Method for maintaining gatekeeper safety data transmission based on intrusion detection system and firewall
By establishing an information sharing and policy linkage mechanism between firewalls, network gates and IDS, the problems of single network security defense methods, lagging responses, and inflexible policy adjustments in the existing technology have been solved, and the formation of a multi-level security defense system and the improvement of network security have been achieved.
Patent Information
- Application Number
- CN202510485975.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-17
- Publication Date
- 2025-05-16
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
In the prior art, network security defense methods are single, response is lagging, and policy adjustments are inflexible, making it difficult to effectively resist complex cyber threats.
By establishing an information sharing and policy linkage mechanism between firewalls, gateways and IDS, rapid detection, accurate response and dynamic adjustment can be achieved, and a multi-level security defense system is formed.
It has achieved in-depth cooperation between firewalls and gateways, intelligent response to gateways, real-time linkage between IDS and gateways, and dynamic adjustment of security policies, which has improved overall security and effectively curbed network attack behavior.
Smart Images

Figure CN120017422A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network security, and mainly to a method for maintaining secure data transmission of a network gate based on an intrusion detection system and a firewall. Background Art
[0002] As network attacks become increasingly complex, traditional single protection methods (such as firewalls, gateways or IDS) can no longer effectively resist various network threats. Although firewalls can filter data traffic based on rules and policies, they lack in-depth protocol detection capabilities; gateways have advantages in protocol adaptation and policy execution, but their response speed and real-time performance are insufficient; IDS has powerful intrusion detection capabilities, but it cannot directly adjust data transmission strategies. Therefore, how to achieve efficient collaboration among the three and form a multi-level security defense system has become a key issue in the current network security field. Summary of the invention
[0003] The present invention aims to solve the problems of single network security defense means, delayed response, and inflexible policy adjustment in the prior art, and provides a multi-layer collaborative security defense method and system based on firewalls, network gates, and IDS. By establishing an information sharing and policy linkage mechanism among the three, rapid detection, accurate response, and dynamic adjustment can be achieved, thereby maximizing the overall security of the system.
[0004] According to a first aspect of the present invention, a method for maintaining secure data transmission based on an intrusion detection system and a firewall is proposed, and the specific steps include: The firewall performs preliminary filtering on the data traffic entering the network gate and generates rules based on the security policy; the network gate executes protocol adaptation and security policy according to the rules provided by the firewall; the intrusion detection system IDS monitors network traffic in real time, analyzes data packet characteristics, and identifies potential attack patterns; When abnormal traffic or attack behavior is detected, the intrusion detection system IDS sends an alarm signal to the firewall and network gatekeeper; the firewall feeds back real-time information based on the alarm signal and dynamically adjusts the security policy; the network gatekeeper executes security measures such as suspending transmission, switching channels or re-authenticating according to the instructions of the firewall and intrusion detection system IDS.
[0005] Furthermore, the firewall performs preliminary filtering on the data traffic entering the network gate, specifically including: blacklist filtering, protocol filtering, port filtering, traffic direction control and packet length and frequency detection on the data traffic.
[0006] Furthermore, the preliminary filtering also includes deep data packet inspection, specifically including: protocol integrity check, content security check and feature matching detection.
[0007] Furthermore, the security policy-based rule generation specifically includes: Dynamic rule generation: Automatically generate temporary blocking or restriction rules based on detected abnormal behaviors and attack characteristics; Strategy matching and optimization: Generate optimized defense strategies based on historical traffic analysis and attack behavior patterns; adjust rules with frequent false positives or false negatives; Rule distribution and synchronization: The generated security policy rules are distributed to the network gate device to ensure that the rules are synchronized among multiple devices and maintain the consistency of security policies.
[0008] Furthermore, the specific steps of executing protocol adaptation and security policy include: The gatekeeper parses the rules and extracts policies provided by the firewall; Use deep packet inspection technology to parse the protocol header and payload in the data packet; Perform protocol adaptation for protocol differences in different security domains; Based on the rules and policies provided by the firewall, security detection and policy execution are performed on the data passing through the network gate, including packet filtering technology, state detection, application layer security inspection, and data desensitization and auditing.
[0009] Furthermore, the steps of analyzing the characteristics of the data packet include: The basic feature extraction of data packets includes: network layer features, transport layer features and application layer features; Statistical feature extraction includes: traffic statistics, behavior statistics and session statistics.
[0010] Timing feature extraction includes: inter-packet time interval, continuous duration and burst traffic detection.
[0011] Furthermore, the identification of potential attack patterns is specifically represented as an anomaly detection stage, including: rule-based detection, behavior-based detection, machine learning-based detection, and feature matching and association analysis.
[0012] Furthermore, the alarm signal specifically includes: attack type, threat level, attack time, attack source, destination address, traffic characteristics, impact range and recommended processing method.
[0013] According to a second aspect of the present invention, a computer program product is provided, on which one or more computer programs are stored. When the one or more computer programs are executed by a computer processor, the above method is implemented.
[0014] According to a third aspect of the present invention, a computer system is provided, comprising a processor and a memory, wherein the processor is configured to implement the above method during execution.
[0015] The above one or more technical solutions in the embodiments of the present application have at least one of the following technical effects: 1. Deep collaboration between firewalls and network gates: The firewall performs preliminary filtering on data traffic and synchronizes security policies to the network gate to ensure consistency in protocol adaptation and policy execution.
[0016] 2. Intelligent response capability of the network gate: The network gate automatically adjusts transmission strategies and channels based on feedback from the firewall and IDS to reduce potential threats.
[0017] 3. Real-time linkage between IDS and network gatekeeper: IDS analyzes network traffic characteristics in real time, identifies attack patterns, and sends warning signals to the network gatekeeper to guide it to take defensive measures.
[0018] 4. Dynamic adjustment mechanism of security policies: After threat detection, the firewall and the network gate work together to optimize the security policy and improve defense capabilities.
[0019] 5. Multi-layer security model: Firewalls, network gates and IDS work together to form a layered defense system to improve overall security. BRIEF DESCRIPTION OF THE DRAWINGS
[0020] The accompanying drawings are included to provide a further understanding of the embodiments and are incorporated into and constitute a part of this specification. The accompanying drawings illustrate the embodiments and are used together with the description to explain the principles of the present invention. It will be easy to recognize other embodiments and many expected advantages of the embodiments because they become better understood by reference to the following detailed description. The elements of the drawings are not necessarily to scale with each other. The same reference numerals refer to corresponding similar parts.
[0021] Figure 1 The present invention shows a flow chart of a method for secure data transmission based on an intrusion detection system and a firewall to maintain a network gate.
[0022] Figure 2 A schematic diagram of an internal and external network architecture for executing a network gate security policy according to an embodiment of the present invention is shown.
[0023] Figure 3 It is a structural diagram of a computer system suitable for implementing an electronic device of an embodiment of the present application. DETAILED DESCRIPTION
[0024] The present application will be further described in detail below in conjunction with the accompanying drawings and embodiments. It is to be understood that the specific embodiments described herein are only used to explain the relevant invention, rather than to limit the invention. It should also be noted that, for ease of description, only the parts related to the relevant invention are shown in the accompanying drawings.
[0025] It should be noted that, in the absence of conflict, the embodiments and features in the embodiments of the present application can be combined with each other. The present application will be described in detail below with reference to the accompanying drawings and in combination with the embodiments.
[0026] Figure 1 FIG. 1 is a flow chart showing a method for secure data transmission based on an intrusion detection system and a firewall to maintain a network gate according to an embodiment of the present invention. Figure 1 As shown: Step 1: The firewall performs preliminary filtering on the data traffic entering the network gate and generates rules based on the security policy; The data traffic can come from the Internet, internal network or specific devices; the firewall captures the data flow entering the network gate in real time through the network port, mirror port or bypass device. Then the data packet is decapsulated to identify the basic information such as protocol type (such as TCP, UDP, ICMP), port, source IP and destination IP.
[0027] The preliminary filtering specifically includes: blacklist filtering, protocol filtering, port filtering, flow direction control and packet length and frequency detection on data traffic.
[0028] Among them, blacklist filtering includes IP address blacklist and whitelist and domain name blacklist and whitelist. The IP address blacklist checks whether the source IP and destination IP of the data packet are in the blacklist or whitelist; the domain name blacklist checks whether the domain name complies with the security policy for traffic based on DNS resolution.
[0029] Protocol filtering is to confirm whether the used protocols (HTTP, HTTPS, FTP and SSH) are within the permitted range, and to block or issue alarms for non-standard or insecure protocols.
[0030] Port filtering discards data packets from illegal ports (non-business ports, default closed ports) and further monitors data from high-risk ports (remote control ports such as 3389 and 445).
[0031] Traffic direction control confirms the data flow direction (unidirectional flow, bidirectional flow) according to the security policy, and directly discards the illegal direction traffic.
[0032] Packet length and frequency detection marks abnormal packet lengths (oversized packets, undersized packets) as abnormal traffic, and high-frequency requests in a short period of time trigger anti-attack strategies.
[0033] Preliminary filtering also requires deep packet inspection (DPI), including protocol integrity check: check whether the protocol complies with the specifications and whether there is any malicious tampering; content security check: filter sensitive information (SQL injection, XSS attack, etc.) of plain text protocols such as HTTP and FTP, and scan compressed packages, documents and other contents in file transfers for viruses and Trojans; feature matching detection: use the feature library to identify whether it contains known attack behaviors (DDoS, APT attacks, Trojan backlinks, etc.).
[0034] Furthermore, the security policy-based generation rules specifically include: Dynamic rule generation: Automatically generate temporary blocking or restriction rules based on detected abnormal behaviors and attack characteristics; Strategy matching and optimization: Generate optimized defense strategies based on historical traffic analysis and attack behavior patterns; adjust rules with frequent false positives or false negatives; Rule distribution and synchronization: The generated security policy rules are distributed to the network gate device to ensure that the rules are synchronized among multiple devices and maintain the consistency of security policies.
[0035] In a specific embodiment, assuming that the firewall finds that a request frequently accesses a certain external IP and generates a large number of HTTP requests in a short period of time, the firewall dynamically generates a rate limit rule to limit the request frequency of the target IP (for example: 93.184.216.34) to 100 times per minute; further analyze the historical access data, automatically add the frequently accessed and safe IP to the whitelist, and synchronize the newly generated rate limit rule to the network gate to ensure unified policy execution.
[0036] Step 2: The network gate executes protocol adaptation and security policies according to the rules provided by the firewall; this step is based on Figure 2 As shown, a schematic diagram of the internal and external network architecture of the network gate security policy execution of an embodiment of the present invention is shown, and the specific contents are as follows: Firewall rules usually perform traffic control based on the "five-tuple" (source IP, destination IP, source port, destination port, protocol), and the network gate needs to extract adaptation and security policies from it.
[0037] The gatekeeper first parses the rules and extracts policies provided by the firewall; Among them, the rule types include: Access control rules (ACL): determine which addresses and ports can access which targets; Protocol control rules: limit the types of protocols allowed to pass (HTTP, HTTPS, FTP, SMTP, proprietary protocols, etc.); Port mapping rules: conversion and mapping for specific protocols and ports; Session control rules: check the connection status of the data packet (whether it is new, established, or terminated).
[0038] Policy extraction includes: security level definition: distinguish between high-security domains and low-security domains, corresponding to different policies; data direction: clarify data flow (such as from the external network to the internal network, from the internal network to the external network); security control strategy: including message filtering, protocol inspection, content auditing, encryption and decryption strategies, etc.
[0039] Furthermore, deep packet inspection technology is used to parse the protocol header and payload in the data packet to confirm the protocol type and its compliance, including TCP / IP protocol stack analysis and application layer protocol analysis.
[0040] Protocol adaptation is performed for protocol differences in different security domains, for example: HTTP to HTTPS: HTTP is used within the security domain, and it is automatically encrypted to HTTPS when accessed from the external network; file protocol conversion: files are accessed via the SMB protocol in the internal network and SFTP is used in the external network; data format conversion: data adaptation between formats such as JSON, XML, and Protobuf.
[0041] Port mapping and address translation (NAT): The gateway may map private network addresses in the security domain to ensure the security and accessibility of data in the public network.
[0042] Next, the gateway performs security checks and policy enforcement on the data passing through the gateway based on the rules and policies provided by the firewall, including packet filtering technology, state detection, application layer security checks, and data desensitization and auditing.
[0043] Packet filtering technologies include: Based on IP and port: intercepting data packets that are not in the whitelist or blacklist; Based on protocol type: confirming whether the protocol is in the allowed list.
[0044] Stateful inspection: Tracks session status to ensure that data packets belong to established legitimate sessions and prevent forged session attacks.
[0045] Application layer security check: Content filtering: Check the data content in protocols such as HTTP and SMTP to prevent sensitive data leakage; Virus and malicious code detection: Use antivirus engines to scan data streams in real time; File security check: Verify the format and security of files in file transfer protocols (such as FTP and SFTP).
[0046] Data desensitization and auditing: Desensitize sensitive information in transmitted data, such as identity information, account number, password, etc. Log data interaction behaviors to facilitate security auditing and tracing.
[0047] Step 3: The intrusion detection system (IDS) monitors network traffic in real time, analyzes data packet characteristics, and identifies potential attack patterns; The specific steps of analyzing the characteristics of the data packet include: The basic feature extraction of data packets includes: network layer features (IP header), transport layer features (TCP / UDP header) and application layer features (HTTP, DNS, etc.); Statistical feature extraction includes: traffic statistics, behavior statistics and session statistics. Traffic statistics: number of packets, bytes and sessions per unit time; behavior statistics: number of connections initiated by a single IP, request frequency and port scanning frequency; session statistics: session duration, packet direction ratio and traffic direction consistency.
[0048] Time series feature extraction includes: inter-packet time interval, continuous duration and burst traffic detection. Inter-packet time interval: calculates the time interval between data packets in the same session. Connection duration: counts the time difference between the start and end of a session. Burst traffic detection: detects a large number of requests or responses in a short period of time.
[0049] Further, identifying potential attack patterns is also called the anomaly detection phase. Detection methods include: ① Rule-based detection (signature detection): Use predefined attack signature libraries, such as Snort and Suricata rule sets; Compare the features in the data packet (such as specific payload, malicious URL, port combination) with the known attack patterns in the rule base; Rule types include: protocol anomalies (such as illegal TCP flag combinations, IP fragmentation attacks); application layer attacks (SQL injection, XSS, buffer overflow); network layer attacks (SYN Flood, ICMP Flood, ARP spoofing).
[0050] ② Based on behavior detection (abnormal traffic detection): Establishing traffic baseline: learning normal traffic behavior patterns and establishing traffic models.
[0051] Abnormal traffic determination: When traffic deviates from the baseline, it is marked as abnormal, such as: a surge in the number of packets, bytes, and sessions. The frequency of single IP requests far exceeds the normal level. A large number of accesses to non-existent ports or addresses.
[0052] ③ Based on machine learning detection (intelligent detection): Classification model: Use supervised learning models (such as SVM, decision tree) to classify normal traffic and malicious traffic.
[0053] Clustering Model: Use unsupervised learning models (such as K-means) to discover unknown attack patterns.
[0054] Deep learning model: Analyze time series data based on LSTM, CNN and other models to identify complex attacks.
[0055] ④Feature matching and association analysis: Correlate and analyze data packet features with historical attack data.
[0056] Combine with SIEM (Security Information and Event Management System) to correlate logs across devices.
[0057] Use the MITRE ATT&CK framework to map detected behaviors to specific attack tactics and techniques.
[0058] In a specific embodiment, an abnormality detection-based support vector machine model (OC-SVM) can be used to detect abnormal features in network traffic; the model is an unsupervised learning method that can build a model based on "normal" data and identify data that deviates from normal behavior as abnormalities during runtime. The specific implementation process is as follows: Collect and detect abnormal patterns in network traffic. The packet feature set is:
[0059] Among them, X represents the data packet feature set, n represents the number of data packets, d represents the feature dimension of each data packet (such as source IP, destination IP, port, data packet size, protocol type, timestamp, etc.), represents the feature vector of the ith data packet, and R represents a set of real numbers.
[0060] The purpose of the model is to find a boundary that encloses most normal data packets within the boundary and identifies abnormal data packets as points outside the boundary. The specific function formula of the model is:
[0061] in, represents the Lagrange multiplier, the importance of the support vector, represents the kernel function, which calculates the similarity between two data points. x represents the test sample feature vector, that is, the new data to be tested (the feature vector of an unknown data packet in the network traffic). represents the training sample feature vector, that is, the i-th sample in the training set (the feature vector of a normal data packet in the network traffic), Represents the offset of the model, defines the location of the boundary, sign represents the sign function, determines the decision boundary, if the value in the brackets 0, output 1 (normal), if the value in the brackets 0, output -1 (abnormal), f(x) represents the output of the function, indicating whether the data point x is judged to be abnormal, f(x)=1 represents normal data, and f(x)=-1 represents abnormal data.
[0062] Since network data is often not linearly separable, the Gaussian kernel function K is introduced, and the specific formula is expressed as: = ,in, Represents a hyperparameter of the Gaussian kernel, controlling the width of the Gaussian distribution.
[0063] The model loss optimization formula is as follows:
[0064] in, represents the normal vector in the feature space, Represents the model offset, defining the location of the boundary, represents the slack variable, represents the i-th slack variable, allowing a certain number of data points to be misclassified, represents a hyperparameter that controls the sensitivity of anomaly detection (a smaller v means that normal data is more strictly surrounded). The above optimization loss satisfies the following constraints:
[0065] Step 4: When abnormal traffic or attack behavior is detected, the intrusion detection system (IDS) sends an alarm signal to the firewall and network gatekeeper; The alarm signal specifically includes: attack type, threat level, attack time, attack source, destination address, traffic characteristics, impact range and recommended processing method.
[0066] Alert formats include standardized formats such as JSON, XML, Syslog, SNMP, etc.
[0067] Step 5: The firewall feeds back real-time information according to the alarm signal and dynamically adjusts the security policy; The firewall extracts key fields based on the alert content, such as attack source IP, target IP, attack type, port, threat level, etc.
[0068] Dynamically adjusted security policies include: access control policy: blocking attack source IP, restricting specific protocols, closing attack ports, etc.; traffic control policy: speed limit, packet loss, delay processing, etc.; behavior audit policy: strengthening behavior monitoring and auditing of related IPs, accounts, and devices.
[0069] Further policy deployment and execution: Send policies to firewall devices in real time through API, CLI, and management console; accurately adjust the policy scope according to the attack target (such as only taking effect on a certain subnet, a certain port, or a certain protocol); ensure that key protection policies take effect first based on the threat level and urgency.
[0070] Step 6: The network gate executes security measures such as suspending transmission, switching channels or re-authenticating according to the instructions of the firewall and intrusion detection system IDS.
[0071] The gateway verifies and confirms the execution action, target system, execution conditions, timeout period and other information in the instruction.
[0072] Pause transmission: interrupt the current cross-network data flow to prevent data leakage or attack spread.
[0073] Switch channel: Switch the data flow to an alternative secure channel or a dedicated encrypted channel to reduce the attack surface.
[0074] Reauthentication: Initiate mandatory identity authentication for the current connection or operation (such as multi-factor authentication, digital certificate verification, etc.).
[0075] If the execution is successful: the execution result and effective time will be fed back to the firewall, IDS and security management platform. If the execution fails: the failure reason (such as policy conflict, equipment failure, network anomaly, etc.) will be recorded and a fault alarm will be generated.
[0076] In summary, the present invention discloses a multi-layer collaborative security defense method and system based on a firewall, a network gate and an intrusion detection system (IDS). By establishing a deep collaboration mechanism between the firewall and the network gate, the intelligent response capability of the network gate, the real-time linkage between the IDS and the network gate, and the dynamic adjustment mechanism of the security strategy, rapid detection, accurate response and dynamic optimization are achieved. The three work together to form a multi-layer security model, improve overall security, effectively curb network attacks, and prevent data leakage and tampering.
[0077] Reference below Figure 3 , which shows a schematic diagram of the structure of a computer system 300 suitable for implementing an electronic device of an embodiment of the present application. Figure 3 The electronic device shown is merely an example and should not bring any limitation to the functions and scope of use of the embodiments of the present application.
[0078] like Figure 3 As shown, the computer system 300 includes a central processing unit (CPU) 301, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 302 or a program loaded from a storage part 308 into a random access memory (RAM) 303. In the RAM 303, various programs and data required for the operation of the system 300 are also stored. The CPU 301, the ROM 302, and the RAM 303 are connected to each other through a bus 304. An input / output (I / O) interface 305 is also connected to the bus 304.
[0079] The following components are connected to the I / O interface 305: an input section 306 including a keyboard, a mouse, etc.; an output section 307 including a liquid crystal display (LCD), etc. and a speaker, etc.; a storage section 308 including a hard disk, etc.; and a communication section 309 including a network interface card such as a LAN card, a modem, etc. The communication section 309 performs communication processing via a network such as the Internet. A drive 310 is also connected to the I / O interface 305 as needed. A removable medium 311, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 310 as needed, so that a computer program read therefrom is installed into the storage section 308 as needed.
[0080] In particular, according to an embodiment of the present disclosure, the process described above with reference to the flowchart can be implemented as a computer software program. For example, an embodiment of the present disclosure includes a computer program product, which includes a computer program carried on a computer-readable storage medium, and the computer program includes a program code for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from the network through the communication part 309, and / or installed from the removable medium 311. When the computer program is executed by the central processing unit (CPU) 301, the above functions defined in the method of the present application are executed. It should be noted that the computer-readable storage medium of the present application can be a computer-readable signal medium or a computer-readable storage medium or any combination of the above two. The computer-readable storage medium can be, for example, - but not limited to - an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or device, or any combination of the above. More specific examples of computer-readable storage media may include, but are not limited to, an electrical connection with one or more conductors, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present application, a computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, device, or device. In the present application, a computer-readable signal medium may include a data signal propagated in a baseband or as part of a carrier wave, in which a computer-readable program code is carried. Such propagated data signals may take a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. A computer-readable signal medium may also be any computer-readable storage medium other than a computer-readable storage medium, which may send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, device, or device. The program code contained on the computer-readable storage medium may be transmitted using any appropriate medium, including but not limited to: wireless, wireline, optical cable, RF, etc., or any suitable combination of the foregoing.
[0081] Computer program code for performing the operations of the present application may be written in one or more programming languages or a combination thereof, including object-oriented programming languages, such as Java, Smalltalk, C++, Matlab, Labview, and conventional procedural programming languages, such as "C" or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, as a separate software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., via the Internet using an Internet service provider).
[0082] The flow chart and block diagram in the accompanying drawings illustrate the possible architecture, function and operation of the system, method and computer program product according to various embodiments of the present application. In this regard, each square box in the flow chart or block diagram can represent a module, a program segment or a part of a code, and the module, the program segment or a part of the code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the square box can also occur in a sequence different from that marked in the accompanying drawings. For example, two square boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each square box in the block diagram and / or flow chart, and the combination of the square boxes in the block diagram and / or flow chart can be implemented with a dedicated hardware-based system that performs a specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.
[0083] The modules involved in the embodiments of the present application may be implemented by software or by hardware.
[0084] As another aspect, the present application also provides a computer-readable storage medium, which may be included in the electronic device described in the above embodiment; or it may exist independently without being assembled into the electronic device. The above computer-readable storage medium carries one or more programs, and when the above one or more programs are executed by the electronic device, the electronic device: the firewall performs preliminary filtering on the data traffic entering the network gate, and generates rules based on the security policy; the network gate executes protocol adaptation and security policy according to the rules provided by the firewall; the intrusion detection system IDS monitors the network traffic in real time, analyzes the characteristics of the data packets, and identifies the potential attack mode; when abnormal traffic or attack behavior is detected, the intrusion detection system IDS sends an alarm signal to the firewall and the network gate; the firewall feeds back real-time information according to the alarm signal and dynamically adjusts the security policy; the network gate executes security measures such as suspending transmission, switching channels or re-authenticating according to the instructions of the firewall and the intrusion detection system IDS.
[0085] The above description is only a preferred embodiment of the present application and an explanation of the technical principles used. Those skilled in the art should understand that the scope of the invention involved in the present application is not limited to the technical solution formed by a specific combination of the above technical features, but should also cover other technical solutions formed by any combination of the above technical features or their equivalent features without departing from the above invention concept. For example, the above features are replaced with the technical features with similar functions disclosed in this application (but not limited to) by each other.
Claims
1. A method for maintaining secure data transmission based on an intrusion detection system and a firewall, characterized in that: The following steps are involved: The firewall performs preliminary filtering on the data traffic entering the network gate and generates rules based on the security policy; the network gate executes protocol adaptation and security policy according to the rules provided by the firewall; Intrusion Detection System (IDS) monitors network traffic in real time, analyzes data packet characteristics, and identifies potential attack patterns; When abnormal traffic or attack behavior is detected, the intrusion detection system IDS sends an alarm signal to the firewall and network gate; the firewall feeds back real-time information based on the alarm signal and dynamically adjusts the security policy; The network gatekeeper executes security measures such as suspending transmission, switching channels or re-authenticating according to the instructions of the firewall and intrusion detection system IDS.
2. The method according to claim 1, characterized in that The firewall performs preliminary filtering on the data traffic entering the network gate, specifically including: blacklist filtering, protocol filtering, port filtering, traffic direction control and packet length and frequency detection on the data traffic.
3. The method according to claim 2, characterized in that The preliminary filtering also includes deep data packet inspection, specifically including: protocol integrity check, content security check and feature matching detection.
4. The method according to claim 1, characterized in that The security policy-based rule generation specifically includes: Dynamic rule generation: Automatically generate temporary blocking or restriction rules based on detected abnormal behaviors and attack characteristics; Strategy matching and optimization: Generate optimized defense strategies based on historical traffic analysis and attack behavior patterns; adjust rules with frequent false positives or false negatives; Rule distribution and synchronization: The generated security policy rules are distributed to the network gate device to ensure that the rules are synchronized among multiple devices and maintain the consistency of security policies.
5. The method according to claim 1, characterized in that The specific steps of executing protocol adaptation and security strategy include: The gatekeeper parses the rules and extracts policies provided by the firewall; Use deep packet inspection technology to parse the protocol header and payload in the data packet; Perform protocol adaptation for protocol differences in different security domains; Based on the rules and policies provided by the firewall, security detection and policy execution are performed on the data passing through the network gate, including packet filtering technology, state detection, application layer security inspection, and data desensitization and auditing.
6. The method according to claim 1, characterized in that The specific steps of analyzing the characteristics of the data packet include: The basic feature extraction of data packets includes: network layer features, transport layer features and application layer features; Statistical feature extraction includes: traffic statistics, behavior statistics and session statistics; Timing feature extraction includes: inter-packet time interval, continuous duration and burst traffic detection.
7. The method according to claim 1, characterized in that The identification of potential attack patterns is specifically represented as an anomaly detection stage, including: rule-based detection, behavior-based detection, machine learning-based detection, and feature matching and association analysis.
8. The method according to claim 1, characterized in that: The alarm signal specifically includes: attack type, threat level, attack time, attack source, destination address, traffic characteristics, impact range and recommended processing method.
9. A computer program product, characterized in that A computer program is stored thereon, and when the computer program is executed by a processor, the method according to any one of claims 1 to 8 is implemented.
10. A computing system, characterized in that: The method comprises a processor and a memory, wherein the processor is configured to execute the method according to any one of claims 1 to 8.
Citation Information
Patent Citations
Intrusion detection method and intrusion detection system for industrial control system based on communication model
CN105204487A
Firewall based on intrusion detection system feedback in cloud environment and implementation method thereof
CN110572412A
Network attack detection and defense method and system based on honeypot
CN117424751A
Hardware firewall, data filtering method and product
CN119030804A
Cited By
Data transmission system and method based on security identification and control
CN120342755A
Equipment information identification method based on deep packet inspection
CN121567447A