Outgoing flow management method and device based on domain name white list, equipment and medium
By dynamically generating and updating the domain name whitelist, the problem of inability to deal with business changes in traditional solutions is solved, and efficient and secure traffic management and control is achieved.
Patent Information
- Application Number
- CN202510686919.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-27
- Publication Date
- 2025-07-25
AI Technical Summary
In the traditional egress gateway proxy solution, the statically configured domain name whitelist cannot be updated dynamically, resulting in the inability to cope with the rapid changes in business needs, and there are problems such as traffic congestion, data transmission interruption, load balancing and insufficient security.
By dynamically generating and updating domain name whitelists, based on user identity information and business needs, the configuration management platform is used to uniformly store and issue them to proxy nodes, and combined with preset update cycles and intelligent matching mechanisms, the timeliness and accuracy of domain name whitelists are ensured.
It realizes intelligent control and security protection of outbound traffic, improves the efficiency and security of traffic management, prevents unauthorized access, and enhances the maintainability and scalability of the system.
Smart Images

Figure CN120378199A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the technical field of network security management, and in particular to a method, device, equipment and medium for managing outbound traffic based on a domain name whitelist. Background Art
[0002] With the Internetization and digitization of financial services, FinTech has not only optimized the service efficiency of the traditional financial industry, but also brought about cross-regional and cross-industry data flow and sharing. However, in this process, the large amount of sensitive information and transaction data involved has put forward higher requirements for network security and efficiency. Financial institutions need to ensure that cross-platform data transmission is not illegally accessed and tampered with, while ensuring the real-time and efficiency of financial transactions. As more and more financial institutions move their businesses to the cloud, how to respond to dynamically changing business needs and ensure the compliance and security of data flows has become a key issue that needs to be urgently addressed in the field of FinTech. Similarly, fields such as medical data management are also facing such problems.
[0003] At present, traditional egress gateway proxy solutions mostly use statically configured domain name whitelists or IP address whitelists to restrict outbound traffic, which has certain disadvantages, including: first, the static configuration method is complex and difficult to update dynamically, and cannot cope with the rapid changes in business needs, resulting in congestion or data transmission interruption during high traffic periods; second, the lack of intelligent traffic scheduling mechanism makes it impossible to achieve efficient load balancing and fault tolerance in multi-node proxy gateway clusters, further affecting data transmission efficiency and reliability; finally, the solution has shortcomings in security and it is difficult to effectively prevent unauthorized access and malicious traffic leakage. Summary of the invention
[0004] The embodiments of the present disclosure at least provide a method, apparatus, device and medium for managing outbound traffic based on a domain name whitelist, which realizes intelligent control and security protection of outbound traffic through automated and intelligent domain name whitelist management and dynamic update mechanisms.
[0005] The embodiment of the present disclosure provides an outbound traffic management method based on a domain name whitelist, including:
[0006] In response to a successful application authentication instruction from a user, obtaining user authentication information of the user; wherein the user authentication information includes user identity information and user service requirements;
[0007] Generate a domain name whitelist corresponding to the user based on the user identity information and the user business requirements, and send the domain name whitelist corresponding to the user to a configuration management platform for storage; and send the domain name whitelist corresponding to the user to a proxy node corresponding to the user business requirements based on the configuration management platform;
[0008] Obtain multiple domain name white lists received by each proxy node according to a preset update period, and generate an update list based on the multiple domain name white lists received by each proxy node; wherein, the update list includes multiple domain name white lists and the proxy nodes corresponding to each domain name white list;
[0009] Send the update list to each proxy node to complete the update task of the domain name white list of each proxy node.
[0010] An embodiment of the present disclosure provides an outbound traffic management device based on a domain name white list, including:
[0011] An information acquisition module, configured to obtain the user authentication information of the user in response to a successful application authentication instruction of the user; wherein, the user authentication information includes user identity information and user service requirements;
[0012] A list processing module, configured to generate a domain name white list corresponding to the user based on the user identity information and the user service requirements, and send the domain name white list corresponding to the user to a configuration management platform for storage; and, based on the configuration management platform, send the domain name white list corresponding to the user to a proxy node corresponding to the user service requirements;
[0013] A list update module, configured to obtain multiple domain name white lists received by each proxy node according to a preset update period, and generate an update list based on the multiple domain name white lists received by each proxy node; wherein, the update list includes multiple domain name white lists and the proxy nodes corresponding to each domain name white list;
[0014] A list sending module, configured to send the update list to each proxy node to complete the update task of the domain name white list of each proxy node.
[0015] An embodiment of the present disclosure provides a computer device, including: a processor, a memory, and a bus, wherein the memory stores machine-readable instructions executable by the processor. When the computer device runs, the processor communicates with the memory through the bus, and when the machine-readable instructions are executed by the processor, the outbound traffic management method based on the domain name white list described in any of the above possible implementation manners is executed.
[0016] An embodiment of the present disclosure provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is run by a processor, the outbound traffic management method based on the domain name white list described in any of the above possible implementation manners is implemented.
[0017] The outbound traffic management method, device, equipment and medium based on the domain name whitelist provided in the embodiments of the present disclosure dynamically respond to the user's application authentication success instruction, obtain the user's identity information and service requirements, and generate a personalized domain name whitelist accordingly; not only ensuring the refined management of user access permissions, but also improving the flexibility and security of traffic management. Subsequently, the generated domain name whitelist is uniformly stored through the configuration management platform and distributed to the corresponding proxy nodes, realizing the rapid deployment and effectiveness of the policy; in addition, according to the preset update period, the domain name whitelist information of each proxy node is automatically collected and integrated to generate an updated list, and then distributed to each proxy node again, thereby ensuring the timeliness and accuracy of the domain name whitelist.
[0018] In this way, the present disclosure improves the efficiency and accuracy of traffic management, effectively preventing unauthorized access and potential security threats; enhancing the maintainability and scalability of the system, making the management of the domain name whitelist more convenient and flexible, and realizing the intelligent control and security protection of outbound traffic.
[0019] To make the above objects, features and advantages of the present disclosure more obvious and understandable, the following specifically gives preferred embodiments and, in conjunction with the accompanying drawings, the detailed description is as follows. BRIEF DESCRIPTION OF THE DRAWINGS
[0020] To more clearly illustrate the technical solutions of the embodiments of the present disclosure, the following briefly introduces the drawings required to be cited in the embodiments. The accompanying drawings are incorporated into the specification and constitute a part of the specification. These drawings show embodiments consistent with the present disclosure and are used together with the specification to illustrate the technical solutions of the present disclosure. It should be understood that the following drawings only show some embodiments of the present disclosure and should not be regarded as limiting the scope. For those of ordinary skill in the art, other related drawings can be obtained based on these drawings without creative efforts.
[0021] Figure 1 Shows a schematic diagram of an application environment of an outbound traffic management method based on a domain name whitelist provided by an embodiment of the present disclosure;
[0022] Figure 2 Shows a flowchart of an outbound traffic management method based on a domain name whitelist provided by an embodiment of the present disclosure;
[0023] Figure 3 Shows a flowchart of an application authentication method for users provided by an embodiment of the present disclosure;
[0024] Figure 4 Shows a flowchart of a method for updating a domain name whitelist provided by an embodiment of the present disclosure;
[0025] Figure 5 The figure shows a schematic structural diagram of an outbound traffic management device based on a domain name whitelist provided by an embodiment of the present disclosure;
[0026] Figure 6 The figure shows a schematic structural diagram of a computer device provided by an embodiment of the present disclosure. Detailed implementation manners
[0027] To make the objectives, technical solutions, and advantages of the embodiments of the present disclosure clearer, the technical solutions in the embodiments of the present disclosure will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present disclosure. Apparently, the described embodiments are only some of the embodiments of the present disclosure, rather than all the embodiments. Components of the embodiments of the present disclosure described and illustrated herein generally may be arranged and designed in a variety of different configurations. Therefore, the detailed description of the embodiments of the present disclosure provided herein is not intended to limit the scope of the claimed present disclosure, but merely represents selected embodiments of the present disclosure. All other embodiments obtained by those skilled in the art based on the embodiments of the present disclosure without creative efforts shall fall within the scope of protection of the present disclosure.
[0028] It should be noted that like reference numerals and letters denote like items in the following figures, and thus, once an item is defined in one figure, it need not be further defined and explained in subsequent figures.
[0029] The term "and / or" in this document merely describes an association relationship and indicates that three relationships may exist. For example, A and / or B may represent: A exists alone, A and B exist simultaneously, and B exists alone. In addition, the term "at least one" in this document means any one of a plurality or any combination of at least two of a plurality. For example, including at least one of A, B, and C may represent including any one or more elements selected from the set composed of A, B, and C.
[0030] For the convenience of understanding this embodiment, first, the execution subject of the outbound traffic management method based on a domain name whitelist provided by the embodiments of the present disclosure will be introduced in detail. The outbound traffic management method based on a domain name whitelist provided by the embodiments of the present invention can be applied in an application environment such as Figure 1 , where the client communicates with the server through a network. Among them, the client may be a mobile device, a user terminal, a terminal, a handheld device, a computing device, etc. The server may be an independent physical server, or a server cluster or a distributed system composed of multiple physical servers, or a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud storage, big data, and artificial intelligence platforms.
[0031] The following will describe in detail the outbound traffic management method based on the domain name whitelist provided by the embodiments of the present application with reference to the accompanying drawings. Refer to Figure 2 As shown, it is a flowchart of an outbound traffic management method based on the domain name whitelist provided by the embodiments of the present disclosure. The method includes the following S201 - S204:
[0032] S201, in response to the user's application authentication success instruction, obtain the user's authentication information.
[0033] It can be understood that the user authentication information refers to the user-related information obtained by the system after the user's application authentication is successful, which may include user identity information and user service requirements. Among them, the user identity information usually includes information that uniquely identifies the user, such as username, password, ID number, mobile phone number, etc.; the user service requirements refer to the specific service requirements put forward by the user when using the application, which may involve specific services, resources or platforms that the user wants to access, such as the data access requirements for a certain platform, the operation requirements for a certain application, etc.
[0034] Exemplarily, in the field of fintech, the user identity information may include the ID number or bank card number of an investor, and the service requirements may involve transaction requests for specific financial products. In the field of medical data management, the user identity information may include the practicing qualification certificate number of medical staff, and the user service requirements may involve the access requirements for the medical record data of a certain patient in the medical data management system.
[0035] In some other embodiments, the user authentication information may further include the user's digital signature, biometric information (such as fingerprint, face recognition, etc.) or dynamic verification code, etc., which are not specifically limited herein.
[0036] Exemplarily, in order to improve the security and compliance of user access to the system and ensure the accuracy of the domain name whitelist, that is, only users with permissions can access specific services or data, refer to Figure 3 As shown, it is an application authentication method for users proposed by the present disclosure, which may include the following S301 - S308:
[0037] S301, construct a user application authentication framework.
[0038] Here, the user application authentication framework is a comprehensive authentication system for authenticating the user's identity, evaluating the permission level, and matching the service requirements. Among them, the framework includes a user identity information module, a user permission level module, and a user service requirement module.
[0039] Specifically, the user identity information module is mainly responsible for storing and verifying user identity information, such as username, password, ID number, mobile phone number, etc. The user permission level module is mainly responsible for storing and verifying user permission information, which may include but is not limited to the user's role (such as administrator, ordinary user, etc.), affiliated department, specific access permission markers (such as data read permission, data modification permission, etc.); through these information, it can be determined which services or data the user can access, so as to implement fine-grained access control; for example, in financial data management, the system administrator can act as the highest permission role and may have comprehensive read and modification permissions for all financial data (including customer privacy information, transaction records, risk assessment reports, etc.) for system maintenance, data backup and global supervision; while ordinary tellers may only have the permission to read the basic account information and transaction details of the customers they serve, as well as the execution permission for basic operations such as small-amount fund transfers, and are unable to access other customers' sensitive data or perform high-risk business operations; or, in medical data management, doctors may have the permission to read medical record data, while nurses may have the permission to update patient status. The user business requirement module is mainly responsible for storing the user's business requirement information, which reflects the specific requirements of the user when using the system. For example, in the field of fintech, the user's requirements may involve transferring money, querying account balances, etc.; while in the field of remote medical services, the user's requirements may involve making appointments with doctors, viewing medical reports, etc.
[0040] S302, in response to the user's application authentication instruction, obtain the user's information to be authenticated based on the user application authentication framework.
[0041] It can be understood that when the user initiates an application authentication request, the user's information to be authenticated can be obtained according to the above user application authentication framework. The information to be authenticated is a set of information that the system needs to verify when the user makes an application authentication request, which may include user identity information, user permission level information, and user business requirement information; it is used for subsequent authentication processes to ensure the authenticity of the user's identity and the legality of the access permission.
[0042] S303, determine whether the user identity information and the user permission level information match; if so, execute step S304, if not, execute step S305.
[0043] Specifically, it can be implemented by adopting a multi-factor authentication mechanism or a rule-based matching algorithm. Here, the multi-factor authentication mechanism is a method of combining multiple authentication factors to verify the user's identity, which can include static factors (such as username and password), dynamic factors (such as one-time password or SMS verification code), and biometric factors (such as fingerprint, facial recognition, etc.). Under this mechanism, first, it is verified whether the identity information provided by the user matches the stored records, and then it is further checked whether the corresponding permission level of this information is consistent with the level declared by the user or assigned by the system. Here, the rule-based matching algorithm mainly evaluates the matching degree of the user identity information and the permission level information according to a preset rule set. The rules may be based on factors such as the user's role, department, position level, specific permission mark, etc. For example, it may be set that only users belonging to the "administrator" role can access all system resources, while ordinary users can only access the resources within their permission scope.
[0044] In some other embodiments, the implementation method of whether the user identity information and the permission level information match can also be combined with machine learning technology to implement a more dynamic and intelligent matching algorithm, which is not specifically limited here.
[0045] S304, determine whether the user level information can meet the user service requirement information; if so, execute step S307, if not, execute step S308.
[0046] Specifically, after confirming that the user identity information and the permission level information match, it can be further determined whether the user level information can meet its service requirement information. If it meets, execute step S306; if it does not meet, execute step S307. For example, a doctor with high-level permissions may wish to access the detailed medical record data of a certain patient for in-depth research, and at this time, it is necessary to confirm whether the doctor's permission level is sufficient to support this requirement.
[0047] S305, determine the correct user permission level information corresponding to the user identity information, and update the user level information in the user information to be authenticated based on the correct user permission level information.
[0048] Specifically, for users whose identity information and permission level information do not match, it is necessary to determine the correct user permission level information corresponding to their identity information, and update the user level information in the user information to be authenticated based on this information. Here, in order to obtain the correct user permission level information, the system administrator can manually review the user information and assign the correct permission level to the user according to factors such as the user's role, department, position level, or specific permission mark.
[0049] In some other embodiments, an Identity and Access Management (IAM) solution can also be integrated to automatically retrieve and assign corresponding permission levels based on the user's identity information. The IAM solution typically includes functions such as user directories, permission management, and access control, and can automate the matching of user identities and permissions.
[0050] S306, determine whether the updated user level information can meet the user service requirement information; if so, execute step S307, if not, execute step S308.
[0051] Subsequently, after obtaining the correct user permission level information, determine again whether the updated user level information can meet its service requirement information. If it meets, the system will execute step S307; if it does not meet, the system will execute step S308.
[0052] S307, determine that the application authentication of the user is successful.
[0053] Here, when the user identity, permission level, and service requirement all match successfully, determine that the application authentication of the user is successful.
[0054] S308, determine that the application authentication of the user fails.
[0055] Here, if any one of the user identity, permission level, or service requirement does not match, it will be determined that the application authentication of the user fails, and the user's access request will be rejected.
[0056] In the present disclosure, by constructing a user application authentication framework, comprehensive and accurate verification of the user's identity information, permission level, and service requirement is achieved, ensuring that only users with specific permissions can access sensitive services or data, improving the authentication efficiency and accuracy, and at the same time enhancing the security and compliance of user access to the system.
[0057] S202, generate a domain name white list corresponding to the user based on the user identity information and the user service requirement, and send the domain name white list corresponding to the user to the configuration management platform for storage; and, based on the configuration management platform, send the domain name white list corresponding to the user to the proxy node corresponding to the user service requirement.
[0058] It is understandable that the domain name whitelist refers to a list of allowed access domain names generated based on user identity information and business requirements. These domain names are recognized as those that can be accessed when the user conducts the required business operations. For example, in the fintech field, the user's business requirements may involve online banking transactions or stock trading, and the domain name whitelist will include the domain names of the secure trading platforms of banks or stock exchanges. In the field of medical data management, the user's business requirements may include accessing their personal health records or participating in telemedicine consultations. At this time, the domain name whitelist will include the domain names of medical information systems or telemedicine platforms that provide these services.
[0059] Here, after generating the domain name whitelist corresponding to the user, it is sent to the configuration management platform for storage. The configuration management platform is a system component that centrally manages various configuration information (such as the domain name whitelist), ensuring the consistency, security, and accessibility of this information. In practical applications, the configuration management platform can be built through distributed coordination services such as Consul, etcd, or Zookeeper. These services provide high availability, strong consistency, and scalability, and can ensure the effective management and synchronization of the domain name whitelist in a distributed system.
[0060] It is understandable that the proxy node refers to a device or system that serves as an intermediate layer in the network architecture. It is responsible for forwarding, filtering, scheduling, and managing network traffic between the client and the server. The main function of the proxy node in this disclosure is to perform access control and forwarding of traffic based on the domain name whitelist. Further, the configuration management platform will, according to the user's business requirements, send the corresponding domain name whitelist to the proxy nodes related to this business requirement. Each proxy node will control which traffic can pass through and which traffic needs to be blocked based on these whitelists.
[0061] Exemplarily, since different business requirements may require access control to be implemented through different proxy nodes, when the domain name whitelist corresponding to the user is sent to the proxy nodes corresponding to the user's business requirements based on the configuration management platform, the following (a) to (b) may also be included:
[0062] (a) Determine whether there is an associated proxy node for the proxy node corresponding to the user's business requirement;
[0063] (b) If there is, based on the configuration management platform, send the domain name whitelist corresponding to the user to the proxy node corresponding to the user's business requirement and the associated proxy node respectively.
[0064] Here, if the proxy node already has a linkage or dependency relationship with other proxy nodes (such as load balancing, backup mechanisms, etc.), then the domain name whitelist will need to be synchronized to these associated proxy nodes to ensure that all relevant proxy nodes can follow consistent access control rules.
[0065] In some possible embodiments, the associated nodes can also be extended to include nodes for the domain name matching mechanism with the proxy node, which can enhance the flexibility and accuracy of the system in processing network requests.
[0066] Specifically, this domain name matching mechanism can support multiple matching methods, including exact matching, fuzzy matching, and regular expression matching. Exact matching means that the matching is triggered only when the domain names are exactly the same. This method is suitable for scenarios where traffic needs to be strictly controlled, such as requests for specific services that need to be processed by dedicated proxy nodes. Fuzzy matching allows partial matching of certain characters or sub-domains in the domain name, and can handle matching scenarios similar to wildcards, enabling the system to flexibly handle some more complex domain name requests. Regular expression matching is more powerful. It allows matching complex domain name patterns through predefined rules, and this method is especially suitable for situations where multiple dynamic domain name structures need to be supported, and can flexibly handle changes in various domain name requests.
[0067] In this way, through this multi-level domain name matching mechanism, not only can the accuracy of proxy node selection be improved, but also the efficiency can be enhanced when processing a large number of requests, reducing unnecessary resource waste.
[0068] S203, obtain multiple domain name whitelists received by each proxy node according to a preset update period, and generate an update list based on the multiple domain name whitelists received by each proxy node.
[0069] It can be understood that the update period refers to the frequency at which the system updates data at regular time intervals. In network security management, the whitelist needs to be updated regularly to adapt to new security requirements and network environments. In the present disclosure, the update period ensures that each proxy node can regularly synchronize the latest domain name whitelist, thereby enhancing the security and data processing efficiency of the entire network.
[0070] Specifically, multiple domain name whitelists received by each proxy node can be obtained according to a preset update period (one day or one week), and an update list can be generated based on the multiple collected domain name whitelists. Among them, the update list includes multiple domain name whitelists and the proxy nodes corresponding to each domain name whitelist.
[0071] In some possible embodiments, the update of the domain name whitelist can also be that the administrator directly intervenes in the management of the domain name whitelist through the console or API interface, which is usually carried out in case of an emergency security event or when a specific security policy adjustment needs to be quickly responded to. After the administrator issues an update trigger instruction, the system will immediately collect and integrate the domain name whitelist information of each proxy node to generate the latest whitelist update.
[0072] In some possible embodiments, in order to address the possible problem of uneven proxy node loads, especially when the number of domain name whitelists received by some proxy nodes increases abnormally, approaching or exceeding a preset warning threshold (which can be set to 10,000 entries, not specifically limited here), a dynamic adjustment strategy can be adopted, including: within a preset update cycle, monitoring the reception of domain name whitelists by each proxy node. Once it is found that a certain node is overloaded, an equivalent proxy node can be generated, and the newly added domain name whitelists of this node can be transferred to this equivalent proxy node for processing. In this way, the system load can be effectively balanced, preventing the situation where the overall performance or security is affected due to the overload of a single node. Subsequently, the domain name whitelist information of all nodes, including the original proxy node and its equivalent proxy node, can be collected again, and the final update list can be generated by integrating this information to ensure the consistency and efficiency of the entire network security policy.
[0073] Exemplarily, due to the complex and changeable network security environment and the persistence of potential threats, the update mechanism of the domain name whitelist needs to be more flexible and have an instant response ability. Referring to Figure 4 as shown, the update of the domain name whitelist can also include the following steps S401 - S402:
[0074] S401, within a preset update cycle, determine whether there is an alarm situation for any proxy node.
[0075] Here, by determining whether there is an alarm situation for each proxy node, it is aimed to monitor the running state of the proxy node in real time and identify any alarm signals that may indicate potential security risks. Among them, the alarm situation may include, but is not limited to, a sudden increase in abnormal traffic, unauthorized access attempts, or frequent access by known malicious IP addresses, etc. Through continuous monitoring, potential security threats can be quickly located and responded to.
[0076] S402, if so, obtain multiple domain name whitelists received by each proxy node, and generate an update list based on the multiple domain name whitelists received by each proxy node; and, when the alarm situation is a malicious attack alarm situation, determine the domain name blacklist corresponding to the malicious attack alarm situation, and send the domain name blacklist to the configuration management platform for storage; and, based on the configuration management platform, distribute the domain name blacklist to each proxy node.
[0077] Specifically, if the system detects an alarm situation in any proxy node, it will trigger the emergency update process of the domain name whitelist. At this time, it will collect multiple domain name whitelists currently received and stored by all proxy nodes, and generate a latest update list based on this information. In this way, it ensures that even in an emergency, the system can quickly integrate the latest domain name whitelist information and provide an accurate basis for subsequent access control decisions.
[0078] It can be understood that when the alarm situation is confirmed as a malicious attack alarm, the domain name blacklist related to this malicious attack can be determined. These domain names are clearly marked as inaccessible due to security threats. Subsequently, this domain name blacklist will be sent to the configuration management platform for secure storage to ensure centralized management and easy access to information. Immediately afterwards, based on the configuration management platform, this updated domain name blacklist will be distributed to all proxy nodes, requiring each proxy node to immediately update its local access control policy to block access requests related to the domain names in the blacklist. In this way, not only the response speed of the system is improved, but also the real-time performance and accuracy of network security protection are effectively strengthened.
[0079] Exemplarily, taking the online integrated financial service platform of a large financial institution as an example, this platform carries core sensitive data such as account information, asset allocation data, and transaction flow records of a large number of customers. To prevent malicious attacks and data leakage risks, when the intelligent security monitoring system deployed on the platform captures abnormal network activities targeting financial data storage nodes, transaction transmission links, or user terminals (for example, certain overseas IPs frequently initiate high-concurrency data sniffing requests, or specific domain names disguise themselves as regular financial institution interfaces and attempt to steal customer login credentials), it will initiate a security emergency response mechanism.
[0080] On the one hand, the security analysis team will, based on the threat intelligence database and real-time traffic characteristics, locate the list of malicious domain names involved in the attack. These domain names may be used by hackers to build phishing websites, implant malicious code, or serve as data transfer springboards. To block the spread of security threats, the platform will first mark these malicious domain names as blacklists and push warning messages to the operation and maintenance team, risk control department, and customers through a multi-channel security warning system, including but not limited to emails, text messages, in-site notifications, and pop-ups on the visual security dashboard.
[0081] On the other hand, the blacklist data will be synchronized to the centralized configuration management platform, which has high availability, distributed storage, and real-time update capabilities. Based on the distribution mechanism of the configuration management platform, the updated domain name blacklist can be sent to all financial system proxy nodes, including but not limited to user access gateways, API service gateways, distributed database middleware, and third-party payment interface protection layers. After receiving the instruction, each node will automatically update its access control policy to ensure that financial transaction requests, data query requests, and service call behaviors are strictly filtered through firewall rules, WAF protection rules, etc.
[0082] Exemplarily, in the field of medical data management and telemedicine services, similar technologies can also be used to enhance data security and service real-time performance. Take a telemedicine platform as an example. Suppose the platform needs to protect patients' personal information and medical data from malicious attacks or data leakage. Specifically, when the system detects a malicious attack on medical data storage or transmission, the platform will first determine the list of malicious domain names involved in the attack (for example, some domain names may attempt to obtain sensitive medical information). These domain names are marked as blacklists due to security threats and are alerted through a security warning system. Subsequently, these domain name blacklists will be sent to the configuration management platform for centralized storage and management. Based on the configuration management platform, the updated domain name blacklists will be sent to each proxy node of the medical system, requiring each node to update its access control policy to ensure that all requests on the medical service platform are not allowed to access the domain names in the blacklist.
[0083] In this way, the medical platform can respond promptly to potential security threats, ensure that patients' data privacy is not violated, and at the same time improve the system's response speed and the real-time performance of overall network security protection. For example, the telemedicine system of a certain hospital can avoid being attacked by the network, protect the communication and medical data transmission between doctors and patients, and ensure the security and reliability of medical services.
[0084] S204: Send the updated list to each proxy node to complete the update task of the domain name whitelist for each proxy node.
[0085] It can be understood that after obtaining the updated list, it can be sent to each proxy node, and each proxy node completes its own domain name whitelist update task according to the above updated list.
[0086] Here, it should be noted that the update list is a file or dataset that contains the domain name whitelists of all proxy nodes. This means that although each proxy node only needs to focus on the domain name whitelist related to itself, it will still receive a complete update list that covers the domain name whitelists of all proxy nodes. The purpose of doing this is to ensure that all proxy nodes can be updated according to the latest list, ensuring the unity and consistency of the domain name whitelists.
[0087] After each proxy node receives the update list, although its main task is to update its own domain name whitelist, at the same time it will also receive the domain name whitelists of other proxy nodes. In this way, it allows the proxy nodes to have flexibility in the actual operation process. Specifically, when a proxy node receives a domain name that does not belong to its own whitelist scope, the proxy node can look up other parts of the update list to identify which proxy node's whitelist the domain name belongs to. In this way, the proxy node can forward the domain name request to the target proxy node to ensure that the tasks of each proxy node in the entire network are correctly completed.
[0088] In this way, it can be ensured that each proxy node can complete its own update task when obtaining all relevant information, and has the ability to forward requests to the target proxy node when needed, thus effectively ensuring the comprehensive update of the domain name whitelist and the efficient operation of the system.
[0089] In some possible embodiments, when the update list is distributed, it may include: sending the update list to the configuration management platform for storage, and then distributing the update list to each proxy node based on the configuration management platform.
[0090] In some possible embodiments, when the update list is distributed, it may also include: passing the update list to each proxy node through a distributed message queue (such as Kafka, RabbitMQ, etc.). As an efficient message passing mechanism, the distributed message queue can achieve asynchronous message passing and high-concurrency data processing in a distributed system, ensuring data consistency and having fault tolerance capabilities. In this architecture, the proxy nodes receive the updated list by listening to the message queue and process and apply it as needed.
[0091] In some possible embodiments, when the update list is distributed, it may also include: implementing a protocol for data synchronization through an inter-node mutual propagation mechanism. In a distributed system, the gossip protocol is used to ensure that information between nodes can be spread quickly and reliably. In the scenario of updating the domain name whitelist, the gossip protocol can automatically synchronize the update list to all proxy nodes through regular "propagation" between nodes to ensure no omission.
[0092] In some other embodiments, in order to avoid repeated updates or missed updates, a version number can also be configured for the update list for each update. Each proxy node will determine whether to perform an update operation based on the version number of the update. Only when the version number changes will the node perform an update. This version number mechanism effectively avoids the overhead of repeated operations while ensuring the efficiency and consistency of the system.
[0093] Thus, the update of the domain name whitelist proposed in this disclosure can involve various technical means, such as a configuration management platform, a distributed message queue, a gossip protocol, etc. These solutions can effectively ensure the synchronous update of each proxy node in the network, avoiding security vulnerabilities and data loss. In fields such as fintech and medical data management, the implementation of this update mechanism can greatly improve data security, system stability, and service efficiency.
[0094] Exemplarily, after each proxy node receives the update list, each proxy node will complete the update task of the domain name whitelist of the proxy node based on the update list. This process can complete the update without restarting each proxy node. In this way, the proxy node can achieve instant update of the domain name whitelist, thereby ensuring that the proxy service can quickly respond to new domain name requests, improving the overall network performance and security. Specifically, each proxy node can make necessary adjustments and supplements to the whitelist according to the received update list without affecting the normal operation of the node.
[0095] During the update process, if any proxy node encounters an exception or error when performing the domain name whitelist update, the proxy node will continue to work with the domain name whitelist before the update. In this way, it can be ensured that even when an exception occurs in a certain node, the network service can still run stably and will not cause the interruption of the overall network service due to the problem of a single node.
[0096] It should be noted that in order to ensure the continuity and stability of traffic processing, the traffic being processed will continue to be forwarded according to the old whitelist configuration, while new traffic will use the updated whitelist configuration. In this way, conflicts between the old and new configurations can be avoided, ensuring that the existing network service will not be affected during the update process and can smoothly transition to the new configuration, avoiding service interruption or instability caused by the update.
[0097] Exemplarily, in a financial trading system, the use of the domain name whitelist can help filter out unauthorized trading requests and ensure the security of fund flows. For example, a certain bank may manage the access to its payment gateway through proxy nodes to ensure that only verified payment platforms can process trading requests. Financial service providers can control which domain names can access their trading systems through a regularly updated domain name whitelist to prevent phishing attacks and fraud.
[0098] Exemplarily, in telemedicine services, which mainly rely on real-time data exchange between patients and medical experts and usually use encrypted Internet connections. To ensure communication security, a telemedicine platform needs to ensure that only trusted devices and systems can participate in the communication. A regularly updated domain name whitelist can help system administrators identify new security risks in a timely manner, ensure that the telemedicine service platform can prevent malicious attacks, and ensure the security of patients' data. For example, in a remote diagnosis and treatment platform, there may be multiple proxy nodes responsible for connecting patients and doctors in different regions. The domain names of these nodes must be included in the whitelist to ensure that the transmitted data is not maliciously intercepted. By regularly updating the whitelist, the platform can add new secure communication nodes in a timely manner, improving the overall security and response speed of the system.
[0099] In the method, device, equipment, and medium for outbound traffic management based on a domain name whitelist provided in the embodiments of the present disclosure, by dynamically responding to the user's application authentication success instruction, obtaining the user's identity information and service requirements, and generating a personalized domain name whitelist accordingly; not only ensuring the refined management of user access permissions, but also improving the flexibility and security of traffic management. Subsequently, the generated domain name whitelist is uniformly stored through a configuration management platform and distributed to the corresponding proxy nodes, realizing the rapid deployment and effectiveness of the policy; in addition, according to a preset update period, automatically collecting and integrating the domain name whitelist information of each proxy node, generating an updated list, and distributing it to each proxy node again, thereby ensuring the timeliness and accuracy of the domain name whitelist.
[0100] In this way, the present disclosure improves the efficiency and accuracy of traffic management, effectively preventing unauthorized access and potential security threats; enhancing the maintainability and scalability of the system, making the management of the domain name whitelist more convenient and flexible, and realizing intelligent control and security protection of outbound traffic.
[0101] Those skilled in the art can understand that in the above method of the specific implementation manner, the writing order of each step does not mean a strict execution order that constitutes any limitation to the implementation process. The specific execution order of each step should be determined according to its function and possible internal logic.
[0102] Based on the same inventive concept, an outbound traffic management device based on a domain name whitelist corresponding to the outbound traffic management method based on a domain name whitelist is also provided in the embodiments of the present disclosure. Since the principle of solving problems by the device in the embodiments of the present disclosure is similar to the above outbound traffic management method based on a domain name whitelist in the embodiments of the present disclosure, the implementation of the device can refer to the implementation of the method, and the repeated parts will not be elaborated.
[0103] Refer to Figure 5As shown in the figure, it is a schematic diagram of an outbound traffic management device 500 provided by an embodiment of the present disclosure. The device includes:
[0104] An information acquisition module 501, configured to acquire user authentication information of the user in response to a successful user application authentication instruction; wherein, the user authentication information includes user identity information and user service requirements;
[0105] A list processing module 502, configured to generate a domain name whitelist corresponding to the user based on the user identity information and the user service requirements, and send the domain name whitelist corresponding to the user to a configuration management platform for storage; and, based on the configuration management platform, send the domain name whitelist corresponding to the user to an agent node corresponding to the user service requirements;
[0106] A list update module 503, configured to acquire multiple domain name whitelists received by each agent node according to a preset update period, and generate an update list based on the multiple domain name whitelists received by each agent node; wherein, the update list includes multiple domain name whitelists and the agent nodes corresponding to each domain name whitelist;
[0107] A list distribution module 504, configured to send the update list to each agent node to complete the update task of the domain name whitelist of each agent node.
[0108] In some possible embodiments, the information acquisition module 501 is further configured to:
[0109] Construct a user application authentication framework; wherein, the user authentication framework includes a user identity information module, a user permission level module, and a user service requirements module;
[0110] In response to a user application authentication instruction, acquire user information to be authenticated of the user based on the user application authentication framework; wherein, the user information to be authenticated includes user identity information, user permission level information, and user service requirements information;
[0111] Judge whether the user identity information and the user permission level information match;
[0112] If they do not match, determine the correct user permission level information corresponding to the user identity information, and update the user level information in the user information to be authenticated based on the correct user permission level information; and, judge whether the updated user level information can meet the user service requirements information; if so, determine that the user's application authentication is successful; if not, determine that the user's application authentication fails;
[0113] If a match is found, determine whether the user level information can meet the user service requirement information; if so, determine that the application authentication of the user is successful; if not, determine that the application authentication of the user fails.
[0114] In some possible embodiments, the list processing module 502 is specifically configured to:
[0115] Determine whether there is an associated proxy node for the proxy node corresponding to the user service requirement;
[0116] If there is, based on the configuration management platform, distribute the domain name white list corresponding to the user to the proxy node corresponding to the user service requirement and the associated proxy node respectively.
[0117] In some possible embodiments, the list updating module 503 is specifically configured to:
[0118] In response to an update trigger instruction for the domain name white list, obtain multiple domain name white lists received by each proxy node, and generate an updated list based on the multiple domain name white lists received by each proxy node;
[0119] And / or,
[0120] Within a preset update period, determine whether the cumulative number of domain name white lists received by any proxy node exceeds a warning threshold; if so, generate an equivalent proxy node corresponding to the any proxy node, and send the newly received domain name white list of the any proxy node to the equivalent proxy node corresponding to the any proxy node; and, obtain multiple domain name white lists received by each proxy node and the equivalent proxy node, and generate an updated list based on the multiple domain name white lists received by each proxy node and the equivalent proxy node.
[0121] In some possible embodiments, the list updating module 503 is further configured to:
[0122] Within a preset update period, determine whether there is an alarm situation for any proxy node;
[0123] If so, obtain multiple domain name white lists received by each proxy node, and generate an updated list based on the multiple domain name white lists received by each proxy node; and, when the alarm situation is a malicious attack alarm situation, determine the domain name black list corresponding to the malicious attack alarm situation, and send the domain name black list to the configuration management platform for storage; and, based on the configuration management platform, distribute the domain name black list to each proxy node.
[0124] In some possible embodiments, the list distribution module 504 is specifically configured to:
[0125] Send the updated list to the configuration management platform for storage; and, based on the configuration management platform, send the updated list to each agent node;
[0126] Or,
[0127] Send the updated list to the configuration management platform for storage; and, based on the distributed message queue, send the updated list to each agent node;
[0128] Or,
[0129] Based on the gossip protocol, use each agent node to spread the updated list through the mutual communication mechanism to ensure that all agent nodes synchronously update the domain name whitelist.
[0130] In some possible embodiments, the list sending module 504 is further configured to:
[0131] Each agent node completes the update task of the domain name whitelist of the agent node based on the updated list;
[0132] If any update agent node has an update exception during the update of the domain name whitelist, the any update agent node continues to use the domain name whitelist before the update.
[0133] Based on the same inventive concept, the embodiments of the present disclosure also provide a computer device. Refer to Figure 6 As shown, it is a schematic structural diagram of a computer device 600 provided by the embodiments of the present disclosure, including a processor 601, a memory 602, and a bus 603. Among them, the memory 602 is used to store execution instructions, including an internal memory 6021 and an external memory 6022; here, the internal memory 6021 is also called the main memory, which is used to temporarily store the operation data in the processor 601 and the data exchanged with the external memory 6022 such as a hard disk, and the processor 601 exchanges data with the external memory 6022 through the internal memory 6021.
[0134] In the embodiments of the present application, the memory 602 is specifically used to store the application program code for implementing the solutions of the present application, and is controlled by the processor 601 to execute. That is, when the computer device 600 runs, the processor 601 communicates with the memory 602 through the bus 603, so that the processor 601 executes the application program code stored in the memory 602, and further executes the methods described in any of the foregoing embodiments.
[0135] Among them, the memory 602 may be, but is not limited to, random access memory (RAM), read only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), etc.
[0136] The processor 601 may be an integrated circuit chip with signal processing capabilities. The above-mentioned processor may be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it may also be a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components. It can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present invention. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.
[0137] It can be understood that the structure schematically shown in the embodiments of this application does not constitute a specific limitation on the computer device 600. In other embodiments of this application, the computer device 600 may include more or fewer components than shown in the figure, or combine certain components, or split certain components, or have different component arrangements. The components shown in the figure may be implemented in hardware, software, or a combination of software and hardware.
[0138] The embodiments of the present disclosure also provide a computer-readable storage medium, on which a computer program is stored. When the computer program is run by a processor, it executes the steps of the method for outbound traffic management based on a domain name whitelist described in the above method embodiments. Among them, the storage medium may be a volatile or non-volatile computer-readable storage medium.
[0139] An embodiment of the present disclosure also provides a computer program product, which carries program codes. The instructions included in the program codes can be used to execute the steps of the method for outbound traffic management based on a domain name whitelist in the above method embodiments. For details, reference can be made to the above method embodiments and will not be elaborated herein.
[0140] Among them, the above computer program product can be specifically implemented in the form of hardware, software, or a combination thereof. In an alternative embodiment, the computer program product is specifically embodied as a computer storage medium. In another alternative embodiment, the computer program product is specifically embodied as a software product, such as a Software Development Kit (SDK), etc.
[0141] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the above-described systems and devices can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated herein. In several embodiments provided by the present disclosure, it should be understood that the disclosed systems and methods can be implemented in other ways. The device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division, and there may be other division methods in actual implementation. For another example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some communication interfaces. The indirect couplings or communication connections of the devices or units can be in electrical, mechanical, or other forms.
[0142] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0143] In addition, in each embodiment of the present disclosure, the functional units can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit.
[0144] When the above-mentioned functions are implemented in the form of software function units and sold or used as independent products, they can be stored in a non-volatile computer-readable storage medium executable by a processor. Based on such an understanding, the technical solution of the present disclosure, in essence, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present disclosure. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROM), random access memories (RAM), magnetic disks, or optical discs that can store program codes.
[0145] Finally, it should be noted that the above-mentioned embodiments are only specific implementation manners of the present disclosure, used to illustrate the technical solutions of the present disclosure, rather than limiting them. The protection scope of the present disclosure is not limited thereto. Although the present disclosure has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that: any person skilled in the art within the technical scope disclosed by the present disclosure can still modify the technical solutions recorded in the foregoing embodiments or can easily think of changes, or perform equivalent replacements on some of the technical features; and these modifications, changes, or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present disclosure, and should all be covered within the protection scope of the present disclosure. Therefore, the protection scope of the present disclosure should be subject to the protection scope of the claims.
Claims
1. A method for outbound traffic management based on a domain name whitelist, characterized in that, Including: Upon receiving a successful application authentication instruction from the user, obtain the user authentication information of the user; wherein, the user authentication information includes user identity information and user service requirements; Generate a domain name whitelist corresponding to the user based on the user identity information and the user service requirements, and send the domain name whitelist corresponding to the user to a configuration management platform for storage; and, based on the configuration management platform, distribute the domain name whitelist corresponding to the user to proxy nodes corresponding to the user service requirements; Obtain multiple domain name whitelists received by each proxy node according to a preset update period, and generate an update list based on the multiple domain name whitelists received by each proxy node; wherein, the update list includes multiple domain name whitelists and proxy nodes corresponding to each domain name whitelist; Distribute the update list to each proxy node to complete the update task of the domain name whitelist of each proxy node.
2. The method according to claim 1, wherein Before the step of responding to the successful application authentication instruction from the user, it includes: Construct a user application authentication framework; wherein, the user authentication framework includes a user identity information module, a user permission level module, and a user service requirements module; Upon receiving a user application authentication instruction, obtain the user's information to be authenticated based on the user application authentication framework; wherein, the information to be authenticated includes user identity information, user permission level information, and user service requirements information; Determine whether the user identity information and the user permission level information match; If they do not match, determine the correct user permission level information corresponding to the user identity information, and update the user level information in the information to be authenticated based on the correct user permission level information; and, determine whether the updated user level information can meet the user service requirements information; if so, determine that the user's application authentication is successful; if not, determine that the user's application authentication fails; If they match, determine whether the user level information can meet the user service requirements information; if so, determine that the user's application authentication is successful; if not, determine that the user's application authentication fails.
3. The method according to claim 1, wherein The step of distributing the domain name whitelist corresponding to the user to proxy nodes corresponding to the user service requirements based on the configuration management platform includes: Determine whether there are associated proxy nodes for the proxy nodes corresponding to the user service requirements; If there are, based on the configuration management platform, distribute the domain name whitelist corresponding to the user to the proxy nodes corresponding to the user service requirements and the associated proxy nodes respectively.
4. The method according to claim 1, characterized in that The step of obtaining multiple domain name whitelists received by each proxy node according to a preset update period and generating an update list based on the multiple domain name whitelists received by each proxy node includes: Upon receiving an update trigger instruction for the domain name whitelist, obtain multiple domain name whitelists received by each proxy node, and generate an update list based on the multiple domain name whitelists received by each proxy node; And / or Within a preset update period, determine whether the cumulative quantity of the domain name whitelists received by any proxy node exceeds a warning threshold; if so, generate an equivalent proxy node corresponding to the any proxy node, and send the domain name whitelists newly received by the any proxy node to the equivalent proxy node corresponding to the any proxy node; and, obtain multiple domain name whitelists received by each proxy node and the equivalent proxy node, and generate an update list based on the multiple domain name whitelists received by each proxy node and the equivalent proxy node.
5. The method according to claim 4, wherein The step of obtaining multiple domain name whitelists received by each proxy node according to a preset update period and generating an update list based on the multiple domain name whitelists received by each proxy node further includes: Within a preset update period, determine whether there is an alarm situation for any proxy node; If so, obtain multiple domain name whitelists received by each proxy node, and generate an update list based on the multiple domain name whitelists received by each proxy node; and, when the alarm situation is a malicious attack alarm situation, determine a domain name blacklist corresponding to the malicious attack alarm situation, and send the domain name blacklist to a configuration management platform for storage; and, based on the configuration management platform, send the domain name blacklist to each proxy node.
6. The method according to claim 1, characterized in that, The step of sending the update list to each proxy node includes: Send the update list to the configuration management platform for storage; and, based on the configuration management platform, send the update list to each proxy node; Or, Send the update list to the configuration management platform for storage; and, based on a distributed message queue, send the update list to each proxy node; Or, Based on the gossip protocol, use each proxy node to spread the update list through an intercommunication mechanism to ensure that all proxy nodes synchronously update the domain name whitelists.
7. The method according to claim 6, characterized in that After the step of sending the update list to each proxy node, it includes: Each proxy node completes the update task of the domain name whitelist of the proxy node based on the update list; If there is any update proxy node with an update exception during the update of the domain name whitelist, the any update proxy node continues to use the domain name whitelist before the update.
8. An outbound traffic management device based on a domain name whitelist, characterized in that, It includes: An information acquisition module, configured to acquire user authentication information of the user in response to a successful application authentication instruction of the user; wherein, the user authentication information includes user identity information and user service requirements; A list processing module, configured to generate a domain name whitelist corresponding to the user based on the user identity information and the user service requirements, and send the domain name whitelist corresponding to the user to a configuration management platform for storage; and, based on the configuration management platform, send the domain name whitelist corresponding to the user to a proxy node corresponding to the user service requirements; A list update module, configured to obtain multiple domain name whitelists received by each proxy node according to a preset update period, and generate an update list based on the multiple domain name whitelists received by each proxy node; wherein, the update list includes multiple domain name whitelists and the proxy nodes corresponding to each domain name whitelist; A list distribution module, configured to distribute the update list to each proxy node to complete the update task of the domain name whitelist of each proxy node.
9. A storage medium, on which a computer program is stored, characterized in that, When the computer program is executed by a processor, it implements the method according to any one of claims 1 to 7.
10. A computer device, comprising a storage medium, a processor, and a computer program stored on the storage medium and executable on the processor, characterized in that, When the processor executes the computer program, it implements the method according to any one of claims 1 to 7.