Communication method and device
By establishing mapping table items to detect the attributes and names of file transmission messages, the problem of inaccurate file content detection in multiple transmission mode is solved, and network security guarantees are achieved in the FTP scenario.
Patent Information
- Application Number
- CN202510561537.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-29
- Publication Date
- 2025-08-05
AI Technical Summary
The prior art cannot effectively or inaccurately detect file content when files are transmitted through multiplexed methods, resulting in problems such as virus transmission or information leakage.
By establishing a mapping table entry, receiving file transmission messages and matching the message attributes and file names, file content detection is performed. If the transmission is not legal, blocking the transmission, and releasing it if it is legal.
It realizes effective detection of file content in FTP multiple transmission scenarios, prevents virus transmission and information leakage, and ensures network security.
Smart Images

Figure CN120433984A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of communication technology, and in particular to a communication method and device. Background Art
[0002] With the development of the Internet, the demand for network security is increasing. File transfer is a common behavior in network transmission. During the file transfer process, the client and server can support single-channel transmission or multi-channel transmission. In the multi-channel transmission method, the client or server splits a file into multiple sub-files and transmits them through multiple data streams.
[0003] Typically, network devices, such as firewalls, perform file content inspection and processing based on streams to prevent risks such as viruses, script exploits, and sensitive information leaks. Network devices treat the contents of a stream as a file and inspect and process the file content based on the file type.
[0004] However, the above detection method also exposes the following problems: the characteristic information of the file is usually carried in the file header. Except for the stream carrying the file header, the network device can correctly identify the file type. The file content transmitted by other streams cannot be identified as the correct file type because it does not carry the file header, and the network device cannot perform real detection processing. Summary of the Invention
[0005] In view of this, the present application provides a communication method and device to solve the problem that when existing files are transmitted through multiple channels, the file type content detection method cannot effectively detect the file content or detects it inaccurately, resulting in virus transmission or information leakage.
[0006] In a first aspect, the present application provides a communication method, applied to a first network device, the method comprising:
[0007] receiving a first file transfer message, wherein the first file transfer message includes message attributes, a file name, and file content;
[0008] If a first mapping table entry that matches both the message attribute and the file name exists in the local mapping table and the execution action included in the first mapping table entry is release, then detecting and processing the file content;
[0009] If the detection result indicates that the file content is illegal file content, the execution action is updated to blocking, and the first file transfer message is discarded.
[0010] In a second aspect, the present application provides a communication device, applied to a first network device, the device comprising:
[0011] A receiving unit, configured to receive a first file transfer message, wherein the first file transfer message includes message attributes, a file name, and file content;
[0012] a detection unit, configured to detect and process the file content if a first mapping table entry that matches both the message attribute and the file name exists in a local mapping table and the execution action included in the first mapping table entry is release;
[0013] an updating unit, configured to update the execution action to blocking if the detection result indicates that the file content is illegal file content;
[0014] A discarding unit, configured to discard the first file transfer message.
[0015] In a third aspect, the present application provides a network device comprising a processor and a machine-readable storage medium, wherein the machine-readable storage medium stores machine-executable instructions that can be executed by the processor, and the processor is prompted by the machine-executable instructions to execute the method provided in the first aspect of the present application.
[0016] Therefore, by applying the communication method and apparatus provided in the present application, a first network device receives a first file transfer message, which includes message attributes, a file name, and file content; if there is a first mapping table entry in the local mapping table that matches both the message attributes and the file name and the execution action included in the first mapping table entry is release, the first network device detects and processes the file content; if the detection result indicates that the file content is illegal file content, the first network device updates the execution action to blocking and discards the first file transfer message.
[0017] In this way, the mapping table entries established through file transfer messages are used to detect and process the file contents upon subsequent receipt of file transfer messages carrying file contents. Based on the detection results, the file transfer messages are blocked or released, and the mapping table entries are updated. This ensures network security in FTP multi-channel transmission scenarios. It also solves the problem that existing file type content detection methods, when used in multi-channel transmission, cannot effectively detect file contents or detect them inaccurately, leading to virus transmission or information leakage. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] Figure 1 A flow chart of a communication method provided in an embodiment of the present application;
[0019] Figure 2 A structural diagram of a communication device provided in an embodiment of the present application;
[0020] Figure 3 The network device hardware structure provided in the embodiment of the present application. DETAILED DESCRIPTION
[0021] Exemplary embodiments will be described in detail herein, with examples illustrated in the accompanying drawings. In the following description, when referring to the drawings, identical numerals in different figures represent identical or similar elements unless otherwise indicated. The embodiments described in the following exemplary embodiments are not intended to represent all embodiments consistent with the present application. Rather, they are merely examples of apparatus and methods consistent with certain aspects of the present application, as detailed in the appended claims.
[0022] The terms used in this application are for the purpose of describing specific embodiments only and are not intended to limit this application. As used in this application and the appended claims, the singular forms "a," "an," "the," and "the" are intended to include the plural forms, unless the context clearly indicates otherwise. It should also be understood that the term "and / or" as used herein refers to and encompasses any and all possible combinations of one or more of the corresponding listed items.
[0023] It should be understood that although the terms first, second, third, etc. may be used in this application to describe various information, such information should not be limited to these terms. These terms are only used to distinguish information of the same type from each other. For example, without departing from the scope of this application, first information may also be referred to as second information, and similarly, second information may also be referred to as first information. Depending on the context, the word "if" as used herein may be interpreted as "at the time of" or "when" or "in response to determining".
[0024] The communication method provided in the embodiment of the present application is described in detail below. Figure 1 , Figure 1 Flowchart of a communication method provided in an embodiment of the present application. The method is applied to a first network device, which is located between a client and a server and serves as a detection device, such as a firewall. The communication method provided in an embodiment of the present application may include the following steps.
[0025] Step 110: Receive a first file transfer message, where the first file transfer message includes message attributes, file name, and file content;
[0026] Specifically, files are transmitted between the client and the server via a multiplexed transmission method. Both ends can transmit files to the other end based on business needs. In the embodiments of the present application, the client transmits a file to the server via a multiplexed transmission method as an example. The process of transmitting a file from the server to the client is the same and will not be repeated here. It should be noted that in the embodiments of the present application, the client and the server can be referred to as the second network device.
[0027] When performing multiplex transmission, the client first divides the file into multiple file blocks (also referred to as sub-files). During the transmission process, the client generates a first file transmission message, which includes message attributes, file name and file content.
[0028] Optionally, in an embodiment of the present application, before receiving the first file transfer message, the first network device will also receive a second file transfer message sent by the client, where the second file transfer message includes a file transfer location.
[0029] It is understandable that the second file transfer message further includes message attributes, and if the file transfer message is sent by the same client, the message attributes included in the second file transfer message are the same as the message attributes included in the first file transfer message.
[0030] After receiving the second file transfer message, the first network device obtains the file transfer location from it. The first network device identifies the value of the file transfer location. If the value of the file transfer location is 0, the first network device determines that the file content being transferred by the client begins at the beginning of the file to be transferred, i.e., the transfer begins at the beginning of the file content. The first network device may also determine that this is the first transmission of the file to be transferred. Subsequently, the first network device waits for a preset period of time to receive the first file transfer message.
[0031] Optionally, in this embodiment of the present application, the value of the file transfer position can be non-zero. If the value of the file transfer position is non-zero, the first network device determines that the file content being transferred by the client begins at the value of the file transfer position, i.e., begins transmission at the content indicated by the file transfer position. Furthermore, the first network device can also determine that this is not the first transmission of the file to be transferred. Subsequently, the first network device waits for a preset period of time to receive the first file transfer message.
[0032] It is understandable that, before transferring the file, the client first generates the second file transfer message to inform the first network device of the file transfer location; and then generates the first file transfer message to formally transfer the file content.
[0033] In one example, the second file transfer message includes a REST command with a parameter of 0, indicating that the file content being transferred starts at byte 0. Meanwhile, the first file transfer message includes a RETH command with a parameter of 1fc3f977c6f12695f462..., indicating that the file being transferred is named 1fc3f977c6f12695f462...
[0034] In another example, the second file transfer message includes a REST command with a parameter of 91980, indicating that the file content being transferred starts at byte 91980. In this case, the first file transfer message includes a RETH command with a parameter of 1fc3f977c6f12695f462..., indicating that the file being transferred is named 1fc3f977c6f12695f462...
[0035] Optionally, in an embodiment of the present application, when the value of the file transfer position included in the second file transfer message is 0, the first file transfer generated by the subsequent client also includes a magic word (magic number). Magic words refer to some specific byte sequences at the beginning of a file that are used to identify the type or format of the file. For example, the magic word is ffd8 ffe0 0010 4a464946 0001 0101 0047, indicating a JPEG type or format; the magic word is GIF87a or GIF89a, indicating a GIF type or format; the magic word is 89 50 4E 47 0D 0A 1A 0A, indicating a PNG type or format; the magic word is %PDF-, indicating a PDF type or format; the magic word is MZ, indicating an EXE type or format; the magic word is 7F 45 4C 46, indicating an ELF type or format.
[0036] Optionally, in an embodiment of the present application, if the file transfer position value included in the first received second file transfer message is 0, and the first file transfer message is received within a preset time after the second file transfer message, the first network device will further perform the following process after receiving the first file transfer message.
[0037] Furthermore, if the message attributes included in the first file transfer message are the same as the message attributes included in the second file transfer message, then based on the message attributes, the first network device establishes a session connection with the second network device (i.e., the client) that sent the second file transfer message. This session connection can be used for subsequent file transfers.
[0038] The first network device obtains a magic word from the first file transfer message and determines the file type of the file content based on the magic word. The first network device searches a local mapping table for a first mapping table entry that matches both the message attributes and the file name based on the message attributes and the file name.
[0039] It is understandable that, because this is the first transmission, the first mapping table entry does not exist in the local mapping table. If the local mapping table does not contain a first mapping entry that matches both the message attributes and the file name, the first network device detects and processes the file content. After detecting and processing the file content, the first network device obtains a detection result. The first network device identifies the detection result.
[0040] If the detection result indicates that the file content is illegal file content, the first network device discards the first file transfer message; at the same time, the first network device also generates a first mapping table entry, which includes message attributes, file type, file name and execution action, and the execution action is blocking.
[0041] If the detection result indicates that the file content is legal file content, the first network device forwards the first file transfer message; at the same time, the first network device also generates a first mapping table entry, which includes message attributes, file type, file name and execution action, and the execution action is release.
[0042] It can be understood that the above-mentioned first network device detects and processes the file content, which can specifically detect sensitive information (for example, whether the file content includes confidential information, virus information, bad information, etc.), calculate the MD5 value (for example, calculate the MD5 value using the file content), etc.
[0043] Optionally, in an embodiment of the present application, the message feature may be specifically a five-tuple of information, for example, source IP address, destination IP address, source port number, destination port number, and application layer protocol.
[0044] According to the above examples, the client can generate multiple file transfer messages at the same time and send them to the server separately through multiplexing. The file transfer message is first received by the first network device, and the message attributes, file name and file content are obtained from it.
[0045] Step 120: If a first mapping table entry that matches both the message attribute and the file name exists in the local mapping table and the execution action included in the first mapping table entry is release, then inspect and process the file content;
[0046] Specifically, according to the description of step 110, after the first network device obtains the message attributes, file name and file content, it searches the local mapping table for a first mapping table entry that matches both the message attributes and the file name.
[0047] If a first mapping table entry that matches both the message attribute and the file name exists in the local mapping table, the first network device obtains the execution action from the first mapping table entry. The first network device continues to identify the execution action.
[0048] If the execution action indicates that the action is to release, the first network device detects and processes the file content.
[0049] Optionally, in the embodiment of the present application, the following process is also included.
[0050] Furthermore, if the execution action indicates that the action is blocking, the first network device discards the first file transfer message.
[0051] Optionally, in the embodiment of the present application, the following process is also included.
[0052] Furthermore, if the local mapping table does not contain a first mapping table entry that matches both the message attribute and the file name, the first network device detects and processes the file content. After detecting and processing the file content, the first network device obtains a detection result. The first network device identifies the detection result.
[0053] If the detection result indicates that the file content is illegal file content, the first network device discards the first file transfer message; at the same time, the first network device also generates a first mapping table entry, which includes message attributes, file name and execution action, and the execution action indicates blocking.
[0054] If the detection result indicates that the file content is legal, the first network device forwards the first file transfer message; at the same time, the first network device also generates a first mapping table entry, which includes message attributes, file name and execution action, and the execution action indicates release.
[0055] It can be understood that the above-mentioned first network device detects and processes the file content, which can specifically detect sensitive information (for example, whether the file content includes confidential information, virus information, bad information, etc.), calculate the MD5 value (for example, calculate the MD5 value using the file content), etc.
[0056] When the first mapping table entry does not exist in the local mapping table, the first network device only receives the first file transfer message carrying the file content, but does not receive the second file transfer message sent earlier. The first network device can identify the file type based on the specific file content and add the file type to the newly generated first mapping table entry.
[0057] Step 130: If the detection result indicates that the file content is illegal, update the execution action to blocking, and discard the first file transfer message;
[0058] Specifically, according to the description of step 120, the first network device detects the file content and obtains a detection result. The first network device identifies the detection result.
[0059] If the detection result indicates that the file content is illegal, the first network device updates the execution action previously set to allow in the first mapping table entry to block. Subsequently, the first network device discards the first file transfer message.
[0060] Optionally, in the embodiment of the present application, the following process is also included.
[0061] Furthermore, if the detection result indicates that the file content is legal file content, the first network device forwards the first file transfer message.
[0062] Therefore, by applying the communication method provided in the present application, the first network device receives a first file transfer message, which includes message attributes, a file name, and file content; if there is a first mapping table entry in the local mapping table that matches both the message attributes and the file name and the execution action included in the first mapping table entry is release, the first network device detects and processes the file content; if the detection result indicates that the file content is illegal file content, the first network device updates the execution action to blocking and discards the first file transfer message.
[0063] In this way, the mapping table entries established through file transfer messages are used to detect and process the file contents upon subsequent receipt of file transfer messages carrying file contents. Based on the detection results, the file transfer messages are blocked or released, and the mapping table entries are updated. This ensures network security in FTP multi-channel transmission scenarios. It also solves the problem that existing file type content detection methods, when used in multi-channel transmission, cannot effectively detect file contents or detect them inaccurately, leading to virus transmission or information leakage.
[0064] Based on the same inventive concept, the present application also provides a communication device corresponding to the communication method. Figure 2 , Figure 2 The communication device provided in an embodiment of the present application is applied to a first network device, and the device includes:
[0065] The receiving unit 210 is configured to receive a first file transfer message, wherein the first file transfer message includes message attributes, a file name, and file content;
[0066] a detection unit 220 configured to detect and process the file content if a first mapping table entry that matches both the message attribute and the file name exists in the local mapping table and the execution action included in the first mapping table entry is release;
[0067] an updating unit 230, configured to update the execution action to blocking if the detection result indicates that the file content is illegal file content;
[0068] The discarding unit 240 is configured to discard the first file transfer message.
[0069] Optionally, the discarding unit 240 is further configured to discard the first file transfer message if the first mapping table entry exists and the execution action included in the first mapping table entry is blocking.
[0070] Optionally, the device further comprises:
[0071] A sending unit (not shown in the figure) is configured to forward the first file transfer request message if the detection result indicates that the file content is legal file content.
[0072] Optionally, the receiving unit 210 is further configured to receive a second file transfer message, where the second file transfer message includes a file transfer location;
[0073] The device also includes: a first determining unit (not shown in the figure), which is used to determine that it is the first transmission of the file to be transmitted based on the file transmission position if the value of the file transmission position is 0, and wait to receive the first file transmission message within a preset time.
[0074] Optionally, the first file transfer message further includes a magic word;
[0075] The device further comprises:
[0076] an establishing unit (not shown in the figure), configured to establish a session connection with the second network device that sends the second file transfer message according to the message attributes if the message attributes are the same as the message attributes included in the second file transfer message;
[0077] A second determining unit (not shown in the figure) is used to determine the file type of the file content according to the magic word;
[0078] The detection unit 220 is further configured to, if the local mapping table does not contain the first mapping table entry that matches both the message attribute and the file name, perform detection processing on the file content;
[0079] The discarding unit 240 is further configured to discard the first file transfer message if the detection result indicates that the file content is illegal file content;
[0080] A generating unit (not shown in the figure) is used to generate the first mapping table entry, where the first mapping table entry includes the message attribute, the file type, the file name, and the execution action, where the execution action is blocking.
[0081] Optionally, the sending unit (not shown in the figure) is further configured to forward the first file transfer message if the detection result indicates that the file content is legal file content;
[0082] The generating unit (not shown in the figure) is further used to generate the first mapping table entry, where the first mapping table entry includes the message attribute, the file type, the file name, and the execution action, where the execution action is release.
[0083] Optionally, the second determination unit (not shown in the figure) is also used to, if the value of the file transfer position is non-0, determine that it is not the first transmission of the file to be transferred based on the file transfer position, and wait to receive the first file transfer message within a preset time.
[0084] Optionally, the detection unit 220 is further configured to, if the local mapping table does not contain the first mapping table entry that matches both the message attribute and the file name, perform detection processing on the file content;
[0085] The discarding unit 240 is further configured to discard the first file transfer message if the detection result indicates that the file content is illegal file content;
[0086] The generating unit (not shown in the figure) is further configured to generate the first mapping table entry, where the first mapping table entry includes the message attribute, the file name, and an execution action, where the execution action indicates blocking.
[0087] Optionally, the sending unit (not shown in the figure) is further configured to forward the first file transfer message if the detection result indicates that the file content is legal file content;
[0088] The generating unit (not shown in the figure) is further configured to generate the first mapping table entry, where the first mapping table entry includes the message attribute, the file name, and an execution action, where the execution action indicates release.
[0089] Therefore, using the communication device provided by the present application, the first network device receives a first file transfer message, which includes message attributes, file name and file content; if there is a first mapping table entry in the local mapping table that matches both the message attributes and the file name and the execution action included in the first mapping table entry is release, the first network device detects and processes the file content; if the detection result indicates that the file content is illegal file content, the first network device updates the execution action to blocking and discards the first file transfer message.
[0090] In this way, the mapping table entries established through file transfer messages are used to detect and process the file contents upon subsequent receipt of file transfer messages carrying file contents. Based on the detection results, the file transfer messages are blocked or released, and the mapping table entries are updated. This ensures network security in FTP multi-channel transmission scenarios. It also solves the problem that existing file type content detection methods, when used in multi-channel transmission, cannot effectively detect file contents or detect them inaccurately, leading to virus transmission or information leakage.
[0091] Based on the same inventive concept, the embodiment of the present application further provides a network device, such as Figure 3 As shown, it includes a processor 310, a transceiver 320 and a machine-readable storage medium 330. The machine-readable storage medium 330 stores machine-executable instructions that can be executed by the processor 310. The processor 310 is prompted by the machine-executable instructions to execute the communication method provided in the embodiment of the present application. Figure 2 The communication device shown can be used as Figure 3 The network device hardware structure shown is implemented.
[0092] The computer-readable storage medium 330 may include random access memory (RAM) or non-volatile memory (NVM), such as at least one disk storage device. Alternatively, the computer-readable storage medium 330 may be at least one storage device located remotely from the processor 310.
[0093] The processor 310 may be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it may also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components.
[0094] In the embodiment of the present application, the processor 310 reads the machine-executable instructions stored in the machine-readable storage medium 330, and the machine-executable instructions enable the processor 310 itself and call the transceiver 320 to execute the communication method described in the aforementioned embodiment of the present application.
[0095] In addition, an embodiment of the present application provides a machine-readable storage medium 330, which stores machine-executable instructions. When called and executed by the processor 310, the machine-executable instructions prompt the processor 310 itself and the calling transceiver 320 to execute the communication method described in the aforementioned embodiment of the present application.
[0096] The implementation process of the functions and effects of each unit in the above-mentioned device is specifically described in the implementation process of the corresponding steps in the above-mentioned method, and will not be repeated here.
[0097] For the device embodiments, since they basically correspond to the method embodiments, the relevant parts can be referred to the partial description of the method embodiments. The device embodiments described above are merely schematic, wherein the units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place, or they may be distributed on multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the present application scheme. A person of ordinary skill in the art can understand and implement it without paying any creative work.
[0098] As for the embodiments of the communication device and the machine-readable storage medium, since the method contents involved are basically similar to those of the aforementioned method embodiments, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiments.
[0099] The above description is only a preferred embodiment of the present application and is not intended to limit the present application. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present application shall be included in the scope of protection of the present application.
Claims
1. A communication method, characterized in that: Applied to a first network device, the method includes: receiving a first file transfer message, wherein the first file transfer message includes message attributes, a file name, and file content; If a first mapping table entry that matches both the message attribute and the file name exists in the local mapping table and the execution action included in the first mapping table entry is release, then detecting and processing the file content; If the detection result indicates that the file content is illegal file content, the execution action is updated to blocking, and the first file transfer message is discarded.
2. The method according to claim 1, characterized in that The method further comprises: If the first mapping table entry exists and the execution action included in the first mapping table entry is blocking, the first file transfer message is discarded.
3. The method according to claim 1, characterized in that The method further comprises: If the detection result indicates that the file content is legal file content, the first file transfer request message is forwarded.
4. The method according to claim 1, wherein Before receiving the first file transfer message, the method further includes: receiving a second file transfer message, wherein the second file transfer message includes a file transfer location; If the value of the file transmission position is 0, it is determined that it is the first transmission of the file to be transmitted according to the file transmission position, and the first file transmission message is received within a preset time.
5. The method according to claim 4, characterized in that The first file transfer message also includes a magic word; After receiving the first file transfer message, the method further includes: If the message attribute is the same as the message attribute included in the second file transfer message, establishing a session connection with the second network device that sends the second file transfer message according to the message attribute; Determining the file type of the file content according to the magic word; If the first mapping table entry that matches both the message attribute and the file name does not exist in the local mapping table, detecting and processing the file content; If the detection result indicates that the file content is illegal file content, discarding the first file transfer message; The first mapping table entry is generated, where the first mapping table entry includes the message attribute, the file type, the file name, and the execution action, where the execution action is blocking.
6. The method according to claim 5, characterized in that The method further comprises: If the detection result indicates that the file content is legal file content, forwarding the first file transfer message; The first mapping table entry is generated, where the first mapping table entry includes the message attribute, the file type, the file name, and the execution action, where the execution action is release.
7. The method according to claim 4, characterized in that The method further comprises: If the value of the file transmission position is not 0, it is determined that the file to be transmitted is not the first transmission according to the file transmission position, and the first file transmission message is received within a preset time.
8. The method according to claim 1, characterized in that The method further comprises: If the first mapping table entry that matches both the message attribute and the file name does not exist in the local mapping table, detecting and processing the file content; If the detection result indicates that the file content is illegal file content, discarding the first file transfer message; The first mapping table entry is generated, where the first mapping table entry includes the message attribute, the file name, and an execution action, where the execution action indicates blocking.
9. The method according to claim 8, characterized in that The method further comprises: If the detection result indicates that the file content is legal file content, forwarding the first file transfer message; The first mapping table entry is generated, where the first mapping table entry includes the message attribute, the file name, and an execution action, where the execution action indicates release.
10. A communication device, characterized in that: Applied to a first network device, the apparatus includes: A receiving unit, configured to receive a first file transfer message, wherein the first file transfer message includes message attributes, a file name, and file content; a detection unit, configured to detect and process the file content if a first mapping table entry that matches both the message attribute and the file name exists in a local mapping table and the execution action included in the first mapping table entry is release; an updating unit, configured to update the execution action to blocking if the detection result indicates that the file content is illegal file content; A discarding unit, configured to discard the first file transfer message.