Multi-protocol compatible processing method and device of protection system, equipment and storage medium

By identifying and processing the server name and target protocol type in the transport layer security protocol in the protection system, compatible processing of multiple transport protocols is achieved, solving the problem that the existing protection system cannot be compatible with other application layer transmission protocols, and enhancing the security of network application servers.

CN120150971APending Publication Date: 2025-06-13CHINA UNITED NETWORK COMM GRP CO LTD +2
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311708394.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-12-12
Publication Date
2025-06-13

AI Technical Summary

Technical Problem

Existing protection systems cannot be compatible with other application layers' transmission protocols while protecting network application servers.

Method used

Obtain access requests through a single instance system user or a unified entry component of the protection system and verify whether the transport layer security protocol is carried. Identifies the server name of the transport layer security protocol. If it is a preset name, it identifies the target protocol type of the access request, and sends the access request to the network application server according to the target protocol type.

Benefits of technology

It realizes compatibility of multiple transmission protocols, solves the problem that existing protection systems cannot be compatible with other application layer transmission protocols, and enhances the security of network application servers.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120150971A_ABST
    Figure CN120150971A_ABST
Patent Text Reader

Abstract

The invention provides a multi-protocol compatible processing method and device of a protection system, equipment and a storage medium, and relates to the technical field of network security. The method comprises the following steps: obtaining an access request through a single instance system user or a unified entry component of a protection system; verifying whether the access request carries a transport layer security protocol; when the access request carries the transport layer security protocol, identifying a server name of the transport layer security protocol; when the server name of the transport layer security protocol is a preset name, target protocol types of the access request are identified, the access request is sent to a network application server according to the target protocol types, and the target protocol types comprise a network socket security protocol and an open source remote procedure call security protocol. According to the method provided by the invention, the problem that an existing protection system cannot be compatible with transmission protocols of other application layers while protecting the network application server is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of network security technology, and in particular, to a multi-protocol compatible processing method, device, equipment and storage medium for a protection system. Background Art

[0002] In recent years, network applications have become increasingly rich. At the same time, network security issues have become increasingly prominent. If the application server is directly deployed on the network without any protection, the real application server will be completely exposed to the Internet, and any user requests from clients can directly access the application server through the browser. The application server is very vulnerable to hacker attacks and can be attacked by various illegal requests, resulting in system crashes, thus having significant security risks.

[0003] In the prior art, a firewall mainly uses the functions of hardware and software to create a protective barrier between the internal and external network environments, thereby blocking computer insecure network factors. Only with the consent of the firewall can users enter the computer; otherwise, they will be blocked outside. A Web Application Firewall (WAF) is a product that specifically provides protection for network applications by executing a series of security policies for the Hypertext Transfer Protocol Secure (HTTPS) and the Hypertext Transfer Protocol (HTTP).

[0004] However, the existing protection systems cannot be compatible with other application layer transport protocols while protecting network application servers. Summary of the Invention

[0005] The present application provides a multi-protocol compatible processing method, device, equipment and storage medium for a protection system to solve the problem that the existing protection systems cannot be compatible with other application layer transport protocols while protecting network application servers.

[0006] In a first aspect, the present application provides a multi-protocol compatible processing method for a protection system, and the method includes:

[0007] Obtain an access request through a single-instance system user or a unified entry component of the protection system;

[0008] Verify whether the access request carries a transport layer security protocol;

[0009] When the access request carries a transport layer security protocol, identify the server name of the transport layer security protocol;

[0010] When the server name of the Transport Layer Security protocol is a preset name, identify the target protocol type of the access request, and send the access request to the network application server according to the target protocol type, where the target protocol type includes the Network Socket Security protocol and the Open Source Remote Procedure Call Security protocol.

[0011] In a possible design, when the server name of the Transport Layer Security protocol is a preset name, identifying the target protocol type of the access request and sending the access request to the network application server according to the target protocol type includes:

[0012] When the server name of the Transport Layer Security protocol is a preset name, identify the Upgrade protocol header of the request header of the access request;

[0013] When the Upgrade protocol header contains the preset Upgrade Network Socket protocol, identify the target protocol type as the Network Socket Security protocol;

[0014] Send the access request to the network application server according to the Network Socket Security protocol.

[0015] In a possible design, when the Upgrade protocol header does not contain the preset Upgrade Network Socket protocol, identify whether the access request is the Hypertext Transfer Protocol version 2;

[0016] When the access request is the Hypertext Transfer Protocol version 2, identify the target protocol type as the Open Source Remote Procedure Call Security protocol;

[0017] Send the access request to the network application server according to the Open Source Remote Procedure Call Security protocol.

[0018] In a possible design, when the access request does not carry the Transport Layer Security protocol, identify the Upgrade protocol header of the request header of the access request;

[0019] When the Upgrade protocol header contains the preset Upgrade Network Socket protocol, identify the protocol type of the access request as the Network Socket protocol;

[0020] Send the access request to the network application server according to the Network Socket protocol.

[0021] In a possible design, when the Upgrade protocol header does not contain the preset Upgrade Network Socket protocol, identify whether the access request is the Hypertext Transfer Protocol version 2;

[0022] When the access request is the Hypertext Transfer Protocol version 2, identify the protocol type of the access request as the Open Source Remote Procedure Call protocol;

[0023] Send the access request to the network application server according to the Open Source Remote Procedure Call protocol.

[0024] In a possible design, when the access request is not the second-generation Hypertext Transfer Protocol, identify the target network system architecture;

[0025] When the target network system architecture is the Hypertext Transfer Security Protocol, send the access request to the network application server according to the Hypertext Transfer Security Protocol;

[0026] When the target network system architecture is the Hypertext Transfer Protocol, send the access request to the network application server according to the Hypertext Transfer Protocol.

[0027] In a possible design, before identifying that the target protocol type is the Network Socket Security Protocol when the upgrade protocol header contains the preset upgraded network socket protocol, the method further includes:

[0028] When the server name of the Transport Layer Security Protocol is not the preset name, verify whether the conversion method of the access request is passed;

[0029] When the conversion method fails, identify the upgrade protocol header of the request header of the access request.

[0030] In a second aspect, the present application provides a multi-protocol compatibility processing device for a protection system, and the device includes:

[0031] An access request acquisition module, configured to obtain an access request through a single-instance system user or a unified entry component of the protection system;

[0032] A Transport Layer Security Protocol determination module, configured to verify whether the access request carries the Transport Layer Security Protocol;

[0033] A server name determination module, configured to identify the server name of the Transport Layer Security Protocol when the access request carries the Transport Layer Security Protocol;

[0034] A target protocol type determination module, configured to identify the target protocol type of the access request when the server name of the Transport Layer Security Protocol is the preset name, and send the access request to the network application server according to the target protocol type, where the target protocol type includes the Network Socket Security Protocol and the Open Source Remote Procedure Call Security Protocol.

[0035] In a third aspect, the present application provides an electronic device, including: a processor, and a memory communicatively connected to the processor;

[0036] The memory stores computer-executable instructions;

[0037] The processor executes the computer-executable instructions stored in the memory to implement the multi-protocol compatibility processing method for the protection system according to any one of claims 1 to 7.

[0038] Fourthly, the present application provides a computer-readable storage medium storing computer-executable instructions, which are used to implement the multi-protocol compatibility processing method of the protection system according to any one of claims 1 to 7 when executed by a processor.

[0039] Fifthly, the present application provides a computer program product including a computer program, which is used to implement the multi-protocol compatibility processing method of the protection system in the invention content of the first aspect when executed by a processor.

[0040] The multi-protocol compatibility processing method, device, equipment and storage medium of a protection system provided by the present application obtain an access request through a single-instance system user or a unified entry component of the protection system; and verify whether the access request carries a transport layer security protocol; thus, when the access request carries a transport layer security protocol, identify the server name of the transport layer security protocol; and then, when the server name of the transport layer security protocol is a preset name, identify the target protocol type of the access request, and send the access request to the network application server according to the target protocol type. The following technical effects are achieved: by verifying whether the access request carries a transport layer security protocol, the problem of initially judging whether the access request comes from a single-instance system user or an access request sent by a multi-instance system user forwarded through a unified entry component is solved; by analyzing whether the server name in the transport layer security protocol configuration is a preset name, the problem of further judging whether the access request carrying the transport layer security protocol comes from a single-instance system user or an access request sent by a multi-instance system user forwarded through a unified entry component is solved; by identifying the specific transport protocol type in the access request, such as the two transport protocols of the network socket security protocol and the open source remote procedure call security protocol, the problem that the existing protection system cannot be compatible with other application layer transport protocols while protecting the network application server is solved. Description of the Drawings

[0041] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0042] The drawings here are incorporated into the specification and form a part of this specification, showing the embodiments in line with the present application, and are used together with the specification to explain the principles of the present application.

[0043] Figure 1 It is a schematic diagram of the system architecture of the multi-protocol compatibility processing method of the protection system provided by the embodiment of the present application;

[0044] Figure 2 It is an application scenario framework diagram of the multi - protocol compatibility processing method for the protection system provided by the embodiments of the present application;

[0045] Figure 3 It is a flowchart of the multi - protocol compatibility processing method for the protection system provided by the embodiments of the present application Figure 1 ;

[0046] Figure 4 It is a flowchart of the multi - protocol compatibility processing method for the protection system provided by the embodiments of the present application Figure 2 ;

[0047] Figure 5 It is a flowchart of the multi - protocol compatibility processing method for the protection system provided by the embodiments of the present application Figure 3 ;

[0048] Figure 6 It is a structural schematic diagram of the multi - protocol compatibility processing device for the protection system provided by the embodiments of the present application;

[0049] Figure 7 It is a structural schematic diagram of the electronic device provided by the embodiments of the present application.

[0050] Reference numerals:

[0051] 110 - Protection system; 111 - Unified entry component; 112 - Fixed - point protection component;

[0052] 210 - Client; 220 - Network application server;

[0053] 300 - Multi - protocol compatibility processing device of the protection system; 310 - Access request acquisition module; 320 - Transport layer security protocol determination module; 330 - Server name determination module; 340 - Target protocol type determination module; 400 - Electronic device; 410 - Processor; 420 - Memory; 430 - Communication component; 440 - Bus. Detailed implementation manners

[0054] Here, the exemplary embodiments will be described in detail, and the examples are shown in the drawings. When the following description refers to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The implementation manners described in the following exemplary embodiments do not represent all the implementation manners consistent with the present application. On the contrary, they are only examples of the devices and methods consistent with some aspects of the present application as detailed in the appended claims.

[0055] In the embodiments of the present application, words such as "exemplary" or "for example" are used to indicate examples, illustrations or descriptions. Any embodiment or design described in the present application as "exemplary" or "for example" should not be interpreted as being more preferred or more advantageous than other embodiments or designs. Specifically, the use of words such as "exemplary" or "for example" is intended to present related concepts in a concrete way. In the embodiments of the present application, "at least one" refers to one or more, and "more than one" refers to two or more.

[0056] It should be noted that the "at..." in the embodiments of the present application can be the instant when a certain situation occurs, or it can be a period of time after a certain situation occurs, and the embodiments of the present application do not specifically limit this. In addition, the multi-protocol compatible processing method for a protection system provided in the embodiments of the present application is only used as an example, and the multi-protocol compatible processing method for a protection system can also include more or less content.

[0057] In order to clearly describe the technical solutions of the embodiments of the present application, some terms and technologies involved in the embodiments of the present application are briefly introduced below:

[0058] Uniform Web Application Firewall (UWAF): It is the only entrance to the multi-instance system. It accepts the user access traffic on the Internet side and includes fine-grained Internet Protocol (IP) whitelist control. It is a front-end access authentication component with the functions of protecting against distributed denial of service (DDoS) and transparently forwarding legitimate requests to fixed-point protection components.

[0059] Adaptive Control Component (ACC): It can receive access requests forwarded by UWAF and can also serve as the user-side entrance of a single-instance system. It includes fine-grained IP whitelist control and is a front-end access authentication component with the functions of protecting against DDoS and hiding the real network application server.

[0060] Hypertext Transfer Protocol (HTTP / 2): refers to the second version of the Hypertext Transfer Protocol, which is the second version of the HTTP protocol.

[0061] Transport Layer Security (TLS): A protocol used to provide confidentiality and data integrity between two communicating applications.

[0062] Web Socket Secure (WSS): It is an encrypted version of the WebSocket (WS) protocol.

[0063] Google Remote Procedure Call (gRPC): It refers to a communication protocol, which is a high-performance, open-source, and general remote procedure call (RPC) protocol designed for mobile and HTTP / 2.

[0064] Upgrade WebSocket: It means upgrading from the HTTP protocol to the WebSocket protocol.

[0065] Target network system architecture (Web system Schema): It refers to the transport protocol supported by the target network application server.

[0066] Transfer Style: It means that the fixed-point protection component can decide whether to pass the access request directly to the network application server or handle it as an intermediary by judging whether the value of Transfer Style is "pass", and continue to identify the transport protocol type of the access request, so as to forward the access request to the network application server according to the specific transport protocol type.

[0067] ValidStyle: It refers to the method of verifying the IP whitelist and / or token.

[0068] Nowadays, with the increasing richness of network applications, network security issues have become increasingly prominent. If the application server is directly deployed on the network, there will be huge security risks. This is because if no protection is added to the application server, the real application server will be completely exposed on the Internet, so that user requests from any client can directly access the application server through the browser at will. At this time, the application server is very vulnerable to hacker attacks and even crashes due to various illegal requests.

[0069] The commonly used firewall and WAF can provide certain protection for the application server, but neither of them can be compatible with other application-layer transport protocols while protecting the network application server.

[0070] Based on this, the embodiments of the present application provide a multi-protocol compatible processing method, device, equipment, and storage medium for a protection system, which can be used in the field of network security technology and aims to solve the above technical problems of the prior art.

[0071] The technical solution of the present application and how the technical solution of the present application solves the above technical problems will be described in detail below with specific embodiments. The following several specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The embodiments of the present application will be described below with reference to the accompanying drawings.

[0072] Figure 1 It is a schematic diagram of the system architecture of the multi-protocol compatibility processing method for the protection system provided in the embodiments of the present application. It should be noted that Figure 1 The figure only shows an example of the system architecture to which the embodiments of the present application can be applied, to help those skilled in the art understand the technical content of the present application, but it does not mean that the embodiments of the present application cannot be used in other devices, systems, environments or scenarios.

[0073] As Figure 1 shown, the system architecture where the method is located is the protection system 110. The protection system 110 is used to prevent the server from being attacked by the network. The protection system 110 includes: a unified entry component 111 and a plurality of fixed-point protection components 112. Among them:

[0074] The unified entry component 111 refers to the entry of the multi-instance system. It undertakes the user access traffic on the Internet side, includes fine-grained IP white list control, is a pre-access authentication component, and has the functions of protecting against DDoS and transparently forwarding legitimate requests to the fixed-point protection component 112.

[0075] The fixed-point protection component 112 can not only receive the access requests forwarded by the unified entry component 111, but also serve as the user-side entry of the single-instance system to receive the access requests sent by the users of the single-instance system. It includes fine-grained IP white list control and is also a pre-access authentication component, and has the functions of protecting against DDoS and hiding the real network application server.

[0076] Figure 2 It is an application scenario framework diagram of the multi-protocol compatibility processing method for the protection system provided in the embodiments of the present application.

[0077] As Figure 2As shown in the figure, the application scenario framework where the method is located includes: a client 210, a protection system 110, and a network application server 220. The client 210 sends an access request through a mobile phone or a computer to request access to the network application server 220; the front-end protection system 110 obtains the access request and performs an access permission check on it, identifying and blocking potential attack behaviors. For a secure access request, it is identified whether the request source is a single-instance system user or a multi-instance system user by verifying whether the access request carries TLS and whether the server name (ServerName) is a pre-agreed name, and then the protocol type of the access request is judged, and the access request is sent to the network application server 220 according to the specific protocol type.

[0078] Figure 3 Flow schematic of the multi-protocol compatibility processing method of the protection system provided by the embodiments of the present application Figure 1 In the present application, the protection system can simultaneously perform access permission checks and transparent forwarding on multiple access requests sent by multiple clients. Among them, the methods for the protection system to process each access request are the same. In this embodiment, only the method for the protection system to process one access request sent by one client is described in detail. As Figure 3 shown, the method includes:

[0079] S101. Obtain an access request through the unified entry component of the single-instance system user or the protection system;

[0080] Specifically, when the user sends an access request through a mobile phone or a computer to request access to the network application server, the fixed-point protection component in the front-end protection system can either directly receive the access request sent by the client as the entry on the single-instance system user side, or receive the access request forwarded by the unified entry component of the first protection barrier as the second protection barrier in the protection system.

[0081] S102. Verify whether the access request carries the Transport Layer Security protocol;

[0082] Specifically, after the fixed-point protection component receives the access request, the specific information of the access request is obtained by parsing the data of the access request. First, it is necessary to verify whether TLS is carried in the access request, so as to initially judge whether the access request comes from a single-instance system user or an access request sent by a multi-instance system user forwarded by the unified entry component. Here, when TLS is not carried in the access request, it can be directly judged that the access request comes from a single-instance system user.

[0083] S103. When the access request carries the Transport Layer Security protocol, identify the server name of the Transport Layer Security protocol;

[0084] Specifically, when the fixed-point protection component preliminarily determines that the received access request carries TLS, it is also necessary to analyze whether the server name in the TLS configuration is a preset name, so as to further determine whether the access request carrying TLS comes from a single-instance system user or an access request sent by a multi-instance system user forwarded by the unified entry component. Here, when the server name in the TLS configuration carried in the access request is not a preset name, it can be determined that the access request comes from a single-instance system user.

[0085] S104. When the server name of the Transport Layer Security protocol is a preset name, identify the target protocol type of the access request, and send the access request to the network application server according to the target protocol type;

[0086] Specifically, when the server name in the TLS configuration carried in the access request is a preset name, it can be determined that the access request is an access request sent by a multi-instance system user forwarded by the unified entry component. At this time, it is necessary to further identify what type of specific transport protocol is in the access request. So as to forward the access request to the network application server to be accessed according to the specific transport protocol. The possible transport protocol types here include WSS and gRPCS, which the previous protection systems could not be compatible with, and at the same time still support the forwarding of HTTPS and HTTP protocols in the prior art.

[0087] A multi-protocol compatibility processing method for a protection system provided in this embodiment obtains an access request through a single-instance system user or the unified entry component of the protection system; and verifies whether the access request carries the Transport Layer Security protocol; thus, when the access request carries the Transport Layer Security protocol, identify the server name of the Transport Layer Security protocol; furthermore, when the server name of the Transport Layer Security protocol is a preset name, identify the target protocol type of the access request, and send the access request to the network application server according to the target protocol type. The following technical effects are achieved: By verifying whether the access request carries TLS, the problem of preliminarily determining whether the access request comes from a single-instance system user or an access request sent by a multi-instance system user forwarded by the unified entry component is solved; by analyzing whether the server name in the TLS configuration is a preset name, the problem of further determining whether the access request carrying TLS comes from a single-instance system user or an access request sent by a multi-instance system user forwarded by the unified entry component is solved; by identifying what type of specific transport protocol is in the access request, such as the two transport protocols of WSS and gRPCS, the problem that the existing protection systems cannot be compatible with other application layer transport protocols while protecting the network application server is solved.

[0088] Figure 4Flow diagram of the multi - protocol compatibility processing method for the protection system provided by the embodiments of the present application Figure 2 In a possible example, as Figure 4 shown, based on the embodiments in Figure 3 this embodiment, a detailed description is given on how the fixed - point protection component processes the access requests sent by multi - instance system users forwarded by the unified entry component. As Figure 4 shown, the method includes:

[0089] S201. Obtain an access request through a single - instance system user or the unified entry component of the protection system;

[0090] S202. Verify whether the access request carries a Transport Layer Security (TLS) protocol;

[0091] S203. When the access request carries a TLS protocol, identify the server name of the TLS protocol;

[0092] S201 - S203 are similar to S101 - S103, and will not be elaborated in this embodiment.

[0093] S204. When the server name of the TLS protocol is a preset name, identify the upgrade protocol header in the request header of the access request;

[0094] Specifically, after the fixed - point protection component determines that the access request is a request sent by a multi - instance system user forwarded by the unified entry component based on the server name in the TLS configuration carried in the access request being a preset name, it is necessary to further identify the type of the specific transport protocol in the access request. First, analyze the specific information of the access request, and check the request - header information of the access request, especially the specific information of the upgrade protocol header.

[0095] S205. When the upgrade protocol header contains a preset upgraded network socket protocol, identify the target protocol type as the network socket security protocol;

[0096] Specifically, when the upgrade protocol header contains the preset "upgrade websocket", it indicates that the transport protocol type of the access request is WSS.

[0097] S206. Send the access request to the network application server according to the network socket security protocol;

[0098] Specifically, after the fixed - point protection component obtains that the transport protocol type of the access request is WSS, it can forward the access request to the network application server according to WSS.

[0099] S207. When the upgrade protocol header does not contain the preset upgrade network socket protocol, identify whether the access request is the second-generation Hypertext Transfer Protocol;

[0100] Specifically, when the upgrade protocol header does not contain the preset upgrade websocket, it is necessary to further identify whether the transport protocol type of the access request is HTTP / 2.

[0101] S208. When the access request is the second-generation Hypertext Transfer Protocol, identify the target protocol type as the open-source Remote Procedure Call Security Protocol;

[0102] Specifically, when the transport protocol type of the access request is HTTP / 2, it indicates that the transport protocol type of the access request is gRPCS.

[0103] S209. According to the open-source Remote Procedure Call Security Protocol, send the access request to the network application server;

[0104] Specifically, after the fixed-point protection component obtains that the transport protocol type of the access request is gRPCS, it can forward the access request to the network application server according to gRPCS.

[0105] S210. When the access request is not the second-generation Hypertext Transfer Protocol, identify the target network system architecture;

[0106] Specifically, when the transport protocol type of the access request is not HTTP / 2, it is necessary to identify the Web system Schema, and then forward the access request to the network application server according to the Web system Schema.

[0107] S211. When the target network system architecture is the Hypertext Transfer Security Protocol, send the access request to the network application server according to the Hypertext Transfer Security Protocol;

[0108] Specifically, when the Web system Schema is HTTPS, the fixed-point protection component can forward the access request to the network application server according to HTTPS.

[0109] When the transport protocol type of the access request at this time is HTTPS and the Web system Schema is also HTTPS, the fixed-point protection component will unload the TLS carried in the access request, check for DDoS, and verify the IP and token according to the fixed method (validStyle), and can adapt to the situation of multiple request links sent by the user-side browser.

[0110] S212. When the target network system architecture is the Hypertext Transfer Protocol, send the access request to the network application server according to the Hypertext Transfer Protocol;

[0111] Specifically, when the Web system schema is HTTP, the fixed-point protection component can forward the access request to the network application server according to HTTP.

[0112] When the transport protocol type of the access request at this time is HTTPS and the Web system schema is HTTP, the fixed-point protection component will also unload the TLS carried in the access request, check for DDoS, and verify the IP and token according to validStyle, and can adapt to the situation of multiple request links sent by the client browser.

[0113] Figure 5 Flow schematic of the multi-protocol compatibility processing method of the protection system provided by the embodiments of the present application Figure 3 . In a possible example, as Figure 5 shown, on the basis of the Figure 3 embodiment, this embodiment details how the fixed-point protection component processes the access requests sent by single-instance system users. As Figure 5 shown, the method includes:

[0114] S301. Obtain an access request through a single-instance system user or the unified entry component of the protection system;

[0115] S302. Verify whether the access request carries a transport layer security protocol;

[0116] S301 - S302 are similar to S101 - S102, and will not be elaborated in this embodiment.

[0117] S303. When the access request does not carry a transport layer security protocol, identify the upgrade protocol header in the request header of the access request;

[0118] Specifically, after the fixed-point protection component directly determines that the access request comes from a single-instance system user based on the fact that the access request does not carry TLS, it also needs to further identify the specific transport protocol type in the access request. First, analyze the specific information of the access request, check the request header information of the access request, especially the specific information of the upgrade protocol header.

[0119] S304. When the upgrade protocol header contains a preset upgrade network socket protocol, identify the protocol type of the access request as the network socket protocol;

[0120] Specifically, when the upgrade protocol header contains the preset upgrade websocket, it indicates that the transport protocol type of the access request is WS.

[0121] S305. Send the access request to the network application server according to the network socket protocol;

[0122] Specifically, after the fixed-point protection component obtains that the transport protocol type of the access request is WS, it can forward the access request to the network application server according to WS.

[0123] S306. When the upgrade protocol header does not contain the preset upgrade network socket protocol, identify whether the access request is the second-generation Hypertext Transfer Protocol;

[0124] Specifically, when the upgrade protocol header does not contain the preset "upgrade websocket", it is necessary to further identify whether the transport protocol type of the access request is HTTP / 2.

[0125] S307. When the access request is the second-generation Hypertext Transfer Protocol, identify that the protocol type of the access request is the open-source Remote Procedure Call Protocol;

[0126] Specifically, when the transport protocol type of the access request is HTTP / 2, it indicates that the transport protocol type of the access request is gRPC.

[0127] S308. Send the access request to the network application server according to the open-source Remote Procedure Call Protocol;

[0128] Specifically, after the fixed-point protection component obtains that the transport protocol type of the access request is gRPC, it can forward the access request to the network application server according to gRPC.

[0129] S309. When the access request is not the second-generation Hypertext Transfer Protocol, identify the target network system architecture;

[0130] Specifically, when the transport protocol type of the access request is not HTTP / 2, it is necessary to identify the Web system Schema, and then forward the access request to the network application server according to the Web system Schema.

[0131] S310. When the target network system architecture is the Hypertext Transfer Security Protocol, send the access request to the network application server according to the Hypertext Transfer Security Protocol;

[0132] Specifically, when the Web system Schema is HTTPS, the fixed-point protection component can forward the access request to the network application server according to HTTPS.

[0133] When the transport protocol type of the access request at this time is HTTP and the Web system Schema is HTTPS, the fixed-point protection component will check for DDoS, and verify the IP and token according to validStyle, and can adapt to the situation of multiple request links sent by the client browser.

[0134] When the access request transmission protocol type at this time is HTTPS, the Web system Schema is HTTPS. Since the fixed-point protection component does not change the Transmission Control Protocol (TCP) request connection attribute on the user side of the single-instance system, the fixed-point protection component cannot obtain the content of the access request (request), and only verifies the IP.

[0135] S311. When the target network system architecture is the Hypertext Transfer Protocol, send an access request to the network application server according to the Hypertext Transfer Protocol;

[0136] Specifically, when the Web system Schema is HTTP, the fixed-point protection component can forward the access request to the network application server according to HTTP.

[0137] When the access request transmission protocol type at this time is HTTP, the Web system Schema is HTTP, and the fixed-point protection component will check for DDoS and verify the IP and token according to validStyle, and can adapt to the situation of multiple request links sent by the user-side browser.

[0138] When the access request transmission protocol type at this time is HTTPS and the Web system Schema is HTTP, since the fixed-point protection component does not change the TCP request connection attribute on the user side of the single-instance system, the system will report an error.

[0139] In a possible design, when the upgrade protocol header includes a preset upgraded network socket protocol and before identifying the target protocol type as the network socket security protocol, the method further includes: when the server name in the Transport Layer Security protocol is not the preset name, verifying whether the conversion method of the access request is passed; when the conversion method is not passed, identifying the upgrade protocol header of the request header of the access request. That is, when the server name in the TLS configuration carried in the access request is not the preset name, it can be determined that the access request comes from the user of the single-instance system. At this time, if the Transfer Style value is passed, the fixed-point protection component will pass the access request through to the network application server; if the Transfer Style value is not passed, the fixed-point protection component will continue to process the access request as a middleman, and the specific processing steps are similar to S205 - S212, which will not be elaborated in this embodiment.

[0140] A multi - protocol compatibility processing method for a protection system provided in this embodiment obtains an access request through a single - instance system user or a unified entry component of the protection system; and verifies whether the access request carries a transport layer security protocol; thus, when the access request carries a transport layer security protocol, it identifies the server name of the transport layer security protocol; further, when the server name of the transport layer security protocol is a preset name, it identifies the target protocol type of the access request, and according to the target protocol type, sends the access request to the network application server. The following technical effects are achieved: By verifying whether the access request carries TLS, it solves the problem of initially determining whether the access request comes from a single - instance system user or an access request sent by a multi - instance system user forwarded through the unified entry component; by analyzing whether the server name in the TLS configuration is a preset name, it solves the problem of further determining whether the access request carrying TLS comes from a single - instance system user or an access request sent by a multi - instance system user forwarded through the unified entry component; by identifying the specific transport protocol type in the access request, such as two transport protocols, WSS and gRPCS, it solves the problem that the existing protection system cannot protect the network application server while being compatible with other application - layer transport protocols; by identifying the upgrade protocol header in the request header of the access request, when the upgrade protocol header contains the preset upgrade websocket, it indicates that the transport protocol type of the access request is WSS, so that the access request can be forwarded to the network application server according to WSS, solving the problem that the existing protection system cannot protect the network application server while being compatible with WSS; by when the upgrade protocol header does not contain the preset upgrade websocket, identifying whether the access request is HTTP / 2, when the transport protocol type of the access request is HTTP / 2, it indicates that the transport protocol type of the access request is gRPCS, and then the access request can be forwarded to the network application server according to gRPCS, solving the problem that the existing protection system cannot protect the network application server while being compatible with gRPCS.

[0141] Embodiments of the present invention can divide functional modules of an electronic device or a main control device according to the above - mentioned method examples. For example, each functional module can be divided corresponding to each function, or two or more functions can be integrated into one processing unit. The above - integrated unit can be implemented in the form of hardware or in the form of a software functional module. It should be noted that the division of modules in the embodiments of the present invention is illustrative, only a logical function division, and there can be other division methods in actual implementation.

[0142] Figure 6 It is a schematic structural diagram of a multi - protocol compatibility processing device for a protection system provided in an embodiment of this application. As Figure 6As shown in the figure, the multi-protocol compatibility processing device 300 of the protection system includes:

[0143] An access request acquisition module 310, a transport layer security protocol determination module 320, a server name determination module 330, and a target protocol type determination module 340;

[0144] The access request acquisition module 310 is used to obtain an access request through a single-instance system user or the unified entry component of the protection system;

[0145] The transport layer security protocol determination module 320 is used to verify whether the access request carries a transport layer security protocol;

[0146] The server name determination module 330 is used to identify the server name of the transport layer security protocol when the access request carries the transport layer security protocol;

[0147] The target protocol type determination module 340 is used to identify the target protocol type of the access request when the server name of the transport layer security protocol is a preset name, and send the access request to the network application server according to the target protocol type, where the target protocol type includes the network socket security protocol and the open source remote procedure call security protocol.

[0148] In a possible design, the target protocol type determination module 340 includes an upgrade protocol header determination module, a network socket security protocol determination module, and an access request sending module;

[0149] The upgrade protocol header determination module is used to identify the upgrade protocol header of the request header of the access request when the server name of the transport layer security protocol is a preset name;

[0150] The network socket security protocol determination module is used to identify that the target protocol type is the network socket security protocol when the upgrade protocol header contains a preset upgraded network socket protocol;

[0151] The access request sending module is used to send the access request to the network application server according to the network socket security protocol.

[0152] In a possible design, the target protocol type determination module 340 further includes a second-generation hypertext transfer protocol determination module and an open source remote procedure call security protocol determination module;

[0153] The second-generation hypertext transfer protocol determination module is used to identify whether the access request is the second-generation hypertext transfer protocol when the upgrade protocol header does not contain a preset upgraded network socket protocol;

[0154] An open-source remote procedure call security protocol determination module, which is used to identify the target protocol type as the open-source remote procedure call security protocol when the access request is the second-generation Hypertext Transfer Protocol;

[0155] An access request sending module, which is further used to send an access request to the network application server according to the open-source remote procedure call security protocol.

[0156] In a possible design, the target protocol type determination module 340 further includes: a network socket protocol determination module;

[0157] An upgrade protocol header determination module, which is further used to identify the upgrade protocol header of the request header of the access request when the access request does not carry the Transport Layer Security protocol;

[0158] The network socket protocol determination module is used to identify the protocol type of the access request as the network socket protocol when the upgrade protocol header contains a preset upgraded network socket protocol;

[0159] An access request sending module, which is further used to send an access request to the network application server according to the network socket protocol.

[0160] In a possible design, the target protocol type determination module 340 further includes: an open-source remote procedure call protocol determination module;

[0161] A second-generation Hypertext Transfer Protocol determination module, which is used to identify whether the access request is the second-generation Hypertext Transfer Protocol when the upgrade protocol header does not contain a preset upgraded network socket protocol;

[0162] The open-source remote procedure call protocol determination module is used to identify the protocol type of the access request as the open-source remote procedure call protocol when the access request is the second-generation Hypertext Transfer Protocol;

[0163] An access request sending module, which is further used to send an access request to the network application server according to the open-source remote procedure call protocol.

[0164] In a possible design, the multi-protocol compatibility processing device 300 of the protection system further includes: a target network system architecture determination module;

[0165] The target network system architecture determination module is used to identify the target network system architecture when the access request is not the second-generation Hypertext Transfer Protocol;

[0166] An access request sending module, which is further used to send an access request to the network application server according to the Hypertext Transfer Security protocol when the target network system architecture is the Hypertext Transfer Security protocol;

[0167] The access request sending module is further configured to send an access request to the network application server according to the Hypertext Transfer Protocol when the target network system architecture is the Hypertext Transfer Protocol.

[0168] In a possible design, the multi-protocol compatibility processing device 300 of the protection system further includes: a conversion method verification module;

[0169] The conversion method verification module is configured to verify whether the conversion method of the access request is passed when the server name of the Transport Layer Security Protocol is not the preset name;

[0170] The upgraded protocol header determination module is further configured to identify the upgraded protocol header of the request header of the access request when the conversion method fails.

[0171] The multi-protocol compatibility processing device of the protection system provided in this embodiment can execute the multi-protocol compatibility processing method of the protection system in the above embodiment, and its implementation principle and technical effect are similar, which will not be elaborated here in this embodiment.

[0172] In the specific implementation of the foregoing multi-protocol compatibility processing device of the protection system, each module can be implemented as a processor, and the processor can execute the computer execution instructions stored in the memory, so that the processor executes the foregoing multi-protocol compatibility processing method of the protection system.

[0173] Figure 7 It is a schematic structural diagram of an electronic device provided in an embodiment of the present application. As Figure 7 shown, the electronic device 400 includes: at least one processor 410 and a memory 420. The electronic device 400 further includes a communication component 430. Among them, the processor 410, the memory 420, and the communication component 430 are connected through a bus 440.

[0174] In the specific implementation process, at least one processor 410 executes the computer execution instructions stored in the memory 420, so that at least one processor 410 executes a multi-protocol compatibility processing method executed on the electronic device side as described above.

[0175] The specific implementation process of the processor 410 can refer to the foregoing method embodiment, and its implementation principle and technical effect are similar, which will not be elaborated here in this embodiment.

[0176] In the above embodiments, it should be understood that the processor may be a central processing unit (CPU for short), or other general-purpose processors, digital signal processors (DSP for short), application specific integrated circuits (ASIC for short), etc. The general-purpose processor may be a microprocessor or any conventional processor, etc. The steps of the method disclosed in combination with the invention can be directly implemented by the execution of the hardware processor, or by the combination of hardware and software modules in the processor.

[0177] The memory may include high-speed RAM memory and may also include non-volatile storage NVM, such as at least one disk memory.

[0178] The bus may be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, an Extended Industry Standard Architecture (EISA) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For the convenience of representation, the buses in the drawings of this application are not limited to only one bus or one type of bus.

[0179] The functions implemented for the electronic device and the main control device are introduced for the solution provided by the embodiments of the present invention. It can be understood that in order for the electronic device or the main control device to implement the above functions, it includes the corresponding hardware structure and / or software module for executing each function. Combining the units and algorithm steps of each example described in the embodiments disclosed in the embodiments of the present invention, the embodiments of the present invention can be implemented in the form of hardware or a combination of hardware and computer software. Whether a certain function is executed in the way of hardware or computer software driving hardware depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the technical solution of the embodiments of the present invention.

[0180] This application also provides a computer-readable storage medium, in which computer-executable instructions are stored. When the processor executes the computer-executable instructions, it is used to implement the multi-protocol compatibility processing method of a protection system as described above.

[0181] The above-readable storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, a magnetic disk, or an optical disk. The readable storage medium can be any available medium accessible by a general-purpose or special-purpose computer.

[0182] An exemplary readable storage medium is coupled to the processor, enabling the processor to read information from the readable storage medium and write information to the readable storage medium. Of course, the readable storage medium can also be a component of the processor. The processor and the readable storage medium can be located in an application specific integrated circuit (ASIC). Of course, the processor and the readable storage medium can also exist as discrete components in an electronic device or a master control device.

[0183] This application also provides a computer program product, which includes: a computer program stored in a readable storage medium. At least one processor of the electronic device can read the computer program from the readable storage medium, and the execution of the computer program by at least one processor causes the electronic device to execute the solution provided in any of the above embodiments.

[0184] Those of ordinary skill in the art can understand that all or part of the steps for implementing the above method embodiments can be completed by hardware related to program instructions. The foregoing program can be stored in a computer-readable storage medium. When the program is executed, it performs the steps including the above method embodiments; and the foregoing storage medium includes various media that can store program codes, such as ROM, RAM, magnetic disks, or optical disks.

[0185] Those of ordinary skill in the art can understand that all or some of the steps in the methods disclosed above, and the functional modules / units in the systems and devices, can be implemented as software, firmware, hardware, and their appropriate combinations. In the hardware implementation, the division of the functional modules / units mentioned above does not necessarily correspond to the division of physical components; for example, a physical component can have multiple functions, or a function or a step can be executed by several physical components in cooperation. Some or all of the physical components can be implemented as software executed by a processor, such as a central processing unit, a digital signal processor, or a microprocessor, or be implemented as hardware, or be implemented as an integrated circuit, such as an application specific integrated circuit.

[0186] So far, the technical solutions of the present application have been described in conjunction with the preferred embodiments shown in the accompanying drawings. However, those skilled in the art can easily understand that the protection scope of the present application is obviously not limited to these specific embodiments. The above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements on some or all of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the various embodiments of the present application.

Claims

1. A multi - protocol compatible processing method for a protection system, characterized in that, the method includes: obtaining an access request through a single - instance system user or a unified entry component of the protection system; verifying whether the access request carries a Transport Layer Security (TLS) protocol; when the access request carries the TLS protocol, identifying the server name of the TLS protocol; when the server name of the TLS protocol is a preset name, identifying the target protocol type of the access request, and sending the access request to a network application server according to the target protocol type, where the target protocol type includes a Network Socket Security (NSS) protocol and an Open - source Remote Procedure Call Security (OpenRPC) protocol.

2. The method according to claim 1, characterized in that, when the server name of the TLS protocol is the preset name, identifying the target protocol type of the access request, and sending the access request to a network application server according to the target protocol type, includes: when the server name of the TLS protocol is the preset name, identifying the upgrade protocol header in the request header of the access request; when the upgrade protocol header contains a preset upgraded network socket protocol, identifying the target protocol type as the NSS protocol; sending the access request to the network application server according to the NSS protocol.

3. The method according to claim 2, characterized in that, when the upgrade protocol header does not contain the preset upgraded network socket protocol, identifying whether the access request is a Hypertext Transfer Protocol 2 (HTTP / 2); when the access request is HTTP / 2, identifying the target protocol type as the OpenRPC protocol; sending the access request to the network application server according to the OpenRPC protocol.

4. The method according to claim 1, characterized in that, when the access request does not carry the TLS protocol, identifying the upgrade protocol header in the request header of the access request; when the upgrade protocol header contains a preset upgraded network socket protocol, identifying the protocol type of the access request as a network socket protocol; sending the access request to the network application server according to the network socket protocol.

5. The method according to claim 4, characterized in that, when the upgrade protocol header does not contain the preset upgraded network socket protocol, identifying whether the access request is HTTP / 2; when the access request is HTTP / 2, identifying the protocol type of the access request as an OpenRPC protocol; sending the access request to the network application server according to the OpenRPC protocol.

6. The method according to claim 3 or 5, characterized in that, when the access request is not HTTP / 2, identifying the target network system architecture; when the target network system architecture is a Hypertext Transfer Security (HTTPS) protocol, sending the access request to the network application server according to the HTTPS protocol; When the target network system architecture is the Hypertext Transfer Protocol, send the access request to the network application server according to the Hypertext Transfer Protocol.

7. The method according to claim 2, wherein, before identifying the target protocol type as the network socket security protocol when the upgrade protocol header includes a preset upgrade network socket protocol, the method further includes: when the server name of the Transport Layer Security Protocol is not the preset name, verify whether the conversion method of the access request is passed; when the conversion method fails, identify the upgrade protocol header of the request header of the access request.

8. A multi-protocol compatible processing device for a protection system, wherein, the device includes: an access request acquisition module, configured to obtain an access request through a single-instance system user or a unified entry component of the protection system; a Transport Layer Security Protocol determination module, configured to verify whether the access request carries the Transport Layer Security Protocol; a server name determination module, configured to identify the server name of the Transport Layer Security Protocol when the access request carries the Transport Layer Security Protocol; a target protocol type determination module, configured to identify the target protocol type of the access request when the server name of the Transport Layer Security Protocol is the preset name, and send the access request to the network application server according to the target protocol type, where the target protocol type includes the network socket security protocol and the Open Source Remote Procedure Call Security Protocol.

9. An electronic device, wherein, it includes: a processor, and a memory communicatively connected to the processor; the memory stores computer-executable instructions; the processor executes the computer-executable instructions stored in the memory to implement the multi-protocol compatible processing method of the protection system according to any one of claims 1 to 7.

10. A computer-readable storage medium, wherein, the computer-readable storage medium stores computer-executable instructions, and when the computer-executable instructions are executed by a processor, they are used to implement the multi-protocol compatible processing method of the protection system according to any one of claims 1 to 7.