Login information acquisition method and device
The login information of the domain server is obtained by calling the built-in tool through the firewall, which solves the problems of complex installation, large data transmission and poor security in the existing technology, and achieves low-complexity and high-security login information acquisition.
Patent Information
- Application Number
- CN202510573362.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-30
- Publication Date
- 2025-07-18
AI Technical Summary
In the prior art, the method of obtaining user login information of firewalls has problems such as high installation and maintenance complexity, large data transmission volume, high configuration complexity and poor network security.
The firewall sends log query and download commands to the domain server by calling the built-in remote operating system command execution tool and resource access tool, and generates and obtains online users' login information, avoiding additional proxy software installation and configuration, and only transmits files corresponding to the target security log.
It reduces the complexity of installation and maintenance, reduces the amount of data transmission between the domain server and the firewall, improves network security and flexibility in networking methods, and reduces the impact on normal business traffic.
Smart Images

Figure CN120342730A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technologies, and in particular, to a method and apparatus for obtaining login information. Background Art
[0002] Single Sign-On (SSO) is a currently popular solution for enterprise business integration. SSO allows users to log in to the domain server through one authentication, obtain the permission to access network resources, and realize "authentication-free" Internet access without repeatedly entering credentials.
[0003] In the process of implementing single sign-on, the firewall needs to obtain the login information of the user terminal. Currently, the firewall can obtain the login information of the user terminal in any of the following ways:
[0004] Way 1: Install supporting proxy software on the domain server or the user terminal. After the user authenticates and logs in to the domain server, the proxy software obtains the login information and sends the login information to the firewall through a private protocol. In this way, the installation and maintenance of the proxy software are complex, and additional security risks will be introduced.
[0005] Way 2: The firewall uses the IP address of the domain server, the account name and password of the domain administrator to remotely call the EventLog interface to obtain the security logs on the domain server, and then extracts the login information from the security logs. In this way, a large amount of security logs are stored on the domain server, and the firewall needs to extract the required login information from a large amount of security logs, which results in a large amount of data transmitted between the domain server and the firewall and affects the normal business traffic.
[0006] Way 3: The firewall obtains the user's login information from the monitored authentication packets by listening to the authentication packets of the user authenticating and logging in to the domain server. In this way, the firewall needs to be deployed between the user terminal and the domain server, and the networking method has poor flexibility. Or, additional configurations are added on the domain server, the user terminal, or the switching device between the domain server and the user terminal to mirror the authentication packets to the firewall, which increases the complexity of the configuration, and obtaining login information by listening to packets poses a threat to network information security. Summary of the Invention
[0007] The purpose of the embodiments of this application is to provide a method and apparatus for obtaining login information to reduce the installation and maintenance complexity, reduce the amount of data transmitted between the domain server and the firewall, reduce the configuration complexity, and improve network security. The specific technical solutions are as follows:
[0008] In a first aspect, the embodiments of this application provide a method for obtaining login information, which is applied to a firewall. The method includes:
[0009] Invoke a remote operating system command execution tool to send a log query command to the domain server, so that the domain server executes the log query command to generate an online user file corresponding to the online user by using the target security log, and the online user file includes the login information of the online user;
[0010] Invoke a remote operating system resource access tool to send a log download command to the domain server, so that the domain server executes the log download command;
[0011] Receive the online user file sent by the domain server.
[0012] In some embodiments, the method further includes:
[0013] Invoke the remote operating system command execution tool to send a time query command to the domain server, so that the domain server executes the time query command to generate a system time file including the current system time;
[0014] Invoke the remote operating system resource access tool to send a time download command to the domain server, so that the domain server executes the time download command;
[0015] Receive the system time file sent by the domain server;
[0016] Adjust the local time of the firewall to the current system time included in the system time file.
[0017] In some embodiments, after obtaining the login information of the online user, the method further includes:
[0018] If the login information is obtained again before the aging duration corresponding to the login information times out, reset the aging duration corresponding to the login information;
[0019] When the aging duration corresponding to the login information times out, delete the login information.
[0020] In some embodiments, the log query command includes at least one of the following information: online event identifier, start time of the target security log, processing method of the target security log, format of the online user file, name of the online user file, and encoding format of the online user file; wherein, the start time is the latest time included in the login information in the historical online user file obtained by the firewall, or a preset time;
[0021] The log download command includes at least one of the following information: name of the online user file, storage location of the online user file in the firewall.
[0022] In some embodiments, the time query command includes at least one of the following pieces of information: the format of the current system time, the name of the system time file;
[0023] The time download command includes at least one of the following pieces of information: the name of the system time file, the storage location of the system time file in the firewall.
[0024] In a second aspect, an embodiment of the present application provides a method for obtaining login information, which is applied to a domain server. The method includes:
[0025] Receiving a log query command sent by the firewall, where the log query command is sent by the firewall by invoking a remote operating system command execution tool;
[0026] Executing the log query command to generate an online user file using the target security log, where the online user file includes the login information of the online users;
[0027] Receiving a log download command sent by the firewall, where the log download command is sent by the firewall by invoking a remote operating system resource access tool;
[0028] Executing the log download command to send the online user file to the firewall.
[0029] In some embodiments, the method further includes:
[0030] Receiving a time query command sent by the firewall, where the time query command is sent by the firewall by invoking the remote operating system command execution tool;
[0031] Executing the time query command to generate a system time file including the current system time;
[0032] Receiving a time download command sent by the firewall, where the time download command is sent by the firewall by invoking the remote operating system resource access tool;
[0033] Executing the time download command to send the system time file to the firewall, so that the firewall adjusts the local time of the firewall to the current system time included in the system time file.
[0034] In some embodiments, the log query command includes at least one of the following pieces of information: an online event identifier, a start time of the target security log, a processing method of the target security log, a format of the online user file, a name of the online user file, and an encoding format of the online user file; wherein, the start time is the latest time included in the login information in the historical online user file obtained by the firewall, or a preset time;
[0035] The log download command includes at least one of the following pieces of information: a name of the online user file, a storage location of the online user file in the firewall.
[0036] In some embodiments, the time query command includes at least one of the following pieces of information: a format of the current system time, a name of the system time file;
[0037] The time download command includes at least one of the following pieces of information: a name of the system time file, a storage location of the system time file in the firewall.
[0038] In a third aspect, an embodiment of the present application provides a login information acquisition device, which is applied to a firewall. The device includes:
[0039] A first calling module, configured to call a remote operating system command execution tool, send a log query command to a domain server, so that the domain server executes the log query command, and generate an online user file by using a target security log corresponding to an online user, where the online user file includes login information of the online user;
[0040] A second calling module, configured to call a remote operating system resource access tool, send a log download command to the domain server, so that the domain server executes the log download command;
[0041] A receiving module, configured to receive the online user file sent by the domain server.
[0042] In some embodiments, the first calling module is further configured to call the remote operating system command execution tool, send a time query command to the domain server, so that the domain server executes the time query command, and generate a system time file including the current system time;
[0043] The second calling module is further configured to call the remote operating system resource access tool, send a time download command to the domain server, so that the domain server executes the time download command;
[0044] The receiving module is further configured to receive the system time file sent by the domain server; and adjust the local time of the firewall to the current system time included in the system time file.
[0045] In some embodiments, the device further includes a management module;
[0046] The management module is configured to, after obtaining the login information of the online user, if the login information is obtained again before the aging duration corresponding to the login information times out, reset the aging duration corresponding to the login information; and delete the login information when the aging duration corresponding to the login information times out.
[0047] In some embodiments, the log query command includes at least one of the following information: the online event identifier, the start time of the target security log, the processing method of the target security log, the format of the online user file, the name of the online user file, and the encoding format of the online user file; wherein, the start time is the latest time included in the login information in the historical online user file obtained by the firewall, or a preset time;
[0048] The log download command includes at least one of the following information: the name of the online user file, the storage location of the online user file in the firewall.
[0049] In some embodiments, the time query command includes at least one of the following information: the format of the current system time, the name of the system time file;
[0050] The time download command includes at least one of the following information: the name of the system time file, the storage location of the system time file in the firewall.
[0051] Fourthly, an embodiment of the present application provides a login information acquisition device, which is applied to a domain server, and the device includes:
[0052] A first receiving module, configured to receive a log query command sent by a firewall, where the log query command is sent by the firewall by invoking a remote operating system command execution tool;
[0053] A first execution module, configured to execute the log query command to generate an online user file by using the target security log, where the online user file includes the login information of the online user;
[0054] A second receiving module, configured to receive a log download command sent by the firewall, where the log download command is sent by the firewall by invoking a remote operating system resource access tool;
[0055] A second execution module, configured to execute the log download command to send the online user file to the firewall.
[0056] In some embodiments, the first receiving module is further configured to receive a time query command sent by the firewall, where the time query command is sent by the firewall by invoking the remote operating system command execution tool;
[0057] The first execution module is further configured to execute the time query command to generate a system time file including the current system time;
[0058] The second receiving module is further configured to receive a time download command sent by the firewall, where the time download command is sent by the firewall by invoking the remote operating system resource access tool;
[0059] The second execution module is further configured to execute the time download command to send the system time file to the firewall, so that the firewall adjusts the local time of the firewall to the current system time included in the system time file.
[0060] In some embodiments, the log query command includes at least one of the following information: an online event identifier, a start time of the target security log, a processing method of the target security log, a format of the online user file, a name of the online user file, and an encoding format of the online user file; where the start time is the latest time included in the login information in the historical online user file obtained by the firewall, or a preset time;
[0061] The log download command includes at least one of the following information: a name of the online user file, a storage location of the online user file in the firewall.
[0062] In some embodiments, the time query command includes at least one of the following information: a format of the current system time, a name of the system time file;
[0063] The time download command includes at least one of the following information: a name of the system time file, a storage location of the system time file in the firewall.
[0064] In a fifth aspect, an embodiment of the present application provides a firewall, including a processor, a communication interface, a memory, and a communication bus, where the processor, the communication interface, and the memory complete communication with each other through the communication bus;
[0065] The memory is used to store a computer program;
[0066] When the processor is used to execute the programs stored in the memory, it implements any of the methods provided in the first aspect.
[0067] In a sixth aspect, an embodiment of the present application provides a domain server, including a processor, a communication interface, a memory, and a communication bus. Among them, the processor, the communication interface, and the memory complete communication with each other through the communication bus;
[0068] The memory is used to store computer programs;
[0069] When the processor is used to execute the programs stored in the memory, it implements any of the methods provided in the second aspect.
[0070] In a seventh aspect, an embodiment of the present application provides a computer-readable storage medium. The computer-readable storage medium stores a computer program. When the computer program is executed by a processor, it implements any of the methods provided in the first aspect, or implements any of the methods provided in the second aspect.
[0071] In an eighth aspect, an embodiment of the present application provides a computer program product containing instructions. When it runs on a computer, it causes the computer to execute any of the methods provided in the first aspect, or execute any of the methods provided in the second aspect.
[0072] Advantageous effects of the embodiments of the present application:
[0073] In the technical solution provided by the embodiments of the present application, the remote operating system command execution tool and the remote operating system resource access tool are tools built into the operating system of the firewall and do not need to be installed manually. The firewall sends the log query command and the log download command to the domain server by invoking the built-in remote operating system command execution tool and the remote operating system resource access tool. The domain server executes the log query command and the log download command, generates an online user file including the login information of the online user by using the target security log corresponding to the online user, and sends the online user file to the firewall, so that the firewall obtains the login information of the online user.
[0074] During the entire process of obtaining login information, there is no need to install additional proxy software or configure it, which reduces the complexity of configuration, has a relatively low installation and maintenance complexity, and improves network security. When the domain server executes the log query command, it can generate an online user file only by using the target security log corresponding to the online user, that is, the security log is filtered. Only the online user file corresponding to the target security log is transmitted between the domain server and the firewall, rather than the file corresponding to all security logs, which reduces the large amount of data transmitted between the domain server and the firewall and reduces the impact on normal business traffic. In addition, the firewall can be deployed anywhere, and there is no need to add additional configuration on the domain server, user terminal, or switching device between the domain server and the user terminal, which improves the flexibility of the networking method, reduces the complexity of configuration, and further improves security.
[0075] Of course, it is not necessary for any product or method implementing the present application to achieve all the above advantages simultaneously. BRIEF DESCRIPTION OF THE DRAWINGS
[0076] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the following drawings are only some embodiments of the present application, and those of ordinary skill in the art can obtain other embodiments based on these drawings.
[0077] Figure 1 It is a schematic structural diagram of a firewall;
[0078] Figure 2 It is a schematic diagram of an AD single sign-on process;
[0079] Figure 3 It is the first interactive signaling diagram of the login information acquisition method provided by the embodiment of the present application;
[0080] Figure 4 It is the second interactive signaling diagram of the login information acquisition method provided by the embodiment of the present application;
[0081] Figure 5 It is an interactive signaling diagram among the firewall, domain server, and user provided by the embodiment of the present application;
[0082] Figure 6 It is the first flow schematic diagram of the login information acquisition method provided by the embodiment of the present application;
[0083] Figure 7 It is the second flow schematic diagram of the login information acquisition method provided by the embodiment of the present application;
[0084] Figure 8The first structural schematic diagram of the login information acquisition device provided by the embodiment of the present application;
[0085] Figure 9 A structural schematic diagram of the networking architecture of single sign-on provided by the embodiment of the present application;
[0086] Figure 10 The second structural schematic diagram of the login information acquisition device provided by the embodiment of the present application;
[0087] Figure 11 A structural schematic diagram of the firewall provided by the embodiment of the present application;
[0088] Figure 12 A structural schematic diagram of the domain server provided by the embodiment of the present application. Detailed implementation manners
[0089] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art based on the present application belong to the scope of protection of the present application.
[0090] For ease of understanding, the terms that appear in the embodiments of the present application will be explained below.
[0091] Lightweight Directory Access Protocol (LDAP): Used to access and operate data in directory services. The directory service in LDAP is a system composed of a directory database and a set of access protocols. This directory service can be understood as a relational database, which stores various configuration information of hosts in the domain. Users can search for a certain object in the directory service through the LDAP hierarchy. LDAP is suitable for scenarios with a multi-platform (Linux / Unix / Mac) hybrid ecological environment, the need to dock with open source systems, or only basic directory services.
[0092] Active Directory (AD): An LDAP implementation solution. AD provides enterprise-level identity management, resource access control, and policy management. AD is essentially a database based on a directory structure, which stores authentication information, permission assignment information, and directory information of objects such as users, computers, and applications. AD is suitable for scenarios with a pure Windows ecological environment, the need for in-depth integration of group policy management, or the implementation of enterprise-level identity federation.
[0093] Distributed Computing Environment / Remote Procedure Call (DCE / RPC): A remote procedure call protocol that allows a program on one computer to call a service on another computer without having to know the underlying network details. DCE / RPC uses a client / server model, where the requesting service program is the client and the providing service program is the server. The client call process sends call information with process parameters to the server and then waits for a reply message; the server-side process remains in a sleep state until the call information arrives, obtains the process parameters, calculates the result, sends a reply message, and then waits to receive the next call information. The client call process receives the reply message and continues to execute the call after obtaining the reply message.
[0094] SAMBA: An open-source software suite based on the Server Message Block (SMB) / Common Internet File System (CIFS) protocol, which enables cross-platform (Linux / Unix and Windows) file sharing, printing services, and domain management functions. The Samba suite includes a large number of utility tools, including remote operating system command execution tools such as winexe, and remote operating system resource access tools (i.e., tools for remotely accessing SMB / CIFS resources on a server), such as smbclient.
[0095] PowerShell: A powerful command-line shell program and scripting language provided by the Windows operating system. PowerShell has a large number of commands called cmdlets (pronounced "command-lets"), each of which performs a specific task, such as obtaining system information, managing processes, operating on files and the registry, etc. By combining these cmdlets, complex system management tasks can be completed.
[0096] Firewall: Monitors and controls network traffic to protect the internal network from external threats. The firewall can include a registration module, a login module, an identity recognition module, and a firewall module, as Figure 1 shown.
[0097] In user mode, the following three operations are performed:
[0098] 1) User account information registration: The administrator registers user account information such as the username and user naming to the registration module; the identity recognition module sends a request to obtain user account information to the registration module, and then the registration module pushes the user account information to the identity recognition module according to the request sent by the identity recognition module.
[0099] Among them, the registration module can be located on the firewall or on a third-party device (such as an AD domain server).
[0100] 2) User online: The user inputs user information such as the username and user naming to the login module; the login module authenticates the user using the user information, and after successful authentication, generates the online user data of the user; the identity recognition module sends a request to obtain the online user data to the login module, and then the login module pushes the online user data to the identity recognition module according to the request sent by the identity recognition module. The identity recognition module distributes the online user data to the kernel.
[0101] Among them, the login module can be located on the firewall or on a third-party device (such as an AD domain server). The online user data can include information such as the Internet Protocol (IP) address, Media Access Control (MAC) address, username, and domain name.
[0102] 3) Security policy configuration: The administrator configures different security policies for different users on the firewall module. The firewall module distributes the security policy to the kernel. The security policy can include the username and traffic allowance rules, etc.
[0103] The security policy in the firewall module references the online user data in the identity recognition module. When the user account information changes (such as the username changes), the identity recognition module sends a notification of the change in the user account information to the firewall module to update the security policy in a timely manner.
[0104] In the kernel state, the firewall module receives the data packet sent by the user, extracts address information such as the IP address and MAC address from the data packet, matches the address information with the online user data in the identity recognition module to determine the username, that is, determines the user to which the data packet belongs; and then matches the determined username with the security policy to obtain the traffic allowance rule that matches the username, and allows or discards the data packet according to the matched traffic allowance rule.
[0105] Single Sign-On (SSO): Allows users to log in to the domain server through a single authentication, obtain the permission to access network resources, and surf the Internet without having to repeatedly enter credentials, achieving "authentication-free" Internet access. Currently, the commonly used SSO includes Active Directory Domain Single Sign-On (AD SSO). AD SSO is an authentication mechanism based on the AD environment that allows users to log in to the AD domain server through a single authentication and obtain the permission to access network resources without having to repeatedly enter credentials. For the specific AD SSO process, please refer to Figure 2 as shown below:
[0106] User A sends a login request to the AD domain server through a switching device (Switch, SW). The login request includes User A's domain username and user password. The AD domain server authenticates User A based on User A's domain username and user password. After successful authentication, it generates User A's online user data (i.e., login information) and sends User A's online user data to the firewall.
[0107] After that, when the firewall receives a data packet sent by User A, based on User A's online user data, it can identify that the data packet belongs to User A and then forward the data packet, enabling User A to access the network. When the firewall receives a data packet sent by User B, since User B has not been authenticated and logged in on the AD domain server and the firewall does not store User B's online user data, the firewall cannot identify the user to whom the data packet belongs and thus discards the data packet, blocking User B from accessing the network.
[0108] Currently, in the process of implementing single sign-on, the firewall can obtain login information in any of the following ways.
[0109] Method 1: Install a supporting proxy software on the domain server or user terminal. When the user authenticates and logs in on the domain server, the proxy software obtains the login information and sends the login information to the firewall through a private protocol.
[0110] In Method 1, it is necessary to install proxy software on the domain server or user terminal. The installation and maintenance are complex and not very user-friendly. In addition, the installation of the proxy software introduces additional security risks, which are unacceptable to enterprises with high security requirements.
[0111] Method 2: The domain server uses the Windows system and supports the DCE / RPC protocol. The IP address of the domain server, the account name and password of the domain administrator are configured on the firewall. The online user data on the domain server (such as an AD domain server) is stored in the form of security logs. The firewall uses the IP address of the domain server, the account name and password of the domain administrator to remotely call the EventLog interface, obtain the security logs on the domain server, and then extract the login information from the security logs.
[0112] The domain server stores a large number of security logs, such as security logs containing online user data and security logs containing other information, and there are duplicate security logs. In addition to the address information and domain username required for single sign-on, the security logs containing online user data also include other information. In Method 2, when the firewall remotely calls the Eventlog interface, a large number of security logs will be obtained. It is necessary to screen out the security logs containing online user data from the large number of security logs, deduplicate the security logs containing online user data, and then extract the address information and domain username and other login information required for single sign-on from the security logs containing online user data. This will result in a large amount of data transmitted between the domain server and the firewall, affecting the normal business traffic.
[0113] In addition, in order to ensure the acquisition of correct login information, it is necessary to manually maintain the time synchronization between the domain server and the firewall, and the maintenance cost is relatively high.
[0114] Method 3: The firewall obtains the user's login information from the monitored authentication packets by listening to the authentication packets of the user authenticating and logging in to the domain server.
[0115] In Method 3, no components need to be installed on the domain server or the user terminal, but it is required to meet any of the following conditions:
[0116] Condition 1: The firewall is deployed between the user terminal and the domain server to ensure that the authentication packets of the user authenticating and logging in to the domain server pass through the firewall. This networking method has poor flexibility.
[0117] Condition 2: Additional configurations are added on the domain server, the user terminal, or the switching device between the domain server and the user terminal to mirror the authentication packets to the firewall through the listening port. This increases the complexity of the configuration, and the method of obtaining login information by listening to the packets poses a threat to network information security.
[0118] To solve the above problems, the embodiments of the present application provide a method for obtaining login information, as Figure 3 shown, which may include the following steps:
[0119] Step S301, the firewall calls the remote operating system command execution tool and sends a log query command to the domain server;
[0120] Step S302, the domain server executes the log query command to generate an online user file using the target security log corresponding to the online user. The online user file includes the login information of the online user;
[0121] Step S303, the firewall calls the remote operating system resource access tool and sends a log download command to the domain server;
[0122] Step S304, the domain server executes the log download command to send the online user file to the firewall;
[0123] Step S305, the firewall parses the online user file to obtain the login information of the online user.
[0124] In the technical solution provided by the embodiment of the present application, during the entire process of obtaining the login information, there is no need to install additional proxy software or configuration, which reduces the complexity of the configuration, and the installation and maintenance complexity is relatively low, improving network security; when the domain server executes the log query command, it can generate an online user file only using the target security log corresponding to the online user, that is, the security log is filtered. Only the online user file corresponding to the target security log is transmitted between the domain server and the firewall, rather than the files corresponding to all security logs, reducing the large amount of data transmitted between the domain server and the firewall and reducing the impact on normal business traffic; in addition, the firewall can be deployed at any location, and there is no need to add additional configuration on the domain server, user terminal, or switching device between the domain server and the user terminal, improving the flexibility of the networking method, reducing the complexity of the configuration, and further improving security.
[0125] In the embodiment of the present application, the domain server can be an AD domain server or other types of domain servers, and this is not limited. Taking the domain server as an AD domain server, the operating system of the domain server is the Window operating system. The firewall is built-in with a remote operating system command execution tool and a remote operating system resource access tool. Among them, the remote operating system command execution tool is used to remotely control the operating system of other devices to execute specified commands, and the remote operating system resource access tool is used to remotely access the resources of other devices.
[0126] In the embodiment of the present application, the remote operating system command execution tool can be the winexe tool in the open-source Samba suite, and the remote operating system resource access tool can be the smbclient tool in the open-source Samba suite. The remote operating system command execution tool and the remote operating system resource access tool can also be other open-source tools, and this is not limited.
[0127] Configure a single sign-on policy on the firewall to allow users to log in through a single authentication operation, so as to achieve subsequent "authentication-free" Internet access. The firewall can also configure the login username and user password of the domain server, and the address of the domain server, such as IP address, MAC address, etc., to facilitate the firewall to remotely operate the domain server. The firewall can also configure security policies to facilitate the release of data packets of domain users and enable domain users to access the network.
[0128] In the embodiment of the present application, the firewall can also configure the aging duration of the login information to timely age the login information of the domain users who have gone offline, saving the storage space of the firewall.
[0129] Domain users (such as Figure 2 User A in) when going online, send a login request to the domain server through the SW. The login request includes the domain username and user password of the domain user; the domain server authenticates the domain user according to the domain username and user password. After the authentication is successfully passed, the online user data (i.e., login information) of the domain user is generated and stored in the domain server in the form of a security log. Among them, the login information can include, but is not limited to, the IP address of the online user (i.e., the domain user), the MAC address of the online user, the username of the online user, the domain name of the domain to which the online user belongs, the online time of the online user, etc. The security log including the login information is the security log corresponding to the online user, such as the target security log.
[0130] Non-domain users (such as Figure 2 User B in) when going online, after the non-domain user logs in to the personal terminal, will not send a login request to the domain server, and the domain server cannot perceive the online of the non-domain user, so it will not generate a security log corresponding to the non-domain user.
[0131] In the above step S301, the log query command is used to query the target security log corresponding to the online user in the domain server. The number of online users can be one or more. Correspondingly, the number of target security logs can be one or more. The log query command can include at least one of the following information: online event identifier, start time of the target security log, processing method of the target security log, format of the online user file, name of the online user file, and encoding format of the online user file.
[0132] Among them, the start time can be the latest time included in the login information in the historical online user file obtained by the firewall, or the start time can be a preset time, such as the system time obtained from the domain server for the last time. The processing method of the target security log can include, but is not limited to, operations such as filtering, sorting, and classification.
[0133] After the firewall is powered on, it can periodically execute step S301, call the remote operating system command execution tool, and send a log query command to the domain server; or it can be triggered by an event to call the remote operating system command execution tool and send a log query command to the domain server. For example, when an administrator inputs a login information acquisition instruction to the firewall, after the firewall receives this instruction, it executes step S301, that is, calls the remote operating system command execution tool and sends a log query command to the domain server.
[0134] In the above step S302, a user may authenticate and log in to the domain server multiple times using the same or different terminals. Correspondingly, the domain server records multiple target security logs corresponding to this user. In addition, multiple users may authenticate and log in to the domain server using the same or different terminals. Correspondingly, the domain server records the target security logs corresponding to multiple users. The online user file may include one or more login information. One login information corresponds to one online user. Two login information may correspond to the same online user or different online users. The specific information included in the online user file can be determined by the log query command.
[0135] After the domain server receives the log query command, it executes the log query command, that is, queries the target security logs corresponding to the online users, and uses the target security logs to generate an online user file including the login information of the online users.
[0136] For example, the remote operating system command execution tool is winexe, and the log query command is a powershell command. The firewall calls winexe and sends a winexe message to the domain server. This winexe message includes the powershell command, and the specific parameters are as follows:
[0137] winexe -U admin%123456 / / 1.1.1.1 "powershell -Command Get-WinEvent -FilterHashtable@{LogName='Security'; Id=4769; StartTime='2025 / 01 / 01 12:00:00'}|Export-Csv users.csv -Encoding UTF8"
[0138] The winexe message includes the login username "admin" of the domain server, the user password "123456", and the IP address "1.1.1.1" of the domain server. Using "admin", "123456", and "1.1.1.1", the firewall can remotely access the domain server and enable the domain server to execute the powershell command included in the winexe message. The above powershell command is a command for obtaining operating system events (Command Get-WinEvent), and this Command Get-WinEvent includes a filtering hash table (FilterHashtable) and output result requirements. The filtering parameters included in the filtering hash table are: the log name (LogName) is Security, the event ID (id) is 4769, and the start time of the target security log is 2025 / 01 / 01 12:00:00. The output result (Export) requirements include: the format of the online user file (i.e., the export format) is Csv, the name of the online user file is users.csv, and the encoding format (Encoding) of the online user file is UTF8.
[0139] After receiving the above winexe message, the domain server parses the powershell command from the winexe message, logs in to the domain server, and executes the powershell command. That is, it queries the security log with the log name Security, event id 4769, and creation time later than 2025 / 01 / 01 12:00:00 as the target security log; each target security log can be used as an online event and encapsulated in the online user file. The domain server stores the online user file.
[0140] In the embodiment of the present application, the log query command may also include parameters for processing methods such as content filtering, sorting, and classification of the target security log. For example, the winexe message sent by the firewall to the domain server can be seen in the following description:
[0141]
[0142] The above powershell command includes content filtering information, that is, for each login information (ForEach-Object), it filters out the username (Username), creation time (TimeCreated), event id (EventRecordID), and the user's IP address (IpAdress). According to this content filtering information, the domain server can filter out the username, creation time, event id, and the user's IP address from each target security log as a piece of login information.
[0143] The above PowerShell command also includes a classification parameter, that is, the grouping object (Group-Object) is the username (Username), that is, the domain server can group the login information by username.
[0144] The above PowerShell command also includes a sorting parameter, that is, the sorting object (Sort-Object) is the creation time (TimeCreated), that is, the domain server can, for each group, sort in descending order by the creation time, select the first login information, and sort the selected login information in ascending order by the creation time.
[0145] The above log query command is only an example and does not serve as a limitation.
[0146] In the above step S303, the log download command is used to access resources in the domain server, such as the above online user file. The log download command may include at least one of the following information: the name of the online user file, the storage location of the online user file in the firewall. Among them, the name of the online user file in the log download command is the same as the name of the online user file in the log query command to ensure that the firewall obtains the accurate online user file.
[0147] The log download command may also include other information, as long as it can accurately obtain the online user file generated in step S302. For example, the log download command may also include the creation time, which is later than the start time in the log query command.
[0148] After sending the log query command, the firewall can wait for a preset duration and then execute step S303, call the remote operating system resource access tool, and send the log download command to the domain server. The preset duration can be set according to actual needs to ensure that the domain server has generated the online user file when sending the log download command.
[0149] In the above step S304, after receiving the log download command, the domain server executes the log download command, that is, queries the online user file and sends the online user file to the firewall.
[0150] For example, the remote operating system resource access tool is smbclient, and the log download command is the get command. The firewall calls smbclient and sends an smbclient message to the domain server. The smbclient message includes the get command, and the specific parameters are as follows:
[0151] smbclient / / 1.1.1.1 / ADMIN$-U admin%123456 -c "get users.csv / var / users.csv" -D\\System32
[0152] The smbclient message includes the login username admin of the domain server, the user password 123456, and the IP address 1.1.1.1 of the domain server. Using admin, 123456, and 1.1.1.1, the firewall can remotely access the domain server, causing the domain server to execute the get command included in the smbclient message. The above get command is a command to obtain the online user file. The parameters included in the get command are: the name of the online user file is users.csv, the location of the online user file in the domain server is System32, and the location where the online user file is stored in the firewall is / var / users.csv.
[0153] After receiving the above smbclient message, the domain server parses the get command from the smbclient message, logs in to the domain server, and executes the get command. That is, it obtains users.csv under the System32 directory of the domain server and stores the obtained users.csv in / var / users.csv of the firewall, realizing the download of the online user file users.csv.
[0154] In the above step S305, after the firewall obtains the online user file from the domain server and parses the online user file, the login information of the online users can be obtained. Among them, each piece of login information can be an online user entry, as shown in the following table:
[0155] User Name Event ID IP Address Creation Time
[0156] After obtaining the login information of the online users, such as the above online user entries, the firewall can use the login information of the online users to implement the single sign-on function for the online users. That is, after receiving a data packet, it can search for the online user entry including the source IP address of the data packet in the online user entries, and use the username (i.e., the domain username) in the found online user entry to search for the security policy and allow the data packet to pass. If the online user entry is not found, the data packet is discarded.
[0157] In an embodiment of the present application, after obtaining the login information of an online user, if the firewall obtains the login information again before the aging duration corresponding to the login information times out, the firewall resets the aging duration corresponding to the login information; when the aging duration corresponding to the login information times out, it indicates that the user has not logged in to the domain server again using the same terminal and the same username. The firewall can delete the login information to save the storage space of the firewall and improve the security of user information.
[0158] In some embodiments, as Figure 4 shown, a system time synchronization method is provided, which may include the following steps:
[0159] Step S401, the firewall calls a remote operating system command execution tool to send a time query command to the domain server;
[0160] The time query command is used to query the current system time in the domain server. After the firewall is powered on and started, it can periodically execute step S401, call the remote operating system command execution tool, and send a time query command to the domain server; it can also be triggered by an event to call the remote operating system command execution tool and send a time query command to the domain server. For example, when the administrator inputs a time acquisition instruction to the firewall, after the firewall receives the instruction, it executes step S401, calls the remote operating system command execution tool, and sends a time query command to the domain server.
[0161] Step S402, the domain server executes the time query command to generate a system time file including the current system time;
[0162] After receiving the time query command, the domain server executes the time query command, that is, queries the current system time on the domain server, creates a system time file, and encapsulates the current system time in the system time file.
[0163] For example, the remote operating system command execution tool is winexe, and the time query command is a powershell command. The firewall calls winexe and sends a winexe message to the domain server. The winexe message includes a powershell command, and the specific parameters are as follows:
[0164] winexe -U admin%123456 / / 1.1.1.1 "powershell -Command Get-Date -Format 'yyyy / MM / dd HH:mm:ss'|Out-File systime.txt"
[0165] The winexe message includes the login username "admin" of the domain server, the user password "123456", and the IP address "1.1.1.1" of the domain server. Using "admin", "123456", and "1.1.1.1", the firewall can remotely access the domain server, enabling the domain server to execute the PowerShell command included in the winexe message. The above PowerShell command is a command to obtain the system time (Command Get-Date), and this Command Get-Date includes a time format (Format), namely year (yyyy) / month (MM) / day (dd), hour (HH):minute (mm):second (ss). Command Get-Date also includes the name of the output file (Out-File) (i.e., systime.txt).
[0166] After receiving the above winexe message, the domain server parses the PowerShell command from the winexe message, logs in to the domain server, and executes the PowerShell command, that is, queries the current system time, creates a system time file systime.txt, and encapsulates the current system time in the system time file systime.txt.
[0167] Step S403, the firewall calls the remote operating system resource access tool and sends a time download command to the domain server;
[0168] The time download command is used to access the resources in the domain server, such as the above system time file. The time download command may include at least one of the following information: the name of the system time file, the storage location of the system time file in the firewall. Among them, the name of the system time file in the time download command is the same as the name of the system time file in the time query command to ensure that the firewall obtains the accurate system time file. The time download command may also include other information as long as it can accurately obtain the system time file generated in step S402.
[0169] After sending the time query command, the firewall can wait for a preset duration and then execute step S403, call the remote operating system resource access tool, and send a time download command to the domain server. Among them, the preset duration can be set according to actual needs to ensure that the domain server has generated the system time file when sending the time download command. The duration required for the domain server to generate the system time file is very short and can be ignored. Therefore, the above preset duration can also be ignored.
[0170] Step S404, the domain server executes the time download command to send the system time file to the firewall;
[0171] After receiving the time download command, the domain server executes the time download command, that is, queries the system time file and sends the system time file to the firewall.
[0172] For example, the remote operating system resource access tool is smbclient, and the time download command is the get command. The firewall invokes smbclient and sends an smbclient message to the domain server. The smbclient message includes the get command, and the specific parameters are as follows:
[0173] smbclient / / 1.1.1.1 / ADMIN$-U admin%123456-c“get systime.txt / var / systime.txt”-D\\System32
[0174] The smbclient message includes the login username admin of the domain server, the user password 123456, and the IP address 1.1.1.1 of the domain server. Using admin, 123456, and 1.1.1.1, the firewall can remotely access the domain server and enable the domain server to execute the get command included in the smbclient message. The above get command is a command to obtain the system time file. The parameters included in the get command are: the name of the system time file is systime.txt, the location of the system time file in the domain server is System32, and the location where the system time file is stored in the firewall is / var / systime.txt.
[0175] After receiving the above smbclient message, the domain server parses the get command from the smbclient message, logs in to the domain server, and executes the get command. That is, it obtains systime.txt under the System32 directory of the domain server and stores the obtained systime.txt in / var / systime.txt of the firewall, realizing the download of the system time file systime.txt.
[0176] Step S405, the firewall parses the system time file to obtain the current system time;
[0177] Step S406, the firewall adjusts the local time of the firewall to the current system time.
[0178] After the firewall obtains the system time file from the domain server, it parses the system time file to obtain the current system time of the domain server, and then sets the local time of the firewall to the current system time, realizing the system time synchronization between the domain server and the firewall.
[0179] In the technical solution provided by the embodiment of the present application, the firewall sends a time query command and a time download command to the domain server by invoking the built-in remote operating system command execution tool and remote operating system resource access tool. The domain server executes the time query command and the time download command, and sends the current system time to the firewall, realizing the system time synchronization between the domain server and the firewall. In the case of system time synchronization, it is ensured that the firewall accurately obtains the login information and ensures single sign-on.
[0180] The following Figure 5 illustrates the acquisition of login information in the embodiment of the present application with reference to the interaction signaling diagram among the firewall, the domain server, and the user as shown. Figure 5 In this example, the domain server is an AD domain server, the remote operating system command execution tool is winexe, and the remote operating system resource access tool is smbclient.
[0181] Step S501, the user logs in to the AD domain server.
[0182] In the embodiment of the present application, the user logging in to the AD domain server is a domain user. The domain user sends a login request to the AD domain server, and the login request includes the domain username and user password of the domain user.
[0183] Step S502, the AD domain server authenticates the user and generates a security log.
[0184] In the embodiment of the present application, the AD domain server authenticates the domain user according to the domain username and user password included in the login request. After successful authentication, a security log is generated, and the security log includes the login information of the domain user. At this time, the domain user goes online, that is, the domain user becomes an online user.
[0185] Step S503, the firewall invokes winexe and sends a time query command to the AD domain server.
[0186] The firewall is configured with a single sign-on policy and a security policy.
[0187] Step S504, the AD domain server executes the time query command and generates a system time file, such as the above-mentioned systime.txt.
[0188] The system time file includes the current system time of the AD domain server.
[0189] Step S505, the firewall invokes smbclient and sends a time download command to the AD domain server.
[0190] Step S506, the AD domain server executes the time download command and sends the system time file to the firewall.
[0191] Step S507, the firewall parses the system time file, obtains the current system time of the AD domain server, and updates the local time to the current system time of the AD domain server.
[0192] Step S508: The firewall calls winexe to send a log query command to the AD domain server.
[0193] Step S509: The AD domain server executes the log query command to generate an online user file, such as the above-mentioned users.csv.
[0194] The online user file contains the login information of online users.
[0195] Step S510: The firewall calls smbclient to send a log download command to the AD domain server.
[0196] Step S511: The AD domain server executes the log download command and sends the online user file to the firewall.
[0197] Step S512: The firewall parses the online user file, obtains the login information of the online user, and generates an online user entry.
[0198] After an online user entry for an online user is generated, if the firewall obtains the online user entry again before the aging time corresponding to the online user entry times out, the firewall resets the aging time corresponding to the online user entry; when the aging time corresponding to the online user entry times out, the firewall deletes the online user entry.
[0199] Step S513: The user sends a data message to access the network.
[0200] Step S514: The firewall uses the source IP address of the data message to query the online user table entry and allows the domain user's data message to pass.
[0201] The firewall uses the source IP address of the datagram to query the online user table, and uses the user name (i.e., domain user name) in the online user table to search the security policy and release the datagram. If the online user table is not found, the datagram is discarded.
[0202] The technical solution provided by the embodiment of the present application has the following beneficial effects:
[0203] (1) Realized the single sign-on function of domain server;
[0204] The embodiment of the present application supports the single sign-on function of the domain server, and the domain user can access the network after being authenticated by the domain server without additional authentication. Users who have not been authenticated by the domain server cannot access the network.
[0205] (2) Compared with the above solution of installing proxy software, the embodiments of the present application do not require the installation of proxy software;
[0206] The embodiments of the present application support the installation-free of proxy software and have the following advantages:
[0207] 1) User-friendly: Users do not need to install proxy software by themselves and do not need to consider the upgrade and maintenance of the software;
[0208] 2) Eliminate users' security concerns: Office equipment in some industries clearly prohibits the installation of third-party software (such as the above proxy software);
[0209] Users do not need to install any proxy programs, drivers or middleware on the user's local or server. They directly rely on the tools built into the operating system (such as Samba and powershell commands), and use the function of remotely calling commands in Samba to obtain login information, which naturally adapts to enterprise-level security policies, reduces maintenance costs, and improves the security level.
[0210] 3) Save costs for equipment manufacturers: Equipment manufacturers do not need to develop and maintain supporting client software additionally.
[0211] In the embodiments of the present application, it is implemented based on the mechanism of remotely calling commands and downloading files provided by Samba. By remotely calling powershell commands through Samba tools (such as winexe), system time files and online user files are generated, and files are downloaded using Samba tools, maximizing the advantages of the operating system itself and reducing duplicate development.
[0212] (3) Compared with the solution of calling the Eventlog interface, the embodiments of the present application use general powershell commands and can support more functions. Specifically, there are the following advantages:
[0213] 1) More flexible: It is not restricted by the version of the domain server. The firewall can use powershell commands to obtain the required data and can customize the output format for easy later parsing;
[0214] 2) Higher scalability: If the user's requirements change later and new data needs to be obtained, only the parameters of the powershell command need to be updated, and there is no need to adapt to other specific interfaces provided by the domain server operating system;
[0215] 3) Support more complex data processing: Powershell commands can fully call various system tools to enable the domain server to perform operations such as data filtering, sorting, and classification in advance, reducing the amount of data transmitted over the network. Especially when the number of users is very large, the effect is more obvious.
[0216] (4) Compared with the solution of listening to authentication messages, the embodiments of the present application support any network configuration, and specifically have the following advantages:
[0217] 1) Flexible deployment method: The firewall can be deployed at any position in the network, as long as it can establish a Transmission Control Protocol (TCP) connection with the domain server; after the firewall and the domain server establish a TCP connection, they can communicate with the domain server through the Samba protocol, remotely execute commands, and download files.
[0218] 2) Improve network security: Reduce the risk of network interruption caused by a single point of failure of the firewall;
[0219] 3) Meet user privacy requirements: There is no need to listen to user messages.
[0220] The embodiments of the present application also provide a method for obtaining login information, as Figure 6 shown, applied to the firewall. The method includes:
[0221] Step S601, call the remote operating system command execution tool, send a log query command to the domain server, so that the domain server executes the log query command, and generate an online user file corresponding to the online user by using the target security log. The online user file includes the login information of the online user;
[0222] Step S602, call the remote operating system resource access tool, send a log download command to the domain server, so that the domain server executes the log download command;
[0223] Step S603, receive the online user file sent by the domain server.
[0224] In some embodiments, the above method for obtaining recording information may further include:
[0225] Call the remote operating system command execution tool, send a time query command to the domain server, so that the domain server executes the time query command, and generate a system time file including the current system time;
[0226] Call the remote operating system resource access tool, send a time download command to the domain server, so that the domain server executes the time download command;
[0227] Receive the system time file sent by the domain server;
[0228] Adjust the local time of the firewall to the current system time included in the system time file.
[0229] In some embodiments, after obtaining the login information, the above method for obtaining recording information may further include:
[0230] If the aging duration corresponding to the login information is obtained again before the aging duration times out, reset the aging duration corresponding to the login information; when the aging duration corresponding to the login information times out, delete the login information.
[0231] In some embodiments, the log query command includes at least one of the following information: online event identifier, start time of the target security log, processing method of the target security log, format of the online user file, name of the online user file, and encoding format of the online user file; wherein, the start time is the latest time included in the login information in the historical online user file obtained by the firewall, or a preset time;
[0232] The log download command includes at least one of the following information: name of the online user file, storage location of the online user file in the firewall.
[0233] In some embodiments, the time query command includes at least one of the following information: format of the current system time, name of the system time file;
[0234] The time download command includes at least one of the following information: name of the system time file, storage location of the system time file in the firewall.
[0235] In the technical solution provided by the embodiments of the present application, the remote operating system command execution tool and the remote operating system resource access tool are tools built into the operating system of the firewall and do not need to be installed manually. The firewall sends the log query command and the log download command to the domain server by calling the built-in remote operating system command execution tool and remote operating system resource access tool. The domain server executes the log query command and the log download command, generates an online user file including the login information of the online user by using the target security log corresponding to the online user, and sends the online user file to the firewall, so that the firewall obtains the login information of the online user.
[0236] During the whole process of obtaining the login information, there is no need to install additional proxy software or configuration, which reduces the complexity of configuration, has low installation and maintenance complexity, and improves network security; when the domain server executes the log query command, it can generate the online user file only by using the target security log corresponding to the online user, that is, filter the security log. Only the online user file corresponding to the target security log is transmitted between the domain server and the firewall, rather than the files corresponding to all security logs, which reduces the large amount of data transmitted between the domain server and the firewall and reduces the impact on normal business traffic; in addition, the firewall can be deployed at any location, and there is no need to add additional configuration on the domain server, user terminal, or switching device between the domain server and the user terminal, which improves the flexibility of the networking method, reduces the complexity of configuration, and further improves security.
[0237] The embodiment of the present application further provides a method for obtaining login information. As Figure 7 shown, it is applied to a domain server, and the method includes:
[0238] Step S701: Receive a log query command sent by the firewall. The log query command is sent by the firewall by invoking a remote operating system command execution tool;
[0239] Step S702: Execute the log query command to generate an online user file by using the target security log. The online user file includes the login information of online users;
[0240] Step S703: Receive a log download command sent by the firewall. The log download command is sent by the firewall by invoking a remote operating system resource access tool;
[0241] Step S704: Execute the log download command to send the online user file to the firewall.
[0242] In some embodiments, the above method for obtaining login information may further include:
[0243] Receive a time query command sent by the firewall. The time query command is sent by the firewall by invoking a remote operating system command execution tool;
[0244] Execute the time query command to generate a system time file including the current system time;
[0245] Receive a time download command sent by the firewall. The time download command is sent by the firewall by invoking a remote operating system resource access tool;
[0246] Execute the time download command to send the system time file to the firewall, so that the firewall adjusts its local time to the current system time included in the system time file.
[0247] In some embodiments, the log query command includes at least one of the following information: online event identifier, start time of the target security log, processing method of the target security log, format of the online user file, name of the online user file, and encoding format of the online user file; wherein, the start time is the latest time included in the login information in the historical online user file obtained by the firewall, or a preset time;
[0248] The log download command includes at least one of the following information: name of the online user file, storage location of the online user file in the firewall.
[0249] In some embodiments, the time query command includes at least one of the following information: format of the current system time, name of the system time file;
[0250] The time download command includes at least one of the following pieces of information: the name of the system time file and the storage location of the system time file in the firewall.
[0251] In the technical solution provided by the embodiments of this application, the remote operating system command execution tool and the remote operating system resource access tool are tools built into the operating system of the firewall and do not need to be installed separately. The firewall sends the log query command and the log download command to the domain server by invoking the built-in remote operating system command execution tool and remote operating system resource access tool. The domain server executes the log query command and the log download command, generates an online user file including the login information of the online users by using the target security logs corresponding to the online users, and sends the online user file to the firewall, so that the firewall obtains the login information of the online users.
[0252] During the entire process of obtaining the login information, there is no need to install additional proxy software or configuration, which reduces the complexity of the configuration, has a lower installation and maintenance complexity, and improves network security; when the domain server executes the log query command, it can generate the online user file only by using the target security logs corresponding to the online users, that is, the security logs are screened. Only the online user file corresponding to the target security logs, rather than the files corresponding to all security logs, is transmitted between the domain server and the firewall, which reduces the large amount of data transmitted between the domain server and the firewall and reduces the impact on normal business traffic; in addition, the firewall can be deployed anywhere, and there is no need to add additional configuration on the domain server, the user terminal, or the switching device between the domain server and the user terminal, which improves the flexibility of the networking method, reduces the complexity of the configuration, and further improves security.
[0253] Corresponding to the above login information acquisition method, the embodiments of this application also provide a login information acquisition device, as Figure 8 shown, which is applied to the firewall. The device includes:
[0254] A first invocation module 801, configured to invoke a remote operating system command execution tool and send a log query command to the domain server, so that the domain server executes the log query command to generate an online user file by using the target security logs corresponding to the online users, and the online user file includes the login information of the online users;
[0255] A second invocation module 802, configured to invoke a remote operating system resource access tool and send a log download command to the domain server, so that the domain server executes the log download command;
[0256] A receiving module 803, configured to receive the online user file sent by the domain server.
[0257] In some embodiments, the first calling module 801 is further configured to call a remote operating system command execution tool to send a time query command to the domain server, so that the domain server executes the time query command to generate a system time file including the current system time;
[0258] The second calling module 802 is further configured to call a remote operating system resource access tool to send a time download command to the domain server, so that the domain server executes the time download command;
[0259] The receiving module 803 is further configured to receive the system time file sent by the domain server; and adjust the local time of the firewall to the current system time included in the system time file.
[0260] In some embodiments, the above-mentioned login information management device may further include a management module;
[0261] The management module is configured to, after obtaining the login information, if the login information is obtained again before the aging duration corresponding to the login information times out, reset the aging duration corresponding to the login information; and delete the login information when the aging duration corresponding to the login information times out.
[0262] In some embodiments, the log query command includes at least one of the following information: online event identifier, start time of the target security log, processing method of the target security log, format of the online user file, name of the online user file, and encoding format of the online user file; wherein, the start time is the latest time included in the login information in the historical online user file obtained by the firewall, or a preset time;
[0263] The log download command includes at least one of the following information: name of the online user file, storage location of the online user file in the firewall.
[0264] In some embodiments, the time query command includes at least one of the following information: format of the current system time, name of the system time file;
[0265] The time download command includes at least one of the following information: name of the system time file, storage location of the system time file in the firewall.
[0266] In the embodiments of the present application, the networking architecture of single sign-on is as Figure 9 shown, wherein the firewall can be deployed at any position in the network. The firewall may include a registration module, a management module, a security log parsing module, a security policy module, etc.
[0267] Among them, the registration module is used to implement the registration of user account information. For example, an administrator registers user account information such as a username and a user name with the registration module; the identity recognition module sends a request to the registration module to obtain user account information, and then the registration module pushes the user account information to the identity recognition module according to the request sent by the identity recognition module.
[0268] The management module may include an online user data management sub-module and a user account data management sub-module.
[0269] The user account data management sub-module is used to maintain user account information. The sources of user account information include local user configurations, Csv files, RESTful servers, LDAP servers, etc.
[0270] The online user data management sub-module is used to create, update, delete, and age online user data (i.e., login information), and provide an online user data query interface. For example, if the aging duration corresponding to the login information times out, the online user data management sub-module deletes the login information.
[0271] The security log parsing module is used to query, download, and parse the system time file of the domain server to obtain the system time, and query, download, and parse the security log file of the domain server to obtain data such as the online user name, domain, and user IP address of the online user.
[0272] In the embodiment of the present application, the security log parsing module can be split into a first call module 801, a second call module 802, and a receiving module 803.
[0273] The first call module 801 is used to query the system time and security logs;
[0274] The second call module 802 is used to download the system time file and the online user file; the system time file and the online user file here are the query results.
[0275] The receiving module 803 is used to parse the system time log file of the domain server to obtain the system time, and parse the security log file of the domain server (i.e., the online user file) to obtain login information such as the online user name, domain, and IP address of the online user.
[0276] The security policy module is used to determine the user to whom the packet belongs according to packet characteristics (such as IP address, MAC address, etc.), and decide to allow or block the traffic according to the security policy configuration of the user.
[0277] For example Figure 9In this case, user A sends a login request to the AD domain server through SW. The login request includes user A's domain username and user password. The AD domain server authenticates user A based on user A's domain username and user password. After successful authentication, a security log 1 corresponding to user A is generated. The security log 1 includes user A's online user data (i.e., login information).
[0278] The security log parsing module (such as the first call module 801 and the second call module 802) queries and downloads the security log 1. The security log parsing module (such as the receiving module 803) parses the security log 1 to obtain user A's online user data and generates an online user entry 1 for user A.
[0279] The online user data management sub-module manages the online user entry 1. If the aging duration corresponding to the online user entry 1 times out, the online user entry 1 is deleted due to aging.
[0280] The security policy module extracts the packet characteristics of the received packet, queries the online user entries managed by the online user data management sub-module to determine the user to which the packet belongs, and decides to allow or block the packet according to the security policy configuration of the user. For example, when receiving a packet from user A, the packet is allowed according to the security policy configuration of user A; when receiving a packet from user B and the login information of user B cannot be queried, the packet is blocked.
[0281] In the technical solution provided by the embodiment of the present application, the remote operating system command execution tool and the remote operating system resource access tool are tools built into the operating system of the firewall and do not need to be installed manually. The firewall sends a log query command and a log download command to the domain server by calling the built-in remote operating system command execution tool and remote operating system resource access tool. The domain server executes the log query command and the log download command, generates an online user file including the login information of the online user by using the target security log corresponding to the online user, and sends the online user file to the firewall, so that the firewall obtains the login information of the online user.
[0282] During the entire process of obtaining login information, there is no need to install additional proxy software or make configurations, reducing the complexity of configuration, with relatively low installation and maintenance complexity, and improving network security. When the domain server executes the log query command, it can generate an online user file only by using the target security log corresponding to the online users, that is, the security log is filtered. Only the online user file corresponding to the target security log, rather than the file corresponding to all security logs, is transmitted between the domain server and the firewall, reducing the large amount of data transmitted between the domain server and the firewall and reducing the impact on normal business traffic. In addition, the firewall can be deployed at any location, and there is no need to add additional configurations on the domain server, user terminal, or switching device between the domain server and the user terminal, improving the flexibility of the networking method, reducing the complexity of configuration, and further enhancing security.
[0283] Corresponding to the above login information acquisition method, an embodiment of the present application further provides a login information acquisition device, as Figure 10 shown, which is applied to a domain server. The device includes:
[0284] A first receiving module 1001, configured to receive a log query command sent by a firewall, where the log query command is sent by the firewall by invoking a remote operating system command execution tool;
[0285] A first execution module 1002, configured to execute the log query command to generate an online user file by using the target security log, where the online user file includes the login information of online users;
[0286] A second receiving module 1003, configured to receive a log download command sent by a firewall, where the log download command is sent by the firewall by invoking a remote operating system resource access tool;
[0287] A second execution module 1004, configured to execute the log download command to send the online user file to the firewall.
[0288] In some embodiments, the first receiving module 1001 is further configured to receive a time query command sent by a firewall, where the time query command is sent by the firewall by invoking a remote operating system command execution tool;
[0289] The first execution module 1002 is further configured to execute the time query command to generate a system time file including the current system time;
[0290] The second receiving module 1003 is further configured to receive a time download command sent by a firewall, where the time download command is sent by the firewall by invoking a remote operating system resource access tool;
[0291] The second execution module 1004 is further configured to execute a time download command to send a system time file to the firewall, so that the firewall adjusts the local time of the firewall to the current system time included in the system time file.
[0292] In some embodiments, the log query command includes at least one of the following pieces of information: a logon event identifier, a start time of the target security log, a processing method of the target security log, a format of the online user file, a name of the online user file, and an encoding format of the online user file; wherein, the start time is the latest time included in the logon information in the historical online user file obtained by the firewall, or a preset time;
[0293] The log download command includes at least one of the following pieces of information: a name of the online user file, a storage location of the online user file in the firewall.
[0294] In some embodiments, the time query command includes at least one of the following pieces of information: a format of the current system time, a name of the system time file;
[0295] The time download command includes at least one of the following pieces of information: a name of the system time file, a storage location of the system time file in the firewall.
[0296] In the technical solution provided by the embodiments of the present application, the remote operating system command execution tool and the remote operating system resource access tool are tools built into the operating system of the firewall and do not need to be installed independently. The firewall sends the log query command and the log download command to the domain server by calling the built-in remote operating system command execution tool and remote operating system resource access tool. The domain server executes the log query command and the log download command, generates an online user file including the logon information of the online user by using the target security log corresponding to the online user, and sends the online user file to the firewall, so that the firewall obtains the logon information of the online user.
[0297] During the entire process of obtaining the logon information, there is no need to install additional proxy software or configuration, which reduces the complexity of configuration, has low installation and maintenance complexity, and improves network security; when the domain server executes the log query command, it can generate the online user file only by using the target security log corresponding to the online user, that is, the security log is filtered, and only the online user file corresponding to the target security log is transmitted between the domain server and the firewall, rather than the files corresponding to all security logs, which reduces the large amount of data transmitted between the domain server and the firewall and reduces the impact on normal service traffic; in addition, the firewall can be deployed at any location, and there is no need to add additional configuration on the domain server, the user terminal, or the switching device between the domain server and the user terminal, which improves the flexibility of the networking method, reduces the complexity of configuration, and further improves security.
[0298] The embodiments of the present application also provide a firewall, as Figure 11 shown, which includes a processor 1101, a communication interface 1102, a memory 1103, and a communication bus 1104. Among them, the processor 1101, the communication interface 1102, and the memory 1103 complete communication with each other through the communication bus 1104.
[0299] The memory 1103 is used to store computer programs;
[0300] The processor 1101, when executing the programs stored on the memory 1103, implements any of the above-mentioned login information acquisition methods applied to the firewall.
[0301] The embodiments of the present application also provide a domain server, as Figure 12 shown, which includes a processor 1201, a communication interface 1202, a memory 1203, and a communication bus 1204. Among them, the processor 1201, the communication interface 1202, and the memory 1203 complete communication with each other through the communication bus 1204.
[0302] The memory 1203 is used to store computer programs;
[0303] The processor 1201, when executing the programs stored on the memory 1203, implements any of the above-mentioned login information acquisition methods applied to the domain server.
[0304] The communication bus can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. This communication bus can be divided into an address bus, a data bus, a control bus, etc. For the sake of convenience of representation, only a thick line is used in the figure, but it does not mean that there is only one bus or one type of bus.
[0305] The communication interface is used for communication between this device and other devices.
[0306] The memory can include a Random Access Memory (RAM), and can also include a Non-Volatile Memory (NVM), such as at least one disk memory. Optionally, the memory can also be at least one storage device located far from the aforementioned processor.
[0307] The processor can be a general-purpose processor, including a Central Processing Unit (CPU), a Network Processor (NP), etc.; it can also be a Digital Signal Processor (DSP), an Application Specific Integrated Circuit (ASIC), a Field-Programmable Gate Array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components.
[0308] In another embodiment provided by the present application, there is also provided a computer-readable storage medium, in which a computer program is stored. When the computer program is executed by a processor, it implements any of the above-mentioned login information acquisition methods applied to a firewall, or implements any of the above-mentioned login information acquisition methods applied to a domain server.
[0309] In another embodiment provided by the present application, there is also provided a computer program product containing instructions. When it runs on a computer, it causes the computer to execute any of the above-mentioned login information acquisition methods applied to a firewall, or execute any of the above-mentioned login information acquisition methods applied to a domain server.
[0310] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions described in the embodiments of the present application are generated in whole or in part. The computer can be a general-purpose computer, a dedicated computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center by wire (such as coaxial cable, optical fiber, Digital Subscriber Line (DSL)) or wireless (such as infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that the computer can access, or a data storage device such as a server or data center that includes one or more integrated available media. The available medium can be a magnetic medium (for example, a floppy disk, a hard disk, a magnetic tape), an optical medium (for example, a DVD), or a semiconductor medium (for example, a Solid State Disk (SSD)).
[0311] It should be noted that in this document, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, such that a process, method, article or device comprising a series of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, article or device comprising the element.
[0312] Each embodiment in this specification is described in a related manner. For the same or similar parts among the embodiments, reference can be made to each other. Each embodiment focuses on the differences from other embodiments. In particular, for embodiments of devices, firewalls, domain servers, storage media and program products, since they are basically similar to method embodiments, the description is relatively simple, and reference can be made to the partial description of method embodiments for the relevant parts.
[0313] The above are only the preferred embodiments of the present application and are not intended to limit the protection scope of the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application are included in the protection scope of the present application.
Claims
1. A method for obtaining login information, characterized in that, Applied to a firewall, the method includes: Invoking a remote operating system command execution tool to send a log query command to a domain server, so that the domain server executes the log query command to generate an online user file corresponding to an online user by using target security logs, where the online user file includes login information of the online user; Invoking a remote operating system resource access tool to send a log download command to the domain server, so that the domain server executes the log download command; Receiving the online user file sent by the domain server.
2. The method according to claim 1, characterized in that, The method further includes: Invoking the remote operating system command execution tool to send a time query command to the domain server, so that the domain server executes the time query command to generate a system time file including the current system time; Invoking the remote operating system resource access tool to send a time download command to the domain server, so that the domain server executes the time download command; Receiving the system time file sent by the domain server; Adjusting the local time of the firewall to the current system time included in the system time file.
3. The method according to claim 1, wherein After obtaining the login information, the method further includes: If the login information is obtained again before the aging duration corresponding to the login information times out, resetting the aging duration corresponding to the login information; When the aging duration corresponding to the login information times out, deleting the login information.
4. The method according to claim 1, wherein The log query command includes at least one of the following information: an online event identifier, a start time of the target security logs, a processing method of the target security logs, a format of the online user file, a name of the online user file, and an encoding format of the online user file; where the start time is the latest time included in the login information in a historical online user file obtained by the firewall, or a preset time; The log download command includes at least one of the following information: a name of the online user file, a storage location of the online user file in the firewall.
5. The method according to claim 2, wherein The time query command includes at least one of the following information: a format of the current system time, a name of the system time file; The time download command includes at least one of the following information: a name of the system time file, a storage location of the system time file in the firewall.
6. A method for obtaining login information, characterized in that, Applied to a domain server, the method includes: Receiving a log query command sent by a firewall, where the log query command is sent by the firewall invoking a remote operating system command execution tool; Executing the log query command to generate an online user file by using the target security logs, where the online user file includes login information of the online user; Receiving a log download command sent by the firewall, where the log download command is sent by the firewall invoking a remote operating system resource access tool; Executing the log download command to send the online user file to the firewall.
7. The method according to claim 6, wherein The method further includes: Receiving a time query command sent by the firewall, where the time query command is sent by the firewall invoking the remote operating system command execution tool; Execute the time query command to generate a system time file including the current system time; Receive the time download command sent by the firewall, where the time download command is sent by the firewall invoking the remote operating system resource access tool; Execute the time download command to send the system time file to the firewall, so that the firewall adjusts the local time of the firewall to the current system time included in the system time file.
8. The method according to claim 6, characterized in that, The log query command includes at least one of the following information: online event identifier, start time of the target security log, processing method of the target security log, format of the online user file, name of the online user file, and encoding format of the online user file; where the start time is the latest time included in the login information in the historical online user file obtained by the firewall, or a preset time; The log download command includes at least one of the following information: name of the online user file, storage location of the online user file in the firewall.
9. The method according to claim 7, wherein The time query command includes at least one of the following information: format of the current system time, name of the system time file; The time download command includes at least one of the following information: name of the system time file, storage location of the system time file in the firewall.
10. A login information acquisition device, characterized in that, Applied to a firewall, the device includes: A first invocation module, configured to invoke a remote operating system command execution tool to send a log query command to a domain server, so that the domain server executes the log query command to generate an online user file using the target security log corresponding to the online user, where the online user file includes the login information of the online user; A second invocation module, configured to invoke a remote operating system resource access tool to send a log download command to the domain server, so that the domain server executes the log download command; A receiving module, configured to receive the online user file sent by the domain server.
11. A login information acquisition device, characterized in that, Applied to a domain server, the device includes: A first receiving module, configured to receive a log query command sent by a firewall, where the log query command is sent by the firewall invoking a remote operating system command execution tool; A first execution module, configured to execute the log query command to generate an online user file using the target security log, where the online user file includes the login information of the online user; A second receiving module, configured to receive a log download command sent by the firewall, where the log download command is sent by the firewall invoking a remote operating system resource access tool; A second execution module, configured to execute the log download command to send the online user file to the firewall.