Online behavior management system
By introducing a variety of authentication methods and application control platforms into the Internet behavior management system, the problems of single authentication methods, high security risks, and poor compatibility in traditional systems have been solved, and higher network security, management efficiency and refinement of application control have been achieved, and network bandwidth can be reasonably managed and encrypted traffic can be identified and controlled.
Patent Information
- Application Number
- CN202510298052.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-13
- Publication Date
- 2025-05-16
AI Technical Summary
Traditional Internet behavior management systems cannot meet the performance needs of users. There are problems such as single authentication methods, high security risks, poor compatibility and scalability, inability to fine-grained application functions, inability to reasonably allocate and manage network bandwidth, and inability to effectively identify and control encrypted traffic.
Provides an Internet behavior management system, including an identity authentication platform and an application control platform. The identity authentication platform supports multiple authentication methods, combining user Internet authentication and terminal Internet access authentication to realize wired and wireless unified authentication, and can be configured with two-factor authentication. The application control platform uses the application identification module, the policy formulation and issuance module, and the traffic control and behavior management module to fine-grained control of applications, and reasonably allocates and manages network bandwidth to identify and control encrypted traffic.
It has implemented the support of multiple authentication methods, enhanced the security of user login, improved network security and management efficiency, and has good compatibility and scalability. It can manage applications in a refined manner, allocate and manage network bandwidth reasonably, and effectively identify and control encrypted traffic.
Smart Images

Figure FT_1
Abstract
Description
Technical Field
[0001] The invention belongs to the technical field of network management, and in particular relates to an online behavior management system. Background Art
[0002] Internet behavior management equipment refers to security equipment specifically used to monitor, manage and control the Internet behavior of users within the network. Its main purpose is to improve the network security, employee work efficiency and compliance of an enterprise or organization.
[0003] With the continuous development of Internet technology, traditional Internet behavior management systems can no longer meet the performance requirements of users and may have the following problems: First, the authentication method is single and cannot meet the needs of different user groups and corporate environments; second, the login password is single and easy to leak, posing a security risk; third, the compatibility and scalability are poor, making it difficult to seamlessly connect with the company's existing identity authentication systems; fourth, the application functions cannot be managed in a refined manner, and the company's personalized needs for application control cannot be met; fifth, the network bandwidth cannot be reasonably allocated and managed, and bandwidth occupation causes network congestion, affecting the stable operation of the network; sixth, the encrypted traffic cannot be effectively identified and controlled, posing a risk of leakage of sensitive corporate information.
[0004] To this end, the present application provides an online behavior management system to avoid the risks and defects of traditional online behavior management systems.
[0005] The information disclosed in this background technology section is only intended to enhance the understanding of the overall background of the invention and should not be regarded as an acknowledgment or any form of suggestion that the information constitutes the prior art already known to a person skilled in the art. Summary of the invention
[0006] The purpose of the present invention is to provide an online behavior management system to solve the problem that traditional online behavior management systems cannot meet the performance requirements of users.
[0007] In order to achieve the above object, the present invention provides the following technical solutions:
[0008] An online behavior management system, comprising:
[0009] The identity authentication platform includes a user information collection and identification module, an authentication request and verification module, and an authentication status maintenance and management module; the user information collection and identification module is used to collect user information to determine the identity of the user and realize accurate identification of the user; the authentication request and verification module intercepts the user's access request through the Internet behavior management device, and sends the authentication information submitted by the user to the corresponding authentication server or local database for verification according to the preset authentication strategy; the authentication status maintenance and management module is used to monitor the user's network activity in real time and update the authentication status when the user logs out or the session ends;
[0010] The application control platform includes an application identification module, a policy formulation and issuance module, and a traffic control and behavior management module; the application identification module is used to deeply identify and classify various application programs and network traffic in the network, and classify them according to their characteristics and behavior patterns; the policy formulation and issuance module is used for enterprise managers to formulate corresponding access control policies for different application categories, users or user groups according to their own management needs and security policies, and issue the formulated policies to the Internet behavior management device; the traffic control and behavior management module controls application traffic according to the issued policies, and restricts specific behaviors of applications.
[0011] Preferably, the identity authentication platform supports multiple authentication methods, including: local password authentication, external authentication server authentication, LDAP authentication, Radius authentication, POP3 authentication, SMS authentication and WeChat authentication.
[0012] Preferably, the identity authentication platform provides a network converged authentication method for combining user Internet access authentication with terminal network access authentication to achieve unified wired and wireless authentication.
[0013] Preferably, the identity authentication platform can be configured with a two-factor authentication method, including static password plus dynamic password authentication and fingerprint recognition plus password authentication.
[0014] Preferably, the identity authentication platform supports authentication policy configuration and can flexibly configure authentication policies according to different users, user groups, time periods and access location factors.
[0015] Preferably, the application control platform includes a comprehensive and continuously updated identification library for quickly and accurately identifying and managing emerging applications and network threats.
[0016] Preferably, the application control platform formulates and issues refined management strategies to control the entire application program, go deep into the specific functions and operations of the application, and set different access rights for each.
[0017] Preferably, the application control platform formulates and issues differentiated control strategies based on users and user groups to accurately manage the online behaviors of employees in different departments and positions.
[0018] Preferably, the application control platform formulates and issues bandwidth management and traffic optimization strategies to reasonably allocate and manage network bandwidth, limit bandwidth usage of non-critical applications, and ensure bandwidth requirements for critical services.
[0019] Preferably, the application control platform develops and issues encrypted traffic identification and management strategies to analyze and control the content and behavior of encrypted applications to prevent sensitive enterprise information from leaking through encrypted channels.
[0020] Compared with the prior art, the present invention has the following beneficial effects:
[0021] (1) The Internet behavior management system of the present invention supports multiple authentication methods to meet the needs of different user groups and enterprise environments; it can be configured with two-factor or two-factor authentication to increase the security of user login and effectively prevent security risks caused by the leakage of a single password.
[0022] (2) The Internet behavior management system of the present invention combines user Internet access authentication with terminal network access authentication to achieve unified wired and wireless authentication, ensuring that only legitimate users and terminals can access the network, which is conducive to improving network security and management efficiency.
[0023] (3) The Internet behavior management system of the present invention has good compatibility and scalability, and can be seamlessly connected with various existing identity authentication systems of the enterprise, thereby reducing management costs and complexity.
[0024] (4) The Internet behavior management system of the present invention can achieve refined control over applications. It can not only control the entire application program, but also go deep into the specific functions and operations of the application, and set different access permissions respectively to meet the personalized needs of enterprises for application control.
[0025] (5) The Internet behavior management system of the present invention, combined with traffic detection and control technology, reasonably allocates and manages network bandwidth, which is conducive to improving the utilization rate of network resources, avoiding network congestion caused by large bandwidth occupation by individual users or applications, and ensuring the stable operation of the enterprise network. BRIEF DESCRIPTION OF THE DRAWINGS
[0026] Figure 1 It is a system framework diagram of the present invention. DETAILED DESCRIPTION
[0027] The following is a clear and complete description of the technical solution of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of them. Based on the embodiments of the present invention, all other embodiments obtained by technicians in this field without creative work are within the scope of protection of the present invention.
[0028] The present invention provides an online behavior management system, including an identity authentication platform and an application control platform. The identity authentication platform includes a user information collection and identification module, an authentication request and verification module, and an authentication status maintenance and management module. The application control platform includes an application identification module, a policy formulation and issuance module, and a flow control and behavior management module.
[0029] The user information collection and identification module is used to collect user information to determine their identity and accurately identify the user. First, the device needs to collect relevant information about the user to determine their identity, such as the user name and password, IP address, MAC address, computer name, etc. entered by the user. It can also use the user information provided by a third-party authentication system, such as the authentication results returned by the Radius server, LDAP server, etc., to accurately identify the user.
[0030] The authentication request and verification module intercepts user access requests through the Internet behavior management device, and sends the authentication information submitted by the user to the corresponding authentication server or local database for verification according to the preset authentication policy. When the user accesses the network, the Internet behavior management device will intercept his access request; after the verification is passed, the user is allowed to access network resources; otherwise, the access request will be rejected.
[0031] The Internet behavior management device will record the user's authentication status. After the user is successfully authenticated, a session will be established for the user and the corresponding permissions will be assigned. At the same time, the authentication status maintenance and management module will monitor the user's network activities in real time to ensure that their access behavior during the authentication validity period complies with the company's security policy, and when the user exits or the session expires, the authentication status will be updated in time to release related resources.
[0032] The identity authentication platform provided by the present invention supports multiple authentication methods, such as local password authentication, external authentication server authentication, LDAP authentication, Radius authentication, POP3 authentication, SMS authentication, WeChat authentication, etc., to meet the needs of different user groups and corporate environments. The identity authentication platform also provides an innovative network-terminal fusion authentication method, which combines user Internet access authentication with terminal network access authentication to achieve unified wired and wireless authentication, ensuring that only legitimate users and terminals can access the network, and improving network security and management efficiency.
[0033] In addition, the identity authentication platform can be configured with two-factor or dual-factor authentication, such as static password plus dynamic password, fingerprint recognition plus password, etc., to increase the security of user login and effectively prevent security risks caused by the leakage of a single password. The identity authentication platform also supports authentication policy configuration, which can be flexibly configured according to different users, user groups, time periods, access locations and other factors. For example, employees must use a specific authentication method to log in during working hours, while visitors can use temporary passwords or SMS verification codes for authentication during non-working hours.
[0034] When connected with a third-party authentication system, the Internet behavior management system of the present invention has good compatibility and scalability, and can be seamlessly connected with various existing identity authentication systems of the enterprise, such as integration with the enterprise's internal AD domain controller, LDAP directory service, etc., and utilize existing user information and organizational structure to achieve single sign-on and centralized management, reducing management costs and complexity.
[0035] On the other hand, the application control platform provided in this embodiment includes an application identification module, a policy formulation and delivery module, and a traffic control and behavior management module.
[0036] The application identification module deeply identifies and classifies various applications and network traffic in the network based on the built-in application identification library and advanced identification technology. Whether it is common HTTP, HTTPS, FTP, SMTP and other protocols, or P2P downloads, online videos, instant messaging, online games and other applications, it can accurately identify and classify them according to their characteristics and behavior patterns.
[0037] The policy formulation and distribution module is used for enterprise managers to formulate and distribute access control policies. Enterprise managers formulate corresponding access control policies for different application categories, users or user groups according to their own management needs and security policies. These policies can include operations such as allowing, prohibiting, and restricting access, and can be finely configured according to conditions such as time, bandwidth, and access frequency. Then, the formulated policies are distributed to the Internet behavior management device, and the device will monitor and control network traffic in real time according to these policies.
[0038] The traffic control and behavior management module controls application traffic according to the issued policies and restricts specific behaviors of applications. When users access network applications, for permitted applications, the Internet behavior management device can allocate corresponding bandwidth resources according to the policies to ensure the network performance of key businesses; for prohibited applications, its access request is directly blocked; at the same time, specific behaviors of applications can also be restricted, such as limiting the size of file uploads and downloads, limiting the resolution of video playback, etc., in order to standardize employees' Internet behavior, improve work efficiency, and reduce network risks.
[0039] The application control platform provided in this embodiment can achieve refined control over applications, not only controlling the entire application, but also going deep into the specific functions and operations of the application. For example, it can distinguish different functions such as WeChat chat, file transfer, and Moments access, and set different access permissions for each function to meet the personalized needs of enterprises for application control.
[0040] Based on differentiated control of users and user groups, the application control platform can formulate differentiated application control strategies according to different users or user groups, and achieve precise management of the online behavior of employees in different departments and positions. For example, the R&D department can be given more access rights to professional tools and technical forums related to work, while the administrative department can be restricted from accessing entertainment applications.
[0041] The application control platform can also combine traffic detection and control technology to reasonably allocate and manage network bandwidth. By limiting the bandwidth usage of non-critical applications, it can ensure the bandwidth requirements of critical businesses, improve the utilization of network resources, avoid network congestion caused by large bandwidth usage by individual users or applications, and ensure the stable operation of the enterprise network.
[0042] With the widespread application of network encryption technology, the Internet behavior management system of the present invention can effectively identify and control encrypted traffic such as HTTPS. By adopting advanced encrypted traffic detection technology, the content and behavior of encrypted applications can be analyzed and controlled without affecting user experience and network performance, preventing the leakage of enterprise sensitive information through encrypted channels, thereby ensuring the comprehensiveness and effectiveness of enterprise network security.
[0043] The Internet behavior management system of the present invention also has an industry-leading application identification library and URL rule library, and can be updated in a timely manner to ensure that newly emerging applications and network threats can be quickly and accurately identified and managed.
[0044] The foregoing description of specific exemplary embodiments of the present invention is for the purpose of illustration and demonstration. These descriptions are not intended to limit the present invention to the precise form disclosed, and it is clear that many changes and variations can be made based on the above teachings. The purpose of selecting and describing the exemplary embodiments is to explain the specific principles of the present invention and its practical application, so that those skilled in the art can realize and utilize various different exemplary embodiments of the present invention and various different selections and changes. The scope of the present invention is intended to be limited by the claims and their equivalents.
Claims
1. A surfing behavior management system, characterized in that: include: Identity authentication platform, including user information collection and identification module, authentication request and verification module, and authentication status maintenance and management module; The user information collection and identification module is used to collect user information to determine their identity and realize accurate identification of users; the authentication request and verification module intercepts user access requests through the Internet behavior management device and sends the authentication information submitted by the user to the corresponding authentication server or local database for verification according to the preset authentication strategy; the authentication status maintenance and management module is used to monitor the user's network activities in real time and update the authentication status when the user logs out or the session ends; The application control platform includes an application identification module, a policy formulation and issuance module, and a traffic control and behavior management module; the application identification module is used to deeply identify and classify various application programs and network traffic in the network, and classify them according to their characteristics and behavior patterns; the policy formulation and issuance module is used for enterprise managers to formulate corresponding access control policies for different application categories, users or user groups according to their own management needs and security policies, and issue the formulated policies to the Internet behavior management device; the traffic control and behavior management module controls application traffic according to the issued policies, and restricts specific behaviors of applications.
2. The online behavior management system according to claim 1, characterized in that: The identity authentication platform supports multiple authentication methods, including: local password authentication, external authentication server authentication, LDAP authentication, Radius authentication, POP3 authentication, SMS authentication and WeChat authentication.
3. The online behavior management system according to claim 1, characterized in that: The identity authentication platform provides a network converged authentication method for combining user Internet access authentication with terminal network access authentication to achieve wired and wireless unified authentication.
4. The online behavior management system according to claim 1, characterized in that: The identity authentication platform can be configured with a two-factor authentication method, including static password plus dynamic password authentication and fingerprint recognition plus password authentication.
5. The online behavior management system according to claim 1, characterized in that: The identity authentication platform supports authentication policy configuration and can flexibly configure authentication policies according to different users, user groups, time periods and access location factors.
6. The online behavior management system according to claim 1, characterized in that: The application control platform includes a comprehensive and continuously updated identification library for quickly and accurately identifying and managing emerging applications and network threats.
7. The online behavior management system according to claim 1, characterized in that: The application control platform formulates and issues refined management strategies, controls the entire application program, goes deep into the specific functions and operations of the application, and sets different access rights for each.
8. The online behavior management system according to claim 1, characterized in that: The application control platform formulates and issues differentiated control strategies based on users and user groups to accurately manage the Internet behavior of employees in different departments and positions.
9. The online behavior management system according to claim 1, characterized in that: The application control platform formulates and issues bandwidth management and traffic optimization strategies, reasonably allocates and manages network bandwidth, limits bandwidth usage of non-critical applications, and guarantees bandwidth requirements for critical services.
10. The online behavior management system according to claim 1, characterized in that: The application control platform formulates and issues encrypted traffic identification and control strategies, analyzes and controls the content and behavior of encrypted applications, and prevents sensitive enterprise information from being leaked through encrypted channels.
Citation Information
Patent Citations
Zero-trust network access control method and system based on time window dynamic switching
CN116545731A
Implementation method of secure and trusted physical network gateway
CN116760633A
Park dynamic network configuration system and network control method applying same
CN119109776A
Multi-factor dynamic identity verification and access control system
CN119272259A
Integration security system and method of PC usingsecure policy network
KR1020050026624A