Intrusion security detection method, device, equipment, medium and program product

By integrating the filtered firewall system into a micro network card and connecting it with the server port, the problem of high cost and poor flexibility of deploying a firewall system for personal computers is solved, and efficient and flexible network security protection is achieved.

CN120223446AActive Publication Date: 2025-06-27ZIGUANG HENGYUE TECH CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202510703282.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-29
Publication Date
2025-06-27
Estimated Expiration
2045-05-29

AI Technical Summary

Technical Problem

The existing personal computers have high cost and poor flexibility to deploy firewall systems.

Method used

The firewall system filtered by the filtering rules is integrated into the micro network card, and a connection is established with the server port through the micro network card, and network data is processed securely based on security rules, including virus interception, network attack rules and access policies.

Benefits of technology

The external micro network card is used to perform network data security processing and security protection on the personal computer server, reducing costs and improving flexibility.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120223446A_ABST
    Figure CN120223446A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides an intrusion security detection method, device and equipment, a medium and a program product, and relates to the technical field of intrusion security, and the method comprises the steps: integrating a firewall system screened by a screening rule to a miniature network card; wherein the screening rule comprises a firewall interception screening rule; establishing connection between the miniature network card and a server port; when the server receives the network data, performing security processing on the network data through the firewall system based on the security rule; wherein the security rule comprises a virus interception rule, a network attack rule and an access strategy; if the network data accords with the security rule, releasing the network data through the firewall system; if the network data does not conform to the security rule, intercepting the network data through the firewall system; according to the firewall system integrated with the micro network card, security processing of network data is carried out on the server of the personal computer through the external micro network card, the flexibility is high, and the cost is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of intrusion security technology. Specifically, it relates to an intrusion security detection method, device, equipment, medium, and program product. Background Art

[0002] A firewall system refers to a combination of a series of components set between different networks (such as a trusted enterprise internal network and an untrusted public network) or network security domains. It can monitor, restrict, and change the data flow across the firewall, and shield the information, structure, and operating conditions inside the network from the outside as much as possible to achieve network security protection. Usually, a firewall system is deployed on a computer to protect network security. However, if a firewall system is deployed on a personal computer, the cost is relatively high and the flexibility is poor. Summary of the Invention

[0003] The purpose of the embodiments of this application is to provide an intrusion security detection method, device, equipment, medium, and program product to solve the problems that the existing personal computers have relatively high costs and poor flexibility if a firewall system is deployed.

[0004] In a first aspect, the embodiments of this application provide an intrusion security detection method applied to a micro network card externally connected to a server. The method includes: Integrate the firewall system screened by the screening rules into the micro network card; where the screening rules include firewall interception screening rules; Establish a connection between the micro network card and the server port; When the server receives network data, based on the security rules, perform security processing on the network data through the firewall system; where the security rules include: virus interception rules, network attack rules, and access policies; If the network data conforms to the security rules, release the network data through the firewall system; If the network data does not conform to the security rules, intercept the network data through the firewall system.

[0005] In the above implementation process, the firewall system screened by the screening rules is integrated into the micro network card; among them, the screening rules include firewall interception screening rules; a connection is established between the micro network card and the server port; when the server receives network data, based on the security rules, the network data is securely processed by the firewall system; among them, the security rules include: virus interception rules, network attack rules, and access policies; if the network data conforms to the security rules, the network data is released through the firewall system; if the network data does not conform to the security rules, the network data is intercepted through the firewall system; after the firewall system is integrated into the micro network card, the external micro network card is used to securely process and protect the network data of the personal computer server, with high flexibility and reduced costs.

[0006] Further, after establishing the connection between the micro network card and the server port, it further includes: Receiving the general protection function and / or customized function of the firewall system by the server according to the feature library; Performing function settings on the firewall system based on the general protection function, and / or, Performing customization processing on the firewall system based on the customized function; among them, the customized function includes: discard function, message setting, and protection setting.

[0007] In the above implementation process, according to requirements, the general protection function of the firewall system can be selected on the server side, or the customized function can be adopted.

[0008] Further, establishing the connection between the micro network card and the server port includes: Docking the micro network card with the set server port to establish a connection between the micro network card and the server port.

[0009] In the above implementation process, a dedicated server port connected to the micro network card is set to implement the security protection function.

[0010] Further, the firewall system screened by the screening rules includes: Based on the screening rules, the firewall interception function and storage function of the firewall system are retained to obtain the screened firewall system.

[0011] In the above implementation process, only the core functions of the firewall system are retained, and the redundant functions are removed to ensure the miniaturization of the network card, improve the flexibility of use, and reduce costs.

[0012] Further, the case where the network data conforms to the security rules includes: According to the security rules, if it is detected that the network data does not have a virus or network attack and the network data conforms to the access policy, it is determined that the network data conforms to the security rules.

[0013] In the above implementation process, it is determined that the network data complies with the security rules, so that the network data can be released, and the network security protection of the server is realized.

[0014] Further, if the network data does not comply with the security rules, it includes: According to the security rules, if it is detected that the network data has a virus or a network attack, or the network data does not comply with the access policy, it is determined that the network data does not comply with the security rules.

[0015] In the above implementation process, it is determined that the network data complies with the security rules, so that the network data can be intercepted, and the network security protection of the server is realized.

[0016] In a second aspect, an intrusion security detection device provided by an embodiment of the present application is integrated in a micro network card externally connected to a server, and the device includes: A system integration module, configured to integrate the firewall system after being screened by the screening rules into the micro network card; wherein, the screening rules include firewall interception screening rules; A connection establishment module, configured to establish a connection between the micro network card and the server port; A security processing module, configured to, when the server receives network data, perform security processing on the network data through the firewall system based on the security rules; wherein, the security rules include: virus interception rules, network attack rules, and access policies; A release operation module, configured to, if the network data complies with the security rules, release the network data through the firewall system; An interception operation module, configured to, if the network data does not comply with the security rules, intercept the network data through the firewall system.

[0017] In a third aspect, an electronic device provided by an embodiment of the present application includes: A processor, a memory, and a bus, the processor is connected to the memory through the bus, and the memory stores computer-readable instructions, which are used to implement the intrusion security detection method as described above when executed by the processor.

[0018] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a server, it implements the intrusion security detection method as described above.

[0019] In a fifth aspect, an embodiment of the present application provides a computer program product, the computer program product includes instructions, and when the instructions are executed by a computer, the computer implements the intrusion security detection method as described above. Brief Description of the Drawings

[0020] To more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required for use in the embodiments of the present application will be briefly introduced below. It should be understood that the following drawings only show some embodiments of the present application, and thus should not be regarded as limiting the scope. For those of ordinary skill in the art, without creative efforts, other related drawings can also be obtained based on these drawings.

[0021] Figure 1 It is a schematic flowchart of an intrusion security detection method provided by an embodiment of the present application; Figure 2 It is a schematic flowchart of an intrusion security detection device provided by an embodiment of the present application; Figure 3 It is a schematic structural diagram of an electronic device provided by an embodiment of the present application. Detailed Description of the Embodiments

[0022] The technical solutions in the embodiments of the present application will be described below with reference to the drawings in the embodiments of the present application.

[0023] It should be noted that: similar reference numerals and letters indicate similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings. At the same time, in the description of the present application, terms such as "first", "second", etc. are only used for distinguishing descriptions and cannot be understood as indicating or implying relative importance.

[0024] Please refer to Figure 1 , Figure 1 It is a schematic flowchart of an intrusion security detection method provided by an embodiment of the present application. This intrusion security detection method is applied to a micro network card externally connected to a server. The method includes: 100. Integrate the firewall system screened by the screening rules into the micro network card; wherein, the screening rules include firewall interception screening rules.

[0025] It can be understood that the screening rules can be set according to requirements, retaining the relevant and necessary functions of the firewall system that are desired, or can be automatically generated according to the specific usage requirements of a personal computer, retaining the necessary functions, and integrating the firewall system into the micro network card. Further, the automatic generation of screening rules can be to generate a firewall interception function according to the usage requirements of a personal computer. This firewall interception function only intercepts set types of network data or network traffic, and the set types of network data or network traffic can be traffic data that poses a threat to a personal computer.

[0026] It should be noted that integrating the firewall system into the micro network card includes screening the software functions and hardware structures of the firewall system, removing the relevant hardware of the functions that do not meet the screening rules, and ensuring the miniaturization of the network card.

[0027] Optionally, based on the screening rules, retain the firewall interception function and storage function of the firewall system to obtain the screened firewall system, only retain the core functions of the firewall system, remove the redundant functions, ensure the miniaturization of the network card, improve the flexibility of use, and reduce costs. Among them, remove the redundant functions, such as functions like encrypted communication, traffic monitoring and analysis, and authentication.

[0028] Optionally, the network card can adopt a DSP (Digital Signal Processor Network Interface Card) network card, which is a dedicated network adapter integrating a digital signal processor, mainly used in real-time signal processing, high-speed data operation, and low-latency communication scenarios.

[0029] 200. Establish a connection between the micro network card and the server port.

[0030] Specifically, dock the micro network card with the configured server port to establish a connection between the micro network card and the server port; thus, set up a dedicated server physical port for connecting to the micro network card, which is simple and fast, and can achieve the security protection function without setting too many ports.

[0031] 300. When the server receives network data, based on the security rules, perform security processing on the network data through the firewall system; among them, the security rules include: virus interception rules, network attack rules, and access policies.

[0032] Exemplarily, based on the security rules, perform security processing on the network data through the firewall system. Security processing can be carried out based on the rule matching priority, such as giving priority to executing the virus interception rule to prevent malicious software from entering the network; then execute the network attack rule: detect attack behaviors such as DDoS and SQL injection; finally, apply the access policy to control the access rights of legitimate traffic.

[0033] Exemplarily, based on the security rules, perform security processing on the network data through the firewall system. Security processing can be carried out based on the dual-engine collaborative detection, such as the stateless rule engine: quickly match the characteristics of a single data packet (such as IP / port blacklist); the stateful rule engine: analyze the traffic context (such as connection status, protocol behavior) to identify hidden attacks.

[0034] 400. If the network data conforms to the security rules, then release the network data through the firewall system.

[0035] Specifically, according to the security rules, if it is detected that the network data does not contain viruses or network attacks and the network data complies with the access policy, it is determined that the network data complies with the security rules; it is determined that the network data complies with the security rules, so that the network data can be released, realizing the network security protection of the server.

[0036] 500. If the network data does not comply with the security rules, the firewall system intercepts the network data.

[0037] Specifically, according to the security rules, if it is detected that the network data contains viruses or network attacks, or the network data does not comply with the access policy, it is determined that the network data does not comply with the security rules; it is determined that the network data complies with the security rules, so that the network data can be intercepted, realizing the network security protection of the server.

[0038] As described above, in the embodiment of the present application, the firewall system screened by the screening rules is integrated into the micro network card; wherein, the screening rules include firewall interception screening rules; a connection between the micro network card and the server port is established; when the server receives network data, based on the security rules, the firewall system performs security processing on the network data; wherein, the security rules include: virus interception rules, network attack rules and access policies; if the network data complies with the security rules, the firewall system releases the network data; if the network data does not comply with the security rules, the firewall system intercepts the network data; after the firewall system is integrally set in the micro network card, the external micro network card performs security processing and security protection on the network data of the server of the personal computer, with high flexibility and reduced costs.

[0039] Based on the above embodiment, the intrusion security detection method of the embodiment of the present application can be further specified as: after establishing the connection between the micro network card and the server port, it further includes: Receiving the general protection function and / or customized function of the firewall system by the server according to the feature library; performing function setting on the firewall system based on the general protection function, and / or performing customized processing on the firewall system based on the customized function; wherein, the customized function includes: discard function, message setting and protection setting.

[0040] Optionally, the server can customize the functions of the firewall system according to requirements, can directly select the general protection function of the firewall system, or can screen out the message types that need security protection from the feature library according to the stored feature library, etc., to customize the functions of the firewall system, so that the firewall system only performs security processing on the screened message types; it can be understood that the server side can also select the general protection function and the customized function at the same time, and perform customized settings on the basis of the general protection function, which can be multiple defenses for specific message types, etc.

[0041] Thus, according to requirements, the general protection function of the firewall system can be selected on the server side, or customized functions can be adopted.

[0042] Exemplarily, function customization for discarding, such as anti-DDoS (Distributed Denial of Service) protection: setting a SYN packet rate threshold and discarding connection requests exceeding the threshold; for example, internal network violation control: discarding traffic accessing illegal websites (such as gambling and phishing sites). Among them, the SYN packet is a type of data packet in the TCP protocol used to initiate a connection request. The SYN packet contains the SYN flag bit and other necessary information, such as source port, destination port, sequence number, etc.

[0043] Exemplarily, customization of packet settings, such as setting the packet type to allow specific types of packets to enter.

[0044] Exemplarily, customization of protection settings, such as setting intrusion detection or defense rules, setting a virus scanning engine, setting an access control policy, etc.

[0045] The above steps are not strictly executed in the order described by the numbers and should be understood as an overall solution.

[0046] In a second aspect, based on the above embodiments, the embodiments of the present application further provide an intrusion security detection device integrated with a micro network card externally connected to the server. Refer to Figure 2 , the intrusion security detection device provided in this embodiment specifically includes: a system integration module 201, a connection establishment module 202, a security processing module 203, an approval operation module 204, and an interception operation module 205.

[0047] Among them, the system integration module 201 is used to integrate the firewall system screened by the screening rules into the micro network card; among them, the screening rules include firewall interception screening rules; the connection establishment module 202 is used to establish a connection between the micro network card and the server port; the security processing module 203 is used to, when the server receives network data, based on security rules, perform security processing on the network data through the firewall system; among them, the security rules include: virus interception rules, network attack rules, and access policies; the approval operation module 204 is used to, if the network data conforms to the security rules, release the network data through the firewall system; the interception operation module 205 is used to, if the network data does not conform to the security rules, intercept the network data through the firewall system.

[0048] As described above, in the embodiment of the present application, the firewall system screened by the screening rules is integrated into the micro network card; wherein, the screening rules include firewall interception screening rules; a connection between the micro network card and the server port is established; when the server receives network data, based on the security rules, the network data is securely processed by the firewall system; wherein, the security rules include: virus interception rules, network attack rules, and access policies; if the network data conforms to the security rules, the network data is allowed to pass through the firewall system; if the network data does not conform to the security rules, the network data is intercepted by the firewall system; after the firewall system is integrated into the micro network card, the external micro network card is used to securely process and protect the network data of the server of the personal computer, with high flexibility and reduced costs.

[0049] In a third aspect, an embodiment of the present application further provides an electronic device, which can integrate the intrusion security detection device with the user-state polling mechanism provided by the embodiment of the present application. Figure 3 It is a schematic structural diagram of an electronic device provided by an embodiment of the present application. Refer to Figure 3 , the electronic device includes: an input device 43, an output device 44, a memory 42, and one or more processors 41; the memory 42 is used to store one or more programs; when the one or more programs are executed by the one or more processors 41, the one or more processors 41 implement the intrusion security detection method with the user-state polling mechanism as provided in the above embodiment. Among them, the input device 43, the output device 44, the memory 42, and the processor 41 can be connected by a bus or other means, Figure 3 Taking the connection by bus as an example.

[0050] The processor 41 executes various functional applications and data processing of the device by running software programs, instructions, and modules stored in the memory 42, that is, implements the above-mentioned intrusion security detection method with the user-state polling mechanism.

[0051] The above-provided electronic device can be used to execute the intrusion security detection method with the user-state polling mechanism provided in the above embodiment, and has corresponding functions and beneficial effects.

[0052] In a fourth aspect, an embodiment of the present application further provides a computer-readable storage medium, which includes a stored computer program; wherein, when the computer program runs, it controls the device where the computer-readable storage medium is located to execute the intrusion security detection method as described above, and can achieve the same beneficial effects.

[0053] Certainly, the storage medium containing computer-executable instructions provided by the embodiments of the present application is not limited to the intrusion security detection method as described above, and can also execute the related operations in the intrusion security detection method provided by any embodiment of the present application.

[0054] In a fifth aspect, the embodiments of the present application further provide a computer program product. The methods described in the embodiments of the present application can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer programs or instructions. When the computer program or instructions are loaded and executed on a computer, the processes or functions described in the embodiments of the present application are executed in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, a network device, a user device, a core network device, an OAM (Open Application Model), or other programmable devices.

[0055] The computer program or instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer program or instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center in a wired or wireless manner. The computer-readable storage medium can be any available medium that can be accessed by a computer, or a data storage device such as a server or data center integrating one or more available media. The available medium can be a magnetic medium, such as a floppy disk, a hard disk, or a magnetic tape; it can also be an optical medium, such as a digital video disc; or it can be a semiconductor medium, such as a solid-state drive. The computer-readable storage medium can be a volatile or non-volatile storage medium, or can include both volatile and non-volatile types of storage media.

[0056] In several embodiments provided by the present application, it should be understood that the disclosed devices and methods can also be implemented in other ways. The device embodiments described above are merely illustrative. For example, the flowcharts and block diagrams in the accompanying drawings show the possible architectures, functions, and operations of devices, methods, and computer program products according to multiple embodiments of the present application. In this regard, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code, and the module, program segment, or part of code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order from that marked in the accompanying drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, as well as the combination of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or actions, or can be implemented by a combination of dedicated hardware and computer instructions.

[0057] In addition, in each embodiment of the present application, the functional modules can be integrated together to form an independent part, or each module can exist alone, or two or more modules can be integrated to form an independent part.

[0058] If the above functions are implemented in the form of software function modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present application. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), magnetic disks, or optical discs that can store program codes.

[0059] The above description is only for the embodiments of the present application and is not intended to limit the protection scope of the present application. For those skilled in the art, the present application can have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application. It should be noted that similar reference numerals and letters represent similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings.

[0060] As described above, this is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present application can easily think of changes or substitutions, which should all be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

[0061] It should be noted that in this text, relational terms such as "first" and "second" are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising a..." does not exclude the existence of additional identical elements in the process, method, article or device comprising the element.

Claims

1. An intrusion security detection method, characterized in that, Applied to a micro network card externally connected to a server, the method includes: Integrating a firewall system filtered by a filtering rule into the micro network card; wherein, the filtering rule includes a firewall interception filtering rule; Establishing a connection between the micro network card and the server port; When the server receives network data, based on a security rule, performing security processing on the network data through the firewall system; wherein, the security rule includes: a virus interception rule, a network attack rule, and an access policy; If the network data conforms to the security rule, the firewall system releases the network data; If the network data does not conform to the security rule, the firewall system intercepts the network data.

2. The intrusion security detection method according to claim 1, wherein After establishing the connection between the micro network card and the server port, it further includes: Receiving the general protection function and / or customized function of the firewall system by the server according to a feature library; Performing function setting on the firewall system based on the general protection function, and / or, Performing customized processing on the firewall system based on the customized function; wherein, the customized function includes: a discard function, a message setting, and a protection setting.

3. The intrusion security detection method according to claim 1, wherein The establishing of the connection between the micro network card and the server port includes: Docking the micro network card with a set server port to establish a connection between the micro network card and the server port.

4. The intrusion security detection method according to claim 1, wherein The firewall system filtered by the filtering rule includes: Based on the filtering rule, retaining the firewall interception function and storage function of the firewall system to obtain the filtered firewall system.

5. The intrusion security detection method according to claim 1, characterized in that, The case where the network data conforms to the security rule includes: According to the security rule, if it is detected that the network data does not have a virus or a network attack, and the network data conforms to the access policy, it is determined that the network data conforms to the security rule.

6. The intrusion security detection method according to claim 1, characterized in that, The case where the network data does not conform to the security rule includes: According to the security rule, if it is detected that the network data has a virus or a network attack, or the network data does not conform to the access policy, it is determined that the network data does not conform to the security rule.

7. An intrusion security detection device, characterized in that, Integrated into a micro network card externally connected to a server, the device includes: A system integration module for integrating a firewall system filtered by a filtering rule into the micro network card; wherein, the filtering rule includes a firewall interception filtering rule; A connection establishment module for establishing a connection between the micro network card and the server port; A security processing module for, when the server receives network data, performing security processing on the network data through the firewall system based on a security rule; wherein, the security rule includes: a virus interception rule, a network attack rule, and an access policy; A release operation module for, if the network data conforms to the security rule, releasing the network data through the firewall system; An interception operation module for, if the network data does not conform to the security rule, intercepting the network data through the firewall system.

8. An electronic device, characterized in that, It includes: A processor, a memory, and a bus. The processor is connected to the memory through the bus. The memory stores computer-readable instructions. When the computer-readable instructions are executed by the processor, they are used to implement the intrusion security detection method according to any one of claims 1-6.

9. A computer-readable storage medium, characterized in that, A computer program is stored on the computer-readable storage medium, and when the computer program is executed by a server, it implements the intrusion security detection method according to any one of claims 1-6.

10. A computer program product, characterized in that, The computer program product includes instructions that, when executed by a computer, cause the computer to implement the method according to any one of claims 1-6.

Citation Information

Patent Citations

  • Network safe network card

    CN2922301Y

  • Designing firewall for home network using raspberry-pi

    IN202441014485A

  • Distributed firewall system and method

    US20030126468A1

  • Embedded Firewall at a Telecommunications Endpoint

    US20080148384A1

  • Network security functions for dynamic construction and programmatic placement

    US20250039130A1