Method for monitoring internal network security and related device

Through the collaborative mechanism of local antivirus software and third-party network software of the user PC terminal, combined with the traffic analysis platform, the monitoring problems of viruses and malware in the local area network are solved, and efficient network security protection is achieved.

CN120342759APending Publication Date: 2025-07-18HUANENG NINGXIA ENERGY CO LTD LINGWULONGQIAO BRANCH +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510683909.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-26
Publication Date
2025-07-18

AI Technical Summary

Technical Problem

The existing technology fails to effectively monitor whether there are viruses and malware in the local area network, and cannot be discovered and notified in a timely manner, resulting in the impact of network security and business continuity.

Method used

The abnormal data is filtered through the local antivirus software of the user's PC terminal, and combined with the data compression and interception mechanism of third-party network software, in-depth protection is carried out, and abnormal behavior detection and alarm are used to use the traffic analysis platform.

Benefits of technology

It realizes timely discovery and intercepts of viruses and malware in local area networks, improves data security and transmission efficiency, and forms an efficient network security protection system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120342759A_ABST
    Figure CN120342759A_ABST
Patent Text Reader

Abstract

The invention discloses a method and a related device for monitoring internal network security, and the method comprises the steps: a user PC terminal carries out the information collection at a data generation stage; the local antivirus software on the user PC terminal processes the collected information so as to screen out abnormal data; the user PC terminal sends the collected information to third-party network software; the third-party network software performs data compression and interception operation on the received data so as to intercept information dangerous to an office area, and the method and the related device can timely discover and inform whether viruses exist in the local area network or not.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of network security and relates to a method for monitoring the security of an internal network and related devices. Background Art

[0002] As the core infrastructure for information exchange within an organization, the security of a local area network (LAN) is directly related to business continuity, data integrity, and user privacy. With the escalation of network attack means (such as ransomware and APT attacks) and the increase in internal threats (such as employee misoperations and malicious behaviors), the security of local area networks faces multi-dimensional challenges. As the application of networks becomes more extensive and the scale grows day by day, the services carried on the network are also becoming more diverse. Enterprises need to timely understand the services carried on the network, timely grasp whether there are viruses, network viruses such as malware application operations, in the local area network, and be notified in a timely manner to make the network smoother and safer. However, no specific solutions are provided in the prior art. Summary of the Invention

[0003] An object of the present invention is to overcome the above-mentioned drawbacks of the prior art and provide a method for monitoring the security of an internal network and related devices, which can timely detect and notify whether there are viruses in the local area network.

[0004] To achieve the above object, the present invention discloses a method for monitoring the security of an internal network, including:

[0005] During the data generation stage of the user PC terminal, the user PC terminal collects information;

[0006] The local anti-virus software on the user PC terminal processes the collected information to screen out abnormal data;

[0007] The user PC terminal sends the collected information to a third-party network software;

[0008] The third-party network software performs data compression and interception operations on the received data to intercept information dangerous to the office area.

[0009] A further improvement of the method for monitoring the security of an internal network according to the present invention lies in:

[0010] Further, the collected information includes the original traffic information generated by the user PC terminal, Internet access traffic information, internal communication traffic information, and security log information.

[0011] Further, the process by which the user PC terminal sends the collected information to the third-party network software is:

[0012] The user's PC terminal sends the collected information to the third-party network software through the access layer switch and the core switch.

[0013] Furthermore, the information dangerous to the office area includes at least one of web weak passwords, abnormal Socks traffic, unauthorized Swagger, zombie network downloading malicious files, and Trojans.

[0014] Furthermore, it also includes:

[0015] Obtain the traffic information of the office area and V1 area, and mirror the traffic information of the office area and V1 area to the traffic analysis platform through the SPAN port of the switch and the splitter;

[0016] The traffic analysis platform performs data analysis on the traffic information of the office area and V1 area through the built-in analysis engine, and detects abnormal behaviors through UEBA and threat intelligence.

[0017] Furthermore, classify and alarm the abnormal behaviors.

[0018] The present invention discloses a system for monitoring the internal network security, including:

[0019] A collection module, which is used for the user's PC terminal to collect information during the data generation stage;

[0020] A screening module, which is used for the local anti-virus software on the user's PC terminal to process the collected information to screen out abnormal data;

[0021] A sending module, which is used for the user's PC terminal to send the collected information to the third-party network software;

[0022] An interception module, which is used for the third-party network software to perform data compression and interception operations on the received data to intercept the information dangerous to the office area.

[0023] The further improvement of the system for monitoring the internal network security according to the present invention lies in:

[0024] Furthermore, it also includes:

[0025] An acquisition module, which is used to obtain the traffic information of the office area and V1 area, and mirror the traffic information of the office area and V1 area to the traffic analysis platform through the SPAN port of the switch and the splitter;

[0026] An analysis module, which is used for the traffic analysis platform to perform data analysis on the traffic information of the office area and V1 area through the built-in analysis engine, and detect abnormal behaviors through UEBA and threat intelligence.

[0027] The present invention discloses a computer device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the steps of the method for monitoring the internal network security are implemented.

[0028] The present invention discloses a computer-readable storage medium storing a computer program, and when the computer program is executed by a processor, the steps of the method for monitoring the internal network security are implemented.

[0029] The present invention has the following beneficial effects:

[0030] When the method and related device for monitoring the internal network security according to the present invention are specifically operated, the local anti-virus software on the user's PC terminal processes the collected information to screen out abnormal data; the third-party network software performs data compression and interception operations on the received data to intercept information dangerous to the office area. Through the collaborative mechanism of "local anti-virus software preprocessing + third-party network software deep protection", significant improvements are achieved in terms of data collection, transmission, security, and efficiency, so as to timely discover and notify whether there is a virus in the local area network. It should be noted that through the comprehensive optimization of "security, efficiency, compliance, and cost", the present invention provides an efficient and flexible network security protection system for various organizations, which is particularly suitable for scenarios with high requirements for data security and real-time performance, and has extremely strong practicability. Description of the Drawings

[0031] The specification drawings forming a part of the present invention are used to provide a further understanding of the present invention. The schematic embodiments and descriptions of the present invention are used to explain the present invention and do not constitute an improper limitation to the present invention. In the drawings:

[0032] Figure 1 is a flowchart of the method of the present invention. Detailed Embodiments

[0033] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0034] In the description of the present invention, it should be understood that the terms "including" and "comprising" indicate the presence of the described features, wholes, steps, operations, elements, and / or components, but do not exclude the presence or addition of one or more other features, wholes, steps, operations, elements, components, and / or their combinations.

[0035] It should also be understood that the terms used in the specification of the present invention are merely for the purpose of describing specific embodiments and are not intended to limit the present invention. As used in the specification of the present invention and the appended claims, unless the context clearly indicates otherwise, the singular forms "a", "an" and "the" are intended to include the plural forms.

[0036] It should be further understood that the term "and / or" used in the specification of the present invention and the appended claims refers to any combination and all possible combinations of one or more of the associated listed items, and includes these combinations. For example, A and / or B can represent three cases: A exists alone, A and B exist simultaneously, and B exists alone. In addition, the character " / " in the present invention generally represents an "or" relationship between the contextually related objects.

[0037] It should be understood that although terms such as first, second, third, etc. may be used in the embodiments of the present invention to describe preset ranges, etc., these preset ranges should not be limited to these terms. These terms are only used to distinguish the preset ranges from each other. For example, without departing from the scope of the embodiments of the present invention, the first preset range may also be referred to as the second preset range, and similarly, the second preset range may also be referred to as the first preset range.

[0038] Depending on the context, the word "if" as used herein can be interpreted as "when" or "while" or "in response to determining" or "in response to detecting". Similarly, depending on the context, the phrase "if determined" or "if detected (stated condition or event)" can be interpreted as "when determined" or "in response to determining" or "when detecting (stated condition or event)" or "in response to detecting (stated condition or event)".

[0039] To make the objectives, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. Usually, the components of the present invention described and shown in the drawings here can be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present invention provided in the drawings is not intended to limit the scope of the claimed present invention, but merely represents selected embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts fall within the scope of protection of the present invention.

[0040] Various structural schematic diagrams according to the disclosed embodiments of the present invention are shown in the accompanying drawings. These figures are not drawn to scale, where certain details are enlarged for the purpose of clear expression, and certain details may be omitted. The shapes of various regions and layers shown in the figures, as well as their relative sizes and positional relationships, are merely exemplary. In practice, there may be deviations due to manufacturing tolerances or technical limitations, and those skilled in the art can design regions / layers with different shapes, sizes, and relative positions according to actual needs.

[0041] Embodiment 1

[0042] Reference Figure 1 , the method for monitoring the internal network security according to the present invention includes the following steps:

[0043] 1) In the data generation stage of the user PC terminal, the user PC terminal collects information. The collected information includes the original traffic information generated by the user PC terminal, the Internet access traffic information, the internal communication traffic information, and the security log information. Among them, the basic information of each user PC terminal is obtained in advance, and when connected to the local area network, an IP and a physical address will be automatically assigned. The user PC terminal can be accurately located through the IP and the physical address;

[0044] 2) The local antivirus software on the user PC terminal processes the collected information to screen out abnormal data;

[0045] 3) The user PC terminal sends the collected information to the third-party network software through the access layer switch and the core switch;

[0046] 4) The third-party network software performs data compression and interception operations on the received data to intercept information dangerous to the office area, such as weak web passwords, abnormal Socks traffic, unauthorized Swagger, zombie network downloading malicious files and Trojans, etc.;

[0047] 5) Obtain the traffic information of the office area and the V1 area, and mirror the traffic information of the office area and the V1 area to the traffic analysis platform through the SPAN port of the switch and the splitter;

[0048] 6) The traffic analysis platform performs data analysis on the traffic information of the office area and the V1 area through the built-in analysis engine, and detects abnormal behaviors through UEBA and threat intelligence;

[0049] 7) Classify and alarm the abnormal behaviors, and at the same time perform visual display and generate alarm information.

[0050] It should be noted that through the collaborative mechanism of "local antivirus software preprocessing + third-party network software deep protection", the present invention achieves significant improvements in data collection, transmission, security, and efficiency. Specifically, the local antivirus software is used as the first line of defense to intercept known threats in real time. Based on the virus database and rule engine, the local antivirus software quickly identifies and intercepts malicious code (such as Trojans and ransomware), preventing it from entering the transmission stage, reducing network bandwidth occupancy (without uploading malicious data to the cloud for analysis), and reducing the risk of attack spread. Additionally, the third-party network software is used as the second line of defense to analyze file behavior through a cloud sandbox or AI model to intercept zero-day vulnerability attacks (such as unknown variant viruses), making up for the lag of the local antivirus software and forming a dual protection of "known threats + unknown threats". The present invention improves the overall protection ability by synchronizing threat data (such as IP anomaly lists and malicious domain names) in real time between the local antivirus software and the third-party software.

[0051] Embodiment 2

[0052] The system for monitoring the internal network security according to the present invention includes:

[0053] A collection module, which is used for the user PC terminal to collect information during the data generation stage.

[0054] A screening module, which is used for the local antivirus software on the user PC terminal to process the collected information to screen out abnormal data.

[0055] A sending module, which is used for the user PC terminal to send the collected information to the third-party network software.

[0056] An interception module, which is used for the third-party network software to perform data compression and interception operations on the received data to intercept information dangerous to the office area.

[0057] In this embodiment, it further includes:

[0058] An acquisition module, which is used to acquire the traffic information of the office area and V1 area, and mirror the traffic information of the office area and V1 area to the traffic analysis platform through the SPAN port and splitter of the switch.

[0059] An analysis module, which is used for the traffic analysis platform to perform data analysis on the traffic information of the office area and V1 area through the built-in analysis engine, and detect abnormal behaviors through UEBA and threat intelligence.

[0060] In the embodiments of the present application, the division of modules is illustrative, merely a logical function division. In actual implementation, there may be other division methods. Additionally, in each embodiment of the present application, each functional module may be integrated in a processor, may exist independently physically, or two or more modules may be integrated in one module. The above integrated modules may be implemented in the form of hardware or in the form of software functional modules.

[0061] Embodiment III

[0062] A computer device includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements the steps of the method for monitoring the internal network security. For example, it includes: at the data generation stage of the user PC terminal, the user PC terminal collects information; the local anti-virus software on the user PC terminal processes the collected information to filter out abnormal data; the user PC terminal sends the collected information to a third-party network software; the third-party network software performs data compression and interception operations on the received data to intercept information dangerous to the office area, obtains the traffic information of the office area and Area V1, and mirrors the traffic information of the office area and Area V1 to the traffic analysis platform through the SPAN port and splitter of the switch; the traffic analysis platform performs data analysis on the traffic information of the office area and Area V1 through the built-in analysis engine, and detects abnormal behaviors through UEBA and threat intelligence. Among them, the memory may include a memory, such as a high-speed random access memory, and may also include a non-volatile memory, such as at least one disk memory, etc.; the processor, network interface, and memory are interconnected through an internal bus, and this internal bus may be an Industry Standard Architecture bus, a Peripheral Component Interconnect standard bus, an Extended Industry Standard Architecture bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. The memory is used to store programs. Specifically, the program may include program code, and the program code includes computer operation instructions. The memory may include a memory and a non-volatile memory, and provides instructions and data to the processor.

[0063] Embodiment IV

[0064] A computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the method for monitoring the internal network security are implemented. For example, it includes: during the data generation phase of the user PC terminal, the user PC terminal collects information; the local anti-virus software on the user PC terminal processes the collected information to filter out abnormal data; the user PC terminal sends the collected information to a third-party network software; the third-party network software performs data compression and interception operations on the received data to intercept information dangerous to the office area, obtains the traffic information of the office area and V1 area, and mirrors the traffic information of the office area and V1 area to the traffic analysis platform through the SPAN port and splitter of the switch; the traffic analysis platform performs data analysis on the traffic information of the office area and V1 area through the built-in analysis engine, and detects abnormal behaviors through UEBA and threat intelligence. Specifically, the computer-readable storage medium includes but is not limited to, for example, volatile memory and / or non-volatile memory. The volatile memory may include random access memory and / or cache memory, etc. The non-volatile memory may include read-only memory, hard disk, flash memory, optical disc, magnetic disk, etc.

[0065] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media containing computer-usable program code.

[0066] The present application is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each flow and / or block in the flowchart and / or block diagram can be implemented by computer program instructions, and the combination of the flows and / or blocks in the flowchart and / or block diagram can also be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate a device for implementing the specified functions in Figure 1 one or more of the processes or multiple processes and / or blocks Figure 1 one or more of the blocks or multiple blocks.

[0067] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured article including an instruction device, and the instruction device implements the processes in Figure 1One or more processes and / or blocks Figure 1 The functions specified in one or more blocks.

[0068] These computer program instructions can also be loaded onto a computer or other programmable data processing device, so that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process. Thus, the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one Figure 1 One or more processes and / or blocks Figure 1 The steps of the functions specified in one or more blocks.

[0069] Those skilled in the art will readily conceive of other embodiments of the present invention upon considering the specification and the disclosure of the invention. This application is intended to cover any variations, uses, or adaptations of the present invention that follow the general principles of the present invention and include known common knowledge or conventional technical means in the technical field not disclosed in the present invention. The specification and the embodiments are only regarded as exemplary, and the true scope and spirit of the present invention are pointed out by the following claims.

[0070] It should be understood that the present invention is not limited to the exact structures described above and shown in the drawings, and various modifications and changes can be made without departing from its scope. The scope of the present invention is only limited by the appended claims.

[0071] As mentioned above, the above are only the preferred embodiments of the present invention, and there is no limitation to the present invention. Any simple modifications, changes, and equivalent structural changes made to the above embodiments according to the technical essence of the present invention still fall within the protection scope of the technical solution of the present invention.

Claims

1. A method for monitoring the security of an internal network, characterized in that, Including: During the data generation phase of the user PC terminal, the user PC terminal collects information. The local antivirus software on the user PC terminal processes the collected information to filter out abnormal data. The user PC terminal sends the collected information to the third-party network software. The third-party network software performs data compression and interception operations on the received data to intercept information dangerous to the office area.

2. The method for monitoring the security of an internal network according to claim 1, wherein The collected information includes the original traffic information, Internet access traffic information, internal communication traffic information, and security log information generated by the user PC terminal.

3. The method for monitoring the internal network security according to claim 1, wherein The process by which the user PC terminal sends the collected information to the third-party network software is as follows: The user PC terminal sends the collected information to the third-party network software via the access layer switch and the core switch.

4. The method for monitoring the internal network security according to claim 1, characterized in that The information dangerous to the office area includes at least one of web weak passwords, abnormal Socks traffic, unauthorized Swagger, zombie network downloading malicious files, and Trojans.

5. The method for monitoring the internal network security according to claim 1, wherein It also includes: Obtain the traffic information of the office area and V1 area, and mirror the traffic information of the office area and V1 area to the traffic analysis platform through the SPAN port of the switch and the splitter. The traffic analysis platform performs data analysis on the traffic information of the office area and V1 area through the built-in analysis engine, and detects abnormal behaviors through UEBA and threat intelligence.

6. The method for monitoring the internal network security according to claim 5, characterized in that, Give hierarchical alarms for the abnormal behaviors.

7. A system for monitoring the security of an internal network, characterized in that, Including: A collection module, which is used for the user PC terminal to collect information during the data generation phase. A screening module, which is used for the local antivirus software on the user PC terminal to process the collected information to filter out abnormal data. A sending module, which is used for the user PC terminal to send the collected information to the third-party network software. An interception module, which is used for the third-party network software to perform data compression and interception operations on the received data to intercept information dangerous to the office area.

8. The system for monitoring the internal network security according to claim 7, characterized in that, It also includes: An acquisition module, which is used to obtain the traffic information of the office area and V1 area, and mirror the traffic information of the office area and V1 area to the traffic analysis platform through the SPAN port of the switch and the splitter. An analysis module, which is used for the traffic analysis platform to perform data analysis on the traffic information of the office area and V1 area through the built-in analysis engine, and detect abnormal behaviors through UEBA and threat intelligence.

9. A computer device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the steps of the method for monitoring the internal network security according to any one of claims 1-6.

10. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by the processor, it implements the steps of the method for monitoring the internal network security according to any one of claims 1-6.