Safety protection method and device

By configuring domain name object groups in the SSL proxy policy of firewall devices, the problem that traditional firewall devices cannot implement SSL proxy based on domain names is solved, and SSL proxy for specific domain names is realized, simplifying the user configuration process.

CN119966715APending Publication Date: 2025-05-09NEW H3C SECURITY TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510125932.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-24
Publication Date
2025-05-09

AI Technical Summary

Technical Problem

Traditional firewall devices cannot implement SSL proxy based on domain names, and it is difficult for users to accurately know the server's IP address, resulting in the inability to implement SSL proxy for specific domain names.

Method used

By configuring the domain name object group in the SSL proxy policy, recording the website domain name and IP address mapping relationship of the SSL proxy to be executed, and determining whether the IP address in the connection establishment request is the same as the IP address of the domain name object group in the policy. If the same, deep message detection will be performed.

Benefits of technology

It implements SSL proxying based on the domain name specified by the user, which meets the user's need to execute SSL proxying when accessing a specific domain name, and simplifies the user configuration process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119966715A_ABST
    Figure CN119966715A_ABST
Patent Text Reader

Abstract

The invention provides a safety protection method and device. The method is applied to firewall equipment deployed at an exit of an intranet client, and comprises the following steps: when the intranet client sends a connection establishment request, judging whether an IP address in the connection establishment request is the same as an IP address of a domain name object group in an SSL proxy strategy, the domain name object group is used for recording a website domain name of the SSL proxy to be executed and a mapping relation between the website domain name and the IP address; and if the judgment result is yes, executing deep message detection on the service message between the intranet client and the target Web server based on the SSL proxy. According to the method, the SSL proxy can be realized on the firewall equipment based on the domain name specified by the user, and the requirement that the user only wants to execute the SSL proxy when accessing the specific domain name is met under the scene that the intranet client accesses the extranet Web server.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of communication technology, and in particular to a security protection method and device. Background Art

[0002] Traditional firewall devices generally implement SSL (Secure Sockets Layer) proxy based on IP (Internet Protocol) addresses. However, in actual use, users often access servers through domain names. For some servers, especially servers that are not in the user's management domain, users often cannot accurately know the server's IP or IP range, but only know the server's domain name. How to use firewall devices to perform SSL proxy for specific domain names accessed by users is a technical problem to be solved in this field. Summary of the invention

[0003] In order to overcome the problems existing in the related art, the present application provides a safety protection method and device.

[0004] According to a first aspect of an embodiment of the present application, a security protection method is provided, the method being applied to a firewall device, the firewall device being deployed at an exit of an intranet client, the method comprising:

[0005] When the intranet client sends a connection establishment request, determine whether the IP address in the connection establishment request is the same as the IP address of the domain name object group in the SSL proxy policy, wherein the domain name object group is used to record the website domain name to be executed by the SSL proxy and the mapping relationship between the website domain name and the IP address;

[0006] If the judgment result is yes, deep message inspection is performed on the business message between the intranet client and the target Web server based on the SSL proxy, wherein the target Web server is the Web server corresponding to the IP address in the connection establishment request.

[0007] According to a second aspect of an embodiment of the present application, a security protection device is provided, the device is applied to a firewall device, the firewall device is deployed at the exit of an intranet client, and the device includes:

[0008] A judgment module, used for judging whether the IP address in the connection establishment request is the same as the IP address of the domain name object group in the SSL proxy policy when the intranet client sends a connection establishment request, wherein the domain name object group is used to record the website domain name to be executed by the SSL proxy and the mapping relationship between the website domain name and the IP address;

[0009] The detection module is used to perform deep message detection on the business message between the intranet client and the target Web server based on the SSL proxy if the judgment result is yes, wherein the target Web server is the Web server corresponding to the IP address in the connection establishment request.

[0010] According to a third aspect of an embodiment of the present application, there is provided an electronic device, including:

[0011] A memory and one or more processors; the memory is coupled to the processor; wherein the memory stores computer program code, the computer program code includes computer instructions, and when the computer instructions are executed by the processor, the electronic device executes the method as described above.

[0012] According to a fourth aspect of an embodiment of the present application, there is provided a computer-readable storage medium, comprising computer instructions, which, when executed on an electronic device, enables the electronic device to execute the method as described above.

[0013] According to a fifth aspect of an embodiment of the present application, a computer program product is provided. When the computer program product is run on a computer, the computer is enabled to execute the method described above.

[0014] The technical solution provided by the embodiments of the present application may have the following beneficial effects:

[0015] This application provides a security protection method applied to firewall devices, which can implement SSL proxy based on the domain name specified by the user. In the scenario where the intranet client accesses the external network Web server, it quickly and effectively meets the user's demand for executing SSL proxy only when accessing a specific domain name.

[0016] It should be understood that the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the present application. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] The accompanying drawings, which are incorporated in the specification and constitute a part of this application, illustrate embodiments consistent with the application and, together with the description, serve to explain the principles of the application.

[0018] Figure 1 A schematic diagram of the system structure of a security protection method provided in an embodiment of the present application;

[0019] Figure 2 A schematic diagram of a safety protection method provided in an embodiment of the present application;

[0020] Figure 3 A schematic diagram of the structure of a safety protection device provided in an embodiment of the present application;

[0021] Figure 4 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0022] The technical solutions in the embodiments of the present application are described below in conjunction with the drawings in the embodiments of the present application. In the description of the embodiments of the present application, the terms used in the following embodiments are only for the purpose of describing specific embodiments and are not intended to be limiting of the present application.

[0023] It should be noted that in this application, "at least one" means one or more, and "more than one" means two or more than two. "And / or" describes the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone, where A and B can be singular or plural. The terms "first", "second", "third", etc. (if any) in the specification, claims and drawings of this application are used to distinguish similar objects, rather than to describe a specific order or sequence.

[0024] In the embodiments of the present application, words such as "exemplary" or "for example" are used to indicate examples, illustrations or descriptions. Any embodiment or design described as "exemplary" or "for example" in the embodiments of the present application should not be interpreted as being more preferred or more advantageous than other embodiments or designs. Specifically, the use of words such as "exemplary" or "for example" is intended to present related concepts in a specific way.

[0025] Currently, firewall devices do not support SSL proxy policies based on domain names. If users want to perform SSL proxy for a specific domain name, they can only cache the mapping relationship between the domain name and the IP address through the client, or obtain the mapping relationship between the domain name and the IP address from the local DNS (Domain Name System) server, and then report the IP address corresponding to the domain name to the firewall device, so that the firewall device can generate an SSL proxy policy based on the IP address. However, this implementation method is relatively cumbersome, and one domain name generally corresponds to multiple IP addresses, which makes it inconvenient for users to confirm the IP address corresponding to a specific domain name.

[0026] In response to the above problems, the present application provides a security protection method and device, which implements a domain name-based SSL proxy policy by configuring a domain name object group in the SSL proxy policy, thereby achieving the purpose of executing SSL proxy for the domain name specified by the user and meeting the user's needs for executing SSL proxy for a specific domain name.

[0027] Next, the embodiments of the present application are described in detail.

[0028] The present application embodiment provides a security protection method, which is applied to a firewall device, such as Figure 1 As shown, the firewall device is deployed at the exit of the intranet client. Figure 2 As shown, the method may include the following steps:

[0029] Step 210: When the intranet client sends a connection establishment request, determine whether the IP address in the connection establishment request is the same as the IP address of the domain name object group in the SSL proxy policy. If the determination result is yes, proceed to step 220; otherwise, transparently transmit the service message between the intranet client and the target Web server.

[0030] Step 220: Perform deep message inspection on the service messages between the intranet client and the target Web server based on the SSL proxy.

[0031] The domain name object group is used to record the website domain name to be executed by the SSL proxy and the mapping relationship between the website domain name and the IP address. The target Web server is the Web server corresponding to the IP address in the connection establishment request.

[0032] In this embodiment, the intranet client communicates with the Web server via the HTTPS (Hypertext Transfer Protocol Secure) protocol.

[0033] Specifically, the user can perform the domain name configuration operation according to their own needs. The firewall device of this embodiment can create a domain name object group according to the domain name configuration operation, and the domain name object group includes the website domain name to be executed by the SSL proxy. After that, this embodiment monitors the DNS message passing through the firewall device, determines the target DNS message containing the website domain name in the domain name object group, determines the mapping relationship between the website domain name and the IP address according to the target DNS message, and records the mapping relationship between the website domain name and the IP address in the domain name object group. Finally, this embodiment generates an SSL proxy policy according to the domain name object group, which is equivalent to referencing the IP address corresponding to the website domain name.

[0034] As a specific implementation method, this embodiment uses a DNS sniffing tool service to capture and analyze DNS messages passing through a firewall device, and determines whether each DNS message passing through the firewall device is a target DNS message containing a website domain name in a domain name object group.

[0035] When a user visits a target website, the user can enter the domain name of the target website in the browser of the intranet client, and then the browser obtains the IP address corresponding to the domain name through the DNS server, and the intranet client establishes a TCP connection with the server through the IP address. When the intranet client sends a connection establishment request, the firewall device of this embodiment will determine whether the IP address in the connection establishment request is the same as the IP address of the domain name object group in the SSL proxy policy. If they are the same, it indicates that the domain name that the user wants to access this time is a domain name that needs to execute SSL proxy. Therefore, at this time, the firewall device of this embodiment will perform deep message inspection on the business message between the intranet client and the target server Web server based on SSL proxy.

[0036] Specifically, the deep packet inspection types supported by this embodiment include at least one of the following service types: IPS (Intrusion Prevention System), URL filtering, data filtering, file filtering, antivirus and NBAR (Network Based Application Recognition). These service types can be turned on or off according to actual needs. In actual applications, the number of website domain names specified by the user may be multiple. This embodiment supports performing deep packet inspection of the same service type on all website domain names specified by the user, and also supports performing deep packet inspection of each service type for each website domain name specified by the user.

[0037] As a preferred implementation, this embodiment also supports configuring the service type of the website domain name in the SSL proxy policy, that is, the service type of the deep packet inspection performed on the network traffic of the target website corresponding to the website domain name. Specifically, the service type of the website domain name is determined according to the security configuration operation, and an SSL proxy policy including the domain name object group and the service type is generated.

[0038] In addition, you can also configure the policy name, user name, source address, destination address, policy start and stop parameters, etc. in the SSL proxy policy.

[0039] It can be seen from the above technical solutions that the security protection method provided by this application can implement SSL proxy based on the domain name specified by the user. In the scenario where the intranet client accesses the external network Web server, it can quickly and effectively meet the user's needs of only executing SSL proxy when accessing a specific domain name.

[0040] Based on the same inventive concept, the present application also provides a security protection device, which is applied to a firewall device, and the firewall device is deployed at the exit of the intranet client. Its structural diagram is as follows Figure 3 As shown, specifically including:

[0041] The judgment module 310 is used to judge whether the IP address in the connection establishment request is the same as the IP address of the domain name object group in the SSL proxy policy when the intranet client sends a connection establishment request, wherein the domain name object group is used to record the website domain name to be executed by the SSL proxy and the mapping relationship between the website domain name and the IP address;

[0042] The detection module 320 is used to perform deep message detection on the business message between the intranet client and the target server Web server based on the SSL proxy if the judgment result is yes, wherein the target server Web server is the server Web server corresponding to the IP address in the connection establishment request.

[0043] As a specific implementation, the device further includes:

[0044] A creation module 330, configured to create a domain name object group according to a domain name configuration operation, wherein the domain name object group includes a website domain name for which an SSL proxy is to be executed;

[0045] A monitoring module 340 is used to monitor the DNS message passing through the firewall device. If a target DNS message containing the website domain name in the domain name object group is monitored, a mapping relationship between the website domain name and the IP address is determined according to the target DNS message, and the mapping relationship is recorded in the domain name object group;

[0046] The generating module 350 is used to generate an SSL proxy policy according to the domain name object group.

[0047] As a specific implementation, the monitoring module 340 monitors the DNS message passing through the firewall device in the following manner:

[0048] Use a DNS sniffing tool to monitor DNS messages passing through the firewall device.

[0049] As a specific implementation, the SSL proxy policy also includes the business type of the website domain name, and the detection module 320 specifically performs deep message inspection in the following manner:

[0050] Perform deep packet inspection corresponding to the business type, and the business type includes any one of the following: intrusion prevention, URL filtering, data filtering, file filtering, and antivirus.

[0051] As a specific implementation, the generation module 350 generates the SSL proxy policy according to the domain name object group in the following manner:

[0052] The business type of the website domain name is determined according to the security configuration operation, and an SSL proxy policy including the domain name object group and the business type is generated.

[0053] An embodiment of the present application provides an electronic device, which may include: a memory and one or more processors. The memory is used to store computer program code, and the computer program code includes computer instructions. When the processor executes the computer instructions, the electronic device may perform various functions or steps of the above method embodiment.

[0054] The structure of the electronic device can refer to Figure 4 The structure of the electronic device 100 is shown.

[0055] The above-mentioned processor can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components.

[0056] An embodiment of the present application also provides a computer-readable storage medium, which includes computer instructions. When the computer instructions are executed on an electronic device, the electronic device executes each function or step of the above method embodiment.

[0057] The computer-readable storage medium includes but is not limited to any one of the following: a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, and other media that can store program codes.

[0058] The embodiment of the present application also provides a computer program product. When the computer program product is run on a computer, the computer is enabled to perform each function or step of the above method embodiment.

[0059] Among them, the electronic device, computer-readable storage medium, and computer program product provided in the embodiments of the present application are all used to execute the corresponding methods provided above. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects in the corresponding methods provided above, and will not be repeated here.

[0060] Through the description of the above implementation methods, technical personnel in the relevant field can clearly understand that for the convenience and simplicity of description, only the division of the above-mentioned functional modules is used as an example. In actual applications, the above-mentioned functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above.

[0061] In the several embodiments provided in the present application, it should be understood that the disclosed method can be implemented in other ways. The device embodiments described above are merely schematic. For example, the division of the modules or units is only a logical function division, and there may be other division methods in actual implementation; for example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of modules or units, which can be electrical, mechanical or other forms.

[0062] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of software functional units.

[0063] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any changes or substitutions within the technical scope disclosed in the present application should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.

Claims

1. A safety protection method, characterized in that: The method is applied to a firewall device, which is deployed at the exit of an intranet client. The method includes: When the intranet client sends a connection establishment request, determine whether the IP address in the connection establishment request is the same as the IP address of the domain name object group in the SSL proxy policy, wherein the domain name object group is used to record the website domain name to be executed by the SSL proxy and the mapping relationship between the website domain name and the IP address; If the judgment result is yes, deep message inspection is performed on the business message between the intranet client and the target Web server based on the SSL proxy, wherein the target Web server is the Web server corresponding to the IP address in the connection establishment request.

2. The method according to claim 1, characterized in that The method further comprises: Creating a domain name object group according to the domain name configuration operation, wherein the domain name object group includes the website domain name to be executed by SSL proxy; Monitoring the DNS messages passing through the firewall device, if a target DNS message containing the website domain name in the domain name object group is monitored, determining the mapping relationship between the website domain name and the IP address according to the target DNS message, and recording the mapping relationship in the domain name object group; Generate an SSL proxy policy based on the domain name object group.

3. The method according to claim 2, characterized in that The method specifically monitors the DNS messages passing through the firewall device in the following manner: Use a DNS sniffing tool to monitor DNS messages passing through the firewall device.

4. The method according to claim 2, characterized in that: The SSL proxy policy also includes the business type of the website domain name. The method specifically performs deep message inspection in the following manner: Perform deep packet inspection corresponding to the business type, and the business type includes any one of the following: intrusion prevention, URL filtering, data filtering, file filtering, and antivirus.

5. The method according to claim 4, characterized in that The method specifically generates an SSL proxy policy according to the domain name object group in the following manner: The business type of the website domain name is determined according to the security configuration operation, and an SSL proxy policy including the domain name object group and the business type is generated.

6. A safety protection device, characterized in that: The device is applied to a firewall device, and the firewall device is deployed at the exit of an intranet client. The device includes: A judgment module, used for judging whether the IP address in the connection establishment request is the same as the IP address of the domain name object group in the SSL proxy policy when the intranet client sends a connection establishment request, wherein the domain name object group is used to record the website domain name to be executed by the SSL proxy and the mapping relationship between the website domain name and the IP address; The detection module is used to perform deep message detection on the business message between the intranet client and the target Web server based on the SSL proxy if the judgment result is yes, wherein the target Web server is the Web server corresponding to the IP address in the connection establishment request.

7. The device according to claim 6, characterized in that The device also includes: A creation module, used to create a domain name object group according to a domain name configuration operation, wherein the domain name object group includes a website domain name for which an SSL proxy is to be executed; A monitoring module, configured to monitor the DNS messages passing through the firewall device, and if a target DNS message containing a website domain name in the domain name object group is monitored, determine a mapping relationship between the website domain name and the IP address according to the target DNS message, and record the mapping relationship in the domain name object group; A generation module is used to generate an SSL proxy policy according to the domain name object group.

8. An electronic device, characterized in that: include: A memory and one or more processors; the memory is coupled to the processor; wherein the memory stores computer program code, the computer program code includes computer instructions, and when the computer instructions are executed by the processor, the electronic device executes the method as described in any one of claims 1-5.

9. A computer-readable storage medium comprising computer instructions, characterized in that: When the computer instructions are executed on an electronic device, the electronic device is caused to execute the method according to any one of claims 1 to 5.

10. A computer program product, characterized in that When the computer program product is executed on a computer, the computer is caused to execute the method according to any one of claims 1 to 5.