Security protection method and device, communication equipment, medium and product

By adding security context identifiers to the business data packets and parsing them to match the target security protection strategy, the problem that traditional firewalls cannot meet the needs of different business scenarios is solved, and differentiated security protection processing is achieved, improving security and flexibility.

CN120281575AInactive Publication Date: 2025-07-08CHINA TELECOM CORP LTD +1

Patent Information

Application Number
CN202510749690.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-06
Publication Date
2025-07-08
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Traditional firewalls cannot meet the security needs of different business scenarios, especially business data packets of the same IP address and port may have different security needs in different scenarios, resulting in problems such as excessive traffic release, over-detection or incorrect blockade.

Method used

By adding a security context identifier to the service data packet, the identifier is parsed to match the corresponding target security protection strategy, and differentiated security protection processing is achieved.

Benefits of technology

It improves the targeted business scenarios of security protection processing, avoids excessive traffic release, over-detection or misblocking, and meets the security needs of different business scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120281575A_ABST
    Figure CN120281575A_ABST
Patent Text Reader

Abstract

The invention relates to a security protection method and device, communication equipment, a medium and a product. The method comprises the following steps: receiving a service data packet sent by a service participant; analyzing the service data packet to obtain a security context identifier in the service data packet; the security context identifier corresponds to a service scene of the service participant; determining a target security protection strategy matched with the security context identifier; and performing security protection processing on the service data packet according to the target security protection strategy. Different business scenes correspond to different security context identifiers, so that different target security protection strategies can be matched, different security protection processing is realized, and security requirements of different business scenes are met. Security protection of business scene differentiation can be realized even for business data packets of the same IP address and port, and business scene pertinence of security protection processing is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of wireless communication networks, and in particular, to a security protection method, apparatus, communication device, computer-readable storage medium, and computer program product. Background Art

[0002] With the continuous evolution of network attack means, traditional firewalls have been difficult to meet the requirements of modern network security. Therefore, firewalls usually need to integrate security protection functions.

[0003] Currently, firewalls usually match corresponding security protection policies according to the IP (Internet Protocol) address and port in service data packets, and then perform security protection processing according to the matched security protection policies. However, in different service scenarios, even service data packets with the same IP address and port may have different security requirements, and the traditional processing methods of current firewalls cannot meet different security requirements. Summary of the Invention

[0004] Based on this, it is necessary to provide a security protection method, apparatus, communication device, medium, and product that can meet the security requirements of different service scenarios for the above technical problems.

[0005] In a first aspect, the present application provides a security protection method applied to a firewall device, and the method includes:

[0006] Receiving a service data packet sent by a service participant;

[0007] Parsing the service data packet to obtain a security context identifier in the service data packet; the security context identifier corresponds to the service scenario of the service participant;

[0008] Determining a target security protection policy that matches the security context identifier;

[0009] Performing security protection processing on the service data packet according to the target security protection policy.

[0010] In one embodiment, the security context identifier includes a service type identifier; determining a target security protection policy that matches the security context identifier includes: if the service type identifier represents an Internet of Things service type, using an abnormal behavior detection policy as the target security protection policy; if the service type identifier represents an Internet service type, using at least one of an abnormal behavior detection policy, an intrusion detection and prevention policy, and a malware protection policy as the target security protection policy.

[0011] In one embodiment, the security context identifier includes a user type identifier; determining a target security protection policy that matches the security context identifier includes: if the user type identifier represents an external visitor type, using a first access policy that allows access to the Internet and prohibits access to the enterprise intranet as the target security protection policy; if the user type identifier represents an enterprise internal user type, using a second access policy that allows access to the Internet and allows access to the enterprise intranet as the target security protection policy.

[0012] In one embodiment, if the user type identifier represents an enterprise internal user type, using a second access policy that allows access to the Internet and allows access to the enterprise intranet as the target security protection policy includes: if the user type identifier represents a business department user type, using a second access sub-policy that allows access to the Internet and only allows access to the data corresponding to the business department in the enterprise intranet as the target security protection policy; wherein, the business department user type is a subtype under the enterprise internal user type.

[0013] In one embodiment, the security context identifier includes a security level identifier; determining a target security protection policy that matches the security context identifier includes: if the security level identifier represents a first security level, using a policy that prohibits cross-region data transmission as the target security protection policy; if the security level identifier represents a second security level, using a policy that allows cross-region data transmission as the target security protection policy; wherein, the first security level is higher than the second security level.

[0014] In one embodiment, parsing a service data packet to obtain a security context identifier in the service data packet includes: extracting a traffic type identifier from the programmable extension header of the service data packet; obtaining a byte occupancy length that matches the traffic type identifier as the target byte length corresponding to the security context identifier; and extracting the security context identifier from the programmable extension header according to the target byte length.

[0015] In a second aspect, the present application provides a security protection method applied to a service participant. The method includes:

[0016] Sending a service data packet to a firewall device;

[0017] Wherein, the service data packet includes a security context identifier, the security context identifier corresponds to the service scenario of the service participant, and the security context identifier is used to instruct the firewall device to match a target security protection policy for performing security protection processing on the service data packet.

[0018] In a third aspect, the present application provides a security protection device configured in a firewall device. The device includes:

[0019] A data packet receiving module, configured to receive service data packets sent by service participants;

[0020] A data packet parsing module, configured to parse the service data packets to obtain security context identifiers in the service data packets; the security context identifiers correspond to the service scenarios of the service participants;

[0021] A policy determination module, configured to determine target security protection policies that match the security context identifiers;

[0022] A protection processing module, configured to perform security protection processing on the service data packets according to the target security protection policies.

[0023] Fourthly, the present application provides a security protection device, configured in a service participant, and the device includes:

[0024] A data packet sending module, configured to send service data packets to a firewall device;

[0025] Wherein, the service data packets include security context identifiers, the security context identifiers correspond to the service scenarios of the service participants, and the security context identifiers are used to instruct the firewall device to match the target security protection policies for performing security protection processing on the service data packets.

[0026] Fifthly, the present application further provides a communication device, which includes a memory, a transceiver, and a processor. The memory stores a computer program, the transceiver is configured to receive or send data under the control of the processor, and when the processor executes the computer program, the following steps are implemented:

[0027] Receive service data packets sent by service participants;

[0028] Parse the service data packets to obtain security context identifiers in the service data packets; the security context identifiers correspond to the service scenarios of the service participants;

[0029] Determine target security protection policies that match the security context identifiers;

[0030] Perform security protection processing on the service data packets according to the target security protection policies;

[0031] Or,

[0032] Send service data packets to a firewall device;

[0033] Wherein, the service data packets include security context identifiers, the security context identifiers correspond to the service scenarios of the service participants, and the security context identifiers are used to instruct the firewall device to match the target security protection policies for performing security protection processing on the service data packets.

[0034] Sixth aspect, the present application also provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the following steps are implemented:

[0035] Receive a service data packet sent by a service participant;

[0036] Parse the service data packet to obtain a security context identifier in the service data packet; the security context identifier corresponds to the service scenario of the service participant;

[0037] Determine a target security protection policy that matches the security context identifier;

[0038] Perform security protection processing on the service data packet according to the target security protection policy;

[0039] Or,

[0040] Send the service data packet to a firewall device;

[0041] Wherein, the service data packet includes a security context identifier, the security context identifier corresponds to the service scenario of the service participant, and the security context identifier is used to instruct the firewall device to match the target security protection policy for performing security protection processing on the service data packet.

[0042] Seventh aspect, the present application also provides a computer program product, including a computer program. When the computer program is executed by a processor, the following steps are implemented:

[0043] Receive a service data packet sent by a service participant;

[0044] Parse the service data packet to obtain a security context identifier in the service data packet; the security context identifier corresponds to the service scenario of the service participant;

[0045] Determine a target security protection policy that matches the security context identifier;

[0046] Perform security protection processing on the service data packet according to the target security protection policy;

[0047] Or,

[0048] Send the service data packet to a firewall device;

[0049] Wherein, the service data packet includes a security context identifier, the security context identifier corresponds to the service scenario of the service participant, and the security context identifier is used to instruct the firewall device to match the target security protection policy for performing security protection processing on the service data packet.

[0050] The above-mentioned security protection method, device, communication device, medium and product send service data packets from the service participation direction to the firewall device, and the firewall device parses the service data packets to obtain a security context identifier corresponding to the service scenario, thereby determining the corresponding target security protection policy according to the security context identifier, and then performing security protection processing on the service data packets according to the target security protection policy. Since different service scenarios correspond to different security context identifiers, different target security protection policies can be matched to achieve different security protection processing and meet the security requirements of different service scenarios. Even for service data packets with the same IP address and port, security protection with different service scenarios can be achieved, improving the pertinence of the security protection processing to service scenarios and avoiding situations such as excessive traffic allowance, excessive detection, or mis-blocking caused by only adopting one security protection policy for service data packets with the same IP address and port. BRIEF DESCRIPTION OF THE DRAWINGS

[0051] In order to more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the following will briefly introduce the drawings required for the description of the embodiments of the present application or related technologies. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other related drawings can also be obtained based on these drawings.

[0052] Figure 1 It is a schematic flowchart of the security protection method in an embodiment;

[0053] Figure 2 It is a schematic flowchart of the target security protection policy determination step in an embodiment;

[0054] Figure 3 It is a schematic flowchart of the target security protection policy determination step in an embodiment;

[0055] Figure 4 It is a schematic flowchart of the target security protection policy determination step in an embodiment;

[0056] Figure 5 It is a schematic flowchart of the parsing step of the service data packets in an embodiment;

[0057] Figure 6 It is a schematic structural diagram of the APN6 packet header in an embodiment;

[0058] Figure 7 It is a schematic flowchart of the security protection method in an embodiment;

[0059] Figure 8 It is a schematic block diagram of the security protection device in an embodiment;

[0060] Figure 9 is the structural block diagram of the security protection device in an embodiment;

[0061] Figure 10 is the internal structure diagram of the communication device in an embodiment. Detailed implementation manners

[0062] In order to make the objectives, technical solutions and advantages of the present application clearer, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.

[0063] Currently, the firewall device determines the corresponding security protection policy according to the IP address and port, which cannot distinguish different security requirements under the same IP address and port, so it is impossible to perform security protection with business scenario differentiation.

[0064] To solve the above problems, in an exemplary embodiment, as Figure 1 shown, a security protection method is provided. This method is applied to a firewall device and includes the following steps:

[0065] S110, receive the service data packet sent by the service participant.

[0066] Among them, the service participant can be a terminal device or a server providing service. When the terminal device needs to interact with the server, for example, when the terminal device needs to send data to the server, the terminal device generates a service data packet and sends the service data packet, and the firewall device located between the terminal device and the server receives the service data packet. Or, when the server needs to interact with the terminal device, for example, when the server needs to send an instruction to the terminal device, the server generates a service data packet and sends the service data packet, and the firewall device connected between the terminal device and the server receives the service data packet.

[0067] Among them, the service data packet can be a data packet generated using IPv6 (Internet Protocol Version 6), and this data packet can be simply referred to as an IPv6 data packet. Among them, IPv6 is the next-generation IP protocol designed by the Internet Engineering Task Force to replace IPv4 (Internet Protocol Version 4). With the rapid development of the Internet, the IPv4 address resources are gradually exhausted, and IPv6 emerges as the times require, aiming to solve the problem of IPv4 address shortage and provide more efficient and secure network communication.

[0068] Of course, the service data packet can also be a data packet generated using other technologies, which is not limited herein.

[0069] S120, Parse the service data packet to obtain the security context identifier in the service data packet; the security context identifier corresponds to the service scenario of the service participant.

[0070] In this embodiment, during the process of generating the service data packet, the service participant, in addition to adding the data or instructions to be sent as service traffic into the service data packet, also adds the security context identifier into the service data packet.

[0071] Among them, the role of the security context identifier is to match the corresponding target security protection policy. As the name implies, the security context identifier is the identifier corresponding to the security context information required to match the corresponding target security protection policy. The security context information represented by the security context identifier can include at least one type, for example, at least one type among service type, user type, and security level. Of course, it can also be other custom types, which is not limited herein.

[0072] Among them, in different service scenarios, there are different service requirements, different service requirements correspond to different security context information, and thus correspond to different security context identifiers. Therefore, during the process of generating the service data packet, the service participant should add the corresponding security context identifier according to the service requirements.

[0073] It can be seen that in S120, the service data packet is parsed to know whether the service data packet contains a security context identifier. If it contains, the security context identifier is extracted.

[0074] Of course, if it is known through parsing the service data packet that the service data packet does not contain a security context identifier, the IP address and port information are extracted from the service data packet, so as to match the corresponding security protection policy according to the IP address and port information, and then perform corresponding protection processing according to the security protection policy.

[0075] S130, Determine the target security protection policy that matches the security context identifier.

[0076] In an alternative implementation, a matching rule table is pre-stored in the firewall device. The matching rule table records the corresponding relationship, that is, the matching relationship, between each security context identifier and each security protection policy. Therefore, the security protection policy corresponding to the security context identifier is found from the matching rule table as the target security protection policy. Among them, the above corresponding relationship can include a one-to-one relationship, a one-to-many relationship, or a many-to-one relationship, etc., which is not limited herein.

[0077] S140. Perform security protection processing on the service data packet according to the target security protection policy.

[0078] It can be seen that after receiving the service data packet, the firewall device parses the service data packet to obtain the security context identifier, thereby determining the corresponding target security protection policy according to the security context identifier, and then performing security protection processing on the service data packet according to the target security protection policy. Since different service scenarios correspond to different security context identifiers, different target security protection policies can be matched, different security protection processes can be realized, and the security requirements of different service scenarios can be met. Even for service data packets with the same IP address and port, differential security protection for service scenarios can be achieved, improving the pertinence of security protection processing for service scenarios and avoiding situations such as excessive traffic release, excessive detection, or mis-blocking caused by only adopting one security protection policy for service data packets with the same IP address and port.

[0079] Moreover, the traditional processing method of the firewall relies on manual configuration of security protection policies corresponding to each IP address and port. Due to the large number of IP addresses, the workload of manual configuration is large and it is easy to make mistakes. In this embodiment, only the correspondence between different security context identifiers and different security protection policies needs to be configured, and there is no need to set corresponding security protection policies for a large number of IP addresses, reducing the workload of manual configuration and the possibility of making mistakes.

[0080] Based on the technical solutions of the above embodiments, the present application also provides an optional embodiment. In this optional embodiment, the security context identifier is refined to include a service type identifier, and the determination step of the target security protection policy in S130 is refined.

[0081] See Figure 2 The target security protection policy determination step shown includes:

[0082] S210. If the service type identifier represents an Internet of Things service type, use the abnormal behavior detection policy as the target security protection policy; if the service type identifier represents an Internet service type, use at least one of the abnormal behavior detection policy, intrusion detection and prevention policy, and malicious software protection policy as the target security protection policy.

[0083] Exemplarily, if the service traffic in the service data packet is the collection result data that the Internet of Things terminal wants to send to the server, or the service traffic is an instruction to notify the Internet of Things terminal to collect Internet of Things data, then the service type is the Internet of Things service type, and the corresponding service type identifier represents the Internet of Things service type. For the Internet of Things service type, the target security protection policy is the abnormal behavior detection policy, and in-depth security detection is no longer performed, which can reduce the computing overhead.

[0084] Exemplarily, if the service traffic in the service data packet is data obtained by accessing Internet resources, or the service traffic is a control instruction notified to the server or the terminal device for transmission via the Internet, then the service type is an Internet service type, and the corresponding service type identifier represents the Internet service type. For the Internet service type, the target security protection policy is at least one of an abnormal behavior detection policy, an intrusion detection and prevention policy, and a malware protection policy, so as to implement at least one of the above security protection processes.

[0085] Among them, different service type identifiers represent different service types. For example, in the service type identifier field in the service data packet, the first value represents the Internet of Things service type, and the second value represents the Internet service type, and the first value is different from the second value.

[0086] Of course, the service types are not limited to the above-mentioned Internet of Things service type and Internet service type, and may also include other service types. Since there are many services in the enterprise intranet, such as production operation services, video surveillance services, etc., the service types also include enterprise intranet service types, and the enterprise intranet service types include many service subtypes, such as production operation service subtypes, video surveillance service subtypes, etc. Different service subtypes also correspond to different service type identifiers.

[0087] Among them, the abnormal behavior detection policy is a policy for quickly identifying abnormal traffic, and various means can be adopted, such as DDOS (Distributed Denial of Service, Chinese for distributed denial of service) attack detection.

[0088] Among them, the intrusion detection and prevention policy is a policy for identifying and preventing unauthorized access or malicious behavior. For example, it detects whether there is traffic performing port scanning, and if it is found, operations such as blocking are performed.

[0089] Among them, the malware protection policy is a series of measures to prevent malware (such as viruses, Trojans, worms, etc.) from damaging devices and data.

[0090] It can be seen that for different service types, different target security protection policies are determined, so as to perform different security protection processes and meet the security requirements of different service scenarios.

[0091] Based on the technical solutions of the above embodiments, the present application also provides an optional embodiment. In this optional embodiment, the security context identifier is refined to include a user type identifier, and the determination step of the target security protection policy in S130 is refined.

[0092] See Figure 3 The target security protection policy determination step shown in, includes:

[0093] S310. If the user type identifier represents the type of external visitor, then use the first access policy that allows access to the Internet and prohibits access to the enterprise intranet as the target security protection policy. If the user type identifier represents the type of enterprise internal user, then use the second access policy that allows access to the Internet and allows access to the enterprise intranet as the target security protection policy.

[0094] Exemplarily, when an external visitor performs a data access operation on a terminal device, the terminal device generates and sends a service data packet in response to the data access operation of the external visitor. The service data packet includes a request instruction for accessing data and a user type identifier representing the type of external visitor. When the firewall device connected between the terminal device and the server receives the service data packet, it obtains the security context identifier therein, and then determines that the target security protection policy is the first access policy. The first access policy allows the external visitor to access the Internet and prohibits access to the enterprise intranet, and sends the first access policy and the service data packet to the server. If the server learns from the request instruction that the external visitor wants to access Internet data through the terminal device, it obtains the corresponding Internet data and feeds it back to the terminal device. If the server learns from the request instruction that the external visitor wants to access enterprise intranet data, it feeds back a prompt message indicating that access is not allowed. It can be seen that for external visitors, a security protection policy that only allows access to the Internet and not to the enterprise intranet is implemented, which can ensure the security of enterprise intranet data.

[0095] Exemplarily, when an enterprise internal user performs a data access operation on a terminal device, the terminal device generates and sends a service data packet in response to the data access operation of the enterprise internal user. The service data packet includes a request instruction for accessing data and a user type identifier representing the type of enterprise internal user. When the firewall device connected between the terminal device and the server receives the service data packet, it obtains the security context identifier therein, determines that the target security protection policy is the second access policy. The second access policy allows access to the Internet and allows access to the enterprise intranet, and sends the second access policy and the service data packet to the server. If the server learns from the request instruction that the enterprise internal user wants to access Internet data, it obtains the corresponding Internet data and feeds it back. If the server learns from the request instruction that the enterprise internal user wants to access enterprise intranet data through the terminal device, it obtains the corresponding enterprise intranet data and feeds it back to the terminal device. It can be seen that for enterprise internal users, a security protection policy that allows access to the Internet and allows access to the enterprise intranet is implemented, ensuring the freedom of enterprise internal users to access data.

[0096] It can be seen that different target security protection policies are determined for different user types, so as to perform different security protection processes and meet the security requirements of different business scenarios.

[0097] Further, there are multiple business departments within an enterprise. To further ensure the security of the enterprise intranet data, data isolation can be implemented between each business department. For this purpose, in one embodiment, S310 is refined. That is, if the user type identifier represents an internal enterprise user type, then the second access policy that allows access to the Internet and allows access to the enterprise intranet is used as the target security protection policy, which may include:

[0098] If the user type identifier represents a business department user type, then the second access sub-policy that allows access to the Internet and only allows access to the data of the corresponding business department in the enterprise intranet is used as the target security protection policy; among them, the business department user type is a subtype under the internal enterprise user type.

[0099] Exemplarily, there are a production department, a sales department, a finance department, etc. within the enterprise. Correspondingly, the business department user types include a production department user type, a sales department user type, a finance department user type, etc., which are not limited herein. If the user type identifier in the business data packet represents a production department user type, then the target security protection policy is the second access sub-policy, and the second access sub-policy allows access to the Internet and only allows access to the production department data in the enterprise intranet. It can be seen that the production department users can only access the production department data and cannot access the data of the sales department and the finance department, etc., realizing the isolation between the data of each business department in the enterprise intranet.

[0100] Among them, different user type identifiers represent different user types. For example, in the user type identifier field in the business data packet, the first value represents the external visitor type, the second value represents the production department user type, the third value represents the sales department user type, the fourth value represents the finance department user type, and the first value, the second value, the third value, and the fourth value are all different.

[0101] Of course, the user types are not limited to the above external visitor type and internal enterprise user type, and may also include other user types, which are not limited herein.

[0102] It can be seen that for different business department user types, the target security protection policy is determined to allow access to the Internet and only allow access to the data of the corresponding business department in the enterprise intranet, realizing the isolation between the data of each business department in the enterprise intranet and further ensuring the security of the enterprise intranet data.

[0103] Based on the technical solutions of the above embodiments, the present application also provides an alternative embodiment. In this alternative embodiment, the security context identifier is refined to include a security level identifier, and the determination step of the target security protection policy in S130 is refined.

[0104] See Figure 4The target security protection policy determination steps shown include:

[0105] S410, if the security level identifier represents the first security level, then use the policy of prohibiting cross-region data transmission as the target security protection policy; if the security level identifier represents the second security level, then use the policy of allowing cross-region data transmission as the target security protection policy; wherein, the first security level is higher than the second security level.

[0106] It can be understood that for business data packets with a relatively high security level, cross-region transmission is not allowed, thus ensuring data security. For business data packets with a relatively low security level, cross-region transmission is allowed. For example, for sensitive data, such as control production data, the security level can be set to the first security level, thereby prohibiting the cross-region transmission of sensitive data.

[0107] Among them, the regions in the policy of prohibiting cross-region data transmission can be any region or a preset region, and moreover, the region can be a physical space region (such as a production area or other physical space regions), or a cyber space region.

[0108] Among them, the regions in the policy of allowing cross-region data transmission can be any region or a preset region, and moreover, the region can be a physical space region (such as a security area, a management area or other physical space regions), or a cyber space region.

[0109] Of course, the security levels are not limited to the above first security level and second security level, and can also include other security levels, which are not limited here.

[0110] Among them, different security level identifiers represent different security levels. For example, in the security level identifier field in the business data packet, the first value represents the first security level, the second value represents the first security level, and the first value and the second value are different.

[0111] It can be seen that for the security level, different target security protection policies are determined, so as to perform different security protection processes, and further ensure different degrees of security, while also having flexibility while ensuring security.

[0112] It can be understood that the security context identifier in the business data packet can include one or more of the business type, user type and security level. When the security context identifier includes multiple items of the business type, user type and security level, the determined target security protection policies are multiple, and the execution of the multiple target security protection policies does not conflict.

[0113] The security protection method provided in this embodiment is suitable for application in enterprise hybrid clouds and production office networks. For enterprise hybrid clouds, the firewall device can determine corresponding security protection policies according to different user types and security levels, and implement strict and differentiated data leakage prevention for cloud services. For production office networks, the firewall device can determine corresponding security protection policies according to different service types and security levels, and implement different security protection processes for traffic data such as production and office.

[0114] In an alternative embodiment, the matching rule table recording the correspondence between the security context identifier and the target security protection policy is shown in Table 1 below.

[0115] Table 1 Matching Rule Table

[0116]

[0117] Based on the technical solutions of the above embodiments, the present application also provides an alternative embodiment, in which the parsing step of the service data packet in S120 is refined.

[0118] See Figure 5 The parsing steps of the service data packet shown can include:

[0119] S510, extract the traffic type identifier from the programmable extension header of the service data packet.

[0120] S520, obtain the byte occupancy length matching the traffic type identifier as the target byte length corresponding to the security context identifier.

[0121] S530, extract the security context identifier from the programmable extension header according to the target byte length.

[0122] Among them, the programmable extension header is a technical mechanism used in network protocols to flexibly add additional information, which allows developers or systems to dynamically expand protocol functions according to needs.

[0123] In an actual scenario, a relatively short byte space can be reserved in the programmable extension header to set the security context identifier field. For example, 4 bytes, or a relatively long byte space can be reserved in the programmable extension header to set the security context identifier field. For example, 16 bytes.

[0124] In order to facilitate the firewall to accurately obtain the security context identifier, it is necessary to determine the length of the byte space reserved for the security context identifier field in the service data packet. Among them, the above length can be a fixed value or determined according to actual needs.

[0125] Since there are differences in the required byte lengths of security context identifiers corresponding to service data packets of different traffic types, a traffic type identifier field can also be set in the service data packet. The traffic type identifier in the traffic type identifier field represents the length type of the byte space reserved for the security context identifier field in the service data packet, facilitating the determination of the length of the byte space reserved for the security context identifier field in the service data packet. Among them, the lengths corresponding to different length types can be preset. For example, the byte space of the first length type corresponds to a length of 4 bytes, and the byte space of the second length type corresponds to a length of 16 bytes.

[0126] Exemplarily, if the traffic type identifier is the first type value, it represents that the byte space reserved for the security context identifier field in the service data packet is the first byte length, such as 4 bytes. If the traffic type identifier is the second type value, it represents that the second byte length reserved for the security context identifier field in the service data packet, such as 16 bytes. Among them, the second byte length is greater than the first byte length. It should be noted that the traffic type identifier is not limited to the above two values, and different values can also be set as needed, and different byte lengths can be correspondingly set, which is not limited here.

[0127] Exemplarily, the security context identifier field includes a service type field, a user type field, a security level field, and a reserved field. Other security context identifiers defined by the user can be set in the reserved field. The lengths occupied by each field in the security context identifier field are also preset. For example, for the case where the length of the byte space reserved for the security context identifier field in the service data packet is 4 bytes, the lengths occupied by the service type field, the user type field, the security level field, and the reserved field are all 32 bits.

[0128] It can be seen that both the traffic type identifier field and the security context identifier field are set in the programmable extension header. Therefore, the traffic type identifier can be obtained from the traffic type identifier field in the programmable extension header. Based on the traffic type identifier, the length of the byte space reserved for the security context identifier field in the service data packet can be determined, thereby determining the target byte length corresponding to the security context identifier. Furthermore, based on the target byte length and the initial position of the security context identifier, the security context identifier field in the programmable extension header can be determined, and finally, the security context identifier can be extracted from the security context identifier field. Therefore, in this embodiment, for security context identifier fields of different lengths, the security context identifier can be accurately extracted, ensuring the smooth execution of subsequent security protection processing.

[0129] In an actual scenario, the service data packet can be an IPv6 packet generated based on IPv6 technology, and the above programmable extension header is the APN6 (Application-Aware IPv6 Networking) packet header. The APN6 packet header encapsulates an APN ID (Application-Aware IPv6 Networking Identity) field, and the APN ID field is simply referred to as the application identification field. The APN6 packet header has programmable characteristics, and different types of traffic identifiers can be defined by defining different fields in the application identification field. Since the information that can be defined in the application identification field is rich, in this embodiment, the security context identifier can be defined through the application identification field, that is, the security context identifier field is set at the position of the application identification field in the APN6 packet header. Thus, the service type, user type, security level, and other security context identifiers defined by the user can be set through the service type field, user type field, security level field, and reserved field, so as to combine the application awareness and security protection in the network architecture.

[0130] In an actual scenario, the IPv6 packet includes an APN6 packet header and an APN6 parameter field, and of course, it can also include other fields. The APN6 parameter field is used to define the specific content of the required parameters for network performance. For example, the minimum acceptable bandwidth value, the maximum acceptable delay value, the maximum acceptable packet loss rate value, etc.

[0131] See Figure 6 , which is a schematic structural diagram of the APN6 packet header of an IPv6 packet. The APN6 packet header includes a traffic type identifier field, a reserved field, a parameter type field, and an application identification field. Among them:

[0132] (1) Traffic type identifier field: used to define the traffic type identifier. For example, identifier 1 indicates that the byte length of the application identification field is 4 bytes, and identifier 2 indicates that the byte length of the application identification field is 16 bytes.

[0133] (2) Reserved field: Users can customize the required parameters according to their needs, and this parameter is different from other security context identifiers defined by the user.

[0134] (3) Parameter type field: used to define the type of APN6 parameters in the APN6 parameter field, and describe the required parameters for network performance included in the APN6 parameters. For example, demand parameters such as bandwidth, delay, jitter, and packet loss rate.

[0135] (4) Application Identification Field: Used to define the security context identification field, which consists of four parts: Service Type Identification Field: Used to define the service type identification; User Type Identification Field: Used to define the user type identification; Security Level Identification Field: Used to define the security level identification; Reserved Field: Used to define other security context identifications defined by the user.

[0136] In an exemplary embodiment, a security protection method is provided. This method is applied to a business participant and includes:

[0137] Sending a service data packet to a firewall device;

[0138] Among them, the service data packet includes a security context identification, which corresponds to the business scenario of the business participant. The security context identification is used to instruct the firewall device to match the target security protection policy for performing security protection processing on the service data packet.

[0139] Among them, the business participant is a terminal device or a server.

[0140] In an actual scenario, the business participant determines the corresponding security context identification according to the business scenario, packs the security context identification and business traffic to obtain a service data packet, and sends the service data packet to the firewall device, so that the firewall device matches the corresponding target security protection policy according to the security context identification in the service data packet, and thus performs security protection processing according to the target security protection policy.

[0141] It can be seen that since different business scenarios correspond to different security context identifications, it is convenient for the firewall device to match different target security protection policies, implement different security protection processes, and meet the security requirements of different business scenarios. Even for service data packets with the same IP address and port, it is possible to implement security protection with different business scenarios, improving the business scenario pertinence of security protection processing, and avoiding situations such as excessive traffic release, excessive detection, or false block due to only using one security protection policy for service data packets with the same IP address and port.

[0142] Based on the technical solutions of the above embodiments, the present application also provides an embodiment. In this embodiment, the security protection method will be described in detail from the perspective of multi-party interaction.

[0143] See Figure 7 , the security protection method includes:

[0144] S710. The business participant determines the corresponding security context identifier according to the business scenario, packages the security context identifier and the business traffic to obtain a business data packet, and sends the business data packet to the firewall device. Here, the business participant is a terminal device or a server.

[0145] S720. The firewall device receives the business data packet and parses the business data packet.

[0146] S730. The firewall device determines whether the parsing result contains a security context identifier; if so, execute S740; otherwise, execute S750.

[0147] S740. Extract the business type, user type, and security level from the security context identifier, determine the corresponding target security protection policy according to the business type, determine the corresponding target security protection policy according to the user type, determine the corresponding target security protection policy according to the security level, and perform corresponding security protection processing according to the determined various target security protection policies.

[0148] S750. Extract the IP address and port from the business data packet, determine the corresponding target security protection policy according to the IP address and port, and perform corresponding security protection processing according to the determined target security protection policy.

[0149] It should be understood that although each step in the flowcharts involved in the above embodiments is displayed sequentially according to the indication of the arrows, these steps do not necessarily need to be executed sequentially according to the order indicated by the arrows. Unless there is a clear description in this article, the execution of these steps has no strict order limit, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above embodiments may include multiple steps or multiple stages. These steps or stages do not necessarily need to be executed at the same moment, but can be executed at different moments. The execution order of these steps or stages does not necessarily need to be sequential, but can be executed alternately or in turn with at least a part of other steps or steps or stages in other steps.

[0150] Based on the same inventive concept, the embodiments of the present application also provide a security protection device for implementing the above-mentioned security protection method. The solution provided by this device to solve the problem is similar to the solution described in the above method. Therefore, the specific limitations in one or more embodiments of the following security protection devices can refer to the limitations on the security protection method in the above text, and will not be repeated here.

[0151] In an exemplary embodiment, as Figure 8As shown, a security protection device is provided and configured in a firewall device. The device includes a data packet receiving module 810, a data packet parsing module 820, a policy determination module 830, and a protection processing module 840, where:

[0152] The data packet receiving module 810 is used to receive service data packets sent by service participants;

[0153] The data packet parsing module 820 is used to parse the service data packets to obtain security context identifiers in the service data packets; the security context identifiers correspond to the service scenarios of the service participants;

[0154] The policy determination module 830 is used to determine a target security protection policy that matches the security context identifier;

[0155] The protection processing module 840 is used to perform security protection processing on the service data packets according to the target security protection policy.

[0156] In one embodiment, the security context identifier includes a service type identifier; the policy determination module is specifically used for: if the service type identifier represents an Internet of Things service type, then use the abnormal behavior detection policy as the target security protection policy; if the service type identifier represents an Internet service type, then use at least one of the abnormal behavior detection policy, the intrusion detection and prevention policy, and the malicious software protection policy as the target security protection policy.

[0157] In one embodiment, the security context identifier includes a user type identifier; the policy determination module is specifically used for: if the user type identifier represents an external visitor type, then use the first access policy that allows access to the Internet and prohibits access to the enterprise internal network as the target security protection policy; if the user type identifier represents an enterprise internal user type, then use the second access policy that allows access to the Internet and allows access to the enterprise internal network as the target security protection policy.

[0158] In one embodiment, when the policy determination module executes that if the user type identifier represents an enterprise internal user type, then use the second access policy that allows access to the Internet and allows access to the enterprise internal network as the target security protection policy, it is specifically used for: if the user type identifier represents a business department user type, then use the second access sub-policy that allows access to the Internet and only allows access to the data of the corresponding business department in the enterprise internal network as the target security protection policy; where the business department user type is a subtype under the enterprise internal user type.

[0159] In one embodiment, the security context identifier includes a security level identifier; specifically, the policy determination module is configured to: if the security level identifier represents a first security level, use the policy of prohibiting cross-region data transmission as the target security protection policy; if the security level identifier represents a second security level, use the policy of allowing cross-region data transmission as the target security protection policy; wherein, the first security level is higher than the second security level.

[0160] In one embodiment, the data packet parsing module is specifically configured to: extract a traffic type identifier from the programmable extension header of the service data packet; obtain a byte occupancy length that matches the traffic type identifier as the target byte length corresponding to the security context identifier; and extract the security context identifier from the programmable extension header according to the target byte length.

[0161] In an exemplary embodiment, as Figure 9 shown, a security protection device is provided, which is configured in a service participant. The device includes: a data packet sending module 910; wherein:

[0162] The data packet sending module 910 is configured to send a service data packet to a firewall device;

[0163] Wherein, the service data packet includes a security context identifier, and the security context identifier corresponds to the service scenario of the service participant. The security context identifier is used to instruct the firewall device to match the target security protection policy for performing security protection processing on the service data packet.

[0164] Each module in the above security protection device can be implemented in whole or in part by software, hardware, and their combination. The above modules can be embedded in or independent of a processor in a communication device in the form of hardware, or stored in a memory in the communication device in the form of software, so as to facilitate the processor to call and execute the operations corresponding to the above modules.

[0165] In an exemplary embodiment, a communication device is provided. The communication device can be a firewall device, a terminal device, or a server, and its internal structure diagram can be as Figure 10As shown. The communication device includes a processor, a memory, a network interface, and a transceiver connected by a system bus. Among them, the processor of the communication device is used to provide computing and control capabilities. The memory of the communication device includes a non-volatile storage medium and an internal memory. The transceiver of the communication device is used to perform operations of receiving data or sending data under the control of the processor. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the communication device can be used to store relevant data, such as the above-mentioned matching rule table. The network interface of the communication device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, it implements a security protection method.

[0166] Those skilled in the art can understand that Figure 10 the structure shown in is only a block diagram of some structures related to the solution of this application, and does not constitute a limitation on the communication device to which the solution of this application is applied. The specific communication device may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.

[0167] In one embodiment, a communication device is provided, including a memory and a processor. A computer program is stored in the memory. When the processor executes the processing logic in the computer program, the following steps are implemented:

[0168] Receive a service data packet sent by a service participant;

[0169] Parse the service data packet to obtain a security context identifier in the service data packet; the security context identifier corresponds to the service scenario of the service participant;

[0170] Determine a target security protection policy that matches the security context identifier;

[0171] According to the target security protection policy, perform security protection processing on the service data packet.

[0172] In one embodiment, the security context identifier includes a service type identifier. When the processor executes the processing logic in the computer program, the following steps are specifically implemented: If the service type identifier represents an Internet of Things service type, then use the abnormal behavior detection policy as the target security protection policy; if the service type identifier represents an Internet service type, then use at least one of the abnormal behavior detection policy, the intrusion detection and prevention policy, and the malicious software protection policy as the target security protection policy.

[0173] In one embodiment, the security context identifier includes a user type identifier; when the processor executes the processing logic in the computer program, the following steps are specifically implemented: if the user type identifier represents an external visitor type, then the first access policy that allows access to the Internet and prohibits access to the enterprise intranet is used as the target security protection policy; if the user type identifier represents an enterprise internal user type, then the second access policy that allows access to the Internet and allows access to the enterprise intranet is used as the target security protection policy.

[0174] In one embodiment, when the processor executes the processing logic in the computer program, the following steps are specifically implemented: if the user type identifier represents a business department user type, then the second access sub-policy that allows access to the Internet and only allows access to the data corresponding to the business department in the enterprise intranet is used as the target security protection policy; wherein, the business department user type is a subtype under the enterprise internal user type.

[0175] In one embodiment, the security context identifier includes a security level identifier; when the processor executes the processing logic in the computer program, the following steps are specifically implemented: if the security level identifier represents the first security level, then the policy of prohibiting cross-region data transmission is used as the target security protection policy; if the security level identifier represents the second security level, then the policy of allowing cross-region data transmission is used as the target security protection policy; wherein, the first security level is higher than the second security level.

[0176] In one embodiment, when the processor executes the processing logic in the computer program, the following steps are specifically implemented: extract the traffic type identifier from the programmable extension header of the service data packet; obtain the byte occupancy length matching the traffic type identifier as the target byte length corresponding to the security context identifier; extract the security context identifier from the programmable extension header according to the target byte length.

[0177] In one embodiment, another communication device is further provided, including a memory and a processor, wherein a computer program is stored in the memory, and when the processor executes the processing logic in the computer program, the following steps are implemented:

[0178] Send a service data packet to the firewall device;

[0179] Wherein, the service data packet includes a security context identifier, the security context identifier corresponds to the business scenario of the business participant, and the security context identifier is used to instruct the firewall device to match the target security protection policy for performing security protection processing on the service data packet.

[0180] In one embodiment, a computer-readable storage medium or a computer program product is provided, on which a computer program is stored, and when the processing logic in the computer program is executed by a processor, the following steps are implemented:

[0181] Receive a service data packet sent by a service participant;

[0182] Parse the service data packet to obtain a security context identifier in the service data packet; the security context identifier corresponds to the service scenario of the service participant;

[0183] Determine a target security protection policy that matches the security context identifier;

[0184] Perform security protection processing on the service data packet according to the target security protection policy.

[0185] In one embodiment, the security context identifier includes a service type identifier; when the processing logic in the computer program is executed by a processor, the following steps are specifically implemented: if the service type identifier represents an Internet of Things service type, then use the abnormal behavior detection policy as the target security protection policy; if the service type identifier represents an Internet service type, then use at least one of the abnormal behavior detection policy, the intrusion detection and prevention policy, and the malware protection policy as the target security protection policy.

[0186] In one embodiment, the security context identifier includes a user type identifier; when the processing logic in the computer program is executed by a processor, the following steps are specifically implemented: if the user type identifier represents an external visitor type, then use the first access policy that allows access to the Internet and prohibits access to the enterprise internal network as the target security protection policy; if the user type identifier represents an enterprise internal user type, then use the second access policy that allows access to the Internet and allows access to the enterprise internal network as the target security protection policy.

[0187] In one embodiment, when the processing logic in the computer program is executed by a processor, the following steps are specifically implemented: if the user type identifier represents a business department user type, then use the second access sub-policy that allows access to the Internet and only allows access to the data of the corresponding business department in the enterprise internal network as the target security protection policy; wherein, the business department user type is a subtype under the enterprise internal user type.

[0188] In one embodiment, the security context identifier includes a security level identifier; when the processing logic in the computer program is executed by a processor, the following steps are specifically implemented: if the security level identifier represents a first security level, then use the policy of prohibiting cross-region data transmission as the target security protection policy; if the security level identifier represents a second security level, then use the policy of allowing cross-region data transmission as the target security protection policy; wherein, the first security level is higher than the second security level.

[0189] In one embodiment, when the processing logic in the computer program is executed by a processor, the following steps are specifically implemented: extracting a traffic type identifier from the programmable extension header of the service data packet; obtaining a byte occupancy length that matches the traffic type identifier as the target byte length corresponding to the security context identifier; and extracting the security context identifier from the programmable extension header according to the target byte length.

[0190] In one embodiment, another computer-readable storage medium or computer program product is further provided, on which a computer program is stored. When the processing logic in the computer program is executed by a processor, the following steps are implemented:

[0191] Sending a service data packet to a firewall device;

[0192] Wherein, the service data packet includes a security context identifier, the security context identifier corresponds to the service scenario of the service participant, and the security context identifier is used to instruct the firewall device to match a target security protection policy for performing security protection processing on the service data packet.

[0193] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in this application are all information and data that have been authorized by the user or fully authorized by all parties.

[0194] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, database, or other medium used in the embodiments provided in this application can include at least one of non-volatile and volatile memories. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The databases involved in the embodiments provided in this application can include at least one of relational databases and non-relational databases. Non-relational databases can include distributed databases based on blockchain, etc., without limitation. The processors involved in the embodiments provided in this application can be general-purpose processors, central processors, graphics processors, digital signal processors, programmable logic devices, data processing logics based on quantum computing, etc., without limitation.

[0195] The technical features of the above embodiments can be combined arbitrarily. For the sake of concise description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope recorded in this specification.

[0196] The above embodiments only represent several implementation manners of this application, and their descriptions are relatively specific and detailed. However, it should not be construed as a limitation on the patent scope of this application. It should be noted that for those of ordinary skill in the art, without departing from the concept of this application, several modifications and improvements can still be made, and these all belong to the protection scope of this application. Therefore, the protection scope of this application should be subject to the appended claims.

Claims

1. A security protection method, characterized in that, Applied to a firewall device, the method includes: Receiving a service data packet sent by a service participant; Parsing the service data packet to obtain a security context identifier in the service data packet; the security context identifier corresponds to the service scenario of the service participant; Determining a target security protection policy that matches the security context identifier; Performing security protection processing on the service data packet according to the target security protection policy.

2. The method according to claim 1, wherein The security context identifier includes a service type identifier; the determining of the target security protection policy that matches the security context identifier includes: If the service type identifier represents an Internet of Things service type, then using an abnormal behavior detection policy as the target security protection policy; If the service type identifier represents an Internet service type, then using at least one of an abnormal behavior detection policy, an intrusion detection and prevention policy, and a malware protection policy as the target security protection policy.

3. The method according to claim 1, wherein The security context identifier includes a user type identifier; the determining of the target security protection policy that matches the security context identifier includes: If the user type identifier represents an external visitor type, then using a first access policy that allows access to the Internet and prohibits access to the enterprise internal network as the target security protection policy; If the user type identifier represents an enterprise internal user type, then using a second access policy that allows access to the Internet and allows access to the enterprise internal network as the target security protection policy.

4. The method according to claim 3, wherein The if the user type identifier represents an enterprise internal user type, then using a second access policy that allows access to the Internet and allows access to the enterprise internal network as the target security protection policy includes: If the user type identifier represents a business department user type, then using a second access sub-policy that allows access to the Internet and only allows access to the data of the corresponding business department in the enterprise internal network as the target security protection policy; wherein, the business department user type is a subtype under the enterprise internal user type.

5. The method according to claim 1, wherein The security context identifier includes a security level identifier; the determining of the target security protection policy that matches the security context identifier includes: If the security level identifier represents a first security level, then using a policy that prohibits cross-region data transmission as the target security protection policy; If the security level identifier represents a second security level, then using a policy that allows cross-region data transmission as the target security protection policy; Wherein, the first security level is higher than the second security level.

6. The method according to any one of claims 1-5, characterized in that, The parsing of the service data packet to obtain the security context identifier in the service data packet includes: Extracting a traffic type identifier from the programmable extension header of the service data packet; Obtaining a byte occupancy length that matches the traffic type identifier as the target byte length corresponding to the security context identifier; Extracting the security context identifier from the programmable extension header according to the target byte length.

7. A security protection method, characterized in that, Applied to a service participant, the method includes: Sending a service data packet to a firewall device; Among them, the service data packet includes a security context identifier, the security context identifier corresponds to the service scenario of the service participant, and the security context identifier is used to instruct the firewall device to match the target security protection policy for performing security protection processing on the service data packet.

8. A safety protection device, characterized in that, Configured in a firewall device, the device includes: A data packet receiving module, configured to receive a service data packet sent by a service participant; A data packet parsing module, configured to parse the service data packet to obtain the security context identifier in the service data packet; the security context identifier corresponds to the service scenario of the service participant; A policy determination module, configured to determine a target security protection policy that matches the security context identifier; A protection processing module, configured to perform security protection processing on the service data packet according to the target security protection policy.

9. A safety protection device, characterized in that, Configured in a service participant, the device includes: A data packet sending module, configured to send a service data packet to a firewall device; Among them, the service data packet includes a security context identifier, the security context identifier corresponds to the service scenario of the service participant, and the security context identifier is used to instruct the firewall device to match the target security protection policy for performing security protection processing on the service data packet.

10. A communication device, comprising a memory, a transceiver, and a processor, wherein the memory stores a computer program, characterized in that, The transceiver is used to receive or send data under the control of the processor, and when the processor executes the computer program, the steps of the method according to any one of claims 1-7 are implemented.

11. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, the steps of the method according to any one of claims 1-7 are implemented.

12. A computer program product comprising a computer program, characterized in that, When the computer program is executed by a processor, the steps of the method according to any one of claims 1-7 are implemented.

Citation Information

Patent Citations

  • Distributed information network security protection method and system and readable storage medium thereof

    CN116566682A

  • Firewall policy configuration method and device, storage medium and electronic equipment

    CN118250032A

  • Strategy item distribution method and device, equipment and storage medium

    CN118984238A

  • Security protection control method and apparatus, and device

    WO2024140277A1

Cited By

  • Large model calling content security control method and system for multiple service scenes

    CN122451920A