Method for improving login security of management page of broadband router
By building a protection model based on IP address distribution, login time and geographical location, dynamically identifying the user's identity and giving corresponding permissions, the IP spoofing and permission management problems of traditional router page security protection is solved, and the security of router management pages is improved.
Patent Information
- Application Number
- CN202510858586.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-25
- Publication Date
- 2025-08-15
AI Technical Summary
Traditional router page security protection is vulnerable to IP spoofing and proxy bypass attacks. A single rule is difficult to deal with complex threats. The static response method cannot dynamically adjust the strategy, and it is impossible to accurately distinguish user identities, resulting in intricate permission management.
The router log file is read through the data acquisition module, a security protection module and an identity prediction module are built, and the IP address distribution, login time, geographical location and time decay factors are used to generate a protection model, dynamically identify the user's identity and give corresponding permissions.
It realizes accurate judgment of user identity, reduces the rate of misjudgment, enhances the ability to identify complex attacks, provides flexible security protection, and adapts to attacks in different scenarios.
Smart Images

Figure CN120498869A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of management page login security of routers, and in particular to a method and a control method for improving the management page login security of broadband routers. Background Art
[0002] Logging in to a broadband router's management page refers to accessing the router's management interface through a browser for configuration and management settings. This usually requires entering the router's IP address, administrator username, and password.
[0003] Traditional router page security management methods rely primarily on simple static rules such as username / password authentication, IP address restrictions, and login limit limits. However, this approach has numerous problems. First, it is vulnerable to IP spoofing and proxy bypass attacks. Attackers can forge IP addresses through VPNs or proxies to bypass protection measures. Second, a single rule is difficult to deal with complex threats, such as brute force cracking and password guessing attacks. Furthermore, static response methods cannot dynamically adjust policies, which may lead to misjudgments or missed judgments. Finally, traditional methods cannot accurately distinguish user identities, making it difficult to implement detailed permission management. Summary of the Invention
[0004] To this end, the present invention provides a method and control method for improving the login security of the management page of a broadband router, which solves the problems that traditional router page security protection is susceptible to IP spoofing and proxy bypass attacks, single rules are difficult to deal with complex threats, static response methods cannot dynamically adjust policies, and cannot accurately distinguish user identities, making it difficult to implement detailed permission management.
[0005] To achieve the above objectives, the present invention provides a method for improving the login security of a management page of a broadband router, comprising:
[0006] Step S1: Login information data collection: Through the data collection module, read the router device log file to obtain the current and historical login information and extract key features;
[0007] Step S2: constructing a security protection module through the data acquisition module, and constructing a comparison model based on the key features read through the security protection module;
[0008] Step S3: Using key features, use the identity prediction and recognition module to determine different identity information contents and accurately determine the identity information of the registrant;
[0009] Step S4: granting different permissions through the permission granting module.
[0010] Furthermore, the data collection module is used to obtain multi-dimensional data when the user enters the management page of the broadband router by reading the local log of the router;
[0011] The security protection module forms a comparison model through the data acquisition module, and provides the model for comparison to the identity recognition module:
[0012] The identity recognition module extracts the login information features through the data collection module and identifies and predicts the login user's identity information;
[0013] The permission granting module is used to grant different usage permissions for different identity information.
[0014] Furthermore, the method for constructing the security protection module of the data acquisition module in step S2 is:
[0015] Extract historical login features and geographical distribution of historical logins through local router logs;
[0016] 2.1. The formula for extracting historical login features is:
[0017] Measure the diversity of IP addresses in historical logins using Shannon entropy or the ratio of login times: where P i is the frequency of an IP address appearing in historical logins, where I h It is the IP address distribution characteristic;
[0018] 2.2. The formula for extracting the geographical location distribution of historical logins is:
[0019] The common locations of logins are determined by the geographical location deviation in historical logins, where G h is the historical login geographical location feature, where (L cu ,L la ) is the distance between the current and historical login locations, where d max is the maximum variable deviation of the geographical location;
[0020] Through the above features, a protection model M is generated h , obtain the protection model M h The formula is: M h =[I h, G h ];
[0021] The protection model M h A baseline reference will be provided for each new login to judge whether the current login behavior is normal.
[0022] Furthermore, the identification module determination method in step S3 is:
[0023] Extract the key information from this login to construct the feature vector X ι include:
[0024] IP Address c : The current logged-in IP address;
[0025] Login time T: timestamp of current login;
[0026] Login success and failure flag S: whether the login is successful (success flag is 1, failure flag is 0);
[0027] Log in to your location c : The current logged-in geographical location deviation, compared with the historical location;
[0028] Time decay factor D: This factor is calculated based on the difference between the current login time and the last login time. It reflects the impact of time on this login and controls the impact of the time difference on the protection model. The formula for calculating the time decay factor D is: Where, β is the attenuation factor, T cu is the login time, T la The last login time;
[0029] The time difference ΔT from the last successful login la : reflects the time difference between the current login behavior and the historical login behavior, which is used to analyze the frequency and regularity of logins; ΔT la =|T cu -T la |;
[0030] By comparing the above data with the protection model, identity prediction is performed;
[0031] Furthermore, the protection model M h The comparison method is: compare the current login characteristics with the historical protection model M h , mainly involving the differences between IP addresses and login geographical locations; by deriving the IP address similarity I S and geographic location similarity G S to draw the difference;
[0032] IP address similarity I S :The similarity is calculated by the distribution of the current login IP address and the historical login IP address, and the cosine similarity is used to measure the similarity of the IP addresses: IP address similarity I S The formula for finding is:
[0033] Geographic location similarity: The similarity is compared by comparing the deviation between the current login location and the historical login location. Euclidean distance or great circle distance can be used: Geographic location similarity G S The formula for finding is: Where (loc cu ,loc hi ) are the current geographical registration location and the last geographical registration location;
[0034] Furthermore, identity prediction can be performed by weighted scoring based on the above features and similarity. The identity prediction formula is as follows:
[0035] Score=ω1·I s +ω2·G s+ ω3·S+ω4·ΔT la+ ω5·D; where:
[0036] Score is a weighted score value used to distinguish different identity information;
[0037] ω1, ω2, ω3, ω4, and ω5 are the weights of each feature, which are adjusted according to the actual situation;
[0038] S is the login success or failure mark, reflecting whether the user's login behavior is legal;
[0039] ΔT la and D reflects the frequency and timeliness of logins;
[0040] The identity information mentioned in S4 includes the following categories:
[0041] Illegal users: A weighted score of less than 50 indicates that the login behavior is high-risk or malicious;
[0042] Potential risk users: A weighted score between 50-70 indicates that the user's login behavior may pose a potential risk.
[0043] Ordinary users: A weighted score between 70 and 90 indicates that the user's login behavior is normal;
[0044] Advanced user: A weighted score between 90 and 100 indicates that the user has administrator privileges and their login behavior conforms to normal patterns.
[0045] Furthermore, the automatic switching module in step S4 grants different permissions to different identity information in the following manner:
[0046] To the illegal users:
[0047] Processing method: directly block the login of illegal users;
[0048] Block login: Based on the judgment of the identity recognition module, if the user is identified as an illegal user, the system will immediately block the user's login attempt; IP blocking: Record the user's IP address. If the user attempts to log in multiple times and is marked as an illegal user, the IP address can be blocked to prevent further attacks; Error prompt: Return a clear error message to the illegal user;
[0049] For the potential risk users:
[0050] Processing method: According to the judgment of the identity recognition module, if the user is identified as a potential risk user, secondary verification is enabled for the potential risk user;
[0051] For ordinary users:
[0052] Processing method: Based on the judgment of the identity recognition module, if the user is identified as a common user, the system grants the user access to basic functions and provides a button for upgrading permissions, providing a secondary verification channel;
[0053] For the advanced users:
[0054] Processing method: Based on the judgment of the identity recognition module, if the user is identified as a high-level user, the user is granted access to all functions;
[0055] The secondary verification method is as follows: when the system detects a potential risk user, a secondary verification step is triggered; this is performed by sending a verification code, SMS, email, or requiring the user to enter a dynamic password. During the secondary verification process, all operations are limited to the most basic functions, only viewing account information or changing passwords. After the secondary verification, an additional judgment feature C is added to the identity prediction formula. C is the security verification pass mark, and S3 is re-judged again;
[0056] Furthermore, after adding the additional judgment feature C to the identity prediction formula, the identity prediction formula changes to: Score = ω1·I s +ω2·G s+ ω3·S+ω4·ΔT la +ω5·D+ω6·C; wherein ω6 is the weight of C, and is given 50% of the total weight of ω6.
[0057] Compared with the prior art, the present invention has the following beneficial effects:
[0058] Compared to traditional router security protection methods, this method combines features such as IP address distribution, login time, geographic location, and login success and failure markers to assess the normality of login behavior in real time and dynamically identify potential risks. By comparing the time decay factor with historical data, the system can effectively distinguish between illegal users, potential risk users, ordinary users, and high-privilege users, reducing the false positive rate. This method enhances attack identification capabilities, enables timely response to complex attacks, and flexibly adapts to different scenarios, providing more comprehensive and accurate security protection. BRIEF DESCRIPTION OF THE DRAWINGS
[0059] Figure 1 It is a schematic diagram of the process of the present invention;
[0060] Figure 2 Schematic diagram of the operation of the identity prediction module of the present invention. DETAILED DESCRIPTION
[0061] In order to enable those skilled in the art to better understand the solutions of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the embodiments described are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of the present invention.
[0062] It should be noted that the terms "first", "second", etc. in the description and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that the numbers used in this way can be interchanged where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0063] The present invention is described in further detail below with reference to the accompanying drawings:
[0064] Step S1: Login information data collection: Through the data collection module, read the router device log file to obtain the current and historical login information and extract key features;
[0065] Step S2: constructing a security protection module through the data acquisition module, and constructing a comparison model based on the key features read through the security protection module;
[0066] Step S3: Using key features, use the identity prediction and recognition module to determine different identity information contents and accurately determine the identity information of the registrant;
[0067] Step S4: granting different permissions through the permission granting module;
[0068] Furthermore, the data collection module is used to obtain multi-dimensional data when the user enters the management page of the broadband router by reading the local log of the router;
[0069] The security protection module forms a comparison model through the data acquisition module and provides a model for comparison for the identity recognition module:
[0070] The identity recognition module extracts the login information features through the data collection module and identifies and predicts the login user's identity information;
[0071] The permission granting module is used to grant different usage permissions for different identity information;
[0072] Furthermore, the method for constructing the security protection module of the data acquisition module in step S2 is:
[0073] Extract historical login features and historical login geographic location distribution;
[0074] 2.1. The formula for extracting historical login features is:
[0075] Measure the diversity of IP addresses in historical logins using Shannon entropy or the ratio of login times: where P i is the frequency of an IP address appearing in historical logins, where I h It is the IP address distribution characteristic;
[0076] 2.2. The formula for extracting the geographical distribution of historical logins is:
[0077] The common locations of logins are determined by the geographical location deviation in historical logins, where G h is the historical login geographical location feature, where (L cu ,L la ) is the distance between the current and historical login locations, where d max is the maximum variable deviation of the geographical location;
[0078] Protection model: Generate a protection model M based on the above features h , obtain the protection model M h The formula is: M h= [I h ,G h ];
[0079] Protection Model M h A benchmark reference will be provided for each new login to determine whether the current login behavior is normal;
[0080] Furthermore, the identification module determination method in step S3 is:
[0081] Extract the key information from this login to construct the feature vector X ι include:
[0082] IP Address c : The current logged-in IP address;
[0083] Login time T: timestamp of current login;
[0084] Login success and failure flag S: whether the login is successful (success flag is 1, failure flag is 0);
[0085] Log in to your location c : The current logged-in geographical location deviation, compared with the historical location;
[0086] Time decay factor D: This factor is calculated based on the difference between the current login time and the last login time. It reflects the impact of time on this login and controls the impact of the time difference on the protection model. The formula for calculating the time decay factor D is: Where, β is the attenuation factor, T cu is the login time, T la The last login time;
[0087] The time difference ΔT from the last successful login la : reflects the time difference between the current login behavior and the historical login behavior, which is used to analyze the frequency and regularity of logins; ΔT la =|T cu -T la |;
[0088] The above data is compared with the protection model and then the identity is predicted.
[0089] Furthermore, with the protection model M h The comparison method is: compare the current login characteristics with the historical protection model M h , mainly involving the differences between IP addresses and login geographical locations; by deriving the IP address similarity I S and geographic location similarity G S to draw the difference;
[0090] IP address similarity I S:The similarity is calculated by the distribution of the current login IP address and the historical login IP address, and the cosine similarity is used to measure the similarity of the IP addresses: IP address similarity I S The formula for finding is:
[0091] Geographic location similarity: The similarity is compared by comparing the deviation between the current login location and the historical login location. Euclidean distance or great circle distance can be used: Geographic location similarity G S The formula for finding is: Where (loc cu ,loc hi ) is the current geographical login location and the last geographical login location.
[0092] Furthermore, identity prediction can be performed by weighted scoring based on the above features and similarity. The identity prediction formula is as follows:
[0093] Score=ω1·I s +ω2·G s+ ω3·S+ω4·ΔT la +ω5·D; where:
[0094] Score is a weighted score value used to distinguish different identity information;
[0095] ω1, ω2, ω3, ω4, and ω5 are the weights of each feature, which are adjusted according to the actual situation;
[0096] S is the login success or failure mark, reflecting whether the user's login behavior is legal;
[0097] ΔT la and D reflects the frequency and timeliness of logins;
[0098] The identity information mentioned in S4 includes the following categories:
[0099] Illegal users: A weighted score of less than 50 indicates that the login behavior is high-risk or malicious;
[0100] Potential risk users: A weighted score between 50-70 indicates that the user's login behavior may pose a potential risk.
[0101] Ordinary users: A weighted score between 70 and 90 indicates that the user's login behavior is normal;
[0102] Advanced user: A weighted score between 90 and 100 indicates that the user has administrator privileges and their login behavior conforms to normal patterns.
[0103] Furthermore, after adding the additional judgment feature C to the identity prediction formula, the identity prediction formula changes to: Score = ω1·I s +ω2·G s+ ω3·S+ω4·ΔT la +ω5·D+ω6·C; where ω6 is the weight of C, and is given 50% of the total weight of ω6.
[0104] The process of using this method is as follows: the user logs in to the router management page, the router management page uploads local log information, and the historical login characteristics and historical login geographical distribution are extracted through the data collection module. Based on these two characteristics, a protection model is constructed to provide a comparative reference for this login. After the customer logs in, the IP address in the customer login information is extracted. c , login time T, login success and failure mark S and login geographic location G c The time attenuation factor D is used to control the influence of the time difference on the protection model. The identity prediction formula in the identity prediction module is used to calculate the various information in this login to obtain a weighted score value. If the user's weighted score value is lower than 50, the user is judged as an illegal user and the illegal user is directly blocked from logging in; if the user's weighted score value is between 50-70, it means that the user's login behavior may have potential risks. If the user is identified as a potential risk user, secondary verification is enabled for the potential risk user; if the user's weighted score value is between 70-90, it means that the user's login behavior is normal, and the user is given permission to access basic functions, and a permission upgrade button is provided to provide a secondary verification channel; if the user's weighted score value is between 90-100, it means that the user has administrator privileges and the login behavior conforms to the normal mode, and the user is given permission to access all functions;
[0105] A privilege escalation button is provided for ordinary users, and a secondary verification channel is provided. The secondary verification method is as follows: when the system detects a potential risk user, a secondary verification step is triggered; it is carried out by sending a verification code, SMS, email, or requiring the user to enter a dynamic password. During the secondary verification process, all operations will be limited to the most basic functions, such as viewing account information or changing passwords. After the secondary verification, an additional judgment feature C is added to the identity prediction formula. C is the security verification pass mark, and the identity is judged again through the identity prediction formula;
[0106] The present invention:
[0107] By detecting login geolocation deviations, we can detect whether login requests originate from locations significantly different from historical login locations. Even if an attacker uses a VPN or proxy to spoof an IP address, it is often difficult to completely forge a geolocation. When the login geolocation deviates significantly from the user's historical locations, it can be considered abnormal behavior.
[0108] Through the security protection module, a distributed I h The comparison model analyzes the IP address distribution in user login behavior; if the IP address of the current login is inconsistent with the common IP address range in historical login records, this will be regarded as a potential risk signal, indicating that the login behavior may be forged:
[0109] The time decay factor D is combined with historical login time data for analysis. If the same IP address frequently attempts to log in within a short period of time, and the login location varies widely, this will trigger an alarm. Using VPN and proxy services often changes the pattern of login times and causes time anomalies.
[0110] The identity prediction module integrates features such as IP address, login time, geographic location, and login success and failure marks. It compares the model with actual login behavior to determine whether there is a possibility of IP spoofing or proxy bypass. For example, login requests from multiple IP addresses with significantly different geographic locations, or IP addresses that do not match historical data, will be marked as abnormal by the system.
[0111] In summary, through comprehensive analysis of multi-dimensional features such as geolocation, IP address distribution, and time decay, we can effectively identify and prevent IP spoofing and proxy bypass attacks, thereby improving the security of router login pages. This method can effectively distinguish between unauthorized users, potential risk users, ordinary users, and high-privilege users, reducing the rate of false positives. This method enhances attack identification capabilities, enables timely response to complex attacks, and flexibly adapts to different scenarios, providing more comprehensive and precise security protection.
[0112] Thus far, the technical solutions of the present invention have been described in conjunction with the preferred embodiments shown in the accompanying drawings. However, it will be readily understood by those skilled in the art that the scope of protection of the present invention is obviously not limited to these specific embodiments. Without departing from the principles of the present invention, those skilled in the art may make equivalent changes or substitutions to the relevant technical features, and the technical solutions after such changes or substitutions will fall within the scope of protection of the present invention.
Claims
1. A method for improving the login security of a broadband router management page, characterized by: include: Step S1: Login information data collection: Through the data collection module, read the router device log file to obtain the current and historical login information and extract key features; Step S2: constructing a security protection module through the data acquisition module, and constructing a comparison model based on the key features read through the security protection module; Step S3: Using key features, use the identity prediction and recognition module to determine different identity information contents and accurately determine the identity information of the registrant; Step S4: granting different permissions through the permission granting module.
2. A method for improving the login security of a management page of a broadband router according to claim 1, characterized in that: The data acquisition module is used to obtain multi-dimensional data when the user enters the management page of the broadband router by reading the local log of the router; The security protection module forms a comparison model through the data acquisition module, and provides the model for comparison to the identity recognition module: The identity recognition module extracts the login information features through the data collection module and identifies and predicts the login user's identity information; The permission granting module is used to grant different usage permissions for different identity information.
3. A method for improving the login security of a management page of a broadband router according to claim 1, characterized in that: The method for constructing the security protection module of the data acquisition module in step S2 is: Extract historical login features and geographical distribution of historical logins through local router logs; 2.
1. The formula for extracting historical login features is: Measure the diversity of IP addresses in historical logins using Shannon entropy or the ratio of login times: where P i is the frequency of an IP address appearing in historical logins, where I h It is the IP address distribution characteristic; 2.
2. The formula for extracting the geographical location distribution of historical logins is: The common locations of logins are determined by the geographical location deviation in historical logins, where G h is the historical login geographical location feature, where (L cu ,L la ) is the distance between the current and historical login locations, where d max is the maximum variable deviation of the geographical location; Through the above features, a protection model M is generated h , obtain the protection model M h The formula is: M h =[I h ,G h ]; The protection model M h A baseline reference will be provided for each new login to judge whether the current login behavior is normal.
4. A method for improving the login security of a management page of a broadband router according to claim 2, characterized in that: The identification module determination method in step S3 is: Extract the key information from this login to construct the feature vector X ι include: IP Address c : The current logged-in IP address; Login time T: timestamp of current login; Login success and failure flag S: whether the login is successful (success flag is 1, failure flag is 0); Log in to your location c : The current logged-in geographical location deviation, compared with the historical location; Time decay factor D: This factor is calculated based on the difference between the current login time and the last login time. It reflects the impact of time on this login and controls the impact of the time difference on the protection model. The formula for calculating the time decay factor D is: Where, β is the attenuation factor, T cu is the login time, T la The last login time; The time difference ΔT from the last successful login la : reflects the time difference between the current login behavior and the historical login behavior, which is used to analyze the frequency and regularity of logins; ΔT la =|T cu -T la |; The above data is compared with the protection model and then identity prediction is performed.
5. A method for improving the login security of a management page of a broadband router according to claim 4, characterized in that: The protective model M h The comparison method is: compare the current login characteristics with the historical protection model M h , mainly involving the differences between IP addresses and login geographical locations; by deriving the IP address similarity I S and geographic location similarity G S to draw the difference; IP address similarity I S :The similarity is calculated by the distribution of the current login IP address and the historical login IP address, and the cosine similarity is used to measure the similarity of the IP addresses: IP address similarity I S The formula for finding is: Geographic location similarity: The similarity is compared by comparing the deviation between the current login location and the historical login location. Euclidean distance or great circle distance can be used: Geographic location similarity G S The formula for finding is: Where (loc cu ,loc hi ) is the current geographical login location and the last geographical login location.
6. A method for improving the login security of a management page of a broadband router according to claim 4, characterized in that: The identity prediction method is to use weighted scoring based on the above features and similarity. The identity prediction formula is as follows: Score = ω1·I s + ω2·G s+ ω3·S + ω4·ΔT la+ ω5·D; Where: Score is a weighted score value used to distinguish different identity information; ω1, ω2, ω3, ω4, and ω5 are the weights of each feature, which are adjusted according to the actual situation; S is the login success or failure mark, reflecting whether the user's login behavior is legal; ΔT la and D reflects the frequency and timeliness of logins; The identity information mentioned in S4 includes the following categories: Illegal users: A weighted score of less than 50 indicates that the login behavior is high-risk or malicious; Potential risk users: A weighted score between 50-70 indicates that the user's login behavior may pose a potential risk. Ordinary users: A weighted score between 70 and 90 indicates that the user's login behavior is normal; Advanced user: A weighted score between 90 and 100 indicates that the user has administrator privileges and their login behavior conforms to normal patterns.
7. A method for improving the login security of a management page of a broadband router according to claim 6, characterized in that: The automatic switching module in step S4 grants different permissions to different identity information in the following manner: To the illegal users: Processing method: directly block the login of illegal users; Block login: Based on the judgment of the identity recognition module, if the user is identified as an illegal user, the system will immediately block the user's login attempt; IP blocking: Record the user's IP address. If the user attempts to log in multiple times and is marked as an illegal user, the IP address can be blocked to prevent further attacks; Error prompt: Return a clear error message to the illegal user; For the potential risk users: Processing method: According to the judgment of the identity recognition module, if the user is identified as a potential risk user, secondary verification is enabled for the potential risk user; For ordinary users: Processing method: Based on the judgment of the identity recognition module, if the user is identified as a common user, the system grants the user access to basic functions and provides a button for upgrading permissions, providing a secondary verification channel; For the advanced users: Processing method: Based on the judgment of the identity recognition module, if the user is identified as a high-level user, the user is granted access to all functions; The secondary verification method is: through sending a verification code, SMS, email or requiring the user to enter a dynamic password, etc. During the secondary verification process, all operations will be limited to the most basic functions, only viewing account information or changing passwords. After the secondary verification, an additional judgment feature C is added to the identity prediction formula. C is the security verification pass mark, and S3 is used for re-judgment.
8. A method for improving the login security of a management page of a broadband router according to claim 7, characterized in that: After adding the additional judgment feature C to the identity prediction formula, the identity prediction formula changes to: Score = ω1·I s +ω2·G s+ ω3·S+ω4·ΔT la+ ω5·D+ω6·C; wherein ω6 is the weight of C, and is given 50% of the total weight of ω6.