Illegal external connection detection method based on temporary device domain name
By registering a domain name on the Internet and building a domain name server, generating temporary domain names for intranet devices, and monitoring the protocol requests and responses of the monitoring device, the problem of difficult to detect illegal outreach intranet devices in the existing technology is solved, and the monitoring and detection effect without a client is achieved.
Patent Information
- Application Number
- CN202311775380.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-22
- Publication Date
- 2025-06-24
AI Technical Summary
The prior art is difficult to detect whether there are illegal outreach behaviors in intranet devices without installing clients, especially in smart terminals and mobile personnel scenarios.
By registering a third-level or second-level domain name on the Internet and building a special domain name server, generating temporary domain names for intranet devices, monitoring the device's protocol request and response, and recording date, time, IP and domain name information to determine whether the device is connected to the Internet.
It realizes illegal outreach behavior of intranet devices without client-side monitoring, with a wider monitoring scope and more convenient deployment, and supports protocols that are generally supported by IP devices.
Smart Images

Figure CN120200765A_ABST
Abstract
Description
Technical Field
[0001] The present invention provides a method for an internal network device to connect to an external network through a temporary device domain name, belonging to the technical field of network security. Background Art
[0002] With the continuous development and popularization of Internet technology, various terminal devices emerge in an endless stream, and more and more intelligent terminals and digital technologies are introduced into the enterprise internal network. In some enterprises or fields, it is often not allowed for internal devices to connect to the Internet. The most common technology is the detection method based on a client program, that is, by deploying a client program on a terminal computer to monitor whether the terminal is connected to the Internet. However, such technologies have problems that they cannot be installed on intelligent terminals and are inconvenient for mobile personnel. Summary of the Invention
[0003] Aiming at the deficiencies of the prior art, the present invention provides a method for detecting illegal external connection based on a device temporary domain name. This method can judge whether an internal network device has an illegal external connection by observing the behavior results of the internal network device from the outside without using a client.
[0004] To achieve the above object, the present invention is realized through the following technical solutions: A method for detecting illegal external connection based on a domain name, characterized by including the following steps: Step 1: Register a third-level or second-level domain name on the Internet. The common format of a second-level domain name is **.com, and the common format of a third-level domain name is **.com.cn; Step 2: Build a special domain name server (hereinafter referred to as Server A) on the Internet to support the resolution of the domain name in Step 1, and construct a batch of subordinate domain names for special purposes (for example, a.a.com.cn is a subordinate domain name of a.com.cn). Such subordinate domain names do not need to correspond to real websites; Step 3: When Server A receives any resolution of the special-purpose subordinate domain names in Step 2, it makes a detailed record of the visitor, and the recorded content includes: date, time, the IP of the visitor, and the accessed domain name. Then Server A discards the request or maps all special-purpose subordinate domain names to a certain special IP address and port; Step 4: Generate a unique number for each device in the internal network. Each number can uniquely correspond to a special-purpose subordinate domain name within the validity period. For example, it can be in the form of "number.**.com" or "number.**.com.cn"; Step 5: Deploy nodes in the intranet, listening for protocols such as SSDP, NBNS, LLMNR, and MDNS. Devices in the intranet will find the gateway address and the screen mirroring device address through the SSDP protocol; find the address of the proxy server through NBNS and LLMNR; find the address of the proxy server and the screen mirroring device address through MDNS. Step 6: When receiving any request from the intranet device in Step 4, reply to the device with its corresponding special-purpose subdomain name and record it in detail. The recorded content includes: date, time, the IP of the intranet device, and the returned domain name. Step 7: Determine whether the intranet device is connected to the Internet based on the records in Step 3 and Step 6. When there are two records with the same domain name and very close times, it can be determined that there is external connection. The internal IP of the device can be obtained from Step 6, and the external IP of the device can be obtained from Step 3.
[0005] The present invention provides a method for detecting illegal external connection based on device temporary domain names, having the following beneficial effects: 1. The present invention does not require installing a client on intranet devices, making it more convenient to monitor the device range and deploy. 2. The protocols monitored by the present invention are the protocols generally supported by current IP-based devices. Description of the Drawings
[0006] Figure 1 It is a flow chart of the present invention Figure 2 It is a schematic diagram of the network deployment of the present invention Detailed Embodiments
[0007] 1. Register a third-level or second-level domain name on the Internet. The common format of a second-level domain name is **.com, and the common format of a third-level domain name is **.com.cn. In this embodiment, it is assumed that the registered domain name is abcd.com.cn.
[0008] 2. Build a special domain name resolution server (hereinafter referred to as Server A) on the Internet, and apply for a public IP address for Server A. The domain name abcd.com.cn points to this IP address. At the same time, a batch of special-purpose subdomain names are opened on Server A. The format of the subdomain names is: number.abcd.com.cn; these subdomain names may not point to any IP address.
[0009] 3: Deploy monitoring devices (hereinafter referred to as Server B) on the intranet. Assign a number to each IP address on the intranet on the monitoring device, and then generate a temporary domain name for the intranet device based on the number. The temporary domain name space should be the same as the special domain name space of the external domain. For example, if the domain name registered on the external network is abcd.com.cn and the number of the internal device is 9873919353, then the temporary domain name of the internal device is 9873919353.abcd.com.cn; for security considerations, the number should be dynamically generated by a random number and have a lifecycle of 15 seconds.
[0010] 4: Deploy some nodes on the intranet. The nodes monitor the SSDP protocol. When receiving a message whose payload first line is M-SEARCH *HTTP / 1.1 and the ST field is urn:dial-multiscreen-org:service:dial:1, actively respond with a response message. In the response message, fill in the temporary domain name of the intranet device in the LOCATION field, and record <date, time, intranet device IP, intranet device temporary domain name>.
[0011] 5: The nodes monitor the LLMNR protocol (UDP port 5355). When receiving a payload that is the IP address for resolving the domain name wpad, actively respond with a response message. The IP address corresponding to wpad in the response message is the node IP address. When the intranet device receives the response, it will try to download the wpad.dat file from port 80 of the node. At this time, the node responds with an http 302 message (redirect), and the message carries the temporary domain name of the intranet device, and record <date, time, intranet device IP, intranet device temporary domain name>.
[0012] 6: The nodes monitor the MDNS (UDP port 5353) protocol. When receiving a payload that is the IP address for resolving the domain name wpad.local, actively respond with a response message. The IP address corresponding to wpad in the response message is the node IP address. When the intranet device receives the response, it will try to download the wpad.dat file from port 80 of the node. At this time, the node responds with an http 302 message (redirect), and the message carries the temporary domain name of the intranet device, and record <date, time, intranet device IP, intranet device temporary domain name>; when receiving a payload that is the domain name address for reverse resolving _googlecast._tcp.local, actively respond with a response message, and the response message carries the temporary domain name of the intranet device, and record <date, time, intranet device IP, intranet device temporary domain name>.
[0013] 7: Node monitoring NBNS (UDP port 137) protocol. When receiving an IP address for resolving the domain name WPAD in the payload, it actively responds with a response message. The IP address corresponding to WPAD in the response message is the node IP address. When the internal network device receives the response, it will attempt to download the wpad.dat file from port 80 of the node. At this time, the node responds with an http 302 message (redirect), and the message carries the temporary domain name of the internal network device, and records <date, time, internal network device IP, internal network device temporary domain name>.
[0014] 8: External network domain name server. When receiving a domain name resolution for a special domain name, it records <date, time, internal network device IP, requested domain name to be resolved>, and then discards the request message.
[0015] 9: The administrator regularly logs in to Server A and Server B. When it is found that there are records of the same special domain name in Service A and Server B and the domain name is valid, it can be determined that the internal network device has an external connection. The internal network IP address of the internal network device is the address recorded in Server B, the external network IP address is the address recorded in Server A, and the time of accessing the external network is the address recorded in A (the time in A is slightly greater than the time recorded in B).
[0016] The above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to the above embodiments, those of ordinary skill in the art should understand that: It is still possible to modify the specific implementation manners of the present invention or make equivalent replacements. Any modification or equivalent replacement without departing from the spirit and scope of the present invention shall be covered by the protection scope of the claims of the present invention.
Claims
1. The present invention provides a method for detecting illegal external connection based on a temporary device domain name, characterized in that It includes the following steps: Step 1: Deploy a monitoring device (hereinafter referred to as Server A) on the intranet. The monitoring device dynamically generates a unique number for each device on the intranet, and then generates a device temporary domain name for each intranet device based on this number; Step 2: Deploy nodes on the intranet. The nodes are used to probe and listen to protocols such as the SSDP protocol, NBNS, LLMNR, and MDNS; Step 3: For the SSDP protocol, the LOCATION field of the response message carries the device temporary domain name; for LLMNR and NBNS, the device temporary domain name is carried in the redirect message; for the MDNS protocol, the device domain name is directly replied according to the content of the message or the device temporary domain name is carried in the redirect message; after sending the device temporary domain name, record <date, time, intranet device IP, device domain name>; Step 4: Deploy a domain name server (hereinafter referred to as Server B) on the public network. Whenever the server receives a domain name resolution, detailed records are made, and the record content includes at least <date, time, visitor IP address, and device domain name>; Step 5: Determine whether the intranet device is connected to the Internet according to the records in Step 3 and Step 4. When there are two identical device domain names and the device domain name is within the valid period, it indicates that an external connection behavior has occurred. The intranet IP address of the device can be obtained from the records of Server A, and the external network IP address of the device can be obtained from the records of Server B.
2. The method for detecting illegal external connection based on a temporary device domain name according to claim 1, wherein Generate a unique device temporary domain name for each internal device.
3. The device domain name according to claim 2, characterized in that Dynamically generate a unique label (number or character) for each internal device, and use the label as the subordinate domain name to generate a device temporary domain name for the device. Each label has a short life cycle.
4. The method for detecting unauthorized external connection based on a temporary device domain name according to claim 1, wherein Carry the device temporary domain name described in Right 2 in the LOCATION of the SSDP protocol response message; When obtaining the address of the server through the LLMNR protocol and the NBNS protocol, transfer the request to the device temporary domain name through redirection; When using the MDNS protocol, directly reply the device domain name according to the content of the message or transfer the request to the device temporary domain name through redirection and actively reply.
5. The method for detecting illegal external connection based on a temporary device domain name according to claim 1, characterized in that The intranet monitoring device records <date, time, intranet device IP, device temporary domain name>, and the external network monitoring device records <date, time, device IP, requested domain name>. When there is the same domain name and the time interval is less than the life cycle, it is considered that an external connection behavior has occurred.