Intrusion security detection method, apparatus, device, medium and program product
By integrating a filtered firewall system into a micro network card on a personal computer and connecting it to a server port, and processing network data based on virus interception rules and access policies, the problem of high cost and poor flexibility of personal computer firewall systems is solved, achieving highly flexible and low-cost network security protection.
Patent Information
- Application Number
- CN202510703282.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-29
- Publication Date
- 2026-02-10
- Estimated Expiration
- 2045-05-29
AI Technical Summary
Deploying firewall systems on personal computers is costly and lacks flexibility.
The firewall system, after being filtered by the rules, is integrated into the miniature network interface card and connected to the server port. The firewall system performs security processing on network data, including virus blocking rules, network attack rules, and access policies. If the data meets the security rules, it is allowed; otherwise, it is blocked.
It enables highly flexible and low-cost network security protection on personal computers, reduces the cost of deploying firewall systems, and increases the flexibility of use.
Smart Images

Figure CN120223446B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of intrusion security technology, and more specifically, to an intrusion security detection method, apparatus, equipment, medium, and program product. Background Technology
[0002] A firewall system is a combination of components placed between different networks (such as a trusted corporate intranet and an untrusted public network) or network security domains. It protects the network by monitoring, restricting, and modifying data flows across the firewall, shielding the network's internal information, structure, and operational status from the outside world as much as possible. Firewall systems are typically deployed on computers to protect network security; however, deploying firewall systems on personal computers is costly and lacks flexibility. Summary of the Invention
[0003] The purpose of this application is to provide an intrusion security detection method, apparatus, device, medium, and program product to solve the problems that the cost of deploying firewall systems on existing personal computers is high and the flexibility is poor.
[0004] In a first aspect, embodiments of this application provide an intrusion security detection method applied to a miniature network interface card connected to a server, the method comprising:
[0005] The firewall system, filtered according to the filtering rules, is integrated into the micro network interface card; the filtering rules include firewall blocking filtering rules.
[0006] Establish a connection between the miniature network interface card and the server port;
[0007] When the server receives network data, it performs security processing on the network data through the firewall system based on security rules; these security rules include: virus blocking rules, network attack rules, and access policies.
[0008] If the network data complies with security rules, the network data will be allowed to pass through the firewall system;
[0009] If network data does not comply with security rules, the network data will be blocked through the firewall system.
[0010] In the above implementation process, the firewall system, filtered by the filtering rules, is integrated into the miniature network interface card (NIC). These filtering rules include firewall blocking rules. A connection is established between the miniature NIC and the server port. When the server receives network data, it processes the network data securely based on security rules, including virus blocking rules, network attack rules, and access policies. If the network data conforms to the security rules, it is allowed through the firewall system; otherwise, it is blocked. The firewall system integrated into the miniature NIC provides high flexibility and reduces costs by enabling secure processing and protection of network data for the personal computer's server through the external miniature NIC.
[0011] Furthermore, after establishing the connection between the micro network card and the server port, the process also includes:
[0012] The receiving server uses a signature database to assess the firewall system's general protection functions and / or customized functions.
[0013] Configure firewall system functions based on general protection features, and / or,
[0014] The firewall system is customized based on its features; these features include: dropping functionality, packet settings, and protection settings.
[0015] During the above implementation process, you can select the general protection functions of the firewall system on the server side or use customized functions, depending on your needs.
[0016] Furthermore, establishing the connection between the miniature network interface card and the server port includes:
[0017] Connect the mini network card to the configured server port to establish a connection between the mini network card and the server port.
[0018] In the above implementation process, a dedicated server port connected to the micro network card is set up to implement security protection functions.
[0019] Furthermore, the firewall system after filtering by the filtering rules includes:
[0020] Based on the filtering rules, the firewall blocking and storage functions of the firewall system are retained, resulting in the filtered firewall system.
[0021] In the above implementation process, only the core functions of the firewall system are retained, while redundant functions are removed, ensuring the miniaturization of the network card, improving the flexibility of use, and reducing costs.
[0022] Furthermore, the condition that the network data conforms to security rules includes:
[0023] According to security rules, if the network data is found to be free of viruses or network attacks, and the network data complies with the access policy, then the network data is deemed to comply with the security rules.
[0024] In the above implementation process, it is determined that the network data complies with security rules, so that the network data can be allowed to pass through, thereby achieving network security protection for the server.
[0025] Furthermore, the statement that network data does not comply with security rules includes:
[0026] According to security rules, if a virus or network attack is detected in the network data, or if the network data does not comply with the access policy, then the network data is deemed to be non-compliant with security rules.
[0027] In the above implementation process, it is determined that the network data conforms to security rules, thereby enabling the interception of network data and achieving network security protection for the server.
[0028] Secondly, embodiments of this application also provide an intrusion security detection device, integrated into a miniature network interface card connected to a server, the device comprising:
[0029] The system integration module is used to integrate the firewall system, after being filtered by the filtering rules, into the micro network interface card; wherein, the filtering rules include firewall blocking filtering rules;
[0030] The connection establishment module is used to establish a connection between the miniature network interface card (NIC) and the server port.
[0031] The security processing module is used to perform security processing on network data received by the server through the firewall system based on security rules; these security rules include: virus interception rules, network attack rules, and access policies.
[0032] The allow operation module is used to allow network data to pass through the firewall system if the network data complies with security rules;
[0033] The interception module is used to block network data through the firewall system if the network data does not comply with security rules.
[0034] Thirdly, embodiments of this application provide an electronic device, including:
[0035] The system includes a processor, a memory, and a bus. The processor is connected to the memory via the bus. The memory stores computer-readable instructions, which, when executed by the processor, are used to implement the intrusion security detection method described above.
[0036] Fourthly, embodiments of this application provide a computer-readable storage medium storing a computer program, which, when executed by a server, implements the intrusion security detection method described above.
[0037] Fifthly, embodiments of this application provide a computer program product, the computer program product including instructions, which, when executed by a computer, cause the computer to implement the intrusion security detection method as described above. Attached Figure Description
[0038] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings used in the embodiments of this application will be briefly introduced below. It should be understood that the following drawings only show some embodiments of this application and should not be regarded as a limitation of the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.
[0039] Figure 1 A flowchart illustrating an intrusion security detection method provided in an embodiment of this application;
[0040] Figure 2 This is a schematic flowchart of an intrusion security detection device provided in an embodiment of this application;
[0041] Figure 3 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation
[0042] The technical solutions in the embodiments of this application will now be described with reference to the accompanying drawings.
[0043] It should be noted that similar reference numerals and letters in the following figures indicate similar items; therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures. Furthermore, in the description of this application, terms such as "first," "second," etc., are used only to distinguish descriptions and should not be construed as indicating or implying relative importance.
[0044] Please refer to Figure 1 , Figure 1 This is a flowchart illustrating an intrusion security detection method provided in an embodiment of this application. The intrusion security detection method is applied to a miniature network interface card (NIC) connected to a server, and the method includes:
[0045] 100. Integrate the firewall system filtered by the filtering rules into the miniature network interface card; wherein, the filtering rules include firewall blocking filtering rules.
[0046] Understandably, filtering rules can be configured according to needs, retaining desired firewall system-related and necessary functions. Alternatively, filtering rules can be automatically generated based on specific personal computer usage requirements, retaining essential functions and integrating the firewall system into the micro network card. Furthermore, automatically generated filtering rules can be used to create firewall blocking functions based on personal computer usage needs. These blocking functions only target specified types of network data or traffic, which can be traffic data that poses a threat to the personal computer.
[0047] It should be noted that integrating the firewall system into the miniature network interface card (NIC) involves screening the firewall system's software functions and hardware structure, removing hardware components that do not meet the screening criteria, and ensuring the miniaturization of the NIC.
[0048] Optionally, based on the filtering rules, the firewall system's blocking and storage functions can be retained to obtain a filtered firewall system. Only the core functions of the firewall system are retained, while redundant functions are removed, ensuring the miniaturization of the network interface card (NIC), improving flexibility, and reducing costs. Redundant functions such as encrypted communication, traffic monitoring and analysis, and authentication are removed.
[0049] Optionally, the network card can be a DSP (Digital Signal Processor Network Interface Card), which is a dedicated network adapter that integrates a digital signal processor and is mainly used for real-time signal processing, high-speed data computation, and low-latency communication scenarios.
[0050] 200. Establish a connection between the miniature network card and the server port.
[0051] Specifically, the mini network card is connected to a pre-configured server port to establish a connection between the mini network card and the server port; thus, a dedicated physical server port for connecting to the mini network card is set up, which is simple and quick, and security protection functions can be achieved without setting up too many ports.
[0052] 300. When the server receives network data, it performs security processing on the network data through the firewall system based on security rules; these security rules include: virus interception rules, network attack rules, and access policies.
[0053] For example, based on security rules, network data can be processed securely through a firewall system. Security processing can be based on rule matching priority, such as prioritizing the execution of virus blocking rules to prevent malware from entering the network; then executing network attack rules to detect DDoS, SQL injection, and other attack behaviors; and finally applying access policies to control access permissions for legitimate traffic.
[0054] For example, based on security rules, network data can be processed securely through a firewall system. This can be done using a dual-engine collaborative detection approach, such as a stateless rule engine that quickly matches individual packet characteristics (e.g., IP / port blacklists) and a stateful rule engine that analyzes traffic context (e.g., connection state, protocol behavior) to identify covert attacks.
[0055] 400. If the network data complies with security rules, the network data will be allowed through the firewall system.
[0056] Specifically, according to security rules, if the network data is found to be free of viruses or network attacks and conforms to the access policy, then the network data is deemed to comply with the security rules. Once the network data is deemed to comply with the security rules, it can be allowed to pass through, thereby achieving network security protection for the server.
[0057] 500. If network data does not comply with security rules, the network data will be blocked through the firewall system.
[0058] Specifically, according to security rules, if a virus or network attack is detected in the network data, or if the network data does not comply with the access policy, then the network data is determined to be non-compliant with the security rules. If the network data is determined to comply with the security rules, then the network data can be intercepted to achieve network security protection for the server.
[0059] As described above, this embodiment integrates a firewall system filtered by filtering rules into a miniature network interface card (NIC). These filtering rules include firewall blocking rules. A connection is established between the miniature NIC and the server port. When the server receives network data, it processes the data securely based on security rules through the firewall system. These security rules include virus blocking rules, network attack rules, and access policies. If the network data conforms to the security rules, it is allowed through the firewall system; if the network data does not conform to the security rules, it is blocked through the firewall system. The firewall system integrated into the miniature NIC provides high flexibility and reduces costs by enabling secure processing and protection of network data for the personal computer's server through the external miniature NIC.
[0060] Based on the above embodiments, the intrusion security detection method of this application can be further specified as follows: after establishing the connection between the micro network card and the server port, it further includes:
[0061] The receiving server performs general protection functions and / or customized functions of the firewall system based on the signature database; it configures the firewall system based on the general protection functions, and / or performs customized processing on the firewall system based on the customized functions; wherein, the customized functions include: dropping functions, packet settings, and protection settings.
[0062] Optionally, the server can customize the firewall system's functionality according to its needs. It can directly select the firewall system's general protection functions, or it can filter out the packet types that require security protection from the stored signature database to customize the firewall system's functions so that the firewall system only processes the selected packet types. Understandably, the server can also select both general protection functions and customized functions at the same time, and make customized settings on the basis of general protection functions, such as implementing multiple defenses for specific packet types.
[0063] Therefore, depending on the needs, the server can select the general protection functions of the firewall system or adopt customized functions.
[0064] For example, the drop-off function can be customized, such as for DDoS (Distributed Denial of Service) protection: setting a SYN packet rate threshold and dropping connection requests exceeding the threshold; or for internal network violation control: dropping traffic accessing illegal websites (such as gambling sites or phishing sites). Here, the SYN packet is a data packet in the TCP protocol used to initiate a connection request. The SYN packet contains the SYN flag and other necessary information, such as the source port, destination port, and sequence number.
[0065] For example, message settings can be customized, such as setting message types to allow specific types of messages to enter.
[0066] For example, protection settings can be customized, such as setting intrusion detection or defense rules, setting virus scanning engines, and setting access control policies.
[0067] The steps described above are not strictly performed in the order of their numbers; they should be understood as a whole.
[0068] Secondly, based on the above embodiments, this application also provides an intrusion security detection device integrated into a miniature network interface card connected to a server, as shown in the reference. Figure 2 The intrusion security detection device provided in this embodiment specifically includes: a system integration module 201, a connection establishment module 202, a security processing module 203, a release operation module 204, and an interception operation module 205.
[0069] The system integration module 201 integrates the firewall system, filtered by rules, into the miniature network interface card (NIC); these filtering rules include firewall blocking filtering rules. The connection establishment module 202 establishes a connection between the miniature NIC and the server port. The security processing module 203 processes network data received by the server based on security rules through the firewall system; these security rules include virus blocking rules, network attack rules, and access policies. The allow operation module 204 allows network data to pass through the firewall system if it conforms to the security rules. The block operation module 205 blocks network data if it does not conform to the security rules.
[0070] As described above, this embodiment integrates a firewall system filtered by filtering rules into a miniature network interface card (NIC). These filtering rules include firewall blocking rules. A connection is established between the miniature NIC and the server port. When the server receives network data, it processes the data securely based on security rules through the firewall system. These security rules include virus blocking rules, network attack rules, and access policies. If the network data conforms to the security rules, it is allowed through the firewall system; if the network data does not conform to the security rules, it is blocked through the firewall system. The firewall system integrated into the miniature NIC provides high flexibility and reduces costs by enabling secure processing and protection of network data for the personal computer's server through the external miniature NIC.
[0071] Thirdly, embodiments of this application also provide an electronic device that can integrate the intrusion security detection device with the user-mode polling mechanism provided in embodiments of this application. Figure 3 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. (Reference) Figure 3 The electronic device includes: an input device 43, an output device 44, a memory 42, and one or more processors 41; the memory 42 is used to store one or more programs; when the one or more programs are executed by the one or more processors 41, the one or more processors 41 implement the intrusion security detection method with user-mode polling mechanism as provided in the above embodiments. The input device 43, output device 44, memory 42, and processor 41 can be connected via a bus or other means. Figure 3 Taking the example of a connection between China and Israel via a bus.
[0072] The processor 41 executes various functional applications and data processing of the device by running software programs, instructions and modules stored in the memory 42, thereby realizing the intrusion security detection method of the user-mode polling mechanism described above.
[0073] The electronic device provided above can be used to execute the intrusion security detection method of the user-mode polling mechanism provided in the above embodiments, and has corresponding functions and beneficial effects.
[0074] Fourthly, embodiments of this application also provide a computer-readable storage medium, which includes a stored computer program; wherein, when the computer program is running, it controls the device where the computer-readable storage medium is located to execute the intrusion security detection method as described above, and can achieve the same beneficial effects.
[0075] Of course, the computer-executable instructions provided in the embodiments of this application are not limited to the intrusion security detection method described above, but can also perform related operations in the intrusion security detection method provided in any embodiment of this application.
[0076] Fifthly, embodiments of this application also provide a computer program product. The methods described in the various embodiments of this application can be implemented entirely or partially through software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented entirely or partially in the form of a computer program product. The computer program product includes one or more computer programs or instructions. When the computer program or instructions are loaded and executed on a computer, the processes or functions described in the various embodiments of this application are executed entirely or partially. The computer can be a general-purpose computer, a special-purpose computer, a computer network, network equipment, user equipment, core network equipment, OAM (Open Application Model), or other programmable devices.
[0077] The computer program or instructions may be stored in a computer-readable storage medium or transferred from one computer-readable storage medium to another. For example, the computer program or instructions may be transferred from one website, computer, server, or data center to another website, computer, server, or data center via wired or wireless means. The computer-readable storage medium may be any available medium that a computer can access, or a data storage device such as a server or data center that integrates one or more available media. The available medium may be a magnetic medium, such as a floppy disk, hard disk, or magnetic tape; or an optical medium, such as a digital video optical disc; or a semiconductor medium, such as a solid-state drive. The computer-readable storage medium may be a volatile or non-volatile storage medium, or may include both volatile and non-volatile types of storage media.
[0078] In the several embodiments provided in this application, it should be understood that the disclosed apparatus and methods can also be implemented in other ways. The apparatus embodiments described above are merely illustrative. For example, the flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of apparatus, methods, and computer program products according to various embodiments of this application. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than those marked in the drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram and / or flowchart, and combinations of blocks in block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or action, or using a combination of dedicated hardware and computer instructions.
[0079] In addition, the functional modules in the various embodiments of this application can be integrated together to form an independent part, or each module can exist independently, or two or more modules can be integrated to form an independent part.
[0080] If the aforementioned functions are implemented as software functional modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0081] The above description is merely an embodiment of this application and is not intended to limit the scope of protection of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of protection of this application. It should be noted that similar reference numerals and letters in the following figures indicate similar items; therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures.
[0082] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
[0083] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.
Claims
1. An intrusion security detection method, characterized in that, The method, applied to a miniature network interface card (NIC) connected externally to a server, includes: The firewall system, filtered according to specific rules, is integrated into the micro network interface card (NIC). These rules include firewall blocking rules, which specifically target and block network data or traffic of a defined type that poses a threat to the personal computer. Integrating the firewall system into the micro NIC involves filtering both the firewall system's software functions and hardware structure. Hardware components that do not conform to the filtering rules are removed. Redundant functions of the firewall system, including encrypted communication, traffic monitoring and analysis, and authentication, are also eliminated. Establish a connection between the miniature network interface card and the server port; When the server receives network data, it performs security processing on the network data through the firewall system based on security rules. These security rules include virus blocking rules, network attack rules, and access policies. The security rules execute virus blocking rules first, then network attack rules, and finally access policies. Based on security rules, network data is processed for security through dual-engine collaborative detection. The dual engines include a stateless rule engine that matches the characteristics of individual data packets, and a stateful rule engine that analyzes traffic context and identifies covert attacks. If the network data complies with security rules, the network data will be allowed to pass through the firewall system; If network data does not comply with security rules, the network data will be blocked through the firewall system.
2. The intrusion security detection method according to claim 1, characterized in that, After establishing the connection between the miniature network card and the server port, the process also includes: The receiving server uses a signature database to assess the firewall system's general protection functions and / or customized functions. Configure firewall system functions based on general protection features, and / or, The firewall system is customized based on its features; these features include: dropping functionality, packet settings, and protection settings.
3. The intrusion security detection method according to claim 1, characterized in that, The process of establishing a connection between the micro network interface card (NIC) and the server port includes: Connect the mini network card to the configured server port to establish a connection between the mini network card and the server port.
4. The intrusion security detection method according to claim 1, characterized in that, The firewall system after being filtered by the filtering rules includes: Based on the filtering rules, the firewall blocking and storage functions of the firewall system are retained, resulting in the filtered firewall system.
5. The intrusion security detection method according to claim 1, characterized in that, If the network data conforms to security rules, it includes: According to security rules, if the network data is found to be free of viruses or network attacks, and the network data complies with the access policy, then the network data is deemed to comply with the security rules.
6. The intrusion security detection method according to claim 1, characterized in that, If the network data does not comply with the security rules, it includes: According to security rules, if a virus or network attack is detected in the network data, or if the network data does not comply with the access policy, then the network data is deemed to be non-compliant with security rules.
7. An intrusion security detection device, characterized in that, The device, which is integrated into a miniature network interface card (NIC) connected to a server, includes: The system integration module is used to integrate the firewall system, filtered according to certain rules, into the micro network interface card (NIC). These filtering rules include firewall blocking rules, which in turn include firewall blocking functions. These firewall blocking functions only block network data or traffic of a specified type, defined as traffic that poses a threat to a personal computer. Integrating the firewall system into the micro NIC involves filtering both the firewall system's software functions and hardware structure. Hardware components that do not conform to the filtering rules are removed. Redundant functions of the firewall system, including encrypted communication, traffic monitoring and analysis, and authentication, are also removed. The connection establishment module is used to establish a connection between the miniature network interface card (NIC) and the server port. The security processing module is used to perform security processing on network data through the firewall system based on security rules when the server receives network data. These security rules include virus interception rules, network attack rules, and access policies. The security rules execute the virus interception rules first, then the network attack rules, and finally the access policies. The allow operation module is used to allow network data to pass through the firewall system if the network data complies with security rules; The interception module is used to block network data through the firewall system if the network data does not comply with security rules.
8. An electronic device, characterized in that, include: The processor, memory, and bus are provided, wherein the processor is connected to the memory via the bus, and the memory stores computer-readable instructions that, when executed by the processor, are used to implement the intrusion security detection method as described in any one of claims 1-6.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by the server, implements the intrusion security detection method as described in any one of claims 1-6.
10. A computer program product, characterized in that, The computer program product includes instructions that, when executed by a computer, cause the computer to perform the method according to any one of claims 1-6.
Citation Information
Patent Citations
Network safe network card
CN2922301Y
Distributed firewall system and method
US20030126468A1
Maintaining firewall rules at a PNIC that performs firewall operations on data message flows
US20250039139A1