Malicious network processing method, device, equipment and program product

By dividing malicious IP networks into multiple sub-IP networks and formulating targeted handling measures based on their autonomous system IP networks, the problem of malicious networks being unable to accurately handle malicious networks in the existing technology is solved, avoiding accidental damage to normal networks and ensuring normal operation of users.

CN120455046APending Publication Date: 2025-08-08CHINA TELECOM CLOUD TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510495277.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-18
Publication Date
2025-08-08

AI Technical Summary

Technical Problem

The existing technology cannot accurately deal with malicious networks, which can easily damage normal networks, and attackers can easily avoid blockades.

Method used

The malicious IP network is divided into multiple sub-IP networks, and corresponding processing measures are defined according to the autonomous system IP network of each target sub-IP network, including blocking, observation and internal processing.

Benefits of technology

It realizes accurate handling of malicious IP networks, avoids accidental damage to the normal network, and ensures that users work normally.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120455046A_ABST
    Figure CN120455046A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of network security, and discloses a malicious network processing method, device and equipment and a program product, a malicious IP network is divided into a plurality of sub-IP networks, and an autonomous system IP network to which a target sub-IP network belongs is defined. If the autonomous system IP networks to which the target sub-IP network belongs are different, the target processing measures corresponding to the target sub-IP network are also different. Therefore, in combination with the autonomous system IP networks to which the different target sub-IP networks belong, the target processing measures corresponding to the target sub-IP networks are formulated in a targeted manner, and the target sub-IP networks are correspondingly processed, so that the malicious IP networks can be accurately processed, and the situation that the normal operation of a user is influenced due to accidental injury of the network in a normal state is avoided.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular to a method, device, equipment and program product for processing malicious networks. Background Art

[0002] In recent years, with the continuous development of attack and defense drills and security activities across the country, the Internet Protocol (IP) of malicious networks has become a major source of security control. These networks are used to carry out network intrusions, distributed denial of service attacks, malware distribution, and other destructive behaviors. Therefore, dealing with malicious networks has become a pressing issue in the field of network security.

[0003] In related technologies, the first approach is typically to block entire IP networks by adding them to a blacklist. However, this approach can accidentally impact healthy networks, and attackers can easily circumvent the blockade by changing their IP addresses. The second approach typically involves monitoring malicious networks on security devices and blocking them when they detect malicious attack alerts. However, this approach also presents some challenges, such as blocking data centers or metropolitan area networks, preventing access to services in a specific area. Therefore, these approaches cannot accurately address high-risk malicious networks. Summary of the Invention

[0004] In view of this, the present invention provides a method, apparatus, device and program product for processing malicious networks to solve the problem that traditional methods cannot accurately process malicious networks in high-risk states.

[0005] In a first aspect, the present invention provides a method for processing a malicious network, the method comprising:

[0006] Step S101, obtaining a malicious IP network and dividing the malicious IP network into multiple sub-IP networks according to the malicious behavior of the malicious IP network;

[0007] Step S102, defining the autonomous system IP network to which the target sub-IP network belongs according to the autonomous system identifier of each target sub-IP network among the multiple sub-IP networks;

[0008] Step S103, formulating target processing measures corresponding to the target sub-IP network according to the autonomous system IP network to which the target sub-IP network belongs;

[0009] Step S104: Process the target sub-IP network according to the target processing measure corresponding to the target sub-IP network.

[0010] The embodiment of the present disclosure, through the above-mentioned implementation method, divides the malicious IP network into multiple sub-IP networks and defines the autonomous system IP network to which the target sub-IP network belongs. Assuming that the autonomous system IP network to which the target sub-IP network belongs is different, the target processing measures corresponding to the target sub-IP network will also be different. Therefore, the embodiment of the present disclosure combines the autonomous system IP network to which different target sub-IP networks belong, formulates the target processing measures corresponding to the target sub-IP network in a targeted manner, and processes the target sub-IP network accordingly, which is conducive to accurately processing malicious IP networks and avoiding accidentally damaging networks in a normal state, thereby affecting the normal operation of users.

[0011] In some optional implementations, the malicious IP network is divided into multiple sub-IP networks according to the malicious behavior of the malicious IP network, including:

[0012] When the malicious behavior of the malicious IP network exceeds a first preset threshold, the malicious IP network is divided into a red team IP network and an advanced persistent threat IP network according to the malicious behavior of the malicious IP network;

[0013] When the malicious behavior of the malicious IP network exceeds the second preset threshold, the malicious IP network is divided into verification IP network, virus IP network, web attack IP network, ransomware IP network and unknown IP network according to the malicious behavior of the malicious IP network.

[0014] The embodiments of the present disclosure, through the above-mentioned implementation methods, are conducive to accurately dividing multiple sub-IP networks where multiple different types of malicious behaviors exist.

[0015] In some optional implementations, the autonomous system IP network includes: a metropolitan area IP network, or a data center IP network, or a private IP network, or a foreign IP network, or an enterprise IP network, or a tenant IP network; the target processing measure includes: a blocking processing measure, or an internal processing measure, or an observation processing measure;

[0016] Based on the autonomous system IP network to which the target sub-IP network belongs, formulate targeted processing measures corresponding to the target sub-IP network, including:

[0017] When the autonomous system IP network to which the target sub-IP network belongs is a red team IP network, an advanced persistent threat IP network, or a web attack IP network, determine whether the autonomous system IP network to which the target sub-IP network belongs is a foreign IP network;

[0018] When the autonomous system IP network to which the target sub-IP network belongs is a foreign IP network, formulate corresponding blocking measures for the target sub-IP network;

[0019] When the autonomous system IP network to which the target sub-IP network belongs is not a foreign IP network, determining whether the autonomous system IP network to which the target sub-IP network belongs is a metropolitan area IP network or a data center IP network;

[0020] When the autonomous system IP network to which the target sub-IP network belongs is a metropolitan area IP network or a data center IP network, formulate observation and handling measures corresponding to the target sub-IP network;

[0021] When the autonomous system IP network to which the target sub-IP network belongs is not a metropolitan area IP network or a data center IP network, determining whether the autonomous system IP network to which the target sub-IP network belongs is a private IP network;

[0022] When the autonomous system IP network to which the target sub-IP network belongs is a private IP network, formulate corresponding blocking measures for the target sub-IP network;

[0023] When the autonomous system IP network to which the target sub-IP network belongs is not a private IP network, determining whether the autonomous system IP network to which the target sub-IP network belongs is an enterprise IP network or a tenant IP network;

[0024] When the autonomous system IP network to which the target sub-IP network belongs is an enterprise IP network or a tenant IP network, formulate internal processing measures corresponding to the target sub-IP network;

[0025] When the autonomous system IP network to which the target sub-IP network belongs is not the enterprise IP network or the tenant IP network, formulate corresponding blocking measures for the target sub-IP network.

[0026] The embodiment of the present disclosure divides the malicious IP network into multiple sub-IP networks and defines the autonomous system IP network to which the target sub-IP network belongs. Assuming that the autonomous system IP network to which the target sub-IP network belongs is different, the target processing measures corresponding to the target sub-IP network will also be different, and ultimately the target processing measures corresponding to the target sub-IP network will also be different. Therefore, the embodiment of the present disclosure combines the autonomous system IP networks to which different target sub-IP networks belong, formulates the target processing measures corresponding to the target sub-IP network in a targeted manner, and processes the target sub-IP network accordingly, which is conducive to accurately processing malicious IP networks and avoiding accidental damage to networks in a normal state.

[0027] In some optional implementations, target processing measures corresponding to the target sub-IP network are formulated based on the autonomous system IP network to which the target sub-IP network belongs, including:

[0028] When the target sub-IP network is determined to be a verification IP network, a virus IP network, a ransomware IP network, or an unknown IP network, it is determined whether the autonomous system IP network to which the target sub-IP network belongs is a foreign IP network;

[0029] When the autonomous system IP network to which the target sub-IP network belongs is a foreign IP network, formulate corresponding blocking measures for the target sub-IP network;

[0030] When the autonomous system IP network to which the target sub-IP network belongs is not a foreign IP network, determining whether the autonomous system IP network to which the target sub-IP network belongs is a metropolitan area IP network or a data center IP network;

[0031] When the autonomous system IP network to which the target sub-IP network belongs is a metropolitan area IP network or a data center IP network, formulate observation and handling measures corresponding to the target sub-IP network;

[0032] When the autonomous system IP network to which the target sub-IP network belongs is not a metropolitan area IP network or a data center IP network, determining whether the autonomous system IP network to which the target sub-IP network belongs is a private IP network;

[0033] When the autonomous system IP network to which the target sub-IP network belongs is a private IP network, formulate observation and handling measures corresponding to the target sub-IP network;

[0034] When the autonomous system IP network to which the target sub-IP network belongs is not a private IP network, determining whether the autonomous system IP network to which the target sub-IP network belongs is an enterprise IP network or a tenant IP network;

[0035] When the autonomous system IP network to which the target sub-IP network belongs is an enterprise IP network or a tenant IP network, formulate internal processing measures corresponding to the target sub-IP network;

[0036] When the autonomous system IP network to which the target sub-IP network belongs is not an enterprise IP network or a tenant IP network, formulate observation and handling measures corresponding to the target sub-IP network.

[0037] The embodiment of the present disclosure divides the malicious IP network into multiple sub-IP networks and defines the autonomous system IP network to which the target sub-IP network belongs. Assuming that the autonomous system IP network to which the target sub-IP network belongs is different, the target processing measures corresponding to the target sub-IP network will also be different, and ultimately the target processing measures corresponding to the target sub-IP network will also be different. Therefore, the embodiment of the present disclosure combines the autonomous system IP networks to which different target sub-IP networks belong, formulates target processing measures corresponding to the target sub-IP network in a targeted manner, and processes the target sub-IP network accordingly, which is conducive to accurately processing malicious IP networks and avoiding accidentally damaging networks in a normal state, affecting users' normal operations.

[0038] In some optional implementations, when the target sub-IP network corresponds to an observation processing measure, the security protection device is queried according to a preset period, and when an alarm occurs in the target sub-IP network, a blocking processing measure is executed on the target sub-IP network.

[0039] The disclosed embodiment periodically queries security protection equipment for target sub-IP networks that need to be observed, and blocks them when an alarm occurs, thereby ensuring the security of the target sub-IP networks under observation.

[0040] In some optional implementations, after the step of formulating target processing measures corresponding to the target sub-IP network, the following steps are further included:

[0041] Steps S101 to S104 are repeatedly executed according to a preset time to update the target processing measures corresponding to the target sub-IP network.

[0042] The embodiments of the present disclosure facilitate flexible adjustment of target processing measures corresponding to target sub-IP networks through the above implementation methods.

[0043] In a second aspect, the present invention provides a device for processing a malicious network, the device comprising:

[0044] An acquisition module is used to acquire malicious IP networks and divide the malicious IP networks into multiple sub-IP networks according to the malicious behaviors of the malicious IP networks;

[0045] A definition module, configured to define the autonomous system IP network to which the target sub-IP network belongs according to the autonomous system identifier of each target sub-IP network among the multiple sub-IP networks;

[0046] A formulation module is used to formulate target processing measures corresponding to the target sub-IP network according to the autonomous system IP network to which the target sub-IP network belongs;

[0047] The processing module processes the target sub-IP network according to the target processing measure corresponding to the target sub-IP network.

[0048] In a third aspect, the present invention provides a computer device comprising: a memory and a processor, the memory and the processor being communicatively connected to each other, the memory storing computer instructions, and the processor executing the malicious network processing method of the first aspect or any corresponding embodiment thereof by executing the computer instructions.

[0049] In a fourth aspect, the present invention provides a computer-readable storage medium having computer instructions stored thereon, the computer instructions being used to enable a computer to execute the method for processing a malicious network according to the first aspect or any corresponding embodiment thereof.

[0050] In a fifth aspect, the present invention provides a computer program product, comprising computer instructions for causing a computer to execute the method for processing a malicious network according to the first aspect or any corresponding embodiment thereof. BRIEF DESCRIPTION OF THE DRAWINGS

[0051] In order to more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the specific embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0052] Figure 1 is a flow chart of a method for processing a malicious network according to an embodiment of the present invention;

[0053] Figure 2 is a schematic diagram of a method for acquiring a high-risk IP network according to an embodiment of the present invention;

[0054] Figure 3 is a flow chart of another method for processing a malicious network according to an embodiment of the present invention;

[0055] Figure 4 is a flow chart of another method for processing a malicious network according to an embodiment of the present invention;

[0056] Figure 5 is a structural block diagram of a malicious network processing device according to an embodiment of the present invention;

[0057] Figure 6 Schematic diagram of the hardware structure of a computer device according to an embodiment of the present invention. DETAILED DESCRIPTION

[0058] To make the purpose, technical solutions, and advantages of the embodiments of the present invention more clear, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without making creative efforts shall fall within the scope of protection of the present invention.

[0059] According to an embodiment of the present invention, an embodiment of a method for processing a malicious network is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.

[0060] In this embodiment, a method for processing a malicious network is provided, which can be used for computer devices such as mobile phones, tablet computers, desktop computers, portable notebooks, servers, etc. Figure 1 FIG. 1 is a flow chart of a method for processing a malicious network according to an embodiment of the present invention. Figure 1 As shown, the process includes the following steps:

[0061] Step S101: Acquire a malicious IP network, and divide the malicious IP network into multiple sub-IP networks according to the malicious behavior of the malicious IP network.

[0062] Malicious IP networks can be high-risk IP networks identified through threat intelligence platforms. Threat intelligence platforms generally categorize malicious IP networks into black and gray IP networks, high-risk IP networks, mobile base stations, and unknown IP networks. Black and gray IP networks are IP networks where malicious activity has been detected. In this disclosure, the primary focus is on high-risk IP networks.

[0063] The acquisition methods of high-risk IP network sources include but are not limited to threat intelligence centers, groups, security groups, and security device logs. After obtaining high-risk IP networks through multiple paths, the collected high-risk IP networks are further filtered and deduplicated. Each collected high-risk IP network can be queried in the database. If the currently queried high-risk IP network is found to be already in the database, it will be removed to ensure the accuracy of the high-risk IP network. Figure 2 FIG. 1 is a schematic diagram of a method for obtaining high-risk IP network sources in an embodiment of the present disclosure.

[0064] In a specific example, the sub-IP network includes: a verification IP network, a virus IP network, a ransomware IP network, a red team IP network, an advanced persistent threat IP network, a web attack IP network, or an unknown IP network.

[0065] The advanced persistent threat mentioned above is referred to as APT, and the web page is referred to as Web.

[0066] Therefore, in the embodiment of the present disclosure, according to the malicious behavior of the malicious IP network, the sub-IP network can be: verification or virus or ransomware or red team or APT or Web attack.

[0067] In some optional implementations, the above step S102 divides the malicious IP network into multiple sub-IP networks according to the malicious behavior of the malicious IP network, including:

[0068] Step a1: When the malicious behavior of the malicious IP network exceeds a first preset threshold, the malicious IP network is divided into a red team IP network and an advanced persistent threat IP network according to the malicious behavior of the malicious IP network.

[0069] The first preset threshold can be set to 1. For example, when the number of red team attacks on a malicious IP network exceeds 1, the malicious IP network is determined to be a red team IP network. The same applies to the example of an advanced persistent threat IP network, which will not be repeated here. The first preset threshold can be flexibly adjusted as needed. When making specific adjustments, it is also possible to first perform a statistical analysis of the number of alarms for target sub-IP networks of the same category over a period of time, and then determine the threshold that requires attention based on the 80 / 20 rule. Assuming that the number of alarms from N security alarm devices covers 80% of the alarm volume, the lower limit of the number of alarms from these N security alarm devices is used as the threshold, and 80% is an empirical value.

[0070] Step a2: When the malicious behavior of the malicious IP network exceeds a second preset threshold, the malicious IP network is divided into verification IP network, virus IP network, web attack IP network, ransomware IP network and unknown IP network according to the malicious behavior of the malicious IP network.

[0071] The second preset threshold can be set to 5. For example, when the number of verification attacks of a malicious IP network exceeds 5, the malicious IP network is determined to be a verification IP network. The examples of virus IP networks, web attack IP networks, ransomware IP networks, and unknown IP networks are similar and will not be repeated here. The second preset threshold can be flexibly adjusted as needed. When making specific adjustments, it is also possible to first perform a statistical analysis on the number of alarms of target sub-IP networks of the same category over a period of time, and then determine the threshold that requires attention based on the 80 / 20 rule. Assuming that the number of alarms of N security alarm devices covers 80% of the alarm volume, the lower limit of the number of alarms of these N security alarm devices is used as the threshold, and 80% is an empirical value.

[0072] Step S102: defining the autonomous system IP network to which the target sub-IP network belongs according to the autonomous system identifier of each target sub-IP network among the multiple sub-IP networks.

[0073] An autonomous system (ASN) is a small unit on the Internet that has the authority to independently determine which routing protocol to use within the system. This network unit can be a simple network or a group of networks controlled by one or more common network administrators. It is a separately manageable network unit (such as a university, an enterprise, or an individual company). An autonomous system is sometimes also called a routing domain. An autonomous system is assigned a globally unique number called an autonomous system number (ASN).

[0074] Target sub-IP networks are categorized by ASNs into international IP networks, metropolitan IP networks, data center IP networks, private IP networks, tenant IP networks, and enterprise IP networks. Therefore, based on the target sub-network's ASN, you can define the autonomous system IP network to which the target sub-IP network belongs: an international IP network, a metropolitan IP network, a data center IP network, a private IP network, a tenant IP network, or an enterprise IP network.

[0075] Step S103: formulate target processing measures corresponding to the target sub-IP network according to the autonomous system IP network to which the target sub-IP network belongs.

[0076] Step S104: Process the target sub-IP network according to the target processing measure corresponding to the target sub-IP network.

[0077] For example, the autonomous system IP network to which the target sub-IP network belongs is a metropolitan area network IP network or the data center IP network, and the target processing measure corresponding to the target sub-IP network is an observation processing measure.

[0078] For example, the autonomous system IP network to which the target sub-IP network belongs is an enterprise IP network or the tenant IP network, and the target processing measure corresponding to the target sub-IP network is an internal processing measure.

[0079] For example, the autonomous system IP network to which the target sub-IP network belongs is a foreign IP network, and the target processing measure corresponding to the target sub-IP network is a blocking processing measure.

[0080] The disclosed embodiment divides the malicious IP network into multiple sub-IP networks and defines the autonomous system IP network to which the target sub-IP network belongs. Assuming that the autonomous system IP network to which the target sub-IP network belongs is different, the target processing measures corresponding to the target sub-IP network will also be different. Therefore, the disclosed embodiment combines the autonomous system IP network to which different target sub-IP networks belong, formulates the target processing measures corresponding to the target sub-IP network in a targeted manner, and processes the target sub-IP network accordingly, which is conducive to accurately processing malicious IP networks and avoiding accidentally damaging networks in a normal state and affecting users' normal operations.

[0081] In this embodiment, a method for processing a malicious network is provided, which can be used for computer devices such as mobile phones, tablet computers, desktop computers, portable notebooks, servers, etc. Figure 3 FIG. 1 is a flow chart of a method for processing a malicious network according to an embodiment of the present invention. Figure 3 As shown, the above step S103, based on the autonomous system IP network to which the target sub-IP network belongs, formulates target processing measures corresponding to the target sub-IP network, including:

[0082] Step S1031A: When the autonomous system IP network to which the target sub-IP network belongs is a red team IP network, an advanced persistent threat IP network, or a web attack IP network, it is determined whether the autonomous system IP network to which the target sub-IP network belongs is a foreign IP network.

[0083] The disclosed embodiments mainly execute corresponding target processing measures when the autonomous system IP network to which the target sub-IP network belongs is a red team IP network, an advanced persistent threat IP network, or a web attack IP network.

[0084] Step S1032A: When the autonomous system IP network to which the target sub-IP network belongs is a foreign IP network, a blocking measure corresponding to the target sub-IP network is formulated.

[0085] Step S1033A: When the autonomous system IP network to which the target sub-IP network belongs is not a foreign IP network, it is determined whether the autonomous system IP network to which the target sub-IP network belongs is a metropolitan area IP network or a data center IP network.

[0086] Step S1034A: When the autonomous system IP network to which the target sub-IP network belongs is a metropolitan area IP network or a data center IP network, an observation and processing measure corresponding to the target sub-IP network is formulated.

[0087] Step S1035A: When the autonomous system IP network to which the target sub-IP network belongs is not a metropolitan area IP network or a data center IP network, it is determined whether the autonomous system IP network to which the target sub-IP network belongs is a private IP network.

[0088] Step S1036A: When the autonomous system IP network to which the target sub-IP network belongs is a private IP network, a blocking measure corresponding to the target sub-IP network is formulated.

[0089] Step S1037A: When the autonomous system IP network to which the target sub-IP network belongs is not a private IP network, it is determined whether the autonomous system IP network to which the target sub-IP network belongs is an enterprise IP network or a tenant IP network.

[0090] Step S1038A: When the autonomous system IP network to which the target sub-IP network belongs is an enterprise IP network or a tenant IP network, internal processing measures corresponding to the target sub-IP network are formulated.

[0091] Step S1039A: When the autonomous system IP network to which the target sub-IP network belongs is not an enterprise IP network or a tenant IP network, a blocking processing measure corresponding to the target sub-IP network is formulated.

[0092] In the above-mentioned embodiment, target processing measures corresponding to the target sub-IP network are formulated according to the degree of influence of the autonomous system IP network to which different types of target sub-IP networks belong on service access. For example, since service access to foreign IP networks is not very extensive, when the autonomous system IP network to which the target sub-IP network belongs is a foreign IP network, the impact of the blocking processing measures corresponding to the target sub-IP network on service access is not very large. For example, since service access to a metropolitan area IP network or a data center IP network is very common, when the autonomous system IP network to which the target sub-IP network belongs is a metropolitan area IP network or a data center IP network, observation processing measures corresponding to the target sub-IP network are formulated to avoid the inability of most services to be normally accessed due to misjudgment. For example, since service access to an enterprise IP network or a tenant IP network is relatively extensive, when the autonomous system IP network to which the target sub-IP network belongs is an enterprise IP network or a tenant IP network, internal processing measures corresponding to the target sub-IP network are formulated to avoid affecting the normal access of most services.

[0093] Therefore, the embodiment of the present disclosure, through the above-mentioned method, formulates target processing measures corresponding to the target sub-IP networks for the autonomous system IP networks to which different types of target sub-IP networks belong, which is conducive to accurately handling different types of malicious networks and avoiding accidental damage to normal networks due to simultaneous batch blocking of IP networks.

[0094] In this embodiment, a method for processing a malicious network is provided, which can be used for computer devices such as mobile phones, tablet computers, desktop computers, portable notebooks, servers, etc. Figure 4 FIG. 1 is a flow chart of a method for processing a malicious network according to an embodiment of the present invention. Figure 4 As shown, the above step S103, based on the autonomous system IP network to which the target sub-IP network belongs, formulates target processing measures corresponding to the target sub-IP network, including:

[0095] Step S1031B: When the target sub-IP network is determined to be a verification IP network, a virus IP network, a ransomware IP network, or an unknown IP network, it is determined whether the autonomous system IP network to which the target sub-IP network belongs is a foreign IP network.

[0096] The embodiments of the present disclosure are mainly aimed at verifying IP networks, or virus IP networks, or ransomware IP networks, or unknown IP networks, and executing corresponding target processing measures.

[0097] Step S1032B: When the autonomous system IP network to which the target sub-IP network belongs is a foreign IP network, a blocking measure corresponding to the target sub-IP network is formulated.

[0098] Step S1033B: When the autonomous system IP network to which the target sub-IP network belongs is not a foreign IP network, determine whether the autonomous system IP network to which the target sub-IP network belongs is a metropolitan area IP network or a data center IP network;

[0099] Step S1034B: When the autonomous system IP network to which the target sub-IP network belongs is a metropolitan area IP network or a data center IP network, an observation and processing measure corresponding to the target sub-IP network is formulated.

[0100] Step S1035B: when the autonomous system IP network to which the target sub-IP network belongs is not a metropolitan area IP network or a data center IP network, it is determined whether the autonomous system IP network to which the target sub-IP network belongs is a private IP network.

[0101] Step S1036B: When the autonomous system IP network to which the target sub-IP network belongs is a private IP network, an observation and processing measure corresponding to the target sub-IP network is formulated.

[0102] Step S1037B: When the autonomous system IP network to which the target sub-IP network belongs is not a private IP network, it is determined whether the autonomous system IP network to which the target sub-IP network belongs is an enterprise IP network or a tenant IP network.

[0103] Step S1038B: When the autonomous system IP network to which the target sub-IP network belongs is an enterprise IP network or a tenant IP network, internal processing measures corresponding to the target sub-IP network are formulated.

[0104] Step S1039B: When the autonomous system IP network to which the target sub-IP network belongs is not an enterprise IP network or a tenant IP network, an observation and processing measure corresponding to the target sub-IP network is formulated.

[0105] In the above embodiment, target processing measures corresponding to the target sub-IP network are formulated according to the degree of influence of the autonomous system IP network to which different types of target sub-IP networks belong on service access. For example, since service access to foreign IP networks is not very widespread, when the autonomous system IP network to which the target sub-IP network belongs is a foreign IP network, the impact of the blocking processing measures corresponding to the target sub-IP network on service access is not very large. For example, since service access to metropolitan area IP networks or data center IP networks is very common, when the autonomous system IP network to which the target sub-IP network belongs is a metropolitan area IP network or a data center IP network, the observation processing measures corresponding to the target sub-IP network are formulated to avoid the inability of most services to be normally accessed due to misjudgment.

[0106] The disclosed embodiment, through the above-mentioned method, formulates target processing measures corresponding to target sub-IP networks for the autonomous system IP networks to which different types of target sub-IP networks belong, which is conducive to accurately handling different types of malicious networks and avoiding accidental damage to normal networks due to simultaneous batch blocking of IP networks.

[0107] In some optional implementations, when the target sub-IP network corresponds to an observation processing measure, the security protection device is queried according to a preset period, and when an alarm occurs in the target sub-IP network, a blocking processing measure is executed on the target sub-IP network.

[0108] The security protection device may be a border protection device. For example, the border protection device may be periodically queried for the target sub-IP network that needs to be observed, and may be blocked when an alarm occurs, thereby ensuring the security of the target sub-IP network under observation.

[0109] In some optional implementations, after step 104 of formulating target processing measures corresponding to the target sub-IP network, the following steps are further included:

[0110] Steps S101 to S104 are repeatedly executed according to a preset time to update the target processing measures corresponding to the target sub-IP network.

[0111] Repeating steps S101 to S104 multiple times at preset intervals is beneficial for adjusting the target processing measures corresponding to the target sub-IP network based on the malicious IP network and divided sub-IP network obtained according to the latest network threat intelligence, thereby ensuring the effectiveness and flexibility of the target processing measures corresponding to the target sub-IP network.

[0112] This embodiment also provides a malicious network processing device, which is used to implement the above-mentioned embodiments and preferred embodiments. Details already described will not be repeated here. As used below, the term "module" may refer to a combination of software and / or hardware that implements a predetermined function. Although the devices described in the following embodiments are preferably implemented in software, implementation using hardware, or a combination of software and hardware, is also possible and contemplated.

[0113] This embodiment provides a malicious network processing device, such as Figure 5 As shown, including:

[0114] An acquisition module 501 is used to acquire a malicious IP network and divide the malicious IP network into multiple sub-IP networks according to the malicious behavior of the malicious IP network;

[0115] A definition module 502, configured to define the autonomous system IP network to which the target sub-IP network belongs according to the autonomous system identifier of each target sub-IP network among the multiple sub-IP networks;

[0116] A formulation module 503 is used to formulate target processing measures corresponding to the target sub-IP network according to the autonomous system IP network to which the target sub-IP network belongs;

[0117] The processing module 504 processes the target sub-IP network according to the target processing measure corresponding to the target sub-IP network.

[0118] In some optional implementations, the definition module 502 includes:

[0119] A first determination submodule is configured to, when the malicious behavior of the malicious IP network exceeds a first preset threshold, classify the malicious IP network into a red team IP network and an advanced persistent threat IP network based on the malicious behavior of the malicious IP network;

[0120] The second determination submodule is used to divide the malicious IP network into verification IP network, virus IP network, web attack IP network, ransomware IP network and unknown IP network according to the malicious behavior of the malicious IP network when the malicious behavior of the malicious IP network exceeds a second preset threshold.

[0121] In some optional implementations, the autonomous system IP network includes: a metropolitan area IP network, a data center IP network, a private IP network, a foreign IP network, an enterprise IP network, or a tenant IP network; the target processing measure includes: a blocking processing measure, an internal processing measure, or an observation processing measure;

[0122] Formulate module 503, including:

[0123] The first judgment submodule is used to judge whether the autonomous system IP network to which the target sub-IP network belongs is a foreign IP network when the autonomous system IP network to which the target sub-IP network belongs is a red team IP network, an advanced persistent threat IP network, or a web attack IP network;

[0124] The first formulation submodule is used to formulate a blocking measure corresponding to the target sub-IP network when the autonomous system IP network to which the target sub-IP network belongs is a foreign IP network;

[0125] The second judgment submodule is used to judge whether the autonomous system IP network to which the target sub-IP network belongs is a metropolitan area IP network or a data center IP network when the autonomous system IP network to which the target sub-IP network belongs is not a foreign IP network;

[0126] The second formulation submodule is used to formulate observation and processing measures corresponding to the target sub-IP network when the autonomous system IP network to which the target sub-IP network belongs is a metropolitan area IP network or a data center IP network;

[0127] The third judgment submodule is used to judge whether the autonomous system IP network to which the target sub-IP network belongs is a private IP network when the autonomous system IP network to which the target sub-IP network belongs is not a metropolitan area IP network or a data center IP network;

[0128] The third formulation submodule is used to formulate a blocking treatment measure corresponding to the target sub-IP network when the autonomous system IP network to which the target sub-IP network belongs is a private IP network;

[0129] a fourth judgment submodule, configured to judge whether the autonomous system IP network to which the target sub-IP network belongs is an enterprise IP network or a tenant IP network when the autonomous system IP network to which the target sub-IP network belongs is not a private IP network;

[0130] The fourth formulation submodule is used to formulate internal processing measures corresponding to the target sub-IP network when the autonomous system IP network to which the target sub-IP network belongs is an enterprise IP network or a tenant IP network;

[0131] The fifth formulation submodule is used to formulate a blocking processing measure corresponding to the target sub-IP network when the autonomous system IP network to which the target sub-IP network belongs is not an enterprise IP network or a tenant IP network.

[0132] In some optional implementations, the formulation module 503 includes:

[0133] A fifth judgment submodule is configured to determine whether the autonomous system IP network to which the target sub-IP network belongs is a foreign IP network when the target sub-IP network is determined to be a verification IP network, a virus IP network, a ransomware IP network, or an unknown IP network;

[0134] The sixth formulation submodule is used to formulate a blocking measure corresponding to the target sub-IP network when the autonomous system IP network to which the target sub-IP network belongs is a foreign IP network;

[0135] a sixth judgment submodule, configured to, when the autonomous system IP network to which the target sub-IP network belongs is not a foreign IP network, determine whether the autonomous system IP network to which the target sub-IP network belongs is a metropolitan area IP network or a data center IP network;

[0136] The seventh formulation submodule is used to formulate observation and processing measures corresponding to the target sub-IP network when the autonomous system IP network to which the target sub-IP network belongs is a metropolitan area IP network or a data center IP network;

[0137] a seventh judgment submodule, configured to determine whether the autonomous system IP network to which the target sub-IP network belongs is a private IP network when the autonomous system IP network to which the target sub-IP network belongs is not a metropolitan area IP network or a data center IP network;

[0138] an eighth formulation submodule, for formulating observation and processing measures corresponding to the target sub-IP network when the autonomous system IP network to which the target sub-IP network belongs is a private IP network;

[0139] an eighth judgment submodule, configured to, when the autonomous system IP network to which the target sub-IP network belongs is not a private IP network, determine whether the autonomous system IP network to which the target sub-IP network belongs is an enterprise IP network or a tenant IP network;

[0140] A ninth formulation submodule, configured to formulate internal processing measures corresponding to the target sub-IP network when the autonomous system IP network to which the target sub-IP network belongs is an enterprise IP network or a tenant IP network;

[0141] The tenth formulation submodule is used to formulate observation and processing measures corresponding to the target sub-IP network when the autonomous system IP network to which the target sub-IP network belongs is not an enterprise IP network or a tenant IP network.

[0142] In some optional embodiments, the malicious network processing device in the embodiment of the present disclosure also includes: a query module, which is used to query the security protection device according to a preset period when the target sub-IP network corresponds to the observation processing measures, and when the target sub-IP network has an alarm, execute a blocking processing measure on the target sub-IP network.

[0143] In some optional implementations, the malicious network processing apparatus in the embodiment of the present disclosure, after the processing module 504, further includes:

[0144] The updating module is used to repeatedly execute the functions of the acquiring module 501 to the processing module 504 according to a preset time, and update the target processing measures corresponding to the target sub-IP network.

[0145] The further functional description of each of the above modules and units is the same as that of the above corresponding embodiments and will not be repeated here.

[0146] The malicious network processing device in this embodiment is presented in the form of a functional unit, where the unit refers to an ASIC (Application Specific Integrated Circuit) circuit, a processor and memory that executes one or more software or fixed programs, and / or other devices that can provide the above functions.

[0147] An embodiment of the present invention further provides a computer device having the above-mentioned malicious network processing device.

[0148] See also Figure 6 , Figure 6 is a structural diagram of a computer device provided by an optional embodiment of the present invention, such as Figure 6 As shown, the computer device includes: one or more processors 10, memory 20, and interfaces for connecting various components, including high-speed interfaces and low-speed interfaces. Various components utilize different buses to communicate with each other and can be installed on a common mainboard or installed in other ways as needed. The processor can process the instructions executed in the computer device, including instructions stored in the memory or on the memory to display the graphical information of the GUI on an external input / output device (such as, a display device coupled to the interface). In some optional embodiments, if necessary, multiple processors and / or multiple buses can be used together with multiple memories and multiple memories. Equally, multiple computer devices can be connected, and each device provides part of the necessary operations (for example, as a server array, a group of blade servers, or a multi-processor system). Figure 6 A processor 10 is taken as an example.

[0149] The processor 10 may be a central processing unit, a network processor, or a combination thereof. The processor 10 may further include a hardware chip. The hardware chip may be an application-specific integrated circuit, a programmable logic device, or a combination thereof. The programmable logic device may be a complex programmable logic device, a field programmable gate array, a general purpose array logic, or any combination thereof.

[0150] The memory 20 stores instructions that can be executed by at least one processor 10, so that the at least one processor 10 executes the method shown in the above embodiment.

[0151] The memory 20 may include a program storage area and a data storage area, wherein the program storage area may store an operating system and application programs required for at least one function; the data storage area may store data created based on the use of the computer device, etc. In addition, the memory 20 may include a high-speed random access memory, and may also include a non-transient memory, such as at least one disk storage device, a flash memory device, or other non-transient solid-state storage device. In some optional embodiments, the memory 20 may optionally include a memory remotely located relative to the processor 10, and these remote memories may be connected to the computer device via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0152] The memory 20 may include a volatile memory, such as a random access memory; the memory may also include a non-volatile memory, such as a flash memory, a hard disk or a solid-state drive; the memory 20 may also include a combination of the above types of memory.

[0153] The computer device further includes a communication interface 30 for the computer device to communicate with other devices or a communication network.

[0154] The embodiment of the present invention also provides a computer-readable storage medium. The above-mentioned method according to the embodiment of the present invention can be implemented in hardware, firmware, or implemented as a computer code that can be recorded in a storage medium, or implemented as a computer code that is originally stored in a remote storage medium or a non-temporary machine-readable storage medium and downloaded through a network and will be stored in a local storage medium, so that the method described herein can be stored in such software processing on a storage medium using a general-purpose computer, a dedicated processor, or programmable or dedicated hardware. Among them, the storage medium can be a magnetic disk, an optical disk, a read-only storage memory, a random access memory, a flash memory, a hard disk or a solid-state drive, etc.; further, the storage medium can also include a combination of the above-mentioned types of memory. It can be understood that a computer, a processor, a microprocessor controller or programmable hardware includes a storage component that can store or receive software or computer code. When the software or computer code is accessed and executed by a computer, a processor or hardware, the method shown in the above embodiment is implemented.

[0155] A portion of the present invention may be applied as a computer program product, such as a computer program instruction, which, when executed by a computer, can call or provide the method and / or technical solution according to the present invention through the operation of the computer. Those skilled in the art should understand that the form in which the computer program instruction exists in a computer-readable medium includes, but is not limited to, a source file, an executable file, an installation package file, etc. Accordingly, the way in which the computer program instruction is executed by the computer includes, but is not limited to: the computer directly executes the instruction, or the computer compiles the instruction and then executes the corresponding compiled program, or the computer reads and executes the instruction, or the computer reads and installs the instruction and then executes the corresponding installed program. Here, the computer-readable medium may be any available computer-readable storage medium or communication medium that can be accessed by the computer.

[0156] Although the embodiments of the present invention have been described with reference to the accompanying drawings, those skilled in the art may make various modifications and variations without departing from the spirit and scope of the present invention. Such modifications and variations are all within the scope defined by the appended claims.

Claims

1. A method for processing a malicious network, characterized in that: The method comprises: Step S101, obtaining a malicious IP network, and dividing the malicious IP network into multiple sub-IP networks according to the malicious behavior of the malicious IP network; Step S102, defining the autonomous system IP network to which the target sub-IP network belongs according to the autonomous system identifier of each target sub-IP network in the multiple sub-IP networks; Step S103, formulating target processing measures corresponding to the target sub-IP network according to the autonomous system IP network to which the target sub-IP network belongs; Step S104: Process the target sub-IP network according to the target processing measure corresponding to the target sub-IP network.

2. The method for processing a malicious network according to claim 1, wherein: The method further comprises dividing the malicious IP network into multiple sub-IP networks according to the malicious behavior of the malicious IP network, including: When the malicious behavior of the malicious IP network exceeds a first preset threshold, classifying the malicious IP network into a red team IP network and an advanced persistent threat IP network according to the malicious behavior of the malicious IP network; When the malicious behavior of the malicious IP network exceeds a second preset threshold, the malicious IP network is divided into verification IP network, virus IP network, web attack IP network, ransomware IP network and unknown IP network according to the malicious behavior of the malicious IP network.

3. The method for processing malicious networks according to claim 2, characterized in that: The autonomous system IP network includes: a metropolitan area IP network, a data center IP network, a private IP network, a foreign IP network, an enterprise IP network, or a tenant IP network; the target processing measures include: a blocking processing measure, an internal processing measure, or an observation processing measure; Formulate target processing measures corresponding to the target sub-IP network based on the autonomous system IP network to which the target sub-IP network belongs, including: When the autonomous system IP network to which the target sub-IP network belongs is the red team IP network, the advanced persistent threat IP network, or the web attack IP network, determining whether the autonomous system IP network to which the target sub-IP network belongs is the foreign IP network; When the autonomous system IP network to which the target sub-IP network belongs is the foreign IP network, formulating the blocking measures corresponding to the target sub-IP network; When the autonomous system IP network to which the target sub-IP network belongs is not the foreign IP network, determining whether the autonomous system IP network to which the target sub-IP network belongs is the metropolitan area IP network or the data center IP network; When the autonomous system IP network to which the target sub-IP network belongs is the metropolitan area IP network or the data center IP network, formulating the observation and processing measures corresponding to the target sub-IP network; When the autonomous system IP network to which the target sub-IP network belongs is not the metropolitan area IP network or the data center IP network, determining whether the autonomous system IP network to which the target sub-IP network belongs is the private IP network; When the autonomous system IP network to which the target sub-IP network belongs is the private IP network, formulating the blocking measures corresponding to the target sub-IP network; When the autonomous system IP network to which the target sub-IP network belongs is not the private IP network, determining whether the autonomous system IP network to which the target sub-IP network belongs is an enterprise IP network or the tenant IP network; When the autonomous system IP network to which the target sub-IP network belongs is the enterprise IP network or the tenant IP network, formulating internal processing measures corresponding to the target sub-IP network; When the autonomous system IP network to which the target sub-IP network belongs is not the enterprise IP network or the tenant IP network, a blocking processing measure corresponding to the target sub-IP network is formulated.

4. The method for processing a malicious network according to claim 3, wherein: Formulate target processing measures corresponding to the target sub-IP network based on the autonomous system IP network to which the target sub-IP network belongs, including: When the target sub-IP network is determined to be the verification IP network, the virus IP network, the ransomware IP network, or the unknown IP network, determining whether the autonomous system IP network to which the target sub-IP network belongs is the foreign IP network; When the autonomous system IP network to which the target sub-IP network belongs is the foreign IP network, formulating the blocking measures corresponding to the target sub-IP network; When the autonomous system IP network to which the target sub-IP network belongs is not the foreign IP network, determining whether the autonomous system IP network to which the target sub-IP network belongs is the metropolitan area IP network or the data center IP network; When the autonomous system IP network to which the target sub-IP network belongs is the metropolitan area IP network or the data center IP network, formulating the observation and processing measures corresponding to the target sub-IP network; When the autonomous system IP network to which the target sub-IP network belongs is not the metropolitan area IP network or the data center IP network, determining whether the autonomous system IP network to which the target sub-IP network belongs is the private IP network; When the autonomous system IP network to which the target sub-IP network belongs is the private IP network, formulating the observation and processing measures corresponding to the target sub-IP network; When the autonomous system IP network to which the target sub-IP network belongs is not the private IP network, determining whether the autonomous system IP network to which the target sub-IP network belongs is an enterprise IP network or the tenant IP network; When the autonomous system IP network to which the target sub-IP network belongs is the enterprise IP network or the tenant IP network, formulating internal processing measures corresponding to the target sub-IP network; When the autonomous system IP network to which the target sub-IP network belongs is not the enterprise IP network or the tenant IP network, an observation and processing measure corresponding to the target sub-IP network is formulated.

5. The method for processing a malicious network according to claim 3 or 4, characterized in that: When the target sub-IP network corresponds to the observation processing measures, the security protection device is queried according to the preset period, and when the target sub-IP network has an alarm, the target sub-IP network is blocked.

6. The method for processing malicious networks according to claim 1, characterized in that: After the step of formulating target processing measures corresponding to the target sub-IP network, the method further includes: Repeat steps S101 to S104 according to a preset time to update the target processing measures corresponding to the target sub-IP network.

7. A malicious network processing device, characterized in that: The device comprises: An acquisition module is used to acquire a malicious IP network and divide the malicious IP network into multiple sub-IP networks according to the malicious behavior of the malicious IP network; A definition module, configured to define the autonomous system IP network to which the target sub-IP network belongs according to the autonomous system identifier of each target sub-IP network among the multiple sub-IP networks; A formulation module, configured to formulate target processing measures corresponding to the target sub-IP network according to the autonomous system IP network to which the target sub-IP network belongs; The processing module processes the target sub-IP network according to the target processing measure corresponding to the target sub-IP network.

8. A computer device, characterized in that: include: A memory and a processor, wherein the memory and the processor are communicatively connected to each other, the memory stores computer instructions, and the processor executes the malicious network processing method according to any one of claims 1 to 6 by executing the computer instructions.

9. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a computer to execute the method for processing a malicious network according to any one of claims 1 to 6.

10. A computer program product, characterized in that The method comprises computer instructions, wherein the computer instructions are used to cause a computer to execute the malicious network processing method according to any one of claims 1 to 6.