Network security verification method and device, computer equipment, readable storage medium and program product
By obtaining the area information of the CDN certificate, the target detection node is determined, which solves the problems of low efficiency and low accuracy of CDN certificate verification, and achieves efficient and accurate network security verification.
Patent Information
- Application Number
- CN202510456033.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-11
- Publication Date
- 2025-07-25
AI Technical Summary
In the prior art, CDN certificate verification has problems such as low efficiency and low accuracy, especially when cross-regional and cross-operator verification, it is easy to have detection blind spots or cause load pressure on the server.
By obtaining the area information of the network certificate to be verified, the target detection node is determined, and the target certificate is obtained using the node. The verification is passed or failed based on the consistency of the certificate, reducing unnecessary detection node communication and improving verification efficiency and accuracy.
It improves the efficiency and accuracy of network security verification, reduces the probability of failure during cross-regional and cross-operator verification, and ensures the accuracy of target certificate acquisition and comprehensiveness of verification results.
Smart Images

Figure CN120378147A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of Internet technology, and in particular to a network security verification method, apparatus, computer equipment, computer-readable storage medium, and computer program product. Background Art
[0002] With the rapid development of the Internet, content distribution networks (CDNs) play an important role in improving website performance and user experience. CDNs quickly deliver content to users by deploying a large number of edge nodes around the world, and establish secure encrypted channels between users and nodes by distributing certificates to each edge node. The validity and security of certificates used on edge nodes (such as SSL / TLS certificates) directly affect the user's access security and trust. However, certificate distribution may fail due to various factors such as network fluctuations and equipment failures, so it is necessary to verify the validity of certificates across the entire network to eliminate potential security risks.
[0003] In the related art, the certificate verification method is based on several nodes for verification. This verification method may have detection blind spots and cannot solve cross-regional and cross-operator problems. Or simply verify all nodes, and the way to verify all nodes will cause load pressure on the server where the domain name is located. In addition, in the related art, when performing certificate verification, the server address is mainly obtained by performing DNS (Domain Name System) resolution on the original domain name, and the obtained server address is verified, but the original domain name may be accelerated among multiple CDN manufacturers, and the server address it responds to does not necessarily belong to the CDN manufacturer itself, which will lead to inaccurate verification results.
[0004] Therefore, the related art has the problem of poor certificate verification efficiency and low accuracy. Summary of the invention
[0005] Based on this, it is necessary to provide a network security verification method, device, computer equipment, computer-readable storage medium and computer program product that can improve verification efficiency and accuracy in response to the above technical problems.
[0006] In a first aspect, the present application provides a network security verification method, comprising:
[0007] Obtain the network security task to be verified, which includes the network certificate to be verified and the task type;
[0008] Based on the task type, determining a parsed value corresponding to the network certificate to be verified;
[0009] Determine a target detection node according to the first area information corresponding to the parsed value, and obtain a target certificate using the target detection node;
[0010] When the network certificate to be verified is consistent with the target certificate, it is determined that the verification of the network security task to be verified passes.
[0011] In one embodiment, based on the task type, the parsing value corresponding to the network certificate to be verified is determined, including: when the task type is the automatic area detection type, obtaining a pre-generated domain name list and a pre-generated parsing value list, where the domain name list stores the mapping relationship between domain name information and network certificates, and the pre-generated parsing value list stores the mapping relationship between domain name information and parsing values; determining the domain name information corresponding to the network certificate to be verified according to the network certificate to be verified and the pre-generated domain name list; and determining the parsing value corresponding to the network certificate to be verified according to the domain name information and the pre-generated parsing value list.
[0012] In one of the embodiments, based on the task type, the parsing value corresponding to the network certificate to be verified is determined, including: when the task type is the specified detection type, obtaining the input parsing value.
[0013] In one of the embodiments, according to the first area information corresponding to the parsing value, the target detection node is determined, including: obtaining the second area information corresponding to each detection node to be determined; and determining the detection node to be determined corresponding to the second area information that matches the first area information corresponding to the parsing value as the target detection node.
[0014] In one embodiment, determining the detection node to be determined corresponding to the second area information that matches the first area information corresponding to the parsing value as the target detection node further includes: when there are multiple detection nodes to be determined corresponding to the second area information that matches the first area information corresponding to the parsing value, using the multiple detection nodes to be determined at the time of matching as intermediate detection nodes; obtaining the first operator information corresponding to each intermediate detection node and the second operator information corresponding to the parsing value; and determining the intermediate detection node corresponding to the first operator information that matches the second operator information as the target detection node.
[0015] In an optional embodiment, after obtaining the first operator information corresponding to each intermediate detection node and the second operator information corresponding to the parsing value, the network security verification method further includes: when the first operator information does not match the second operator information, obtaining the first traffic data of the first operator information and the second traffic data of the second operator information; selecting the larger traffic data from the first traffic data and the second traffic data; and determining the target detection node based on the larger traffic data.
[0016] In a second aspect, the present application also provides a network security verification device, including:
[0017] A task acquisition module, configured to acquire a network security task to be verified, where the network security task to be verified includes a network certificate to be verified and a task type;
[0018] A parsing value determination module, configured to determine a parsing value corresponding to the network certificate to be verified based on the task type;
[0019] A target certificate acquisition module, configured to determine a target detection node according to the first region information corresponding to the parsing value, and use the target detection node to acquire a target certificate;
[0020] A verification module, configured to determine that the network security task to be verified passes the verification when the network certificate to be verified is consistent with the target certificate.
[0021] In a third aspect, the present application further provides a computer device, including a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the steps of the above method embodiments are implemented.
[0022] In a fourth aspect, the present application further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the above method embodiments are implemented.
[0023] In a fifth aspect, the present application further provides a computer program product, including a computer program. When the computer program is executed by a processor, the steps of the above method embodiments are implemented.
[0024] The above network security verification method, device, computer device, computer-readable storage medium, and computer program product use the region information of the network certificate to be verified to determine the target detection node, and use the target detection node to acquire the target certificate. According to the consistency verification result of the network certificate to be verified and the target certificate, it is determined whether the network certificate to be verified passes the verification. Determining the target detection node through the region information can targetedly acquire the corresponding detection node, improve the clarity of the determination of the detection node, thereby ensuring the accuracy of the acquisition of the target certificate, and thus improving the accuracy of the verification result; and also targetedly acquire the target detection node, and acquire the target certificate according to the target detection node, reducing unnecessary communication between detection nodes, improving the data acquisition efficiency, and thus improving the network security verification efficiency. Description of the Drawings
[0025] In order to more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the following will briefly introduce the drawings required for use in the description of the embodiments of the present application or related technologies. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other related drawings can be obtained based on these drawings.
[0026] Figure 1 It is an application environment diagram of the network security verification method in an embodiment;
[0027] Figure 2 It is a schematic flowchart of the network security verification method in an embodiment;
[0028] Figure 3 It is a schematic flowchart of the network security verification method in another embodiment;
[0029] Figure 4 It is a structural block diagram of the network security verification device in an embodiment;
[0030] Figure 5 It is an internal structure diagram of a computer device in an embodiment. Detailed implementation manners
[0031] In order to make the objectives, technical solutions and advantages of the present application clearer, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0032] The network security verification method provided by the embodiments of the present application can be applied to an application environment as Figure 1 shown. Among them, the terminal 102 communicates with the server 104 through a network. The data storage system can store the data that the server 104 needs to process. The data storage system can be integrated on the server 104, or placed in the cloud or other network servers. The server 104 obtains the to-be-verified network security task transmitted by the terminal 102. The to-be-verified network security task includes a to-be-verified network certificate and a task type; based on the task type, it determines the parsing value corresponding to the to-be-verified network certificate; according to the first area information corresponding to the parsing value, it determines the target detection node and uses the target detection node to obtain the target certificate; when the to-be-verified network certificate is consistent with the target certificate, it determines that the to-be-verified network security task passes the verification. Among them, the terminal 102 can be but is not limited to various personal computers, laptop computers, smart phones, tablet computers, Internet of Things devices and portable wearable devices. The Internet of Things devices can be smart speakers, smart TVs, smart air conditioners, smart vehicle-mounted devices, projection devices, etc. The portable wearable devices can be smart watches, smart bracelets, head-mounted devices, etc. The head-mounted device can be a virtual reality (VR) device, an augmented reality (AR) device, a smart glasses, etc. The server 104 can be an independent physical server, or a server cluster or distributed system composed of multiple physical servers, or a cloud server providing cloud computing services.
[0033] In an exemplary embodiment, asFigure 2 As shown, a network security verification method is provided. Taking the server in Figure 1 as an example, the method includes the following steps 202 to 208. Wherein:
[0034] Step 202, obtain the network security task to be verified.
[0035] Wherein, the network security task to be verified is used to represent the task of performing security verification on the network certificate to be verified.
[0036] In one embodiment, the network security task to be verified can be initiated by a terminal.
[0037] In one embodiment, when a user uses a terminal to make a network connection, the terminal can generate a network security task to be verified according to the network connection.
[0038] In an exemplary embodiment, when a user uses a terminal to initiate a network connection, the terminal performs DNS resolution on the network connection to obtain the target IP address, and obtains the corresponding network certificate to be verified according to the obtained target IP address.
[0039] In one embodiment, after obtaining the network certificate to be verified, the attribute information can be obtained according to the network certificate to be verified, so that the server can perform network security verification on the network certificate to be verified according to the attribute information of the network certificate to be verified.
[0040] Optionally, the attribute information of the network certificate to be verified includes but is not limited to the common name, authorized domain name, issuing authority, validity period, public key, serial number, hash value (MD5) of the certificate, and customer information, etc.
[0041] In one embodiment, after the terminal determines the network certificate to be verified, it can obtain a pre-generated domain name list, obtain the domain name information corresponding to the network certificate to be verified from the domain name list, and can display the obtained domain name information, so that the user can check the required domain name information and / or cancel the unnecessary domain name information according to the displayed domain name information.
[0042] In an optional embodiment, the domain name list can be obtained in advance, so as to obtain the corresponding domain name information from the domain name list according to the network certificate to be verified. Wherein, the domain name list stores the mapping relationship between the domain name information and the network certificate, as shown in Table 1 below:
[0043] Table 1 Domain Name List
[0044]
[0045] Optionally, a configuration system can be set up, which stores network certificates and the domain name information corresponding to the network certificates, and is used to distinguish whether the domain name associated with the certificate is accelerated in the CDN system.
[0046] In an exemplary embodiment, the terminal is communicatively connected to the configuration system. After obtaining the network certificate and the domain name information corresponding to the network certificate from the configuration system, a domain name list is generated, as shown in Table 1 above.
[0047] In one embodiment, the terminal can also provide an IP type selection. Optionally, the IP type can include, but is not limited to, IPV4 and / or IPV6. Exemplarily, the selection of the IP type can be either IPV4 or IPV6, or both IPV4 and IPV6 can be selected simultaneously.
[0048] In one of the embodiments, a selection of operator information can also be provided.
[0049] In an optional embodiment, a selection of verification area information can also be provided, which is used to determine the verification scope of the network certificate to be verified. Exemplarily, the verification area can include, but is not limited to, the world, continents, countries, regions, provinces, and cities, etc.
[0050] In one embodiment, a selection of task types can also be provided. Exemplarily, the task types include, but are not limited to, automatic area detection and specified detection types, etc. Optionally, the specified detection types can include, but are not limited to, specified domain name CNAME information and specified node IPs, etc.
[0051] In one of the embodiments, there can also be a parsing value mapping relationship. Optionally, the parsing value mapping relationship can be determined according to the task type.
[0052] Exemplarily, when the task type is automatic area detection, the parsing value mapping relationship can be determined according to a pre-generated parsing value list, and based on the parsing value mapping relationship and the domain name information, the parsing value is determined.
[0053] Exemplarily, when the task type is specified domain name CNAME information, the parsing value can be the CNAME information input by the user using the terminal.
[0054] Exemplarily, when the task type is specified node IP, the parsing value can be the specified IP address input by the user using the terminal.
[0055] In an optional embodiment, the pre-generated parsing value list can obtain the domain name information and the parsing value corresponding to the domain name information, and generate a parsing value list according to the obtained domain name information and the parsing value corresponding to the domain name information, as shown in Table 2 below:
[0056] Table 2 Parsing Value List
[0057]
[0058] Among them, the parsed values include three types: CNAME, IPv4, and IPv6; the regional information ranges from coarser to finer as global, continent, country, region, province, and city; the parsed values of type CNAME include the CNAME records held by the CDN manufacturer itself and the CNAME records with part of the traffic offloaded to the cooperative CDN manufacturer.
[0059] Optionally, a coverage planning system can be set up to store domain name information and the parsed values corresponding to the domain name information. The terminal obtains the domain name information and the parsed values corresponding to the domain name information from the coverage planning system, and generates a parsed value list based on the obtained domain name information and the parsed values corresponding to the domain name information.
[0060] In one embodiment, the terminal encapsulates the network certificate to be verified and the task type to form a network security task to be verified, and sends the network security task to be verified to the server via the terminal, so that after obtaining the network security task to be verified, the server can extract the network certificate to be verified and the task type from the network security task to be verified and perform network security verification on the network certificate to be verified.
[0061] In an alternative embodiment, the terminal can also encapsulate the IP type, operator information, verification region information, etc. in the network security task to be verified.
[0062] In one embodiment, network security tasks can be generated at regular intervals and sent to the server. Exemplarily, a task scheduling program can be set on the terminal-side server connected to the terminal to generate network security tasks at regular intervals and send the network security tasks to the server, so that the server can perform network security verification after receiving the network security tasks.
[0063] Step 204, based on the task type, determine the parsed value corresponding to the network certificate to be verified.
[0064] In one embodiment, after obtaining the network security task to be verified, the server can obtain the network certificate to be verified and the task type from the network security task to be verified, so as to verify the obtained network certificate to be verified. Optionally, relevant data can also be obtained for the task type, and the obtained relevant data can be used to verify the network certificate to be verified.
[0065] In one embodiment, according to the obtained task type, different parsed value mapping relationships are determined, and the parsed values are determined according to the different parsed value mapping relationships.
[0066] In an exemplary embodiment, when the task type is the automatic area detection type, obtain a pre-generated domain name list and a pre-generated resolution value list; determine the domain name information corresponding to the network certificate to be verified according to the network certificate to be verified and the pre-generated domain name list; determine the resolution value corresponding to the network certificate to be verified according to the domain name information and the pre-generated resolution value list.
[0067] For example, if the network certificate to be verified is Certificate A, according to Certificate A and the pre-generated domain name list, the obtained domain name information corresponding to Certificate A is a.com. Then, according to the domain name information and the pre-generated resolution value list, the obtained resolution value corresponding to the domain name information is a.cdn.com. This obtained resolution value a.cdn.com is the resolution value corresponding to the network certificate to be verified. As shown in Table 3 below:
[0068] Table 3
[0069]
[0070] In an exemplary embodiment, when the task type is the specified detection type, obtain the input resolution value.
[0071] Optionally, when the task type is the specified detection type, the resolution value input by the terminal can be obtained, and this resolution value input by the terminal is the resolution value corresponding to the network certificate to be verified.
[0072] Exemplarily, when the task type is the specified domain name CNAME information, the resolution value can be the CNAME information input by the user using the terminal. As shown in Table 4 below:
[0073] Table 4
[0074]
[0075] Exemplarily, when the task type is the specified node IP, the resolution value can be the specified IP address input by the user using the terminal. For example, 1.1.1.1, 2.2.2.2.
[0076] In one embodiment, when the terminal generates a network security task to be verified, the resolution value is encapsulated therein, so that after the server receives the network security task to be verified and parses the network security task to be verified, the resolution value can be obtained.
[0077] Exemplarily, when the user uses the terminal to select the task type, when the terminal detects that the selected task type is the specified detection type, the user is prompted to input the resolution value. After detecting that the user has input the resolution value, a network security task to be verified is generated.
[0078] In one embodiment, when the server parses the to-be-verified network security task and obtains that the task type is the specified detection type, an instruction for inputting a parsed value is sent to the terminal. After receiving the instruction for inputting the parsed value, the user inputs the parsed value using the terminal, and the terminal sends the parsed value to the server. After receiving the parsed value returned by the terminal, the server sets the received parsed value corresponding to the to-be-verified network security task.
[0079] Step 206: Determine a target detection node according to the first region information corresponding to the parsed value, and obtain a target certificate using the target detection node.
[0080] In one embodiment, the second region information of each to-be-determined detection node can be obtained, and the first region information and the second region information are used to determine the target detection node from each to-be-determined detection node.
[0081] In one of the embodiments, a monitoring system can be set up, and the IP address, second region information, operator, health value, and detection task queue information of each to-be-determined detection node are recorded in the monitoring system.
[0082] Optionally, when it is necessary to determine the target detection node, the second region information is obtained from the monitoring system, so as to determine the target detection node according to the obtained second region information and the first region information.
[0083] In one embodiment, the first region information and the second region information include but are not limited to the world, continent, country, region, province, and city, etc.
[0084] In an alternative embodiment, when matching using the first region information and the second region information, the matching can be performed in order from fine-grained to coarse-grained, and once the matching is successful, the matching action is stopped.
[0085] Optionally, performing the matching in order from fine-grained to coarse-grained can first match the city. If the city does not match, then match the province. If the province does not match, then match the region. If the region does not match, then match the country. If the country does not match, then match the continent. If the continent does not match, then match the world. If the world also does not match, it indicates that there is no available detection node.
[0086] In an exemplary embodiment, obtain the second region information corresponding to each to-be-determined detection node; determine the to-be-determined detection node corresponding to the second region information that matches the first region information corresponding to the parsed value as the target detection node.
[0087] Exemplarily, assume that currently three detection nodes are deployed at F1, F2, and F3, and there is a parsed value a.com that needs to perform DNS resolution, as shown in Table 5 below:
[0088] Table 5
[0089]
[0090] Optionally, when the first area information of the network certificate to be verified is matched with the second area information of the detection node to be determined, the matching at the city level can be performed first. The city level of the first area information is F1, the city level of the first detection node area is also F1, the city level of the second detection node area is F2, and the city level of the third detection node area is F3. Then, the second area information of the first detection node matches the first area information of the network certificate to be verified. Therefore, the first detection node can be considered as the target detection node.
[0091] In one embodiment, if the first detection node fails and is removed due to the failure at this time, there is no matching node at the city level. At this time, the matching can be performed at the provincial level. Optionally, the first area information of the network certificate to be verified is E1 at the provincial level, the second detection node is E2 at the provincial level, and the third detection node is E1 at the provincial level. Then, the first area information of the network certificate to be verified matches the third detection node at the provincial level. Therefore, the third detection node can be used as the target detection node.
[0092] In one embodiment, when using the first area information and the second area information to match and determine the target detection node, if there are multiple pieces of second area information that match the first area information, it can be further determined based on the operator information. Exemplarily, it may include: when there are multiple detection nodes to be determined corresponding to the second area information that matches the first area information corresponding to the parsed value, the multiple detection nodes to be determined during the matching are used as intermediate detection nodes; obtaining the first operator information corresponding to each intermediate detection node and the second operator information corresponding to the parsed value; determining the intermediate detection node corresponding to the first operator information that matches the second operator information as the target detection node.
[0093] In one embodiment, the operator information can be sorted by priority in advance.
[0094] In an exemplary embodiment, if the first operator information of the intermediate detection node is the same as the second operator information, this intermediate detection node can be used as the target detection node.
[0095] In an exemplary embodiment, if the first operator information of the intermediate detection node is different from the second operator information, the target detection node can be determined according to the priority of the operator information. For example, the intermediate detection node corresponding to the operator information with the highest priority information is selected as the target detection node.
[0096] In an alternative embodiment, the priority of the operator information can be determined according to the traffic volume of the operator. Optionally, the larger the traffic volume, the higher the priority of the operator information.
[0097] In one embodiment, when the first operator information does not match the second operator information, obtain the first traffic data of the first operator information and the second traffic data of the second operator information; select the larger traffic data from the first traffic data and the second traffic data; based on the larger traffic data, determine the target detection node.
[0098] In one of the embodiments, when the verification area information is included in the network security task to be verified, the verification area information needs to be considered when determining the target detection area. Optionally, perform a matching process according to the verification area information and the area information of the detection node to be determined. When the area information of the detection node to be determined matches the verification area information, determine the detection node to be determined as the preselected node.
[0099] Optionally, after determining the preselected node, the target detection node can be determined according to the preselected node. Exemplarily, determine the target detection node according to the matching result of the second area information and the first area information of the preselected node. The target detection node can also be determined in combination with the operator information. For the specific steps of determining the target detection node using the area information and the operator information, refer to step 206 and will not be elaborated here.
[0100] In one of the embodiments, after determining the target detection node, use the target detection node to initiate an SSL connection request to the server corresponding to the target detection node, and the server returns the target certificate to the target detection node.
[0101] In an alternative embodiment, after each detection node to be determined performs DNS resolution, it can transmit the resolved A record (Address Record) to the monitoring system. The monitoring system determines the target detection node from the detection nodes to be determined according to the received A record, and sends an instruction to verify the network certificate to be verified to the target detection node, so that after the target detection node receives the instruction to verify the network certificate to be verified, it executes the steps of verifying the network certificate to be verified, for example, executes steps such as obtaining the target certificate and verifying whether the target certificate is consistent with the network certificate to be verified.
[0102] Step 208, when the network certificate to be verified is consistent with the target certificate, determine that the verification of the network security task to be verified passes.
[0103] In one embodiment, after receiving the target certificate, the target detection node performs a matching process on the network certificate to be verified and the target certificate, and determines whether the verification of the network security task to be verified passes according to the matching result.
[0104] Exemplarily, when the network certificate to be verified is consistent with the target certificate, it is determined that the verification of the network security task to be verified passes.
[0105] Exemplarily, when the network certificate to be verified is inconsistent with the target certificate, it is determined that the verification of the network security task to be verified passes.
[0106] In an optional embodiment, the attribute information of the target certificate can be obtained, and based on the attribute information of the network certificate to be verified and the attribute information of the target certificate, it is determined whether the network certificate to be verified is consistent with the target certificate.
[0107] Optionally, the attribute information of the target certificate may include but is not limited to the common name, authorized domain name, issuing authority, validity period, serial number, and hash value (MD5) of the certificate, etc.
[0108] In one embodiment, when the network certificate to be verified is inconsistent with the target certificate, the target certificate is uploaded to the certificate management system for subsequent analysis and processing.
[0109] In one of the embodiments, when the network certificate to be verified is inconsistent with the target certificate, the holder of the certificate to be verified can be determined through customer information, and the information indicating that the verification of the network certificate to be verified is inconsistent with the target certificate can be sent to the holder of the certificate to be verified for communication and traceability with the holder.
[0110] Among them, the certificate management system is used to maintain the basic information of the certificate, including operations such as addition, deletion, query, and modification. Optionally, when a certificate is newly added or modified, a corresponding certificate deployment task is created, and the certificate is distributed to the edge nodes through the task system. Optionally, the certificate management system provides a UI interface for creating a network-wide certificate verification task and displaying the task result.
[0111] In one embodiment, when the verification result is abnormal, the certificate management system will send an alarm notification via text message or phone call for the operation and maintenance to intervene and handle.
[0112] In an optional embodiment, if the target detection node feedbacks detection failure information, the target detection node can be reused to perform detection, for example, continue to use the detection node to obtain the target certificate to increase the probability of obtaining the target certificate.
[0113] In one embodiment, the number of times of detection failure by the detection node can be counted. If the number of failures exceeds the preset number of times, the failure information is reported to the monitoring system. After removing the detection node in this detection task, the monitoring system performs reallocation according to the principles of fine-grained priority allocation by region and priority allocation by the same operator. If the reallocation exceeds three times, the allocation is stopped and this detection subtask is marked as failed. Optionally, the preset number of times can be set as needed, for example, three times.
[0114] In the above network security verification method, the area information of the network certificate to be verified is used to determine the target detection node, and the target certificate is obtained by using the target detection node. According to the consistency verification result of the network certificate to be verified and the target certificate, it is determined whether the network certificate to be verified passes the verification. Determining the target detection node through the area information can obtain the corresponding detection node in a targeted manner, improve the clarity of the determination of the detection node, thereby ensuring the accuracy of obtaining the target certificate, and thus improving the accuracy of the verification result; and the target detection node is also obtained in a targeted manner, and the target certificate is obtained according to the target detection node, reducing unnecessary communication between detection nodes, improving the data acquisition efficiency, and thus improving the network security verification efficiency. Further, in the above network security verification method, in the process of determining the target detection node, matching is performed in turn from fine-grained to coarse-grained according to the area information, improving the comprehensiveness and accuracy of the determination of the target detection node, thereby determining the comprehensiveness and accuracy of the determination of the target certificate, reducing the probability of detection failure caused by network link failures across regions and across operators, and improving the accuracy of verification.
[0115] In an exemplary embodiment, as Figure 3 shown, a network security verification method is provided. Taking the server in Figure 1 as an example for illustration, it includes the following steps 302 to step 336. Among them:
[0116] Step 302, obtain the network security task to be verified.
[0117] Among them, the network security task to be verified includes the network certificate to be verified and the task type.
[0118] Step 304, determine whether the task type is the automatic area detection type. If so, execute step 306. If not, execute step 312.
[0119] Step 306, obtain the pre-generated domain name list and the pre-generated resolution value list.
[0120] Among them, the domain name list stores the mapping relationship between domain name information and network certificates, and the pre-generated resolution value list stores the mapping relationship between domain name information and resolution values.
[0121] Step 308, determine the domain name information corresponding to the network certificate to be verified according to the network certificate to be verified and the pre-generated domain name list.
[0122] Step 310, determine the resolution value corresponding to the network certificate to be verified according to the domain name information and the pre-generated resolution value list, and continue to execute step 314.
[0123] Step 312, obtain the input resolution value.
[0124] Step 314, obtain the second area information corresponding to each detection node to be determined.
[0125] Step 316, determine the number of detection nodes to be determined corresponding to the second area information that matches the first area information corresponding to the parsing value;
[0126] Step 318, determine whether the number is multiple. If so, execute Step 320. If not, execute Step 326.
[0127] Step 320, use the multiple detection nodes to be determined during matching as intermediate detection nodes;
[0128] Step 322, obtain the first operator information corresponding to each intermediate detection node and the second operator information corresponding to the parsing value.
[0129] Step 324, determine whether the first operator information matches the second operator information. If so, execute Step 326. If not, execute Step 328.
[0130] Step 326, determine that the intermediate detection node corresponding to the first operator information that matches the second operator information is the target detection node, and continue to execute Step 334.
[0131] Step 328, obtain the first traffic data of the first operator information and the second traffic data of the second operator information.
[0132] Step 330, select the larger traffic data from the first traffic data and the second traffic data.
[0133] Step 332, determine the target detection node based on the larger traffic data.
[0134] Step 334, use the target detection node to obtain the target certificate.
[0135] Step 336, when the network certificate to be verified is consistent with the target certificate, determine that the verification of the network security task to be verified passes.
[0136] In the above network security verification method, the area information of the network certificate to be verified is used to determine the target detection node, and the target certificate is obtained by using the target detection node. According to the consistency verification result between the network certificate to be verified and the target certificate, it is determined whether the network certificate to be verified passes the verification. Determining the target detection node through the area information can targetedly obtain the corresponding detection node, improve the clarity of the determination of the detection node, thus ensuring the accuracy of obtaining the target certificate, and then improving the accuracy of the verification result; and also targetedly obtain the target detection node, and obtain the target certificate according to the target detection node, reduce unnecessary communication between detection nodes, improve the data acquisition efficiency, and thus improve the network security verification efficiency.
[0137] It should be understood that although the steps in the flowcharts involved in the above embodiments are displayed in sequence according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless there is a clear indication in this article, the execution of these steps has no strict order limit, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above embodiments may include multiple steps or multiple stages. These steps or stages are not necessarily executed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be executed alternately or alternately with at least a part of other steps or steps in other steps.
[0138] Based on the same inventive concept, an embodiment of the present application further provides a network security verification device for implementing the above-mentioned network security verification method. The implementation solution provided by this device to solve problems is similar to the implementation solution described in the above method. Therefore, the specific limitations in one or more embodiments of the network security verification device provided below can refer to the limitations on the network security verification method in the above text, and will not be repeated here.
[0139] In an exemplary embodiment, as Figure 4 shown, a network security verification device 400 is provided, including: a task acquisition module 402, a parsing value determination module 404, a target certificate acquisition module 406, and a verification module 408, where:
[0140] The task acquisition module 402 is configured to acquire a network security task to be verified, and the network security task to be verified includes a network certificate to be verified and a task type;
[0141] The parsing value determination module 404 is configured to determine a parsing value corresponding to the network certificate to be verified based on the task type;
[0142] The target certificate acquisition module 406 is configured to determine a target detection node according to the first region information corresponding to the parsed value, and obtain a target certificate by using the target detection node;
[0143] The verification module 408 is configured to determine that the to-be-verified network security task passes the verification when the to-be-verified network certificate is consistent with the target certificate.
[0144] In one embodiment, the parsed value determination module is further configured to, when the task type is the automatic region detection type, obtain a pre-generated domain name list and a pre-generated parsed value list, where the domain name list stores the mapping relationship between domain name information and network certificates, and the pre-generated parsed value list stores the mapping relationship between domain name information and parsed values; determine the domain name information corresponding to the to-be-verified network certificate according to the to-be-verified network certificate and the pre-generated domain name list; and determine the parsed value corresponding to the to-be-verified network certificate according to the domain name information and the pre-generated parsed value list.
[0145] In one of the embodiments, the parsed value determination module is further configured to, when the task type is the specified detection type, obtain the input parsed value.
[0146] In one of the embodiments, the target certificate acquisition module is further configured to obtain the second region information corresponding to each to-be-determined detection node; and determine the to-be-determined detection node corresponding to the second region information that matches the first region information corresponding to the parsed value as the target detection node.
[0147] In one embodiment, the target certificate acquisition module is further configured to, when there are multiple to-be-determined detection nodes corresponding to the second region information that matches the first region information corresponding to the parsed value, use the multiple to-be-determined detection nodes at the time of matching as intermediate detection nodes; obtain the first operator information corresponding to each intermediate detection node and the second operator information corresponding to the parsed value; and determine the intermediate detection node corresponding to the first operator information that matches the second operator information as the target detection node.
[0148] In an optional embodiment, the target certificate acquisition module is further configured to, when the first operator information does not match the second operator information, obtain the first traffic data of the first operator information and the second traffic data of the second operator information; select the larger traffic data from the first traffic data and the second traffic data; and determine the target detection node based on the larger traffic data.
[0149] Each module in the above network security verification device can be implemented in whole or in part by software, hardware, and their combination. The above modules can be embedded in the processor in the computer device in the form of hardware or be independent of the processor, or can be stored in the memory in the computer device in the form of software, so that the processor can call and execute the operations corresponding to the above modules.
[0150] In an exemplary embodiment, a computer device is provided. The computer device may be a server, and its internal structural diagram may be as shown in Figure 5 . The computer device includes a processor, a memory, an input / output interface (Input / Output, abbreviated as I / O), and a communication interface. Among them, the processor, the memory, and the input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store data. The input / output interface of the computer device is used to exchange information between the processor and external devices. The communication interface of the computer device is used to communicate with external terminals through a network connection. When the computer program is executed by the processor, it implements a network security verification method.
[0151] Those skilled in the art can understand that Figure 5 the structure shown in is only a block diagram of some structures related to the solution of this application, and does not constitute a limitation on the computer device to which the solution of this application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.
[0152] In an exemplary embodiment, a computer device is provided, including a memory and a processor. A computer program is stored in the memory, and when the processor executes the computer program, the steps of the above method embodiments are implemented.
[0153] In an embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by the processor, the steps of the above method embodiments are implemented.
[0154] In an embodiment, a computer program product is provided, including a computer program. When the computer program is executed by the processor, the steps of the above method embodiments are implemented.
[0155] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use, and processing of relevant data need to comply with relevant regulations.
[0156] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, database, or other medium used in the embodiments provided in this application can include at least one of non-volatile memory and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The databases involved in the embodiments provided in this application can include at least one of relational databases and non-relational databases. Non-relational databases can include distributed databases based on blockchain, etc., without limitation. The processors involved in the embodiments provided in this application can be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, data processing logics based on quantum computing, artificial intelligence (AI) processors, etc., without limitation.
[0157] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered to be within the scope recorded in this application.
[0158] The above embodiments merely represent several implementation manners of the present application. The description thereof is relatively specific and detailed, but it should not be construed as a limitation on the patent scope of the present application. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all fall within the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the appended claims.
Claims
1. A network security verification method, characterized in that, The method includes: Obtain a network security task to be verified, where the network security task to be verified includes a network certificate to be verified and a task type; Based on the task type, determine an analysis value corresponding to the network certificate to be verified; According to the first area information corresponding to the analysis value, determine a target detection node, and use the target detection node to obtain a target certificate; When the network certificate to be verified is consistent with the target certificate, determine that the network security task to be verified passes the verification.
2. The method according to claim 1, wherein The determining, based on the task type, an analysis value corresponding to the network certificate to be verified includes: When the task type is an automatic area detection type, obtain a pre-generated domain name list and a pre-generated analysis value list, where the domain name list stores the mapping relationship between domain name information and network certificates, and the pre-generated analysis value list stores the mapping relationship between the domain name information and the analysis value; According to the network certificate to be verified and the pre-generated domain name list, determine the domain name information corresponding to the network certificate to be verified; According to the domain name information and the pre-generated analysis value list, determine the analysis value corresponding to the network certificate to be verified.
3. The method according to claim 1, wherein The determining, based on the task type, an analysis value corresponding to the network certificate to be verified includes: When the task type is a specified detection type, obtain the input analysis value.
4. The method according to claim 1, wherein The determining a target detection node according to the first area information corresponding to the analysis value includes: Obtain the second area information corresponding to each detection node to be determined; Determine the detection node to be determined corresponding to the second area information that matches the first area information corresponding to the analysis value as the target detection node.
5. The method according to claim 4, wherein The determining the detection node to be determined corresponding to the second area information that matches the first area information corresponding to the analysis value as the target detection node includes: When there are multiple detection nodes to be determined corresponding to the second area information that matches the first area information corresponding to the analysis value, use the multiple detection nodes to be determined at the time of matching as intermediate detection nodes; Obtain the first operator information corresponding to each of the intermediate detection nodes, and the second operator information corresponding to the analysis value; Determine the intermediate detection node corresponding to the first operator information that matches the second operator information as the target detection node.
6. The method according to claim 5, characterized in that, After obtaining the first operator information corresponding to each of the intermediate detection nodes and the second operator information corresponding to the analysis value, the method further includes: When the first operator information does not match the second operator information, obtain the first traffic data of the first operator information and the second traffic data of the second operator information; Select the larger traffic data from the first traffic data and the second traffic data; Based on the larger traffic data, determine the target detection node.
7. A network security verification device, characterized in that, The device includes: A task acquisition module, configured to acquire a network security task to be verified, where the network security task to be verified includes a network certificate to be verified and a task type; An analysis value determination module, configured to determine an analysis value corresponding to the network certificate to be verified based on the task type; A target certificate acquisition module, configured to determine a target detection node according to the first area information corresponding to the parsing value, and acquire a target certificate by using the target detection node; A verification module, configured to determine that the to-be-verified network security task passes the verification when the to-be-verified network certificate is consistent with the target certificate.
8. A computer device, comprising a memory and a processor, the memory storing a computer program, characterized in that, When the processor executes the computer program, the steps of the method according to any one of claims 1 to 6 are implemented.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.
10. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.