Network attack protection method for secure computer platform

By deploying a transparent transmission mode firewall on the rail transit security computer platform, combining DDoS attack protection methods, dynamically configure attack protection rules and record logs, the platform's security and real-time problems in the face of network attacks are solved, and more efficient troubleshooting and security guarantees are achieved.

CN120034357APending Publication Date: 2025-05-23卡斯柯信号(成都)有限公司
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510040444.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-10
Publication Date
2025-05-23

AI Technical Summary

Technical Problem

When facing a network attack, existing firewall devices cannot effectively protect the internal LAN, resulting in threats to the real-time and security of data communication and difficulty in troubleshooting.

Method used

A network attack protection system for secure computer platforms is designed, a firewall deployed in transparent transmission mode, combined with DDoS attack protection methods, dynamically configure attack protection rules, and record and query network attack protection logs.

Benefits of technology

It effectively enhances the network security of the rail transit safety computer platform, ensures the real-time nature of data communication, simplifies the investigation and resolution of network problems, and reduces costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120034357A_ABST
    Figure CN120034357A_ABST
Patent Text Reader

Abstract

The invention discloses a network attack protection method for a secure computer platform, and relates to the technical field of rail transit secure computer platforms, comprising: setting a firewall to provide network attack protection for a secure computer platform cluster in the same local area network, the firewall being deployed based on a transparent transmission mode, performing network attack protection on the secure computer platform by using a DDoS attack protection method, and recording and querying a network attack protection log; wherein the rest of the DDoS attack protection methods except the LAND attack can dynamically configure attack protection rules through a strategy database, and the LAND attack protection method in the DDoS attack protection methods can automatically and dynamically create and delete the LAND attack protection rules. The introduction of the invention can protect the secure computer platform from DDoS attacks from the internal network. The cost is saved while the data communication security of the security calculator platform is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of rail transit safety computer platforms, and more specifically to a network attack protection method for a safety computer platform. Background Art

[0002] The security computer platform used in the rail transit industry has high requirements for data communication security. Although the security computer platform equipment will not be directly connected to the external network, it does not exclude the need for other network nodes in its network topology to connect to the external network, which in turn makes the security computer platform vulnerable to network attacks. On the other hand, network attacks from internal network nodes also pose a threat to the security computer platform.

[0003] At the same time, the security computer platform has high requirements for data real-time performance. The general network firewall devices available on the market have complex functions and usually adopt corresponding attack protection strategies after complex analysis and judgment of the data. Too many intermediate links greatly reduce the timeliness of the data.

[0004] Furthermore, most of the security computer platforms used in the rail transit industry use embedded real-time operating systems. Due to their relatively limited resources, they are often faced with failures caused by network attacks, which are relatively difficult to troubleshoot. If the front-end firewall device has log records related to network attacks, it can help troubleshoot the failure.

[0005] With the continuous development of network technology, network attacks have become more covert. For rail transit safety computer platforms with high security levels, only deploying firewalls at the outermost gateway can no longer absolutely protect the safety computer platforms in the local area network from network attacks. At present, there is still a lack of network attack protection systems and equipment for the internal local area network of safety computer platforms in the rail transit industry.

[0006] Chinese patent publication number CN118921232A discloses a ship network firewall, which mainly describes a firewall body deployed in the network exit area and the internal network boundary area. It includes a device management module, a configuration module, a monitoring and alarm module, a virus detection module, an attack detection module, an audit function module, and a data encryption algorithm module. The firewall is mainly deployed in the network boundary area and used in ship systems.

[0007] The network firewall disclosed in the above patent is not applicable to the internal LAN area of ​​the rail transit safety computer platform. Summary of the invention

[0008] In order to overcome the defects in the above-mentioned prior art, the present invention discloses a network attack protection method for a secure computer platform. There are many types of network attacks, among which DDoS (distributed denial of service attack) attack is the most representative. The present invention provides a network attack protection system and device (also referred to as a firewall) for a secure computer platform for DDoS attack protection. It aims to ensure the real-time data communication of the secure computer platform while enhancing its security and the convenience of troubleshooting network problems.

[0009] In order to achieve the above objectives, the technical solution adopted by the present invention is: A network attack protection method for a secure computer platform, comprising: setting a firewall to provide network attack protection for a secure computer platform cluster in the same local area network, wherein the firewall is deployed based on a transparent transmission mode, using a DDoS attack protection method to protect the secure computer platform from network attacks, and recording and querying a network attack protection log; Among them, the attack protection methods other than the LAND attack in the DDoS attack protection method can dynamically configure attack protection rules through a policy database, and the LAND attack protection method in the DDoS attack protection method can dynamically create and delete LAND attack protection rules by itself.

[0010] Preferably, the firewall is deployed on a layer above the upper switch of the security computer platform, or the firewall replaces the terminal Ethernet switch to complete the data exchange task. The firewall provides network attack protection for the security computer platform cluster 1 and cluster 2 in the same local area network, and the underlying operating system of the firewall is the openwrt system.

[0011] 1. Attack protection rules other than LAND attack protection in DDoS attack protection Preferably, the attack protection methods other than the LAND attack in the DDoS attack protection method can dynamically configure attack protection rules through a policy database, including the following steps: S101. Build a public network attack strategy database in the local area network; S102, the firewall accesses the established network attack strategy database to obtain a common DDoS attack protection iptables rule set; Preferably, in step S102, a general DDoS attack protection rule set that is independent of the network environment IP address is obtained, including: ICMP flood attack protection rules, UDP flood attack protection rules, SYN flood attack protection rules, tear attack protection rules, and ping of death protection rules.

[0012] S103, loading the obtained iptables rule set into the iptables table and chain of the openwrt operating system; S104. Restart the iptables service and the newly added rules will take effect; S105. When it is detected that the relevant policy rules of the public network attack policy database are updated, the old rules are deleted, and steps S102 to S104 are re-executed to load and make the new rules effective.

[0013] 2. LAND attack protection rules in DDoS attack protection Preferably, the LAND attack protection method creates a LAND attack protection rule for each IP node to be protected in the forwarding chain of the iptables table, and dynamically creates and deletes the LAND attack protection rules, including the following steps: S201. When the firewall is started, an empty file arplist_last.user is created in the tmp folder to store active IP addresses in the arp table. S202, obtaining active IP addresses from the arp list and creating an IP address list; S203, compare the IP addresses in the IP address list with the IP addresses in the arplist_last.user file. If: a certain IP address exists in the current arp active IP list and the IP address also exists in arplist_last.user, proceed to step S204; if a certain IP address exists in the current arp active IP list and the IP address does not exist in arplist_last.user, proceed to step S205; if a certain IP address does not exist in the current arp active IP list and the IP address exists in arplist_last.user, proceed to step S206; S204, continue to traverse the next IP address, and execute step S204, S205 or S206 according to the judgment condition described in step S203, until the last IP address is processed and then proceed to step S207; S205, add the IP address that exists in the current arp active IP list but does not exist in arplist_last.user to the arplist_last.user file, and create a command for a LAND protection rule for the IP address, execute the command, add the LAND protection rule of the IP address to the delegate_forward chain of iptables, and then proceed to step S204; S206, delete the IP address that does not exist in the current arp active IP list but exists in arplist_last.user from the arplist_last.user file, and delete the LAND protection rule corresponding to the IP in the delegate_forward chain of iptables. After completion, proceed to step S204; S207. After executing the traversal and judgment processing of all IP addresses once, the above steps S202 to S206 are executed again after waiting for n seconds, and the LAND attack protection rules are dynamically added and deleted in a cyclic manner.

[0014] 3. Log record query Preferably, in the recording and querying of the network attack protection log, a method for generating a corresponding LOG log is added for each attack protection rule.

[0015] Preferably, in the DDoS attack protection rule, the method for generating a corresponding LOG log for the ping of death protection rule includes: Create a new chain named ping_of_death to handle ICMP traffic; Add a rule to the FORWARD chain to match packets of the ICMP protocol and jump the matching packets to the created ping_of_death chain for further processing; Add a rule to the ping_of_death chain to match ICMP type 8 packets; use the -mlength module to check the length of the ICMP packet. If the length is less than or equal to 65499 bytes, perform a RETURN action to allow the packet to pass; Add another rule to the ping_of_death chain to match ICMP type 8 packets and use the -m length module to check the length of the ICMP packet. If the length is greater than or equal to 65500 bytes, execute the LOG action, log it, and add a prefix.

[0016] Preferably, the log query includes: S301, adding a method for generating a corresponding LOG log for each attack protection rule; S302, when a network attack occurs, the generated log is recorded in a log specifically used to record network attacks, and the log is transferred to a log management server by date; S303. Add a network attack log filtering and exporting interface in the openwrt interface, filter out the logs according to the filtering conditions and present them on the interface, and export the filtered logs as files with a .txt suffix.

[0017] Preferably, in step S303, the filter items provided include: start time, end time, attack type, source IP address, source Port, destination IP address, destination Port, and the filter items can be arbitrarily combined for filtering.

[0018] 4. Transparent transmission mode deployment Preferably, the firewall is deployed based on a transparent transmission mode, including: When compiling the openwrt kernel, compile the ebtables and br_netfilter modules into the kernel together; Set the transparent transmission mode switch on the openwrt interface. When the switch is turned on, enable the bridge-nf-call-iptables parameter of the br_netfilter module to support Layer 2 forwarding to call Layer 3 iptables table rules; When set to transparent transmission mode, the firewall is deployed at any location in the intranet to protect the devices connected to the firewall from network attacks.

[0019] Beneficial effects of the present invention: 1. The rail transit safety computer platform has high requirements for data communication security. The current common practice is to block the safety computer platform network from the external network through a gateway firewall to avoid network attacks from the external network. However, if the network attack comes from within the local area network, because there is no corresponding bridge firewall inside the local area network to prevent such network attacks, it will pose a relatively serious threat to the security equipment. The DDoS attack protection firewall solution with log record query that can be deployed in transparent transmission mode provided by the present invention is tailor-made for this scenario in the rail transit industry. Transparent transmission mode deployment is insensitive to network topology and is very suitable for deployment within a local area network. The introduction of this invention can protect the safety computer platform from DDoS attacks from the internal network. While improving the data communication security of the safety computer platform, it saves costs.

[0020] 2. The LAND attack protection solution proposed in the present invention has not been proposed in the existing technology. The present invention utilizes the characteristic that the arp list will be updated following the network topology structure, periodically extracts the active IP addresses in the current arp list, and compares them with the active IP addresses recorded last time, so as to realize the dynamic addition and deletion of LAND attack protection rules. The solution has good adaptability and can respond quickly following the arp list. At the same time, in attack protection solutions other than LAND attacks, the policy rules are obtained from the network attack policy database built in the local area network, and its modular design enhances the flexibility of firewall policy configuration.

[0021] 3. The existing firewall log system contains a lot of content, such as system logs, attack logs, audit logs, application logs, etc., and some logs are not further classified and recorded separately. When encountering problems, it is time-consuming and laborious to query the logs. The log generation and query scheme proposed in the present invention generates logs with specific attack prefixes for DDoS attacks in a targeted manner, and stores the DDoS logs separately. At the same time, a query and export method with detailed and meticulous filter items is provided, which enhances the convenience of querying and exporting attack logs. BRIEF DESCRIPTION OF THE DRAWINGS

[0022] Figure 1 This is the first deployment mode of the present invention; Figure 2 This is the second deployment mode of the present invention; Figure 3 A flow chart is generated for the LAND attack protection rule of the present invention. DETAILED DESCRIPTION

[0023] The concept, specific structure and technical effects of the present invention will be clearly and completely described below in combination with the embodiments and drawings to fully understand the purpose, characteristics and effects of the present invention.

[0024] There are many types of network attacks, among which DDoS (distributed denial of service) attacks are the most representative. The present invention provides a network attack protection system and device (also referred to as a firewall) for a secure computer platform for DDoS attack protection. It aims to ensure the real-time data communication of the secure computer platform while enhancing its security and the convenience of troubleshooting network problems.

[0025] The objectives of the present invention can be achieved through the following solutions: 1. Providing a DDoS attack protection system with dynamically configurable rules; 2. Providing a complete log record query system; 3. Providing a transparent transmission mode deployment solution.

[0026] The network attack protection system and device for a secure computer platform proposed by the present invention can be deployed on the upper layer of the upper switch of the secure computer platform. Figure 1 Under this deployment mode, the firewall proposed by the present invention can provide network attack protection for the secure computer platform cluster 1 and cluster 2 in the same local area network. The underlying operating system of the system is the openwrt system (a highly modularized and highly automated embedded Linux system).

[0027] At the same time, the firewall device can replace the terminal Ethernet switch to complete the data exchange task, such as the attached Figure 2 Deployment method in .

[0028] The technical solution of the present invention is described in detail according to the above three parts: 1. The present invention provides a set of DDoS attack protection system solutions with dynamically configurable rules. The working principle of the DDoS attack protection solution other than LAND attack is as follows: Step 1: Build a public network attack strategy database in the local area network.

[0029] Step 2: The firewall system accesses the general network attack strategy database built in step 1 to obtain the general DDoS attack protection iptables rule set. The general DDoS attack protection rule set obtained that is not related to the network environment IP address includes: ICMP Flood (ICMP flood attack) protection rule, UDP Flood (UDP flood attack) protection rule, SYN Flood (SYN flood attack) protection rule, TearDrop (tear attack) protection rule, Ping of Death (death ping) protection rule.

[0030] Step 3: Load the obtained iptables rules into the iptables table and chain of the openwrt operating system.

[0031] Step 4: Restart the iptables service to make the newly added rules take effect.

[0032] Step 5: When it is detected that the relevant policy rules of the public network attack policy database are updated, delete the old rules, re-execute steps 2 to 4 to load and make the new rules effective.

[0033] LAND attack: By sending SYN packets with the same source IP address and target IP address, the target host is forced to create a large number of empty connections, which eventually leads to resource exhaustion of the target host. For LAND attacks, it is necessary to create a LAND protection rule for each IP node that needs to be protected in the forwarding chain of the iptables table. The present invention proposes a method for fully automated dynamic creation and deletion of LAND attack protection rules, as shown in the attached figure. Figure 3 , the steps are as follows: Step 1: When the firewall device starts, first create an empty file arplist_last.user in the tmp folder to store the active IP addresses in the arp table. Go to step 2.

[0034] Step 2: Get active IP addresses from the arp list and create a list. Go to step 3.

[0035] Step 3: Compare the IP addresses in the IP address list obtained in step 2 with the IP addresses in the arplist_last.user file. If: an IP address exists in the current arp active IP list and also exists in arplist_last.user, go to step 4; if an IP address exists in the current arp active IP list and does not exist in arplist_last.user, go to step 5; if an IP address does not exist in the current arp active IP list and exists in arplist_last.user, go to step 6.

[0036] Step 4: Continue to traverse the next IP address. Execute step 4, step 5 or step 6 according to the judgment condition described in step 3. After the last IP address is processed, proceed to step 7.

[0037] Step 5: Add the IP address that exists in the current arp active IP list but does not exist in arplist_last.user to the arplist_last.user file. At the same time, create a LAND protection rule command for the IP address: iptables -I delegate_forward 1 -p tcp --tcp-flags SYN,ACK SYN -d "IP" -s "IP"-j DROP. Execute this command to add the LAND protection rule of the IP address to the delegate_forward chain of iptables. After completion, go to step 4.

[0038] Step 6: Delete the IP address that does not exist in the current arp active IP list but exists in arplist_last.user from the arplist_last.user file. At the same time, delete the LAND protection rule corresponding to the IP in the delegate_forward chain of iptables. The corresponding execution command is: iptables -D delegate_forward -p tcp --tcp-flags SYN,ACK SYN -d "IP" -s "IP" -j DROP. After completion, go to step 4.

[0039] Step 7: After executing the traversal judgment process of all IP addresses once, wait for n seconds (n is configurable) and execute the above steps 2 to 6 again. Dynamically add and delete LAND attack protection rules in a loop.

[0040] 2. The present invention provides a complete log record query system solution, which is described in detail as follows: Step 1: Add a rule to generate corresponding LOG logs for each of the above DDoS attack protection policy rules. Take the Ping of Death protection rule as an example: iptables -t filter -N ping_of_death\n iptables -A FORWARD -p icmp -j ping_of_death\n iptables -A ping_of_death -p icmp --icmp-type 8 -m length --length :65499 -j RETURN\n iptables -A ping_of_death -p icmp --icmp-type 8 -m length --length65500: -j LOG --log-prefix \"ddos_ping_of_death\"--log-level 4 Statement explanation: Create a new chain named ping_of_death, which is dedicated to handling ICMP traffic. Add a rule to the FORWARD chain to match packets with the ICMP protocol (-picmp), and jump the matching packets to the created ping_of_death chain for further processing. Add a rule to the ping_of_death chain to match packets with ICMP type 8 (i.e. ICMP Echo request, also known as ping request). Use the -m length module to check the length of the ICMP packet. If the length is less than or equal to 65499 bytes, perform the RETURN action, which means that the packet is allowed to pass. Add another rule to the ping_of_death chain that matches ICMP type 8 packets and uses the -m length module to check the length of the ICMP packet. If the length is greater than or equal to 65500 bytes, perform the LOG action, log it, and use --log-prefix "ddos_ping_of_death" to add a prefix, and --log-level 4 to set the log level to warning (DEBUG level).

[0041] The last of the above four statements is a rule added to generate corresponding LOG logs for Ping of Death protection rules.

[0042] Step 2: When a DDoS attack occurs, the generated logs are recorded in a log specifically for recording DDoS attacks, and the logs are transferred to the log management server by date.

[0043] Step 3: Add a DDoS log filtering and exporting interface in the openwrt interface. You can filter the logs according to the filtering conditions and display them on the interface. You can also export the filtered logs as files with a .txt suffix. The provided filtering items include: start time, end time, attack type, source IP address, source port, destination IP address, and destination port. The filtering items can be combined arbitrarily.

[0044] The log record query system framework not only provides DDoS attack log recording and query, but also provides other iptables rule log recording and query. You only need to follow step 1 above to add the rules that generate the corresponding rule logs.

[0045] 3. The present invention provides a transparent transmission mode deployment solution.

[0046] Transparent transmission mode can avoid the trouble caused by the modification of network topology. The firewall is equivalent to a transparent bridge, which is completely transparent to subnet users and routers. Users cannot feel the existence of the firewall at all. At the same time, the firewall can call the iptables attack protection rules of the third-layer network when forwarding the second-layer Ethernet data to protect users from intranet attacks. The detailed steps are as follows: Step 1: When compiling the openwrt kernel, compile the ebtables and br_netfilter modules into the kernel.

[0047] Step 2: Set a transparent transmission mode switch on the openwrt interface. When the switch is turned on, turn on the bridge-nf-call-iptables parameter of the br_netfilter module to support layer 2 forwarding to call layer 3 iptables table rules.

[0048] Step 3: When set to transparent transmission mode, the firewall can theoretically be deployed anywhere in the intranet to protect the devices connected to the firewall from DDoS network attacks.

[0049] Compared with patent CN118921232A, patent CN118921232A discloses a ship network firewall, which is mainly used in the network boundary area of ​​the ship system. The present invention is mainly used in the internal LAN area of ​​the rail transit safety computer platform. The rail transit safety computer platform has high requirements for the real-time, security and stability of data communication. At the same time, if a fault occurs, rapid troubleshooting and rapid recovery are also very important. The DDoS attack protection firewall solution with log record query that can be deployed in transparent transmission mode proposed by the present invention has no requirements or effects on the local area network topology, and is plug-and-play, which enhances the flexibility and adaptability of firewall deployment; its log record query module classifies DDoS attack logs and multiple combinations of filter items, making log analysis simpler and clearer; its DDoS attack protection module has dynamically configurable rules, which increases the flexibility, scalability and availability of the firewall, and proposes a method for dynamically adding and deleting protection rules following the active IP addresses in the arp list for LAND attacks, which enhances the adaptability of the firewall, making the protection more comprehensive and flexible without manual intervention.

[0050] The above is a specific description of the implementation mode of the present invention, but the present invention is not limited to the described embodiments. Those skilled in the art may make various equivalent modifications or substitutions without violating the spirit of the present invention, and these equivalents or substitutions are all included in the scope defined by the claims of the present invention.

Claims

1. A network attack protection method for a secure computer platform, characterized in that: include: Setting up a firewall to provide network attack protection for a cluster of secure computer platforms in the same local area network, wherein the firewall is deployed based on a transparent transmission mode, uses a DDoS attack protection method to protect the secure computer platform from network attacks, and records and queries network attack protection logs; Among them, the attack protection methods other than the LAND attack in the DDoS attack protection method can dynamically configure attack protection rules through a policy database, and the LAND attack protection method in the DDoS attack protection method can dynamically create and delete LAND attack protection rules by itself.

2. The network attack protection method according to claim 1, characterized in that: The firewall is deployed on the upper layer of the upper switch of the security computer platform, or the firewall replaces the terminal Ethernet switch to complete the data exchange task. The firewall provides network attack protection for the security computer platform cluster 1 and cluster 2 in the same local area network, and the underlying operating system of the firewall is the openwrt system.

3. The network attack protection method according to claim 1, characterized in that: The remaining attack protection methods except LAND attack in the DDoS attack protection method can dynamically configure attack protection rules through a policy database, including the following steps: S101. Build a public network attack strategy database in the local area network; S102, the firewall accesses the established network attack strategy database to obtain a common DDoS attack protection iptables rule set; S103, loading the obtained iptables rule set into the iptables table and chain of the openwrt operating system; S104. Restart the iptables service and the newly added rules will take effect; S105. When it is detected that the relevant policy rules of the public network attack policy database are updated, the old rules are deleted, and steps S102 to S104 are re-executed to load and make the new rules effective.

4. The network attack protection method according to claim 3, characterized in that: In step S102, a general DDoS attack protection rule set that is independent of the network environment IP address is obtained, including: ICMP flood attack protection rules, UDP flood attack protection rules, SYN flood attack protection rules, tear attack protection rules, and ping of death protection rules.

5. The network attack protection method according to claim 1, characterized in that: The LAND attack protection method creates a LAND attack protection rule for each IP node to be protected in the forwarding chain of the iptables table, and dynamically creates and deletes the LAND attack protection rule, including the following steps: S201. When the firewall is started, an empty file arplist_last.user is created in the tmp folder to store active IP addresses in the arp table. S202, obtaining active IP addresses from the arp list and creating an IP address list; S203, compare the IP addresses in the IP address list with the IP addresses in the arplist_last.user file. If: a certain IP address exists in the current arp active IP list and the IP address also exists in arplist_last.user, proceed to step S204; if a certain IP address exists in the current arp active IP list and the IP address does not exist in arplist_last.user, proceed to step S205; if a certain IP address does not exist in the current arp active IP list and the IP address exists in arplist_last.user, proceed to step S206; S204, continue to traverse the next IP address, and execute step S204, S205 or S206 according to the judgment condition described in step S203, until the last IP address is processed and then proceed to step S207; S205, add the IP address that exists in the current arp active IP list but does not exist in arplist_last.user to the arplist_last.user file, and create a command for a LAND protection rule for the IP address, execute the command, add the LAND protection rule of the IP address to the delegate_forward chain of iptables, and then proceed to step S204; S206, delete the IP address that does not exist in the current arp active IP list but exists in arplist_last.user from the arplist_last.user file, and delete the LAND protection rule corresponding to the IP in the delegate_forward chain of iptables. After completion, proceed to step S204; S207. After executing the traversal and judgment processing of all IP addresses once, the above steps S202 to S206 are executed again after waiting for n seconds, and the LAND attack protection rules are dynamically added and deleted in a cyclic manner.

6. The network attack protection method according to claim 1, characterized in that: In the recording and querying of the network attack protection log, a method for generating a corresponding LOG log is added for each attack protection rule.

7. The network attack protection method according to claim 6, characterized in that: In the DDoS attack protection rules, the methods for generating corresponding LOG logs for the ping of death protection rules include: Create a new chain named ping_of_death to handle ICMP traffic; Add a rule to the FORWARD chain to match packets of the ICMP protocol and jump the matching packets to the created ping_of_death chain for further processing; Add a rule to the ping_of_death chain to match ICMP type 8 packets; use the -m length module to check the length of the ICMP packet. If the length is less than or equal to 65499 bytes, perform a RETURN action to allow the packet to pass; Add another rule to the ping_of_death chain to match ICMP type 8 packets and use the -mlength module to check the length of the ICMP packet. If the length is greater than or equal to 65500 bytes, execute the LOG action, log it, and add the prefix.

8. The network attack protection method according to claim 1, characterized in that: Log queries include: S301, adding a method for generating a corresponding LOG log for each attack protection rule; S302, when a network attack occurs, the generated log is recorded in a log specifically used to record network attacks, and the log is transferred to a log management server by date; S303. Add a network attack log filtering and exporting interface in the openwrt interface, filter out the logs according to the filtering conditions and present them on the interface, and export the filtered logs as files with a .txt suffix.

9. The network attack protection method according to claim 8, characterized in that: In step S303, the filter items provided include: start time, end time, attack type, source IP address, source Port, destination IP address, destination Port, and the filter items can be combined arbitrarily for filtering.

10. The network attack protection method according to claim 1, characterized in that: The firewall is deployed based on transparent transmission mode, including: When compiling the openwrt kernel, compile the ebtables and br_netfilter modules into the kernel together; Set the transparent transmission mode switch on the openwrt interface. When the switch is turned on, enable the bridge-nf-call-iptables parameter of the br_netfilter module to support Layer 2 forwarding to call Layer 3 iptables table rules; When set to transparent transmission mode, the firewall is deployed at any location in the intranet to protect the devices connected to the firewall from network attacks.

Citation Information

Patent Citations

  • Ship network firewall

    CN118921232A