Network information isolation method and system based on router
By analyzing and tracking the source address of network data packets in the terminal router, combining multiple analysis methods, the delay problem in network isolation technology is solved, fast and accurate data packet security judgment and isolation is achieved, and network security is improved.
Patent Information
- Application Number
- CN202510564773.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-30
- Publication Date
- 2025-08-05
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The existing network isolation technology leads to delays in information and data exchange, which brings great inconvenience to users.
The network data packet is obtained through the terminal router, the source address is parsed and the source address is tracked. If different, the data packet is intercepted. In-depth analysis is carried out in combination with technologies such as disassembly, language models, virtual machines and malicious machine code library to judge the security of the data packets and isolate or release them.
It realizes fast and accurate network data security judgment, reduces information and data exchange delays, and improves network isolation efficiency and security.
Smart Images

Figure CN120433993A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of Internet technology, and in particular to a network information isolation method and system based on a router. Background Art
[0002] Network isolation technology refers to a security technology that can not only meet the needs of information and data exchange between internal and external networks, but also prevent network security incidents. Network isolation technology usually avoids direct information exchange and physical connection between two computers to block direct online network attacks between the two computers. However, this also causes delays in information and data exchange between computers, causing great inconvenience to users. Summary of the Invention
[0003] In response to the above technical problems, the embodiments of the present application propose a router-based network information isolation method and system, which can solve the problem of information and data exchange delays in current network isolation technology, causing great inconvenience to users.
[0004] In a first aspect, an embodiment of the present application provides a router-based network information isolation method, comprising:
[0005] Obtain network data packets from the WAN through the terminal router;
[0006] Parsing the network data packet and obtaining the source address in the network data packet;
[0007] Tracking the source address of the network data packet;
[0008] If the source address is different from the origin address, the network data packet is intercepted.
[0009] In some embodiments, if the source address is different from the origin address, intercepting the network data packet further comprises:
[0010] The source address is added to the routing blacklist of the terminal router.
[0011] In some embodiments, tracing the source address of the network data packet includes:
[0012] Record the port, source address, and destination address of forwarded data through the router;
[0013] Obtaining the destination address of the network data packet;
[0014] Based on the source address, the destination address and the port, query the routing table of the intermediate forwarding router step by step to obtain the starting router that sends the network data packet;
[0015] The source address is obtained based on the origin router.
[0016] In some embodiments, the router-based network information isolation method further includes:
[0017] If the source address is the same as the origin address, disassembling the network data in the network data packet to obtain disassembled data;
[0018] Calculating disassembled data similarity between the disassembled data and malicious assembly data in a malicious assembly database;
[0019] If the disassembly data similarity is greater than the disassembly interception threshold, the network data packet is discarded.
[0020] In some embodiments, the router-based network information isolation method further includes:
[0021] If the disassembly data similarity is less than or equal to the disassembly interception threshold and greater than the disassembly pass threshold, identifying the disassembly semantics of the disassembly data by using a language model;
[0022] Obtaining a data execution operation on the disassembled data based on the disassembly semantics;
[0023] If the data execution operation is a malicious operation, the network data packet is discarded.
[0024] In some embodiments, the router-based network information isolation method further includes:
[0025] If the data execution operation is a suspicious operation, inputting the disassembled data into a virtual machine for virtual operation to obtain a virtual operation result;
[0026] If the virtual operation result is dangerous, the network data packet is discarded.
[0027] In some embodiments, the router-based network information isolation method further includes:
[0028] generating a malicious machine code library based on the malicious assembly data in the malicious assembly database;
[0029] Calculating the similarity between the network data in the network data packet and the malicious machine code in the malicious machine code library to obtain the machine code similarity;
[0030] If the machine code similarity is greater than the machine code interception threshold, the network data packet is discarded.
[0031] In some embodiments, tracing the source address of the network data packet further includes:
[0032] Capturing network data from the source address to obtain multiple captured data packets;
[0033] Extracting features from the network data in the network data packet to obtain feature data;
[0034] Extracting features from the plurality of captured data packets to obtain a plurality of feature data to be verified;
[0035] If the characteristic data is identical to the characteristic data to be verified, the source address is added to the grey list of the router.
[0036] In some embodiments, the router-based network information isolation method further includes:
[0037] Calculating the similarity between the network data in the plurality of captured packet data and the malicious machine code in the malicious machine code library to obtain the captured machine code similarity;
[0038] If the similarity of the captured machine code is greater than a machine code interception threshold, the source address is added to the blacklist of the router.
[0039] In a second aspect, an embodiment of the present application provides a router-based network information isolation system, comprising:
[0040] Acquisition module: used to acquire network data packets from the wide area network through the terminal router; parse the network data packets and obtain the source address in the network data packets;
[0041] A tracking module, used for tracking the source address of the network data packet;
[0042] An interception module is used to intercept the network data packet if the source address is different from the source address.
[0043] The present application provides a router-based network information isolation method and system, comprising: obtaining a network data packet of a wide area network through a terminal router; parsing the network data packet and obtaining a source address in the network data packet; tracking the source address of the network data packet; and intercepting the network data packet if the source address is different from the source address. The method and system can quickly judge the security of the network data based on the source address and source address of the network data packet, and isolate or release the network data, and can solve the problem of information and data exchange delay in current network isolation technology, which causes great inconvenience to users. BRIEF DESCRIPTION OF THE DRAWINGS
[0044] Hereinafter, the present invention will be described in more detail based on embodiments with reference to the accompanying drawings.
[0045] Figure 1This is a flow chart of a method for isolating network information based on a router provided by one embodiment of the present invention;
[0046] Figure 2 This is a schematic diagram of a router-based network information isolation system provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0047] The present invention will be further described below with reference to the accompanying drawings.
[0048] Network isolation refers to a technology that isolates two or more routable networks by exchanging data through non-routable means. Network isolation technology is mainly used to protect network information security. It isolates the internal and external networks and exchanges data through measures such as dedicated communication channels and proprietary security protocols.
[0049] Since today's network communications are all based on the TCP / IP protocol, most network attacks are launched using the TCP / IP protocol as a carrier. If there is no connection, there is no exploitable vulnerability. The most effective way to achieve network isolation is to disconnect the connection of one or several layers of the TCP / IP communication model and enable data to be exchanged using non-TCP / IP protocols. The specific ways to disconnect each layer are: 1) Disconnection of the physical layer: ensure that the network cannot establish a data link layer connection based on the physical layer; 2) Disconnection of the data link layer: disconnecting the data link layer means removing the link layer protocol. Although this reduces transmission reliability, it also eliminates the threats that the protocol may bring; 3) Disconnection of the network layer: disconnecting the network layer means stripping off the IP protocol and repackaging and reassembling the data packets in a non-IP protocol format; 4) Disconnection of the transport layer: the transport layer protocols include TCP and UDP. Disconnecting the transport layer means eliminating TCP or UDP, thus avoiding network attacks caused by TCP and UDP protocols; 5) Disconnection of the application layer: disconnecting the application layer means not using the common application layer protocol. Although the above technologies achieve information isolation, they also cause delays in information and data exchange between computers, causing great inconvenience to users.
[0050] First, as Figure 1 As shown, in order to solve the above technical problems, the embodiment of the present application provides a network information isolation method based on a router, including:
[0051] S101: Obtaining network data packets from the WAN through the terminal router;
[0052] S102: Parsing the network data packet and obtaining the source address in the network data packet;
[0053] S103: Tracking the source address of the network data packet;
[0054] S104: If the source address is different from the origin address, intercept the network data packet.
[0055] It should be noted that the terminal router is the router at the user end, that is, the terminal router is connected to the user's computer, and the wide area network is the external network or public network, which is a remote network connecting local area networks or metropolitan area networks in different regions for computer communication.
[0056] It should be noted that, since many attackers of network attacks need to hide their own addresses (such as IP addresses), they usually use false source addresses to carry out network attacks, and the source address of the network data packet cannot be hidden. At this time, by tracking the source address of the network data packet, if the source address is different from the source address, it can be determined that the network data packet is a network attack (such as a network virus, worm, malicious email, etc.), and the network data packet can be directly intercepted by the terminal router, wherein the network data packet can be parsed by the terminal router.
[0057] In some embodiments, if the source address is different from the origin address, intercepting the network data packet further comprises:
[0058] The source address is added to the routing blacklist of the terminal router.
[0059] It should be noted that by adding the source address to the blacklist of the terminal router, when the source address launches a network attack again, it can be directly intercepted to avoid further judgment, which can improve the interception efficiency. The blacklist of the router can be shared in the network to fully grasp the source of the network attack.
[0060] In some embodiments, tracing the source address of the network data packet includes:
[0061] Record the port, source address, and destination address of forwarded data through the router;
[0062] Obtaining the destination address of the network data packet;
[0063] Based on the source address, the destination address and the port, query the routing table of the intermediate forwarding router step by step to obtain the starting router that sends the network data packet;
[0064] The source address is obtained based on the origin router.
[0065] It should be noted that when forwarding network data, the router will parse the network data packet, obtain the source address, the destination address, and query the forwarding port (including the receiving port and the sending port, the network address of the router). By recording the source address, the destination address and the port, it is convenient to trace the source address of the network data packet. When tracing the source address of the network data packet, it is usually traced step by step, that is, from the terminal router to the intermediate forwarding router of the previous level, and then traced step by step to the starting router, and then the source address of the starting router, that is, the source address of the network data packet, can be obtained. Among them, the source address, the destination address and the port can be stored in a computer or server in the local area network connected to the intermediate router.
[0066] It should be noted that when querying the routing table of the intermediate forwarding router based on the source address, the destination address and the port, a query request is initiated to the upper-level router through the lower-level router (i.e., the source address, the destination address and the port are sent), and the upper-level router performs the query and returns the address of the intermediate forwarding router of the upper-level router, so as to perform the query step by step and ensure the security of the intermediate forwarding router.
[0067] In some embodiments, the router-based network information isolation method further includes:
[0068] If the source address is the same as the origin address, disassembling the network data in the network data packet to obtain disassembled data;
[0069] Calculating disassembled data similarity between the disassembled data and malicious assembly data in a malicious assembly database;
[0070] If the disassembly data similarity is greater than the disassembly interception threshold, the network data packet is discarded.
[0071] It should be noted that if the source address is the same as the origin address, it does not mean that the network data packet is safe and further testing is required. Since the network data in the network data packet is machine code, it is usually difficult to understand the operation of the network data packet. By disassembling the network data in the network data packet into disassembled data, it is easier to judge the operation of the network data packet. Among them, the disassembly similarity threshold is 90%, which can also be adjusted according to actual needs. This application does not make specific restrictions on this.
[0072] In some embodiments, the router-based network information isolation method further includes:
[0073] If the disassembly data similarity is less than or equal to the disassembly interception threshold and greater than the disassembly pass threshold, identifying the disassembly semantics of the disassembly data by using a language model;
[0074] Obtaining a data execution operation on the disassembled data based on the disassembly semantics;
[0075] If the data execution operation is a malicious operation, the network data packet is discarded.
[0076] It should be noted that since the nature of many operations is difficult to determine through simple code comparison, such as continuous security verification, it may be a normal operation or a malicious operation. At this time, the disassembled data is identified by the language model to obtain the disassembly semantics, and the programming logic of the network data packet can be sorted out, thereby determining whether the operation nature of the network data packet is normal or malicious. Among them, the disassembly pass threshold can be 50%, etc. This application does not make specific restrictions on this, and the language model can be obtained through training.
[0077] It should be noted that if the data execution operation is a normal operation, the network data packet will be forwarded to the user end (i.e., the computer or server in the local area network); if the data execution operation is a malicious operation, the malicious disassembled data can be added to the malicious assembly database before discarding the network data packet, so that the next time the corresponding disassembled data is received, it can be judged based on the malicious assembly database without the need to use the language model to perform disassembly semantic recognition on the network data, thereby improving the speed of judging the nature of the network data, wherein the malicious operation may be tampering with system data, obtaining user data, etc.
[0078] In some embodiments, the router-based network information isolation method further includes:
[0079] If the data execution operation is a suspicious operation, inputting the disassembled data into a virtual machine for virtual operation to obtain a virtual operation result;
[0080] If the virtual operation result is dangerous, the network data packet is discarded.
[0081] It should be noted that the suspicious operation may be a link that needs to be clicked in a sent email, certain programs that need to be run, etc. At this time, it is impossible to determine whether it is dangerous through code comparison. By inputting the disassembled data (or the network data packet) into the virtual machine for virtual operation, it is possible to accurately determine whether the network data packet is malicious or dangerous without affecting the computer or server, wherein the virtual machine is deployed on a server or computer.
[0082] It should be noted that if the virtual operation result is safe, the network data packet will be forwarded to the user end (i.e., the computer or server in the local area network); if the virtual operation result is dangerous, before discarding the network data packet, the dangerous disassembly data can be added to the malicious assembly database, so that the next time the corresponding disassembly data is received, it can be judged based on the malicious assembly database without the need to virtually run the network data through the virtual machine, thereby improving the speed of judging the nature of the network data.
[0083] In some embodiments, the router-based network information isolation method further includes:
[0084] generating a malicious machine code library based on the malicious assembly data in the malicious assembly database;
[0085] Calculating the similarity between the network data in the network data packet and the malicious machine code in the malicious machine code library to obtain the machine code similarity;
[0086] If the machine code similarity is greater than the machine code interception threshold, the network data packet is discarded.
[0087] It should be noted that by converting the malicious assembly data in the malicious assembly database into malicious machine code and obtaining the malicious machine code library based on the malicious machine code, the malicious machine code can be used to compare the network data in the network data packet, thereby eliminating the need to disassemble the network data in the network data packet before comparing, thereby improving the processing speed. The machine code interception threshold can be 90%, etc., and this application does not make any specific limitations on this.
[0088] It should be noted that if the machine code similarity is less than or equal to the machine code interception threshold and greater than the machine code passing threshold, at this time, the network data packet is in a suspicious state, and the network data in the network data packet can continue to be disassembled and the disassembly similarity calculation can be performed again. By judging the data situation in the network data packet, corresponding judgment and processing methods can be adopted for different situations of the network data in the network data packet, which can not only ensure network security but also reduce the impact on network data transmission.
[0089] In some embodiments, the router-based network information isolation method, wherein the tracing of the source address of the network data packet further comprises:
[0090] Capturing network data from the source address to obtain multiple captured data packets;
[0091] Extracting features from the network data in the network data packet to obtain feature data;
[0092] Extracting features from the plurality of captured data packets to obtain a plurality of feature data to be verified;
[0093] If the characteristic data is identical to the characteristic data to be verified, the source address is added to the grey list of the router.
[0094] It should be noted that if the network data packet is malicious or unsafe, it means that the source address is in an unsafe state, and the source address may launch attacks on many computers in the same time period. At this time, by extracting features from the network data received by this application and comparing the feature data with the feature data to be verified, if the feature data is the same as the feature data to be verified, it means that the source address is a valid address, and the source address is entered into the gray list of the router (or terminal router) for key monitoring. The feature data may include data location and corresponding data values. The data location of the feature data to be verified is the same as the data location of the feature data, that is, when extracting data from the network data packet and the captured packet, the data at the same location is extracted for comparison.
[0095] In some embodiments, the router-based network information isolation method further includes:
[0096] Calculating the similarity between the network data in the plurality of captured packet data and the malicious machine code in the malicious machine code library to obtain the captured machine code similarity;
[0097] If the similarity of the captured machine code is greater than a machine code interception threshold, the source address is added to the blacklist of the router.
[0098] It should be noted that by calculating and processing the network data in the captured data packets sent by the source address within a period of time and judging them, it is possible to determine whether the source address is a potentially harmful address. By adding the source address to the blacklist of the router, the network data sent by the source address can be intercepted.
[0099] In summary, the present application provides a network information isolation method based on a router, including: obtaining a network data packet of a wide area network through a terminal router; parsing the network data packet and obtaining the source address in the network data packet; tracking the source address of the network data packet; if the source address is different from the source address, intercepting the network data packet, and being able to quickly judge the security of the network data based on the source address and source address of the network data packet, and isolate or release the network data, which can solve the problem of information and data exchange delay in the current network isolation technology, causing great inconvenience to users.
[0100] Second, as Figure 2 As shown, the embodiment of the present application provides a network information isolation system based on a router, including:
[0101] The acquisition module 210 is configured to acquire a network data packet from a wide area network through a terminal router; parse the network data packet and acquire a source address from the network data packet;
[0102] a tracking module 220 for tracking the source address of the network data packet;
[0103] The interception module 230 is configured to intercept the network data packet if the source address is different from the origin address.
[0104] In some embodiments, if the source address is different from the origin address, intercepting the network data packet further comprises:
[0105] The source address is added to the routing blacklist of the terminal router.
[0106] In some embodiments, tracing the source address of the network data packet includes:
[0107] Record the port, source address, and destination address of forwarded data through the router;
[0108] Obtaining the destination address of the network data packet;
[0109] Based on the source address, the destination address and the port, query the routing table of the intermediate forwarding router step by step to obtain the starting router that sends the network data packet;
[0110] The source address is obtained based on the origin router.
[0111] In some embodiments, the interception module 230 is further configured to:
[0112] If the source address is the same as the origin address, disassembling the network data in the network data packet to obtain disassembled data;
[0113] Calculating disassembled data similarity between the disassembled data and malicious assembly data in a malicious assembly database;
[0114] If the disassembly data similarity is greater than the disassembly interception threshold, the network data packet is discarded.
[0115] In some embodiments, the interception module 230 is further configured to:
[0116] If the disassembly data similarity is less than or equal to the disassembly interception threshold and greater than the disassembly pass threshold, identifying the disassembly semantics of the disassembly data by using a language model;
[0117] Obtaining a data execution operation on the disassembled data based on the disassembly semantics;
[0118] If the data execution operation is a malicious operation, the network data packet is discarded.
[0119] In some embodiments, the interception module 230 is further configured to:
[0120] If the data execution operation is a suspicious operation, inputting the disassembled data into a virtual machine for virtual operation to obtain a virtual operation result;
[0121] If the virtual operation result is dangerous, the network data packet is discarded.
[0122] In some embodiments, the interception module 230 is further configured to:
[0123] generating a malicious machine code library based on the malicious assembly data in the malicious assembly database;
[0124] Calculating the similarity between the network data in the network data packet and the malicious machine code in the malicious machine code library to obtain the machine code similarity;
[0125] If the machine code similarity is greater than the machine code interception threshold, the network data packet is discarded.
[0126] In some embodiments, tracing the source address of the network data packet further includes:
[0127] Capturing network data from the source address to obtain multiple captured data packets;
[0128] Extracting features from the network data in the network data packet to obtain feature data;
[0129] Extracting features from the plurality of captured data packets to obtain a plurality of feature data to be verified;
[0130] If the characteristic data is identical to the characteristic data to be verified, the source address is added to the grey list of the router.
[0131] In some embodiments, the interception module 230 is further configured to:
[0132] Calculating the similarity between the network data in the plurality of captured packet data and the malicious machine code in the malicious machine code library to obtain the captured machine code similarity;
[0133] If the similarity of the captured machine code is greater than a machine code interception threshold, the source address is added to the blacklist of the router.
[0134] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (apparatus, systems), and / or computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the steps in the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0135] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.
[0136] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.
[0137] The specific embodiments described above further illustrate the purpose, technical solutions and beneficial effects of the present application. It should be understood that the above description is only a specific embodiment of the present application and is not intended to limit the scope of protection of the present application. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present application should be included in the scope of protection of the present application.
Claims
1. A network information isolation method based on a router, characterized in that: include: Obtain network data packets from the WAN through the terminal router; Parsing the network data packet and obtaining the source address in the network data packet; Tracking the source address of the network data packet; If the source address is different from the origin address, the network data packet is intercepted.
2. The network information isolation method based on router according to claim 1, characterized in that: If the source address is different from the source address, intercepting the network data packet further includes: The source address is added to the routing blacklist of the terminal router.
3. The network information isolation method based on router according to claim 1, characterized in that: The tracing of the source address of the network data packet includes: Record the port, source address, and destination address of forwarded data through the router; Obtaining the destination address of the network data packet; Based on the source address, the destination address and the port, query the routing table of the intermediate forwarding router step by step to obtain the starting router that sends the network data packet; The source address is obtained based on the origin router.
4. The network information isolation method based on router according to claim 1, characterized in that: Also includes: If the source address is the same as the origin address, disassembling the network data in the network data packet to obtain disassembled data; Calculating disassembled data similarity between the disassembled data and malicious assembly data in a malicious assembly database; If the disassembly data similarity is greater than the disassembly interception threshold, the network data packet is discarded.
5. The network information isolation method based on router according to claim 4, characterized in that: Also includes: If the disassembly data similarity is less than or equal to the disassembly interception threshold and greater than the disassembly pass threshold, identifying the disassembly semantics of the disassembly data by using a language model; Obtaining a data execution operation on the disassembled data based on the disassembly semantics; If the data execution operation is a malicious operation, the network data packet is discarded.
6. The network information isolation method based on router according to claim 5, characterized in that: Also includes: If the data execution operation is a suspicious operation, inputting the disassembled data into a virtual machine for virtual operation to obtain a virtual operation result; If the virtual operation result is dangerous, the network data packet is discarded.
7. The network information isolation method based on router according to claim 4, characterized in that: Also includes: generating a malicious machine code library based on the malicious assembly data in the malicious assembly database; Calculating the similarity between the network data in the network data packet and the malicious machine code in the malicious machine code library to obtain the machine code similarity; If the machine code similarity is greater than the machine code interception threshold, the network data packet is discarded.
8. The network information isolation method based on router according to claim 7, characterized in that: The tracking of the source address of the network data packet further includes: Capturing network data from the source address to obtain multiple captured data packets; Extracting features from the network data in the network data packet to obtain feature data; Extracting features from the plurality of captured data packets to obtain a plurality of feature data to be verified; If the characteristic data is identical to the characteristic data to be verified, the source address is added to the grey list of the router.
9. The network information isolation method based on router according to claim 8, characterized in that: Also includes: Calculating the similarity between the network data in the plurality of captured packet data and the malicious machine code in the malicious machine code library to obtain the captured machine code similarity; If the similarity of the captured machine code is greater than a machine code interception threshold, the source address is added to the blacklist of the router.
10. A network information isolation system based on a router, characterized in that: include: An acquisition module is used to acquire a network data packet of a wide area network through a terminal router; parse the network data packet and acquire a source address in the network data packet; A tracking module, used for tracking the source address of the network data packet; An interception module is used to intercept the network data packet if the source address is different from the source address.