 3 , Figure 3 A structural diagram of a zero-trust based network access control system provided for an optional embodiment in the second embodiment of the present application. In the optional embodiment, the system also includes a network access device 202 and a network access control device 203; the network access device 202 is used to send the network access request information of the user terminal to the network access control device 203; the network access control device 203 is used to authenticate the user terminal once according to the network access request information, and grant the user terminal network access rights after the user terminal passes the primary authentication; the zero-trust server 201 is also used to perform a secondary authentication on the user terminal after the user terminal obtains the network access right, and grant the user terminal resource access rights after the user terminal passes the secondary authentication.
[0104] In an optional embodiment, the evaluation of the network access security index value of the user terminal includes: performing a health check on the user terminal to obtain a health score of the user terminal; wherein the health check includes checking whether open ports are compliant, checking whether the terminal has joined a compliant AD domain, checking whether the installation and operation of software programs are compliant, checking whether a guest account is enabled, checking whether a file sharing function is enabled, whether a display interface protection function is enabled, and checking whether there are one or more of the following vulnerabilities; and using the health score as the network access security index value.
[0105] In an optional embodiment, the preset value condition includes the health score being greater than a preset score threshold.
[0106] In an optional embodiment, the evaluation of the network access security index value of the user terminal includes: determining the resource access statistics of the user terminal; wherein the resource access statistics include one or more of the number of resource accesses and the frequency of resource access; and using the resource access statistics as the network access security index value.
[0107] In an optional embodiment, the preset value condition includes that the resource access statistic is less than a preset statistic threshold.
[0108] In an optional embodiment, the user terminal includes a dumb terminal.
[0109] The implementation process of the functions and effects of each device in the above system is specifically described in the implementation process of the corresponding steps in the method described in the first embodiment of the present application, and will not be repeated here.
[0110] Please see Figure 4 , Figure 4 The third embodiment of the present application provides an electronic device 30, comprising a processor 301, a memory 302, and a computer program stored in the memory 302 and configured to be executed by the processor 301; when the processor 301 executes the computer program, the method described in the first embodiment of the present application is implemented and the same beneficial effects can be achieved.
[0111] When the processor 301 reads the computer program from the memory 302 through the bus 303 and executes the computer program, the method of any embodiment included in the method described in the first embodiment of the present application can be implemented.
[0112] Processor 301 can process digital signals and can include various computing structures, such as complex instruction set computer structure, reduced instruction set computer structure, or a structure that implements a combination of multiple instruction sets. In some examples, processor 301 can be a microprocessor.
[0113] The memory 302 may be used to store instructions executed by the processor 301 or data related to the execution of instructions. These instructions and / or data may include codes for implementing some or all functions of one or more modules described in the embodiments of the present application. The processor 301 of the disclosed embodiment may be used to execute instructions in the memory 302 to implement the method described in the first embodiment of the present application. The memory 302 includes a dynamic random access memory, a static random access memory, a flash memory, an optical memory, or other memory known to those skilled in the art.
[0114] The fourth embodiment of the present application provides a computer-readable storage medium, which includes a stored computer program; wherein, when the computer program is running, the device where the computer-readable storage medium is located is controlled to execute the method described in the first embodiment of the present application, and can achieve the same beneficial effects as the method.
[0115] The method described in the first embodiment of the present application can be implemented in whole or in part by software, hardware, firmware or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer programs or instructions. When the computer program or instruction is loaded and executed on a computer, the process or function described in each embodiment of the present application is executed in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, a network device, a user device, a core network device, an OAM (Open Application Model) or other programmable device.
[0116] The computer program or instructions may be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium, for example, the computer program or instructions may be transmitted from one website, computer, server or data center to another website, computer, server or data center by wired or wireless means. The computer-readable storage medium may be any available medium that can be accessed by a computer or a data storage device such as a server or data center that integrates one or more available media. The available medium may be a magnetic medium, such as a floppy disk, a hard disk, or a magnetic tape; it may also be an optical medium, such as a digital video disk; it may also be a semiconductor medium, such as a solid-state drive. The computer-readable storage medium may be a volatile or non-volatile storage medium, or may include both volatile and non-volatile types of storage media.
[0117] In summary, the embodiments of the present application provide a zero-trust-based network access control method, system, device and medium. The zero-trust-based network access control method is applicable to a zero-trust server. The method includes: after the user terminal obtains the network access authority and resource access authority of the target network, evaluating the network access security index value of the user terminal; when the network access security index value does not meet the preset value conditions, controlling the user terminal to disconnect from the target network. The embodiments of the present application are to evaluate the network access security index value of the user terminal after the user terminal obtains the network access authority and resource access authority of the target network by the zero-trust server, and when the network access security index value does not meet the preset value conditions, controlling the user terminal to disconnect from the target network. Based on the zero-trust mechanism, the network access security of the user terminal can continue to be monitored after the user terminal enters the network, thereby ensuring timely discovery and blocking of abnormal terminals, and effectively improving network security.
[0118] In several embodiments provided in the present application, it should be understood that the disclosed devices and methods can also be implemented in other ways. The device embodiments described above are merely schematic. For example, the flowcharts and block diagrams in the accompanying drawings show the possible architecture, functions and operations of the devices, methods and computer program products according to multiple embodiments of the present application. In this regard, each box in the flowchart or block diagram can represent a module, a program segment or a part of a code, and the module, a program segment or a part of a code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a different order from the order marked in the accompanying drawings. For example, two consecutive boxes can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flowchart, and the combination of boxes in the block diagram and / or flowchart can be implemented with a dedicated hardware-based system that performs a specified function or action, or can be implemented with a combination of dedicated hardware and computer instructions.
[0119] In addition, the functional modules in the various embodiments of the present application may be integrated together to form an independent part, or each module may exist separately, or two or more modules may be integrated to form an independent part.
[0120] If the functions are implemented in the form of software function modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application can be essentially or partly embodied in the form of a software product that contributes to the prior art. The computer software product is stored in a storage medium, including several instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the methods described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.
[0121] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art who is familiar with the present technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.
Claims
1. A network access control method based on zero trust, characterized in that: Applicable to a zero-trust server, the method includes: After the user terminal obtains the network access authority and resource access authority of the target network, evaluating the network access security index value of the user terminal; When the network access security index value does not meet a preset value condition, the user terminal is controlled to disconnect from the target network.
2. The method according to claim 1, characterized in that The network access right is granted by the network access control device to the user terminal after the user terminal passes the authentication once after the network access request information of the user terminal is authenticated once; the network access request information is sent by the network access device to the network access control device; After the user terminal obtains the network access authority and resource access authority of the target network, before evaluating the network access security index value of the user terminal, the method further includes: After the user terminal obtains the network access authority, a secondary authentication is performed on the user terminal, and after the user terminal passes the secondary authentication, the resource access authority is granted to the user terminal.
3. The method according to claim 1, characterized in that The evaluating the network access security index value of the user terminal includes: Performing a health check on the user terminal to obtain a health score of the user terminal; wherein the health check includes one or more of checking whether the open port is compliant, checking whether the terminal has joined a compliant AD domain, checking whether the installation and operation of the software program is compliant, checking whether the guest account is enabled, checking whether the file sharing function is enabled, checking whether the display interface protection function is enabled, and checking whether there are vulnerability patches; The health score is used as the network access security index value.
4. The method according to claim 3, characterized in that The preset value condition includes that the health score is greater than a preset score threshold.
5. The method according to claim 1, characterized in that: The evaluating the network access security index value of the user terminal includes: Determine resource access statistics of the user terminal; wherein the resource access statistics include one or more of the number of resource accesses and the frequency of resource accesses; The resource access statistics are used as the network access security index value.
6. The method according to claim 5, characterized in that The preset value condition includes that the resource access statistic is less than a preset statistic threshold.
7. The method according to any one of claims 1 to 6, characterized in that: The user terminal includes a dumb terminal.
8. A zero-trust based network access control system, characterized in that: Includes zero-trust servers; The zero trust server is used to: After the user terminal obtains the network access authority and resource access authority of the target network, evaluating the network access security index value of the user terminal; When the network access security index value does not meet a preset value condition, the user terminal is controlled to disconnect from the target network.
9. The system according to claim 8, characterized in that The system also includes a network access device and a network admission control device; The network access device is used to send the network access request information of the user terminal to the network admission control device; The network access control device is used to authenticate the user terminal once according to the network access request information, and grant the network access authority to the user terminal after the user terminal passes the authentication once; The zero-trust server is also used to perform secondary authentication on the user terminal after the user terminal obtains the network access authority, and grant the resource access authority to the user terminal after the user terminal passes the secondary authentication.
10. An electronic device, characterized in that: The method comprises a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor; when the processor executes the computer program, the method according to any one of claims 1 to 7 is implemented.
11. A computer-readable storage medium, characterized in that: The computer-readable storage medium includes a stored computer program; wherein, when the computer program is running, the device where the computer-readable storage medium is located is controlled to execute the method according to any one of claims 1 to 7.