Illegal external connection detection method based on screen projection protocol

By using the screen projection protocol and SSDP protocol between the intranet device and the public network server to generate unique numbers and record URL access, the problem of intranet device connection Internet detection in the prior art is solved, and extensive monitoring and detection of client-free installation is achieved.

CN120200763APending Publication Date: 2025-06-24HUIDUN INFORMATION SECURITY TECH (SUZHOU) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311775346.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-12-22
Publication Date
2025-06-24

AI Technical Summary

Technical Problem

When the prior art detects whether the intranet device is connected to the Internet, there is a problem that the smart terminal cannot install the client and is inconvenient to the mobile personnel.

Method used

Violation outreach detection method based on screen projection protocol is adopted, by deploying monitoring devices and nodes on the intranet, using SSDP protocol to generate a unique number, and deploying servers on the public network to record URL access, and determining whether the intranet device is connected to the Internet.

Benefits of technology

It realizes illegal outreach detection without installing clients on intranet devices, has a wider monitoring range, is more convenient to deploy, and supports the currently commonly used IP device protocol.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120200763A_ABST
    Figure CN120200763A_ABST
Patent Text Reader

Abstract

The invention relates to the field of information security, and discloses an illegal external connection detection method based on a screen projection protocol, and the method comprises the steps: deploying equipment in an intranet, monitoring an SSDP protocol, actively sending an SSDP response message, carrying a special URL in the response message, and deploying a URL server outside the intranet. The method does not depend on deployment of client software on intranet equipment, and the SSDP is in an open state by default, so that the method has a wide application range.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention provides a method for connecting an internal network device to the external network through a screen mirroring protocol, belonging to the technical field of network security. Background Art

[0002] With the continuous development and popularization of Internet technology, various terminal devices emerge in an endless stream, and more and more intelligent terminals and digital technologies are introduced into the enterprise internal network. In some enterprises or fields, internal devices are often not allowed to connect to the Internet. The most common technology is the detection method based on the client program, that is, by deploying the client program on the terminal computer to monitor whether the terminal is connected to the Internet, but this kind of technology has the problems that it cannot be installed in intelligent terminals and is inconvenient for mobile personnel. Summary of the Invention

[0003] Aiming at the deficiencies of the prior art, the present invention provides a method for detecting illegal external connection based on domain name. This method can judge whether an internal network device has an illegal external connection by observing the behavior results of the internal network device from the outside without using a client.

[0004] To achieve the above objectives, the present invention is realized through the following technical solutions: A method for detecting illegal external connection based on the screen mirroring protocol, characterized by including the following steps: Step 1: Deploy a monitoring device in the internal network. The monitoring device generates a unique number for each device in the internal network, and a one-to-one mapping relationship needs to be formed between each number and the internal device; Step 2: Deploy a node in the internal network. The node is used to probe and listen to the SSDP protocol, and the internal network device will find the screen mirroring device address through the SSDP protocol; Step 3: When the node device receives the SSDP packet sent by the internal network device, it mainly sends a response packet, and a special URL path is carried in the packet. The path contains number information and is recorded in detail. The recorded content includes at least <date, time, internal device IP address, and special URL>; Step 4: Deploy a server on the public network to provide access services for the above URL path. Whenever the server receives an access to a special and valid URL, it records in detail. The recorded content includes at least <date, time, visitor IP address, and special URL>; Step 5: Judge whether the internal network device is connected to the Internet according to the records in Step 3 and Step 4. When there are two records with the same special URL path and very close times, it can be judged that there is an external connection. The internal network IP address of the device can be obtained from Step 3, and the external network IP address of the device can be obtained from Step 4.

[0005] The present invention provides a method for detecting illegal external connection based on domain name. It has the following beneficial effects: 1: The present invention does not require installing a client on the intranet devices, making it more convenient to monitor the device scope and deploy. 2: The protocol monitored by the present invention is a protocol generally supported by current IP-based devices. BRIEF DESCRIPTION OF THE DRAWINGS

[0006] Figure 1 It is a flowchart of the present invention Figure 2 Schematic diagram of network deployment for the present invention DETAILED DESCRIPTION OF THE INVENTION

[0007] 1: Deploy a monitoring device (hereinafter referred to as device A) on the intranet. The monitoring device maps the IP address of each intranet device to a unique number (hereinafter referred to as the device number), and records this mapping relationship.

[0008] 2: Deploy a node on the intranet. The node joins the multicast group of 239.255.255.250 and listens on port 1900 (the well-known port of the SSDP protocol). When receiving a message with the first line of the payload being M-SEARCH * HTTP / 1.1 and the ST field being urn:dial-multiscreen-org:service:dial:1, start the response mechanism.

[0009] 3: Construct a special URL. The format of the URL is IP:PORT / path / device.xml, where IP is the IP address of the external detection device, PORT = (public IP + random number + device number) / 65536, path = encrypt(str(time) + str(random number) + str(device number)), and the time granularity is 10 seconds. Such a design is to prevent malicious access by public network users, resulting in misjudgment of the system.

[0010] 4: Assemble the LOCATION field according to the requirements of the SSDP protocol, that is, the LOCATION field carries the just-constructed special URL, and then send the response message to the corresponding intranet device. If the intranet device is also connected to the Internet at this time, it will send a request to the IP address in the URL.

[0011] 5: Deploy an external detection device (hereinafter referred to as device B). When receiving an access to the special URL, decrypt the path of the URL address using the same algorithm, and then generate the PORT port. If the generated port is the same as the port carried in the message, it is considered that the URL is valid, and then record <date, time, intranet device IP, returned special domain name>, and then discard the request message; for other cases, directly discard the message.

[0012] 6: View the recorded information on Device A and Device B. If it is found that there are records pointing to the same URL on both devices, and the time recorded on Device A is slightly earlier than that on Device B, it is considered that an internal network device has accessed the external network. The internal network IP address of the internal network device comes from the record on Device A, and the external network IP address of the internal network device comes from the record on Device B.

[0013] The above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them. Although the present invention has been described in detail with reference to the above embodiments, those of ordinary skill in the art should understand that: modifications or equivalent replacements can still be made to the specific implementation manners of the present invention, and any modifications or equivalent replacements that do not depart from the spirit and scope of the present invention shall be covered by the protection scope of the claims of the present invention.

Claims

1. The present invention provides a method for detecting unauthorized external connections based on a screen mirroring protocol, characterized in that It includes the following steps: Step 1: Deploy monitoring devices on the internal network. Each monitoring device generates a unique number for each device on the internal network, and a one-to-one mapping relationship needs to be formed between each number and the internal device; Step 2: Deploy nodes on the internal network. The nodes are used to probe and listen to the SSDP protocol; Step 3: When the node device receives the SSDP message sent by the internal network device, it actively sends a response message. The message carries a special URL, which contains at least the number information of the internal network device, and details of the response action are recorded. The recorded content includes at least <date, time, internal device IP address, and special URL>; Step 4: Deploy a server that provides access services for the above URL on the public network. Whenever the server receives an access to the above URL, after completing the validity check of the URL, detailed records are made. The recorded content includes at least <date, time, visitor IP address, and special URL>. Access requests that do not pass the validity check are not recorded; Step 5: Determine whether the internal network device is connected to the Internet based on the records in Step 3 and Step 4. When there are two records with the same URL and very close times, it indicates that an external connection behavior has occurred. The internal network IP address of the device can be obtained from the record in Step 3, and the external network IP address of the device can be obtained from the record in Step 4.

2. The method for detecting illegal external connection based on the screen mirroring protocol according to claim 1, wherein Generate a special URL for each internal device.

3. The special URL according to claim 2, characterized in that The URL contains the identification information of the internal device. The identification information should correspond one-to-one with the device, and the URL should have timeliness and a certain anti-forgery ability.

4. The method for detecting illegal external connection based on the screen mirroring protocol according to claim 1, characterized in that Actively monitor the SSDP protocol and actively respond.

5. The active response according to claim 4, wherein Carry the special URL described in Claim 3 in the LOCATION.

6. The method for detecting illegal external connection based on a screen mirroring protocol according to claim 1, wherein Deploy a URL access server on the external network and record valid special URLs.

7. The method for detecting illegal external connection based on screen mirroring protocol according to claim 1, wherein Deploy monitoring devices on the internal network to monitor specific SSDP protocol messages. The response message to the internal network device contains a special URL.