A network device security service enhancement method, system, device and program product
By configuring proactive network disconnection isolation policies and additional security services locally on network devices, the problem of lack of proactive network disconnection isolation after network devices are de-managed is solved, realizing the security and risk control of network devices, and ensuring data security and reliable management.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-30
- Publication Date
- 2026-04-07
AI Technical Summary
Existing network equipment lacks an active disconnection and isolation mechanism after being de-managed, making it difficult to meet the security requirements of classified units and posing a risk of data leakage.
Configure proactive network disconnection isolation policies, basic service forwarding policies, and additional security services locally on network devices, including device network management, security protection, log and alarm services, and network management recovery services. These policies and services enable service forwarding and security management in a managed state.
It enables controllable risks after network devices are de-managed, ensures the security and availability of network devices, supports local network disconnection or isolation, and adds management and protection measures to ensure data security.
Smart Images

Figure CN120915599B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network security technology, and more specifically, to a method, system, device, and program product for enhancing network device security services. Background Technology
[0002] In classified units, network device disconnection is a high-risk event. However, the local processing mechanism of current mainstream network devices is usually designed based on the principle of "decoupling service forwarding and management functions," which results in a lack of proactive network disconnection and isolation mechanisms after the network device is disconnected, making it difficult to meet the security requirements of classified units. Summary of the Invention
[0003] The purpose of this application is to provide a method, system, device, and program product for enhancing network device security services, so as to achieve the technical effect of enhancing network device security services from multiple aspects and ensuring that the risks of network devices after being de-managed are controllable.
[0004] In a first aspect, embodiments of this application provide a method for enhancing network device security services, applied to a network device; the method includes:
[0005] When the network device itself is in a disconnected state, determine whether the network device has a proactive network disconnection isolation policy configured locally; wherein, the proactive network disconnection isolation policy is used to guide the network device to proactively disconnect or isolate the target device connected to the network device, so as to refuse to forward the service packets of the target device;
[0006] If so, the network device's service forwarding task is executed according to the proactive network disconnection isolation policy;
[0007] If not, the service forwarding task is executed according to the basic service forwarding policy of the network device; wherein, the basic service forwarding policy is used to guide the network device to forward service packets of each device connected to the network device;
[0008] Run additional security services locally on the network device; wherein, the additional security services include one or more of the following: device network management service, device security protection service, log and alarm service, and network management recovery service.
[0009] In the above implementation process, by pre-configuring basic service forwarding policies and one or more additional security services from among device network management services, device security protection services, log and alarm services, and network management recovery services locally on the network device, and by customizing proactive network disconnection isolation policies, the network device, after being de-managed, will execute local service forwarding tasks according to the proactive network disconnection isolation policy if such a policy is configured locally, and will execute local service forwarding tasks according to the basic service forwarding policy if no such policy is configured locally, and will also run additional security services locally. This addresses the risk of data leakage due to the inability to proactively disconnect and isolate network devices after they are de-managed. It supports adding proactive network disconnection isolation policies to the network device, prioritizing the execution of service forwarding tasks according to the proactive network disconnection isolation policy, refusing to forward service packets from de-managed or isolated devices, and adding additional security services to ensure the comprehensiveness and availability of the local processing mechanism of the network device. This strengthens the security services of the network device from multiple aspects and ensures that the risks after the network device is de-managed are controllable.
[0010] Furthermore, the method also includes:
[0011] The network connectivity status monitoring results and device management function monitoring results sent by the network management device are obtained; wherein, the network connectivity status monitoring results indicate whether the network device is connected to the network management device, and the device management function monitoring results indicate whether the management function of the network management device is operating normally;
[0012] If the network connectivity status monitoring result indicates that the network device is connected to the network management device, and the device management function monitoring result indicates that the management function of the network management device is operating normally, then it is determined that the network device itself is in a managed state.
[0013] If the network connectivity monitoring result indicates that the network device is not connected to the network management device, or the device management function monitoring result indicates that the management function of the network management device is malfunctioning, then it is determined that the network device itself is in a disconnected state.
[0014] In the above implementation process, by obtaining network connectivity status monitoring results and device management function monitoring results sent by the network management device, the network device is determined to be in a managed state when the network connectivity status monitoring result shows that the network device is connected to the network management device and the device management function monitoring result shows that the management function of the network management device is operating normally. When the network connectivity status monitoring result shows that the network device is not connected to the network management device or the device management function monitoring result shows that the management function of the network management device is operating abnormally, the network device is determined to be in a dismantled state. The network management status of the network device can be determined by combining the monitoring results of the network management device on the two dimensions of network connectivity and management function effectiveness, thereby achieving accurate monitoring of the network management status of the network device.
[0015] Furthermore, the acquisition of network connectivity status monitoring results and device management function monitoring results sent by the network management device includes:
[0016] In response to a ping request sent by the network management device, verify whether the source IP address carried in the ping request is the same as the IP address of the target network management device stored locally by the network device;
[0017] If the source IP address carried in the ping request is the same as the IP address of the target network management device, a ping response is returned to the network management device; otherwise, the ping request is discarded, so that the network management device can send the network connectivity status monitoring result to the network device by determining whether the ping request has timed out.
[0018] In response to the encrypted management request sent by the network management device, the system verifies whether the identity information carried in the encrypted management request is the same as the identity information of the target network management device, and verifies whether the remote management command carried in the encrypted management request is a legitimate command.
[0019] If the identity information carried in the encryption management request is the same as the identity information of the target network management device, and the remote management instruction carried in the encryption management request is a valid instruction, then an encryption management response is returned to the network management device; otherwise, the encryption management request is discarded, so that the network management device can send the device management function monitoring result to the network device by determining whether the encryption management request has timed out.
[0020] In the above implementation process, by supporting network management devices to use ping monitoring to monitor network connectivity status and encrypted anti-spoofing monitoring to monitor device management functions, the network device selects whether to return a ping response to the network management device by verifying whether the source IP address carried in the ping request is the same as the IP address of the target network management device stored locally on the network device. The network management device sends the network connectivity status monitoring result to the network device by determining whether the ping request has timed out. Similarly, by verifying whether the identity information carried in the encrypted management request is the same as the identity information of the target network management device and whether the remote management command carried in the encrypted management request is a valid command, the network management device selects whether to return an encrypted management response to the network management device. The network management device sends the device management function monitoring result to the network device by determining whether the encrypted management request has timed out. This allows for interaction with the network management device to collaboratively monitor network connectivity status and device management functions, thereby ensuring accurate monitoring of the network management status of the network device itself.
[0021] Further, the step of executing the service forwarding task of the network device according to the proactive network disconnection isolation policy includes:
[0022] For each device connected to the network device, determine whether the current device meets the triggering conditions of the proactive network disconnection and isolation policy; wherein, the triggering conditions include one or more of the following: the device is under security threat, the device is performing an unauthorized operation, and the device is malfunctioning;
[0023] If the conditions are met, the current device will be used as the target device for network disconnection or isolation according to the active network disconnection and isolation policy, and the service packets of the target device will be refused to be forwarded.
[0024] If the conditions are not met, the service packets of the current device are forwarded according to the basic service forwarding policy.
[0025] In the above implementation process, by pre-setting the trigger conditions for the proactive network disconnection and isolation policy, including one or more of the following: the device is a security threat, the device is performing illegal operations, and the device is malfunctioning, the network device determines for each device connected to it whether the current device meets the trigger conditions of the proactive network disconnection and isolation policy. If it does, the current device is disconnected or isolated as the target device according to the proactive network disconnection and isolation policy, and the service packets of the target device are refused to be forwarded. If it does not meet the conditions, the service packets of the current device are forwarded according to the basic service forwarding policy. This can ensure that the network device can completely and accurately identify the risky devices for disconnection or isolation, effectively avoiding errors and omissions.
[0026] Furthermore, the additional security services include device network management services; the additional security services running locally on the network device include:
[0027] The network management device responds to local management commands input by the management user through its local network management protocol and / or its own network management interface, and executes network management tasks. The network management protocol includes the SNMP protocol, and the network management interface includes one or more of Telnet, SSH, and Web interfaces.
[0028] In the above implementation process, by pre-configuring network management protocols and / or the network management interfaces of the network devices locally, such as one or more of the SNMP protocol, Telnet interface, SSH interface, and Web interface, the network devices respond to local management commands input by the management users through the network management protocols and / or the network management interfaces of the network devices, and execute the network management tasks of the network devices. This enables management users to manage network devices locally after the network devices are de-managed, meeting the management needs of the network devices, thereby strengthening the security services of the network devices from multiple aspects and ensuring that the risks of the network devices after de-management are controllable.
[0029] Furthermore, the additional security services include device security protection services; the additional security services running locally on the network device include:
[0030] The network device performs its security protection tasks according to its local security protection policy; wherein the security protection policy includes one or more of the following: device access control policy, device attack protection policy, and traffic redirection control policy.
[0031] In the above implementation process, by pre-configuring one or more of the following device security protection policies locally on the network device: device access control policy, device attack protection policy, and traffic redirection control policy, the network device executes the device security protection task according to the local device security protection service policy. This enables the network device to be protected, ensuring the security of the network device and optimizing its performance, thereby strengthening the security service of the network device from multiple aspects and ensuring that the risks after the network device is de-managed are controllable.
[0032] Furthermore, the additional security services include logging and alarm services; the additional security services running locally on the network device include:
[0033] Generate system logs for the network device and store the system logs locally on the network device;
[0034] According to the local alarm processing policy of the network device, a target alarm message is sent; wherein, the target alarm message is used to indicate that the network device is in a dismantled state.
[0035] In the above implementation process, by pre-configuring log and alarm services locally on the network device, the network device generates system logs and stores them locally. According to the alarm handling policy of the network device, target alarm information indicating that the network device is in a dismantled state is sent. After the network device is dismantled, it can automatically record system logs and alarm dismantling events locally, which can facilitate timely reminders to management users that the network device is dismantled, and allow them to quickly view the system logs and take countermeasures. This strengthens the security services of the network device from multiple aspects and ensures that the risks after the network device is dismantled are controllable.
[0036] Furthermore, the additional security services include network management recovery services; the additional security services running locally on the network device include:
[0037] The network management recovery task of the network device is executed according to the network management recovery policy configured locally on the network device, so as to restore the network management device's management of the network device.
[0038] In the above implementation process, by pre-configuring network management recovery services locally on the network devices, the network devices execute network management recovery tasks according to the network management recovery policy to restore the network management device's management of the network devices. This enables the network devices to automatically attempt to restore their own network management status from the unmanaged state to the managed state after they are de-managed, helping the network management device to restore its management of the network devices as soon as possible. This strengthens the security services of the network devices from multiple aspects and ensures that the risks after the network devices are de-managed are controllable.
[0039] Furthermore, the network device includes one or more of a switch, router, firewall, and server.
[0040] In the above implementation process, by selecting one or more of switches, routers, firewalls, and servers as network devices, diverse application requirements can be met.
[0041] Secondly, embodiments of this application provide a network device security service enhancement device, applied to a network device; the device includes:
[0042] The local configuration query module is used to determine whether the network device has a proactive network disconnection isolation policy configured locally when the network device itself is in a disconnected state; wherein, the proactive network disconnection isolation policy is used to guide the network device to proactively disconnect or isolate the target device connected to the network device, so as to refuse to forward the service packets of the target device;
[0043] The first service forwarding module is used to execute the service forwarding task of the network device according to the active network disconnection isolation policy if necessary.
[0044] The second service forwarding module is used to execute the service forwarding task according to the basic service forwarding policy of the network device if no such policy exists; wherein the basic service forwarding policy is used to guide the network device to forward service packets of each device connected to the network device.
[0045] The security service operation module is used to run additional security services locally on the network device; wherein, the additional security services include one or more of the following: device network management service, device security protection service, log and alarm service, and network management recovery service.
[0046] Thirdly, embodiments of this application provide a network device security service enhancement system, including a network management device and at least one network device connected to the network management device; each of the at least one network device is used for:
[0047] When the network device itself is in a disconnected state, determine whether the network device has a proactive network disconnection isolation policy configured locally; wherein, the proactive network disconnection isolation policy is used to guide the network device to proactively disconnect or isolate the target device connected to the network device, so as to refuse to forward the service packets of the target device;
[0048] If so, the network device's service forwarding task is executed according to the proactive network disconnection isolation policy;
[0049] If not, the service forwarding task is executed according to the basic service forwarding policy of the network device; wherein, the basic service forwarding policy is used to guide the network device to forward service packets of each device connected to the network device;
[0050] Run additional security services locally on the network device; wherein, the additional security services include one or more of the following: device network management service, device security protection service, log and alarm service, and network management recovery service.
[0051] Fourthly, embodiments of this application provide an electronic device, including a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor; when the processor executes the computer program, it implements the method described above.
[0052] Fifthly, embodiments of this application provide a computer program product including instructions that, when executed by a computer, cause the computer to perform the method described above.
[0053] In a sixth aspect, embodiments of this application provide a computer-readable storage medium, the computer-readable storage medium including a stored computer program; wherein, when the computer program is executed, it controls the device where the computer-readable storage medium is located to perform the method described above. Attached Figure Description
[0054] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings used in the embodiments of this application will be briefly introduced below. It should be understood that the following drawings only show some embodiments of this application and should not be regarded as a limitation of the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.
[0055] Figure 1 A flowchart illustrating a method for enhancing network device security services provided in the first embodiment of this application;
[0056] Figure 2 This is a schematic diagram of the structure of a network device security service enhancement device provided in the second embodiment of this application;
[0057] Figure 3 This is a schematic diagram of the structure of a network device security service enhancement system provided in the third embodiment of this application;
[0058] Figure 4 This is a schematic diagram of the structure of an electronic device provided in the fourth embodiment of this application. Detailed Implementation
[0059] The technical solutions in the embodiments of this application will now be described with reference to the accompanying drawings.
[0060] It should be noted that in the description of this application, the terms "first," "second," etc., are used only for distinguishing descriptions and should not be construed as indicating or implying relative importance. Furthermore, the step numbers in the text are only for the convenience of explaining the embodiments of this application and are not intended to limit the order in which the steps are executed. The methods provided in the embodiments of this application can be executed by relevant terminal devices, and the following description uses the processor within a storage server as the execution entity.
[0061] In classified units, network device disconnection is a high-risk event. However, in related technologies, the local processing mechanism of network devices is usually designed based on the principle of "decoupling service forwarding and management functions," resulting in a lack of proactive network disconnection and isolation mechanisms after disconnection, which makes it difficult to meet the security requirements of classified units.
[0062] To address this, this application proposes a method for enhancing network device security services. This method involves pre-configuring basic service forwarding policies and one or more additional security services (such as device network management services, device security protection services, log and alarm services, and network management recovery services) locally on the network device. It also includes custom configuration of proactive network disconnection and isolation policies. After the network device is de-managed, if a proactive network disconnection and isolation policy is configured locally, it executes local service forwarding tasks according to that policy. If no such policy is configured, it executes local service forwarding tasks according to the basic service forwarding policy and runs additional security services locally. This approach addresses the risk of data leakage due to the inability to proactively disconnect and isolate network devices after de-management. It supports adding proactive network disconnection and isolation policies locally on the network device, prioritizing service forwarding tasks based on these policies, rejecting the forwarding of service packets from de-managed or isolated devices, and configuring additional security services for operation. This ensures the comprehensiveness and availability of the network device's local processing mechanism, thereby enhancing network device security services from multiple perspectives and guaranteeing that risks after network device de-management are controllable.
[0063] Please refer to Figure 1 , Figure 1 This is a flowchart illustrating a method for enhancing network device security services according to the first embodiment of this application. The first embodiment of this application provides a method for enhancing network device security services, applied to a network device; the method includes steps S101-S104:
[0064] S101. When the network device itself is in a disconnected state, determine whether the network device has a proactive network disconnection isolation policy configured locally; wherein, the proactive network disconnection isolation policy is used to guide the network device to proactively disconnect or isolate the target device connected to the network device, so as to refuse to forward the target device's service packets.
[0065] As an example, a network of classified units typically includes a network management device and at least one network device connected to the network management device. The network management device can perform management operations on each of the at least one network device, such as managing the ledger information of each network device, monitoring the operating status of each network device, detecting operational faults of each network device, and upgrading the software versions of each network device. To meet the complex business needs of classified units, the network devices in the classified unit network are usually also connected to other devices such as user terminals or servers to interact with the connected devices.
[0066] Considering the security requirements of classified units in actual application scenarios, proactive network disconnection and isolation policies can be defined in advance for the security requirements of classified units. It is optional to configure the predefined proactive network disconnection and isolation policies locally on each network device. The proactive network disconnection and isolation policies are used to guide network devices to proactively disconnect or isolate target devices connected to the network devices in order to refuse to forward the service packets of the target devices.
[0067] In practical applications, proactive network disconnection and isolation policies can include, but are not limited to: the target of the network disconnection or isolation operation, such as defining the type of the target device, or even specifying which network segment or region the target device is located in; the method of network disconnection or isolation; and the duration of the network disconnection or isolation operation. Different levels of proactive network disconnection and isolation policies can be defined according to network security regulations.
[0068] For any network device, the network device monitors its own network management status in real time to determine whether the network device is under management or out of management.
[0069] It is understandable that if a network device is in a managed state, it means that the network management device can perform management operations on the network device; if a network device is in a dismantled state, it means that the network management device cannot perform management operations on the network device.
[0070] If the network device is detected to be in a state of being out of control, determine whether the network device has a proactive network disconnection isolation policy configured locally.
[0071] S102. If so, the network device's service forwarding task shall be executed according to the active network disconnection and isolation policy.
[0072] As an example, when a network device determines that it has a proactive network disconnection and isolation policy configured locally, it executes the network device's service forwarding task according to the proactive network disconnection and isolation policy. Specifically, it can determine the target device connected to the network device itself, as well as the network disconnection or isolation operation method, according to the proactive network disconnection operation method, or isolate the target device according to the isolation operation method, refuse to forward the target device's service packets, and at the same time allow the forwarding of service packets of other devices, that is, the at least one device connected to the network device other than the target device, thereby performing service forwarding locally on the network device.
[0073] S103. If not, perform the service forwarding task according to the basic service forwarding policy of the network device; wherein, the basic service forwarding policy is used to guide the network device to forward service packets of each device connected to the network device.
[0074] As an example, when a network device determines that it has no locally configured active network disconnection isolation policy, it obtains the basic service forwarding policy configured locally on the network device. The basic service forwarding policy is used to guide the network device to forward service packets from various devices connected to the network device.
[0075] In practical applications, the content of basic service forwarding strategies may include, but is not limited to: forwarding objects, such as any service message; forwarding paths; forwarding methods, such as chunked transmission; and special processing mechanisms, such as message encryption or digital signatures.
[0076] After obtaining the basic service forwarding policy configured locally on the network device, the service forwarding task is executed according to the basic service forwarding policy. Specifically, the forwarding object, forwarding path and forwarding method can be determined according to the basic service forwarding policy. The specified service packet is obtained and forwarded along the forwarding path according to the forwarding method, thereby performing service forwarding locally on the network device.
[0077] S104. Run additional security services locally on the network device; wherein, the additional security services include one or more of the following: device network management service, device security protection service, log and alarm service, and network management recovery service.
[0078] As an example, in order to ensure the comprehensiveness and availability of the local processing mechanism of the network device, one or more additional security services among the device network management service, device security protection service, log and alarm service and network management recovery service are pre-configured locally on the network device.
[0079] It should be noted that the device network management service is used to implement the local network management function of the network device, the device security protection service is used to implement the local security protection function of the network device, the log and alarm service is used to implement the local log recording and abnormal alarm function of the network device, and the network management recovery service is used to restore the network device's own network management status from the unmanaged state to the managed state.
[0080] If the additional security service includes device network management service, then the device network management service on the network device will be run; if the additional security service includes device security protection service, then the device security protection service on the network device will be run; if the additional security service includes logging and alarm service, then the logging and alarm service on the network device will be run; if the additional security service includes network management recovery service, then the network management recovery service on the network device will be run.
[0081] In practical applications, business forwarding tasks and additional security services can be executed simultaneously. Business forwarding tasks can be executed first and then additional security services can be run, or additional security services can be run first and then business forwarding tasks can be executed.
[0082] This application embodiment pre-configures basic service forwarding policies and one or more additional security services from among device network management services, device security protection services, log and alarm services, and network management recovery services locally on the network device, and customizes and configures proactive network disconnection isolation policies. After the network device is disconnected from management, if a proactive network disconnection isolation policy is configured locally, it will execute local service forwarding tasks according to the proactive network disconnection isolation policy; if no proactive network disconnection isolation policy is configured locally, it will execute local service forwarding tasks according to the basic service forwarding policy and run additional security services locally. This addresses the risk of data leakage and other problems caused by the inability to proactively disconnect and isolate network devices after disconnection from management. It supports adding proactive network disconnection isolation policies to the network device, prioritizing the execution of service forwarding tasks according to the proactive network disconnection isolation policy, refusing to forward service packets from disconnected or isolated devices, and adding and configuring additional security services to ensure the comprehensiveness and availability of the local processing mechanism of the network device. This strengthens the security services of the network device from multiple aspects and ensures that the risks after the network device is disconnected from management are controllable.
[0083] In an optional embodiment, the method further includes steps S105-S107:
[0084] S105. Obtain the network connectivity status monitoring results and device management function monitoring results sent by the network management device; wherein, the network connectivity status monitoring results indicate whether the network device and the network management device are connected, and the device management function monitoring results indicate whether the management function of the network management device is operating normally.
[0085] As an example, the network management device can monitor the network connectivity status of the network device, monitor the network connectivity status between the network management device itself and the network device, and obtain the network connectivity status monitoring results. It can also monitor the device management function of the network device, monitor whether the network management device can effectively manage the network device after issuing management instructions to the network device, obtain the device management function monitoring results, and send the network connectivity status monitoring results and device management function monitoring results to the network device.
[0086] The network device obtains the network connectivity status monitoring results and device management function monitoring results sent by the network management device, determines whether the network device and the network management device are connected or not, and determines whether the device management function monitoring results are normal or abnormal.
[0087] S106. If the network connectivity status monitoring result shows that the network device is connected to the network management device, and the device management function monitoring result shows that the management function of the network management device is operating normally, then the network device itself is determined to be in a managed state.
[0088] As an example, if a network device determines that the network connectivity status monitoring result indicates that the network device is connected to the network management device, and the device management function monitoring result indicates that the management function of the network management device is operating normally, then the network management device is considered to be able to perform management operations on the network device, and the network device itself is determined to be in a managed state.
[0089] S107. If the network connectivity status monitoring result indicates that the network device and the network management device are not connected, or the device management function monitoring result indicates that the management function of the network management device is malfunctioning, then it is determined that the network device itself is in a state of being out of control.
[0090] As an example, if a network device determines that the network connectivity monitoring result is that the network device and the network management device are not connected, or the device management function monitoring result is that the management function of the network management device is malfunctioning, then it is considered that the network management device cannot perform management operations on the network device, and at this time it is determined that the network device itself is in a state of being out of control.
[0091] This application embodiment obtains network connectivity status monitoring results and device management function monitoring results sent by the network management device from the network device. When the network connectivity status monitoring result shows that the network device is connected to the network management device and the device management function monitoring result shows that the management function of the network management device is operating normally, it is determined that the network device is in a managed state. When the network connectivity status monitoring result shows that the network device is not connected to the network management device or the device management function monitoring result shows that the management function of the network management device is operating abnormally, it is determined that the network device is in a dismantled state. It can combine the monitoring results of the network management device on the two dimensions of network connectivity and management function effectiveness to determine the network management status of the network device, thereby achieving accurate monitoring of the network management status of the network device.
[0092] In an optional embodiment, obtaining the network connectivity status monitoring results and device management function monitoring results sent by the network management device includes: responding to a ping request sent by the network management device, verifying whether the source IP address carried in the ping request is the same as the IP address of the target network management device stored locally on the network device; if the source IP address carried in the ping request is the same as the IP address of the target network management device, then returning a ping response to the network management device; otherwise, discarding the ping request, so that the network management device sends the network connectivity status monitoring results to the network device by determining whether the ping request has timed out; responding to an encryption management request sent by the network management device, verifying whether the identity information carried in the encryption management request is the same as the identity information of the target network management device, and verifying whether the remote management command carried in the encryption management request is a valid command; if the identity information carried in the encryption management request is the same as the identity information of the target network management device, and the remote management command carried in the encryption management request is a valid command, then returning an encryption management response to the network management device; otherwise, discarding the encryption management request, so that the network management device sends the device management function monitoring results to the network device by determining whether the encryption management request has timed out.
[0093] As an example, network management devices can use ping monitoring to monitor network connectivity and encryption / anti-counterfeiting monitoring to monitor device management functions.
[0094] When using ping monitoring to monitor network connectivity, the network management device can pre-set a first monitoring period. After the first monitoring period arrives, it sends a ping request to the network device, which carries the source IP address (Internet Protocol Address) of the network management device.
[0095] After receiving a ping request from the network management device, the network device responds to the ping request and verifies whether the source IP address carried in the ping request is the same as the IP address of the target network management device stored locally on the network device. If the source IP address carried in the ping request is the same as the IP address of the target network management device, the network device returns a ping response to the network management device. If the source IP address carried in the ping request is different from the IP address of the target network management device, the ping request is discarded directly.
[0096] It should be noted that the target network management device is a network management device that is pre-configured locally on the network device to allow management of the network device, such as configuring a network management device whitelist.
[0097] The network management device can preset a first waiting time to determine whether a ping response is received within the first waiting time after a ping request is sent. If a response is received, the ping request is determined not to have timed out; otherwise, it is determined to have timed out. If the ping request has not timed out, the generated network connectivity status monitoring result indicates that the network device and the network management device are connected. If the ping request has timed out, the generated network connectivity status monitoring result indicates that the network device and the network management device are not connected, and the device then sends the network connectivity status monitoring result to the network device.
[0098] For monitoring the device management function of network devices using encrypted anti-counterfeiting monitoring, the network management device can pre-set a second monitoring cycle. After the second monitoring cycle arrives, it sends an encrypted management request to the network device. The encrypted management request carries the device identifier of the network management device, such as the device ID (Identity document), as well as encrypted information obtained by encrypting the remote management command specified by the network management device using a digital signature generated based on the network management device key. The remote management command is used to instruct the network management device to perform management operations on the network device.
[0099] Upon receiving an encryption management request from a network management device, the network device responds, identifies the device identifier and encryption information carried in the request, decrypts the encryption information, and obtains the digital signature of the network management device and the remote management command specified by the network management device. It verifies whether the identity information carried in the encryption management request matches the identity information of the target network management device by checking whether the device identifier of the network management device is the same as that of the target network management device and whether the digital signature of the network management device is the same as that generated based on the key of the target network management device. In essence, if the device identifier of the network management device matches the device identifier of the target network management device, and both the digital signature of the network management device and the digital signature of the network management device match those of the target network management device, then the identity information carried in the encryption management request is determined to match the identity information of the target network management device. If the identity information is the same, but the device identifier of the network management device is different from that of the target network management device, or the digital signature of the network management device is different from that of the target network management device, then it is determined that the identity information carried in the encrypted management request is different from the identity information of the target network management device. It is also verified whether the remote management instruction specified by the network management device is a legitimate instruction, such as verifying whether the remote management instruction is within the management authority scope of the network management device. If it is determined that the identity information carried in the encrypted management request is the same as that of the target network management device and the remote management instruction carried in the encrypted management request is a legitimate instruction, an encrypted management response is returned to the network management device. If it is determined that the identity information carried in the encrypted management request is different from that of the target network management device, or the remote management instruction carried in the encrypted management request is not a legitimate instruction, the encrypted management request is directly discarded.
[0100] The network management device can preset a second waiting time to determine whether an encryption management response is received within the second waiting time after the encryption management request is sent. If a response is received, the encryption management request is determined to have not timed out; otherwise, the encryption management request is determined to have timed out. If the encryption management request has not timed out, the generated device management function monitoring result indicates that the network management device's management function is operating normally. If the encryption management request has timed out, the generated device management function monitoring result indicates that the network management device's management function is operating abnormally, and the device management function monitoring result is then sent to the network device.
[0101] In practical applications, the first monitoring cycle can be equal to the second monitoring cycle, meaning the network management device can simultaneously send network connectivity status monitoring requests and device management function monitoring requests to the network device. Alternatively, the first monitoring cycle can be shorter than the second monitoring cycle, meaning the network management device can send the network connectivity status monitoring request first and then the device management function monitoring request. The first waiting time and the second waiting time can be the same or different.
[0102] This application embodiment supports network management devices in using ping monitoring to monitor network connectivity and encrypted anti-spoofing monitoring to monitor device management functions. The network device verifies whether the source IP address carried in the ping request matches the IP address of the target network management device stored locally, allowing the network management device to choose whether to return a ping response. The network management device then determines whether the ping request times out and sends network connectivity monitoring results to the network device. Similarly, the network management device verifies whether the identity information carried in the encrypted management request matches the identity information of the target network management device and whether the remote management command carried in the encrypted management request is valid, allowing the network management device to determine whether the encrypted management request times out and send device management function monitoring results to the network device. This enables interaction with the network management device to collaboratively monitor network connectivity and device management functions, ensuring accurate monitoring of the network device's own network management status.
[0103] In an optional embodiment, the step of executing the service forwarding task of the network device according to the proactive network disconnection and isolation policy includes: for each device connected to the network device, determining whether the current device meets the triggering conditions of the proactive network disconnection and isolation policy; wherein, the triggering conditions include one or more of the following: the device is under security threat, the device is performing unauthorized operations, and the device is malfunctioning; if the conditions are met, the current device is disconnected or isolated as the target device according to the proactive network disconnection and isolation policy, and the service packets of the target device are refused to be forwarded; if the conditions are not met, the service packets of the current device are forwarded according to the basic service forwarding policy.
[0104] As an example, in order to ensure that network devices can completely and accurately identify risky devices and disconnect or isolate them from the network, and avoid errors or omissions, the trigger conditions for the proactive network disconnection and isolation policy can be preset. The trigger conditions include one or more of the following: the device poses a security threat, the device performs an illegal operation, and the device malfunctions.
[0105] For each device connected to the network device, the network device determines whether the current device meets the trigger conditions for the proactive network disconnection and isolation policy. Specifically, this can be done by performing a series of risk monitoring operations, such as identifying security threats to the current device, checking whether the current device's operations are compliant, and detecting whether the current device has malfunctioned. If the current device meets the trigger conditions, it is considered to be at risk. In this case, according to the proactive network disconnection and isolation policy, the current device is designated as the target device, and its network is disconnected or isolated, and its service packets are refused forwarding. If the current device does not meet the trigger conditions, it is considered not at risk, and its service packets are forwarded directly according to the basic service forwarding policy configured locally on the network device, allowing the forwarding of its service packets, thus enabling service forwarding locally on the network device.
[0106] This application embodiment pre-sets the trigger conditions for the proactive network disconnection and isolation policy, including one or more of the following: the device poses a security threat, the device performs an illegal operation, and the device malfunctions. The network device determines whether each connected device meets the trigger conditions for the proactive network disconnection and isolation policy. If the conditions are met, the current device is disconnected or isolated according to the proactive network disconnection and isolation policy, and the service packets of the target device are refused to be forwarded. If the conditions are not met, the service packets of the current device are forwarded according to the basic service forwarding policy. This ensures that the network device can completely and accurately identify and disconnect or isolate devices with risks, effectively avoiding errors and omissions.
[0107] In an optional embodiment, the additional security service includes a device network management service; the additional security service running locally on the network device includes: responding to local management commands input by the management user through the network device's local network management protocol and / or the network device's own network management interface, and executing network management tasks of the network device; wherein the network management protocol includes the SNMP protocol, and the network management interface includes one or more of the Telnet interface, SSH interface, and Web interface.
[0108] As an example, in order to support management users to manage network devices locally after the network devices are de-managed, a device network management service protocol and / or the network management interface of the network device itself can be pre-configured locally on the network device. This allows management users to input local management commands through the network device's local network management protocol and / or the network device's own network management interface. The network management protocol includes the SNMP protocol, and the network management interface includes one or more of Telnet, SSH, and Web interfaces. The local management commands are used to instruct management users on management operations for the network device.
[0109] The SNMP (Simple Network Management Protocol) consists of a set of network management standards, including an application layer protocol, a database schema, and a set of data objects. This protocol enables network management systems to monitor devices connected to the network for any situations that warrant management attention.
[0110] The Telnet protocol is a member of the TCP (Transmission Control Protocol) / IP (Internet Protocol) protocol suite and is the standard protocol and primary method for remote login services on the Internet. It provides users with the ability to perform tasks on a remote host from their local computer. The user uses the Telnet program on their computer to connect to the server. The user can then enter commands in the Telnet program, which are executed on the server as if entered directly on the server's console, enabling local control of the server.
[0111] SSH (Secure Shell) is a protocol used for secure remote login and other secure network services over insecure networks. SSH is a reliable protocol specifically designed to provide security for remote login sessions and other network services. Using SSH can effectively prevent information leakage during remote management.
[0112] Web APIs (Web Application Programming Interfaces) are standardized programming interfaces built on the HTTP (Hypertext Transfer Protocol) protocol. They are used to enable service calls and data interaction between different systems, support data format transmission such as JSON / XML, and have characteristics such as statelessness and caching. Their core value lies in reducing application development complexity by remotely invoking network services such as storage, messaging, and computing. Typical applications include enterprise-level storage services, cross-platform messaging communication, and vertical domain data processing.
[0113] After receiving local management commands input by the management user through the network management protocol of the network device and / or the network management interface of the network device, the network device responds to the local management commands and executes the network management tasks of the network device to perform corresponding management operations on the network device.
[0114] It should be noted that responding to local management commands input by the management user through the network device's local network management protocol and / or the network device's own network management interface includes the following scenarios: responding to local management commands input by the management user through the network device's local network management protocol; responding to local management commands input by the management user through the network device's own network management interface; and responding to local management commands input by the management user through both the network device's local network management protocol and the network device's own network management interface.
[0115] This application embodiment pre-configures network management protocols and / or the network device's own network management interface, such as one or more of SNMP protocol, Telnet interface, SSH interface, and Web interface, locally on the network device. The network device responds to local management commands input by the management user through the network device's local network management protocol and / or its own network management interface, and executes network management tasks. This enables management users to manage the network device locally after it is de-managed, meeting the management needs of the network device and thereby enhancing the security services of the network device from multiple aspects, ensuring that the risks after the network device is de-managed are controllable.
[0116] In an optional embodiment, the additional security service includes a device security protection service; the additional security service running locally on the network device includes: performing device security protection tasks on the network device according to the device security protection policy of the network device; wherein, the device security protection policy includes one or more of the following: device access control policy, device attack protection policy, and traffic redirection control policy.
[0117] As an example, in order to ensure the security of network devices and optimize their performance, device security protection services can be pre-configured locally on the network devices. The device security protection policies include one or more of the following: device access control policies, device attack protection policies, and traffic redirection control policies.
[0118] It should be noted that device access control policies are predefined policies used to manage device access permissions, device attack protection policies are predefined policies used to take security measures against devices, and traffic redirection control policies are predefined policies used to control the network traffic transmission of devices. The specific content of these device security protection policies can be defined according to actual application requirements.
[0119] In practical applications, device access control policies can include ACL (Access Control List) policies to prevent unauthorized access. ACL policies are the processing mechanism in network devices that implements access control and traffic filtering. By defining a series of rules to allow or block network traffic, based on characteristics such as the source / destination address, port, and protocol of data packets, they finely control the flow and permissions of network traffic, making them an indispensable tool for ensuring network security and optimizing network performance. Device attack protection policies can include setting authentication methods, attack defense methods, and virus scanning methods. Traffic redirection control policies can include redirecting target traffic such as audit traffic to a security gateway, restricting data packets from accessing target IP addresses or URLs (uniform resource locators), etc.
[0120] Network devices perform security protection tasks according to their local security protection policies to protect the network devices.
[0121] This application embodiment pre-configures one or more device security protection policies, including device access control policies, device attack protection policies, and traffic redirection control policies, locally on the network device. The network device then executes its device security protection tasks according to its local device security protection service policies. This enables security protection for the network device, ensuring its security and optimizing its performance. As a result, the security services of the network device are strengthened from multiple aspects, ensuring that the risks after the network device is de-managed are controllable.
[0122] In an optional embodiment, the additional security services include logging and alarm services; the additional security services running locally on the network device include: generating system logs for the network device and storing the system logs locally on the network device; sending target alarm information according to the alarm handling policy of the network device; wherein the target alarm information is used to indicate that the network device is in a dismantled state.
[0123] As an example, in order to support network devices to automatically record system logs and alarm events locally after they are de-managed, so as to facilitate timely reminders to management users that the network devices are de-managed and to quickly view system logs and take countermeasures, the log and alarm service can be configured locally on the network device in advance, and the alarm handling strategy on which the log and alarm service depends can be configured.
[0124] In practical applications, log processing policies can also be configured. These policies can include setting the encryption algorithm, storage path, storage location (e.g., local buffer or NVRAM), and download method for system logs. For example, the storage location can be set to a local buffer or NVRAM (Non-Volatile Random Access Memory). Alarm processing policies can include setting alarm events, such as network attack events and virus intrusion events in addition to network device mismanagement events; setting alarm objects, such as LED lights, buzzers, mail servers, or SMS management systems; and setting alarm message templates.
[0125] Network devices record various operation commands in real time by running the log and alarm services configured locally on the network device, generate system logs for the network device, and store the system logs locally on the network device. In addition, according to the alarm removal policy configured locally on the network device, target alarm information is sent to indicate that the network device is in a dismantled state.
[0126] This application embodiment pre-configures log and alarm services locally on the network device, generates system logs for the network device, stores these system logs locally on the network device, and sends target alarm information indicating that the network device is in a dismantled state according to the alarm handling policy of the network device. This enables the network device to automatically record system logs and alarm dismantling events locally after the network device is dismantled, facilitating timely reminders to management users that the network device is dismantled, allowing them to quickly view system logs and take countermeasures. This strengthens the security services of the network device from multiple aspects and ensures that the risks after the network device is dismantled are controllable.
[0127] In an optional embodiment, the additional security service includes a network management recovery service; the additional security service running locally on the network device includes: executing a network management recovery task of the network device according to the network management recovery policy configured locally on the network device, so as to restore the network management device's management of the network device.
[0128] As an example, in order to restore the network management status of network devices from a dismantled state to a managed state as soon as possible and help the network management device to restore its management function over the network devices as soon as possible, a network management recovery service can be pre-configured locally on the network device, and the network management recovery policy on which the network management recovery service depends can be configured.
[0129] It should be noted that network management recovery policies are predefined strategies used to guide network devices in restoring the management functions of network management devices. The specific content of the network management recovery policy can be defined according to actual application requirements.
[0130] In practical applications, network management recovery strategies may include triggering network devices to re-establish connections with network management devices, and triggering network devices to establish connections with backup network management devices.
[0131] The network device executes the network management recovery task according to the network management recovery policy configured locally on the network device, restores the network management device's management of the network device, and restores the network device's own network management status from the unmanaged state to the managed state.
[0132] This application embodiment pre-configures a network management recovery service locally on the network device. The network device then executes a network management recovery task according to the network management recovery policy to restore the network management device's management of the network device. This enables the network device to automatically attempt to restore its network management status from a de-managed state to a managed state after it has been de-managed, helping the network management device to quickly resume management of the network device. This strengthens the security services of the network device from multiple aspects and ensures that the risks after the network device is de-managed are controllable.
[0133] In optional embodiments, the network device includes one or more of a switch, router, firewall, and server.
[0134] As an example, considering that the network architecture of classified units is relatively complex, it usually includes network interconnection devices such as switches and routers, as well as network service devices such as servers. Furthermore, the security requirements of classified unit networks are high, usually including network security devices such as firewalls. Based on actual application needs, one or more of switches, routers, firewalls, and servers can be selected as network devices to build a classified unit network.
[0135] This application embodiment can meet diverse application needs by selecting one or more of switches, routers, firewalls, and servers as network devices.
[0136] The method for enhancing network device security services provided in the first embodiment of this application allows the network device to prioritize the execution of service forwarding tasks according to the proactive network disconnection and isolation policy after being disconnected from management. It refuses to forward service packets from disconnected or isolated devices, enabling optional configuration for access users of different ranges and levels. At the same time, it runs one or more additional security services among device network management services, device security protection services, log and alarm services, and network management recovery services, ensuring the comprehensiveness and availability of the network device's local processing mechanism. This strengthens the security services of the network device from multiple aspects and ensures that the risks after the network device is disconnected from management are controllable.
[0137] Please refer to Figure 2 , Figure 2This is a schematic diagram of a network device security service enhancement device provided in the second embodiment of this application. The second embodiment of this application provides a network device security service enhancement device applied to a network device; the device includes: a local configuration query module 201, used to determine whether the network device has a locally configured active network disconnection isolation policy when the network device itself is in a managed state; wherein, the active network disconnection isolation policy is used to guide the network device to actively disconnect or isolate target devices connected to the network device, so as to refuse to forward the service packets of the target devices; a first service forwarding module 202, used to execute the network device's service forwarding task according to the active network disconnection isolation policy if such a policy exists; a second service forwarding module 203, used to execute the service forwarding task according to the network device's local basic service forwarding policy if such a policy does not exist; wherein, the basic service forwarding policy is used to guide the network device to forward the service packets of each device connected to the network device; and a security service operation module 204, used to run additional security services locally on the network device; wherein, the additional security services include one or more of the following: device network management service, device security protection service, log and alarm service, and network management recovery service.
[0138] In an optional embodiment, the device further includes a management status monitoring module, configured to: acquire network connectivity status monitoring results and device management function monitoring results sent by the network management device; wherein, the network connectivity status monitoring result indicates whether the network device is connected to the network management device, and the device management function monitoring result indicates whether the management function of the network management device is operating normally; if the network connectivity status monitoring result indicates that the network device is connected to the network management device, and the device management function monitoring result indicates that the management function of the network management device is operating normally, then it is determined that the network device itself is in a managed state; if the network connectivity status monitoring result indicates that the network device is not connected to the network management device, or the device management function monitoring result indicates that the management function of the network management device is operating abnormally, then it is determined that the network device itself is in a dismantled state.
[0139] In an optional embodiment, obtaining the network connectivity status monitoring results and device management function monitoring results sent by the network management device includes: responding to a ping request sent by the network management device, verifying whether the source IP address carried in the ping request is the same as the IP address of the target network management device stored locally on the network device; if the source IP address carried in the ping request is the same as the IP address of the target network management device, then returning a ping response to the network management device; otherwise, discarding the ping request, so that the network management device sends the network connectivity status monitoring results to the network device by determining whether the ping request has timed out; responding to an encryption management request sent by the network management device, verifying whether the identity information carried in the encryption management request is the same as the identity information of the target network management device, and verifying whether the remote management command carried in the encryption management request is a valid command; if the identity information carried in the encryption management request is the same as the identity information of the target network management device, and the remote management command carried in the encryption management request is a valid command, then returning an encryption management response to the network management device; otherwise, discarding the encryption management request, so that the network management device sends the device management function monitoring results to the network device by determining whether the encryption management request has timed out.
[0140] In an optional embodiment, the step of executing the service forwarding task of the network device according to the proactive network disconnection and isolation policy includes: for each device connected to the network device, determining whether the current device meets the triggering conditions of the proactive network disconnection and isolation policy; wherein, the triggering conditions include one or more of the following: the device is under security threat, the device is performing unauthorized operations, and the device is malfunctioning; if the conditions are met, the current device is disconnected or isolated as the target device according to the proactive network disconnection and isolation policy, and the service packets of the target device are refused to be forwarded; if the conditions are not met, the service packets of the current device are forwarded according to the basic service forwarding policy.
[0141] In an optional embodiment, the additional security service includes a device network management service; the additional security service running locally on the network device includes: responding to local management commands input by the management user through the network device's local network management protocol and / or the network device's own network management interface, and executing network management tasks of the network device; wherein the network management protocol includes the SNMP protocol, and the network management interface includes one or more of the Telnet interface, SSH interface, and Web interface.
[0142] In an optional embodiment, the additional security service includes a device security protection service; the additional security service running locally on the network device includes: performing device security protection tasks on the network device according to the device security protection policy of the network device; wherein, the device security protection policy includes one or more of the following: device access control policy, device attack protection policy, and traffic redirection control policy.
[0143] In an optional embodiment, the additional security services include logging and alarm services; the additional security services running locally on the network device include: generating system logs for the network device and storing the system logs locally on the network device; sending target alarm information according to the alarm handling policy of the network device; wherein the target alarm information is used to indicate that the network device is in a dismantled state.
[0144] In an optional embodiment, the additional security service includes a network management recovery service; the additional security service running locally on the network device includes: executing a network management recovery task of the network device according to the network management recovery policy configured locally on the network device, so as to restore the network management device's management of the network device.
[0145] In optional embodiments, the network device includes one or more of a switch, router, firewall, and server.
[0146] The specific implementation process of the functions and roles of each module in the above device can be found in the implementation process of the corresponding steps in the above method, and will not be repeated here.
[0147] Please refer to Figure 3 , Figure 3 This is a schematic diagram of the structure of a network device security service enhancement system provided in the third embodiment of this application. The third embodiment of this application provides a network device security service enhancement system 30, including a network management device 301 and at least one network device 302 connected to the network management device 301. Each network device 302 is configured to: determine whether a proactive network disconnection isolation policy is configured locally when the network device 302 is in a disconnected state; wherein the proactive network disconnection isolation policy is used to guide the network device 302 to proactively disconnect or isolate target devices connected to the network device 302 to refuse to forward service packets of the target devices; if so, execute the service forwarding task of the network device 302 according to the proactive network disconnection isolation policy; if not, execute the service forwarding task according to the basic service forwarding policy of the network device 302; wherein the basic service forwarding policy is used to guide the network device 302 to forward service packets of each device connected to the network device 302; and run additional security services locally on the network device 302; wherein the additional security services include one or more of the following: device network management service, device security protection service, log and alarm service, and network management recovery service.
[0148] The specific implementation process of the functions and roles of each network device 302 in the above system can be found in the implementation process of the corresponding steps in the above method, and will not be repeated here.
[0149] Please refer to Figure 4 , Figure 4This is a schematic diagram of the structure of an electronic device provided in the fourth embodiment of this application. The fourth embodiment of this application provides an electronic device 40, including a processor 401, a memory 402, and a computer program stored in the memory 402 and configured to be executed by the processor 401; when the processor 401 executes the computer program, it implements the method described in the first embodiment of this application and can achieve the same beneficial effects.
[0150] When the processor 401 reads a computer program from the memory 402 via the bus 403 and executes the computer program, it can implement any of the methods described in the first embodiment of this application.
[0151] Processor 401 can process digital signals and can include various computing architectures. For example, it can be a complex instruction set computer architecture, a reduced instruction set computer architecture, or an architecture that implements multiple instruction set combinations. In some examples, processor 401 can be a microprocessor.
[0152] Memory 402 can be used to store instructions executed by processor 401 or data related to the execution of instructions. These instructions and / or data may include code for implementing some or all of the functions of one or more modules described in the embodiments of this application. The processor 401 of this disclosure embodiment can be used to execute instructions in memory 402 to implement the method described in the first embodiment of this application. Memory 402 includes dynamic random access memory, static random access memory, flash memory, optical memory, or other memories well known to those skilled in the art.
[0153] The fifth embodiment of this application provides a computer program product, which includes instructions that, when executed by a computer, cause the computer to perform the method described in the first embodiment of this application and achieve the same beneficial effects.
[0154] The methods described in the first embodiment of this application can be implemented, in whole or in part, by software, hardware, firmware, or any combination thereof. When implemented in software, they can be implemented, in whole or in part, in the form of a computer program product. A computer program product includes one or more computer programs or instructions. When the computer program or instructions are loaded and executed on a computer, the processes or functions described in the various embodiments of this application are performed, in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, a network device, a user equipment, a core network device, an OAM (Open Application Model), or other programmable devices.
[0155] Computer programs or instructions can be stored in or transferred from one computer-readable storage medium to another. For example, a computer program or instructions can be transferred from one website, computer, server, or data center to another via wired or wireless means. A computer-readable storage medium can be any usable medium that a computer can access, or a data storage device such as a server or data center that integrates one or more usable media. Usable media can be magnetic media, such as floppy disks, hard disks, and magnetic tapes; optical media, such as digital video discs; or semiconductor media, such as solid-state drives. The computer-readable storage medium can be volatile or non-volatile, or may include both types.
[0156] The sixth embodiment of this application provides a computer-readable storage medium, which includes a stored computer program; wherein, when the computer program is running, it controls the device where the computer-readable storage medium is located to perform the method described in the first embodiment of this application, and can achieve the same beneficial effects.
[0157] In summary, this application provides a method, system, device, and program product for enhancing network device security services. The method is applied to a network device; the method includes: when the network device is in a managed state, determining whether the network device has a locally configured active network disconnection isolation policy; wherein, the active network disconnection isolation policy guides the network device to actively disconnect or isolate target devices connected to the network device to refuse forwarding the target devices' service packets; if so, executing the network device's service forwarding task according to the active network disconnection isolation policy; if not, executing the service forwarding task according to the network device's local basic service forwarding policy; wherein, the basic service forwarding policy guides the network device to forward service packets from various devices connected to the network device; and running additional security services locally on the network device; wherein, the additional security services include one or more of device network management services, device security protection services, log and alarm services, and network management recovery services. This application embodiment pre-configures basic service forwarding policies and one or more additional security services from among device network management services, device security protection services, log and alarm services, and network management recovery services locally on the network device, and customizes and configures proactive network disconnection isolation policies. After the network device is disconnected from management, if a proactive network disconnection isolation policy is configured locally, it will execute local service forwarding tasks according to the proactive network disconnection isolation policy; if no proactive network disconnection isolation policy is configured locally, it will execute local service forwarding tasks according to the basic service forwarding policy and run additional security services locally. This addresses the risk of data leakage and other problems caused by the inability to proactively disconnect and isolate network devices after disconnection from management. It supports adding proactive network disconnection isolation policies to the network device, prioritizing the execution of service forwarding tasks according to the proactive network disconnection isolation policy, refusing to forward service packets from disconnected or isolated devices, and adding and configuring additional security services to ensure the comprehensiveness and availability of the local processing mechanism of the network device. This strengthens the security services of the network device from multiple aspects and ensures that the risks after the network device is disconnected from management are controllable.
[0158] In the several embodiments provided in this application, it should be understood that the disclosed apparatus and methods can also be implemented in other ways. The apparatus embodiments described above are merely illustrative; for example, the flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of apparatus, methods, and computer program products according to various embodiments of this application. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than those marked in the drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram and / or flowchart, and combinations of blocks in block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or action, or using a combination of dedicated hardware and computer instructions.
[0159] In addition, the functional modules in the various embodiments of this application can be integrated together to form an independent part, or each module can exist independently, or two or more modules can be integrated to form an independent part.
[0160] If the aforementioned functions are implemented as software functional modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0161] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. A method for enhancing network device security services, characterized in that, Applied to network devices; the method includes: When the network device itself is in a disconnected state, determine whether the network device has a proactive network disconnection isolation policy configured locally; wherein, the proactive network disconnection isolation policy is used to guide the network device to proactively disconnect or isolate the target device connected to the network device, so as to refuse to forward the service packets of the target device; If so, the network device's service forwarding task is executed according to the proactive network disconnection isolation policy; If not, the service forwarding task is executed according to the basic service forwarding policy of the network device; wherein, the basic service forwarding policy is used to guide the network device to forward service packets of each device connected to the network device; Run additional security services locally on the network device; wherein, the additional security services include one or more of the following: device network management service, device security protection service, log and alarm service, and network management recovery service.
2. The method according to claim 1, characterized in that, The method further includes: Obtain network connectivity status monitoring results and device management function monitoring results sent by the network management device; wherein, the network connectivity status monitoring results indicate whether the network device is connected to the network management device, and the device management function monitoring results indicate whether the management function of the network management device is operating normally; If the network connectivity monitoring result indicates that the network device is connected to the network management device, and the device management function monitoring result indicates that the management function of the network management device is operating normally, then it is determined that the network device itself is in a managed state. If the network connectivity monitoring result indicates that the network device is not connected to the network management device, or the device management function monitoring result indicates that the management function of the network management device is malfunctioning, then the network device itself is determined to be in a disconnected state.
3. The method according to claim 2, characterized in that, The acquisition of network connectivity status monitoring results and device management function monitoring results sent by the network management device includes: In response to a ping request sent by the network management device, verify whether the source IP address carried in the ping request is the same as the IP address of the target network management device stored locally by the network device; If the source IP address carried in the ping request is the same as the IP address of the target network management device, a ping response is returned to the network management device; otherwise, the ping request is discarded, so that the network management device can send the network connectivity status monitoring result to the network device by determining whether the ping request has timed out. In response to the encrypted management request sent by the network management device, the system verifies whether the identity information carried in the encrypted management request is the same as the identity information of the target network management device, and verifies whether the remote management command carried in the encrypted management request is a legitimate command. If the identity information carried in the encryption management request is the same as the identity information of the target network management device, and the remote management instruction carried in the encryption management request is a valid instruction, then an encryption management response is returned to the network management device; otherwise, the encryption management request is discarded, so that the network management device can send the device management function monitoring result to the network device by determining whether the encryption management request has timed out.
4. The method according to claim 1, characterized in that, The step of executing the service forwarding task of the network device according to the active network disconnection isolation policy includes: For each device connected to the network device, determine whether the current device meets the triggering conditions of the proactive network disconnection and isolation policy; wherein, the triggering conditions include one or more of the following: the device is under security threat, the device is performing an unauthorized operation, and the device is malfunctioning; If the conditions are met, the current device will be used as the target device for network disconnection or isolation according to the active network disconnection and isolation policy, and the service packets of the target device will be refused to be forwarded. If the conditions are not met, the service packets of the current device are forwarded according to the basic service forwarding policy.
5. The method according to claim 1, characterized in that, The additional security services include device network management services; the additional security services running locally on the network device include: The network management device responds to local management commands input by the management user through its local network management protocol and / or its own network management interface, and executes network management tasks. The network management protocol includes the SNMP protocol, and the network management interface includes one or more of Telnet, SSH, and Web interfaces.
6. The method according to claim 1, characterized in that, The additional security services include device security protection services; the additional security services running locally on the network device include: The network device performs its security protection tasks according to its local security protection policy; wherein the security protection policy includes one or more of the following: device access control policy, device attack protection policy, and traffic redirection control policy.
7. The method according to claim 1, characterized in that, The additional security services include logging and alerting services; The additional security services that run locally on the network device include: Generate system logs for the network device and store the system logs locally on the network device; According to the local alarm processing policy of the network device, a target alarm message is sent; wherein, the target alarm message is used to indicate that the network device is in a dismantled state.
8. The method according to claim 1, characterized in that, The additional security services include network management and recovery services; the additional security services running locally on the network device include: The network management recovery task of the network device is executed according to the network management recovery policy configured locally on the network device, so as to restore the network management device's management of the network device.
9. The method according to any one of claims 1 to 8, characterized in that, The network devices include one or more of switches, routers, firewalls, and servers.
10. A network device security service enhancement system, characterized in that, It includes a network management device and at least one network device connected to the network management device; each of the at least one network device is used for: When the network device itself is in a disconnected state, determine whether the network device has a proactive network disconnection isolation policy configured locally; wherein, the proactive network disconnection isolation policy is used to guide the network device to proactively disconnect or isolate the target device connected to the network device, so as to refuse to forward the service packets of the target device; If so, the network device's service forwarding task is executed according to the proactive network disconnection isolation policy; If not, the service forwarding task is executed according to the basic service forwarding policy of the network device; wherein, the basic service forwarding policy is used to guide the network device to forward service packets of each device connected to the network device; Run additional security services locally on the network device; wherein, the additional security services include one or more of the following: device network management service, device security protection service, log and alarm service, and network management recovery service.
11. An electronic device, characterized in that, It includes a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor; when the processor executes the computer program, it implements the method according to any one of claims 1 to 9.
12. A computer program product, characterized in that, The computer program product includes instructions that, when executed by a computer, cause the computer to perform the method according to any one of claims 1 to 9.
Citation Information
Patent Citations
Business response method and device, equipment, storage medium and program product
CN118713987A
Security isolation exchange method and system for network data exception
CN120658507A