Illegal external connection detection method based on proxy configuration file
By deploying proxy configuration file download services on the intranet and building a domain name server on the Internet, using proxy configuration files and domain name resolution technology, the problem of intranet devices being unable to detect illegally connecting to the external network in the existing technology is solved, and the detection effect of no client and no simultaneous connection to the intranet and the Internet is achieved.
Patent Information
- Application Number
- CN202311775367.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-22
- Publication Date
- 2025-06-24
AI Technical Summary
When the prior art detects whether the intranet device is illegally connected to the external network, there is a problem that the client cannot be installed, and the method that does not rely on the client requires the intranet device to connect to the intranet and the Internet at the same time.
By deploying the proxy configuration file download service server A on the intranet and building a domain name server B on the Internet, using proxy configuration file and domain name resolution technology, illegal outreach detection of intranet devices is achieved without the need for a client or connection between the intranet and the Internet at the same time.
It realizes illegal outreach detection without client and simultaneous connection of the intranet and the Internet, and monitors the scope and deployment of equipment more conveniently and covers a wide range of scenarios.
Smart Images

Figure CN120200764A_ABST
Abstract
Description
Technical Field
[0001] The present invention provides a method for enabling an internal network device to connect to an external network through a special proxy configuration file, belonging to the technical field of network security. Background Art
[0002] With the continuous development and popularization of Internet technology, various terminal devices emerge in an endless stream, and more and more intelligent terminals and digital technologies are introduced into the enterprise internal network. In some enterprises or fields, internal devices are often not allowed to connect to the Internet. The most common technology is the detection method based on a client program, that is, by deploying a client program on a terminal computer to monitor whether the terminal is connected to the Internet. However, such technologies have problems that they cannot be installed on intelligent terminals and are inconvenient for mobile personnel. And some methods that do not rely on clients require some specific applications or services to run on internal network devices and connect to both the internal network and the Internet at the same time. Summary of the Invention
[0003] Aiming at the deficiencies of the prior art, the present invention provides a method for detecting illegal external connection based on a proxy configuration file. This method can be used without a client and does not require an internal network device to connect to both the internal network and the Internet at the same time.
[0004] To achieve the above object, the present invention is realized through the following technical solutions: A method for detecting illegal external connection based on a proxy configuration file, characterized by including the following steps:
[0005] Step 1: Deploy a node in the internal network (hereinafter referred to as Server A), and the node provides a service for downloading a proxy configuration file, that is, provides a download service for the wpad.dat file;
[0006] Deployment 2: If a DHCP or DNS server is provided in the internal network, point the server for downloading the proxy configuration file to Server A. Otherwise, listen to protocols such as NBNS, LLMNR, and MDNS, and requests from internal network devices to find a proxy configuration file that can be downloaded are directed to Server A;
[0007] Step 3: Set up a domain name server on the Internet (hereinafter referred to as Server B) to be responsible for resolving special domain names;
[0008] Step 4: When Server A receives a request to download a proxy configuration file (wpad.dat), provide different and unique wpad.dat for each internal network device that requests it, that is, the proxy access points provided by different internal network devices are different, and set this configuration file to a relatively long retention time and make a detailed record. The recorded content includes: date, time, internal network device IP address, and wpad.dat content;
[0009] Step 5: After receiving a special domain name, Server B resolves the IP address of the intranet device from the domain name after completing the domain name validity check.
[0010] The present invention provides a method for detecting illegal external connections based on domain names, having the following beneficial effects:
[0011] 1. The present invention does not require installing a client on the intranet device, making it more convenient to monitor the device range and deploy.
[0012] 2. The protocol used in the present invention is a protocol commonly supported by current IP-enabled devices.
[0013] 3. The present invention covers a wide range of scenarios, not only supporting the inspection of intranet devices connecting to both the intranet and the Internet simultaneously, but also supporting the inspection of intranet devices connecting to the Internet after disconnecting from the intranet. Description of the Drawings
[0014] Figure 1 is the format of the host domain name
[0015] Figure 2 is the flow chart of the present invention
[0016] Figure 3 is the schematic diagram of the network deployment of the present invention Detailed Embodiment
[0017] 1. Deploy nodes in the intranet (hereinafter referred to as Server A). The node starts a service on TCP port 80, that is, it supports intranet devices to download the wpad.dat file through an HTTP GET request.
[0018] 2. If a DHCP service is deployed in the intranet, option 252 is enabled and the IP address is configured as the address of Server A; if a DNS service is deployed in the intranet, the resolution of the wpad domain name is added to the DNS, and its corresponding IP address is configured as the address of Server A.
[0019] 3. When there is no DHCP and DNS service in the intranet, deploy some nodes in the intranet, and by adjusting the network configuration, the NBNS, LLMNR, and MDNS packets are directed to the nodes.
[0020] 4. After the node receives requests for NBNS, LLMNR, and MDNS, if it is a request for the wpad file, it actively sends a response packet, and the address of Server A is carried in the response packet.
[0021] 5: When Server A receives an HTTP GET / wpad.dat HTTP / 1.0 request on port 80, it provides different wpad.dat files according to the IP address. According to the standard, the wpad.dat file should contain at least one FindProxyForURL(url,host) function written in JavaScript. In this method, for access between internal network devices, the FindProxyForURL() function returns direct access. For other cases, it returns the host domain name that can uniquely identify this internal network device. The host domain name format is as follows Figure 1 shown, where A0 to A7 are unique strings randomly generated for each IP in the internal network in advance, with a string length of 7, and B0 to B3 are IP address check bits of 3 bytes; finally, the following parameter is carried synchronously in the HTTP response: Cache-Control: max-age=604800 (the network proxy configuration file is valid for one week); Server A updates all host domain names every month.
[0022] 6: Devices that have connected to the internal network within one week will still try to establish a connection with the proxy server according to the requirements in the proxy configuration file when connecting to the Internet.
[0023] 7: When the external network server B receives a domain name resolution for a special domain name, it records <date, time, device IP, requested special domain name>, and then discards the request message.
[0024] 8: The administrator logs in to Server B regularly and imports the data recorded by Server B into Server A. Server A first resolves A 0~6 and B 0~1 from the domain names recorded by Server B, then finds the corresponding IP address according to A 0~6 , then calculates the checksum. If the checksum == B 0~1 , it is considered that an external connection has occurred. The external connection record is <external connection time, device internal network IP, device external network IP, special domain name accessed by the device, time when the device obtained the configuration file>, where Server A provides "device internal network IP" and "time when the device obtained the configuration file", and Server B provides "external connection time", "device external network IP" and "special domain name accessed by the device".
[0025] The above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to the above embodiments, those of ordinary skill in the art should understand that: still can modify the specific implementation manners of the present invention or make equivalent replacements, and any modification or equivalent replacement without departing from the spirit and scope of the present invention should be covered within the protection scope of the claims of the present invention.
Claims
1. The present invention provides a method for detecting unauthorized external connections based on a proxy configuration file, characterized in that It includes the following steps: Step 1: Deploy a device (hereinafter referred to as Server A) that provides the download service of the network proxy configuration file (wpad.dat) in the intranet. Server A provides a unique and different network proxy configuration file for each device in the intranet; Step 2: Modify the configurations of the DHCP service and DNS service in the intranet, that is, set the IP address providing the network proxy configuration file download service to the IP address of Server A. If there is no DHCP and DNS protocols in the intranet, then by listening to the NBNS, LLMNR, and MDNS protocols, actively respond to the requests of the intranet devices to find the IP address of the network proxy configuration file download service; Step 3: When Server A receives a request to download the wpad.dat file, provide the corresponding unique and different configuration file for the device according to the source IP of the device; Step 4: Deploy a domain name server (hereinafter referred to as Server B) on the public network. Whenever the server receives a domain name resolution, make a detailed record, and the record content includes at least <date, time, visitor IP address, and domain name for which the resolution is requested>; Step 5: Judge whether the intranet device is connected to the Internet according to the records in Step 3 and Step 4. First, resolve the intranet IP address from the record in Step 4, then judge whether the IP is valid, and finally report an external connection warning. The intranet IP address of the device can be obtained from the record of Server A, and the external network IP address of the device can be obtained from the record of Server B.
2. The method for detecting illegal external connection based on a proxy configuration file according to claim 1, characterized in that Generate a unique and different network proxy configuration file for each internal device.
3. The unique network proxy configuration file as described in claim 2, characterized in that Generate a unique proxy server domain name for each intranet device, and generate the corresponding network proxy configuration file based on this.
4. Each internal device as claimed in claim 3 generates a unique proxy server domain name, characterized in that Point the request to access the Internet to the proxy server, that is, access the Internet through the proxy server, and at the same time, the host domain name of the proxy server has the ability to prevent forgery and can be updated regularly.
5. The method for detecting unauthorized external connection based on a proxy configuration file according to claim 1, wherein When receiving a request from an intranet device to download a network proxy configuration file, the intranet device can only download the corresponding network proxy configuration file.
6. Deploy a domain name resolution server on the external network. When the server records receive a resolution service for a special domain name, record <date, time, device IP, domain name for which the resolution is requested>.
7. The method for detecting illegal external connection based on a proxy configuration file according to claim 1, wherein Obtain the record from Server B, combine the data on Server A, first resolve the IP and checksum from the "domain name for which the resolution is requested", then calculate the checksum using the IP address, and then compare whether the two checksums are the same. If they are the same, report an external connection warning.