Network security terminal

By designing network security terminals on enterprise intranets, data collection and collaborative processing from multiple IP addresses are achieved. By utilizing deep learning and situational awareness technologies, the problem of insufficient real-time monitoring in enterprise intranet terminal security management is solved, thereby improving network security defense performance and information security.

CN121125237APending Publication Date: 2025-12-12山东省地质矿产勘查开发局第一地质大队(山东省第一地质矿产勘查院)
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511304071.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-12
Publication Date
2025-12-12

AI Technical Summary

Technical Problem

The existing security management of enterprise intranet terminals lacks real-time monitoring of network interfaces and different data access points of terminals, leading to network security risks caused by unauthorized operations and illegal intrusions, and increasing the risk of information security leaks.

Method used

Design a network security terminal that includes a network security inspection module, an analysis module, a collaboration module, an operation module, an antivirus module, and a management module. It can monitor and defend against network threats in real time by collecting and collaboratively processing data from multiple IP addresses, and uses deep learning and situational awareness technologies for security protection.

Benefits of technology

It effectively improves the performance of large-scale network security defense, reduces the risk of information leakage, and enhances the security of enterprise internal networks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121125237A_ABST
    Figure CN121125237A_ABST
Patent Text Reader

Abstract

The invention provides a network security terminal, which belongs to the technical field of network security equipment and is characterized in that a network security check module, a network security analysis module, a network security collaboration module and a network security management module are arranged, a plurality of IP addresses in a plurality of networks are subjected to data acquisition, and the acquired data are subjected to comparison and collaboration processing; dynamic network data packets are effectively collected, and when an alarm event occurs, security protection is performed through data interaction of a plurality of IP addresses, so that the security defensive performance of a large-scale network is effectively improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The application belongs to the technical field of network security devices, and relates to a network security terminal. BACKGROUND

[0002] The current human resource information management system includes functions such as system login, personal center, password modification, leave, system homepage, employee management, department management, salary management, attendance management, role management, menu management, and has a relatively perfect security defense system in a wide area network. Security hardware such as a protective wall is deployed at the network entrance, and under the monitoring and defense of these security devices, network threats from the outside are greatly reduced. However, in the enterprise internal LAN, although some enterprises have established corresponding security protection systems, they do not have good protection effect in actual use. And the conventional network security defense is mostly concentrated in the gateway level and the defense of the network boundary, and the access data volume and the safety management operation specification supervision of the interface of the enterprise internal network data are less, which easily leads to the weak protection layer of the internal network, and the problems such as system vulnerability and illegal software access are prone to occur.

[0003] The security management of the existing enterprise internal network terminal mostly adopts the security management of the network resources obtained by the terminal, and the centralized management of various risks that the terminal network may face is reduced by constructing a security risk system to prevent security accidents from occurring in the terminal access network resources. However, in the specific security management process, the flow of different access points of the network interface and the data of the terminal is not monitored in real time, which leads to the network security hidden trouble problem caused by the illegal operation of the enterprise internal network user and other information illegal intrusion, increases the risk of enterprise information security leakage, and causes huge economic loss. SUMMARY

[0004] In order to solve the technical problems in the background art, the application provides a network security terminal, which comprises a network security checking module, a network security analysis module, a network security cooperation module, a network security running module, a network security antivirus module and a network security management module. The network security checking module detects data and sends the obtained address to the network security analysis module. The network security analysis module processes and analyzes the data to obtain a data analysis result and sends the result to the network security cooperation module. The network security cooperation module matches the analysis result with information of a database to obtain a risk coefficient and sends the result to the network security running module. The network security running module obtains a running strategy, issues an alarm and executes the running strategy when network intrusion occurs. The network security antivirus module performs antivirus processing on data with a high risk coefficient. The network security management module supervises and manages the running of each module.

[0005] Further, the network security inspection modules are arranged at different positions in the network, and are used for cooperative data collection and sending of the type and IP address of the detection position corresponding to the detection event.

[0006] Further, the network security inspection module comprises a cooperative data collection module and an intrusion detection management module connected with each other, the cooperative data collection module is used for cooperative collection of intrusion detection data and vulnerability scanning system data, and cooperative collection of intrusion detection data and virus killing system data; the intrusion detection management module comprises a communication unit and a response and test unit, the communication unit receives an alarm event of the cooperative data collection unit, and sends the alarm event to the network security analysis module; the response and test unit is used for obtaining an IP address of the position, and obtaining real-time running data and historical running data under the IP address, and transmitting the real-time running data and the historical running data to the network security analysis module through the communication unit, and receiving and running a response instruction issued by the network security cooperative module.

[0007] Further, the network security analysis module is connected with the network security inspection module, and is used for cooperative analysis of the data collected by the network security inspection modules.

[0008] Further, the network security analysis module comprises a learning unit used for deep learning of a plurality of intrusion events, a detection data acquisition unit used for obtaining detection events and IP addresses, a detection point data comparison unit used for comparing the obtained detection event data with security events corresponding to the IP addresses, a mixed list unit used for making a list of the obtained detection events and the corresponding security events and generating a network log, and an error correction and anomaly checking unit used for performing abnormality checking on the list content made by the learning unit.

[0009] Further, the network security cooperative module is connected with the network security analysis module, and is used for obtaining the analysis result of the network security analysis module and performing defense based on network security situation awareness, and timely controlling the running of the network security module.

[0010] Further, the network security cooperative module comprises an intrusion detection and firewall cooperative unit, a network security running module, an intrusion detection and switch cooperative unit, a network security killing module, and an intrusion detection and honeypot cooperative unit, and performs defense based on network security situation awareness.

[0011] The present application has the following advantages: The application provides a network security terminal, through the setting of a network security checking module, a network security analysis module, a network security cooperation module and a network security management module, data collection is carried out on multiple IP addresses in multiple networks, and the collected data is compared and cooperatively processed, dynamic network data packets are effectively collected, and when an alarm event occurs, security protection is carried out through data interaction of multiple IP addresses, and large-scale network security defense performance is effectively improved.

[0012] Advantages of the additional aspects of the application will be partially given in the following description, partially will become obvious from the following description, or will be known by the practice of the application. BRIEF DESCRIPTION OF DRAWINGS

[0013] The drawings constituting a part of the specification of the application are used to provide further understanding of the application, the illustrative embodiments of the application and the description thereof are used to explain the application, and do not constitute improper limitation on the application.

[0014] Figure 1 It is a whole structure schematic view of a network security terminal of the application. DETAILED DESCRIPTION

[0015] The application will be further described below in combination with the drawings and embodiments.

[0016] It should be pointed out that the following detailed description is all exemplary, and is intended to provide further description of the application. Unless otherwise specified, all technical and scientific terms used in the embodiments have the same meaning as that generally understood by the ordinary skilled in the art to which the application belongs.

[0017] It should be noted that the terms used herein are only for the purpose of describing specific embodiments, and are not intended to limit the exemplary embodiments according to the application. As used herein, unless the context clearly indicates otherwise, the singular form is also intended to include the plural form, and in addition, it should be understood that when the terms contain, and / or, include are used in the specification, it indicates the presence of the features, steps, operations, devices, components and / or their combinations.

[0018] Embodiment one, as Figure 1As shown, the embodiment provides a network security terminal, comprising: a network security inspection module, a network security analysis module, a network security cooperation module, a network security running module, a network security antivirus module and a network security management module; the network security inspection module detects data and sends the address obtained to the network security analysis module, the network security analysis module processes and analyzes the data to obtain a data analysis result and sends it to the network security cooperation module; the network security cooperation module performs defense based on network security situation awareness and sends defense instructions to the network security running module; the network security running module obtains a running strategy, issues an alarm when network intrusion occurs and executes the running strategy; the network security antivirus module performs antivirus processing on data with a higher risk coefficient; and the network security management module supervises and manages the operation of each module.

[0019] The network security inspection module is arranged at multiple different positions in the network and is used for cooperative data collection and sending of the type and IP address of the detection position corresponding to the detection event. The network security inspection module comprises a cooperative data collection module and an intrusion detection management module connected with each other. The cooperative data collection module is used for cooperative collection of intrusion detection data and vulnerability scanning system data, and cooperative collection of intrusion detection data and virus killing system data. The intrusion detection management module comprises a communication unit and a response and test unit. The communication unit receives an alarm event of the cooperative data collection unit and sends the alarm event to the network security analysis module. The response and test unit is used for obtaining the IP address of the position and obtaining real-time running data and historical running data under the IP address and transmitting them to the network security analysis module through the communication unit. Meanwhile, the response and test unit receives and runs a response instruction issued by the network security cooperation module. The response instruction comprises termination of the current connection, automatic configuration of a firewall access control chain table, automatic configuration of a router access control chain table and automatic configuration of a switch access control chain table.

[0020] The network security analysis module is connected with the network security inspection module and is used for summarizing and cooperative analysis of the data collected by the multiple network security inspection modules. The network security analysis module comprises a learning unit used for deep learning of multiple intrusion events, a detection data acquisition unit used for acquisition of detection events and IP addresses, a detection point data comparison unit used for comparison of the acquired detection event data and the security events corresponding to the IP addresses, a mixed list unit used for making a list of the acquired detection events and the corresponding security events and generating a network log, and an error correction and anomaly checking unit used for abnormality checking of the list content made according to the deep learning content of the learning unit. The detection data acquisition unit is in communication connection with the network security inspection module. The detection point data comparison unit is connected with the detection data acquisition unit and the network security management module respectively. The mixed list unit is connected with the detection point data comparison unit. The error correction and anomaly checking unit is connected with the mixed list unit and the network security cooperation module respectively.

[0021] The observation sequence and state transition matrix are needed to aggregate the data collected by multiple network security check modules and to perform collaborative analysis. This paper proposes an improved method, which mainly includes two points: first, based on the statistical characteristics of the alarm, the concept of alarm quality is proposed, and the observation sequence is obtained according to the alarm quality, which improves the effectiveness of the data source; second, based on the game process of security events and protective measures, a method for determining the state transition matrix is proposed, and it is modified by combining the probability of attack success, which improves the effectiveness of the state transition matrix.

[0022] Network security check modules usually generate a large amount of alarm information, a large proportion of which is false or irrelevant. The large number of alarms and irrelevant alarms make it difficult to obtain HMM observation vectors. In order to more clearly define the effective degree of alarm representing network security characteristics, a new concept of alarm quality is introduced, which is based on the idea of quality factor. The alarm quality is defined as the effective degree of alarm representing network security characteristics. The higher the quality of the alarm, the more effectively it represents the security characteristics of the network. In order to quantify the alarm quality, the alarm is modeled as a Cartesian product:

[0023] Where: represents the attributes of the alarm, represents the value range of attribute . The attributes of the alarm include both the basic attributes of the alarm, such as the source IP, destination IP, type, and generation time, and the statistical characteristics of the alarm, such as the frequency of alarm occurrence, alarm criticality, and alarm severity. In each sampling period, the observation vector of HMM is obtained by selecting the alarm with the highest quality. The observation vector obtained according to the alarm quality can effectively improve the data source and improve the evaluation accuracy.

[0024] The network security coordination module is connected with the network security analysis module, which is used to obtain the analysis results of the network security analysis module and to control the operation of the network security module in a timely manner. The network security coordination module includes an intrusion detection and firewall coordination unit, a network security operation module, an intrusion detection and switch coordination unit, a network security antivirus module, an intrusion detection and honeypot coordination unit, and a defense based on network security situation awareness.

[0025] In actual network attacks, the scanning of malicious adversaries is usually scanning all addresses of a certain address block, which will send a large number of data packets to the network in a short time. According to this feature, when the honeypot deployed in the overall defense mechanism receives the data packet, it will send it to the control center. If the destination address of the message or the destination address of the message is not in the window period, the address is non-active, and the data packet is classified as a suspicious data packet. The scanning attack strategy analysis module in the control center uses a network security situation awareness algorithm based on scanning traffic entropy to analyze the scanning strategy of malicious adversaries in real time, and triggers different active defense strategies to realize real-time awareness of the network security situation. Random variable The value set of the random variable is , and the probability distribution of the value is independent distribution, where n is the number of suspicious data packets, and the information entropy of the variable is as follows: Based on information entropy, the behavior characteristics of different scanning strategies are analyzed to perceive different scanning strategies, which can effectively perceive the network security situation and the direction of attack behavior.

[0026] In the SDN environment, if the end node tries to access the end node , it is assumed that the host owns the domain name of and the IP address of the DNS server. The data packet sent by the source host enters the first switch of the ADSS network, which is called the source switch, and the last switch that leaves the ADSS network is called the destination switch. The defense process based on network security situation awareness is as follows: The end node sends a domain name resolution request to the server, requesting the IP address of the end node ; The DNS server responds to the domain name resolution request and sends the domain name resolution response to the control center. The control center randomly selects one for , replaces the real address in the domain name resolution response with , and opens a window period for .

[0027] The control center forwards the domain name resolution response to the end node .

[0028] The end node gets the virtual address , and uses its own address as the source address,​​ As the destination address to Send IP packet, because at this time address forwarding switch has no corresponding flow rules can route this flow, address forwarding switch will send the data packet to the total control center.

[0029] The total control center checks whether the destination IP is in the window period, if in the window period, according to the policy randomly selects Assign , and generate flow rules to Replace . The total control center updates the flow table rules, and according to, reverse order adds, order deletes, the order of deployment to the routing node on the forwarding path.

[0030] In the source switch flow rule modification end node Send to the end node The source address of the data packet, replace the source address with And forward.

[0031] Network routing node according to flow table rules for forwarding.

[0032] When the destination switch receives the data packet, replace the destination address with the The And forward.

[0033] The end node Can receive the data packet, and take As the source address, As the destination address to answer the data packet.

[0034] Switch to modify the source address of the answer data packet, replace the source address with the end node The And forward.

[0035] Switch to receive the answer data packet, replace the destination address with the end node The And forward, to the end node , the end node Can normally receive the answer data packet.

[0036] Unlike the existing network communication protocol, the end node in the ADSS network must first make a domain name resolution request for the destination host before communicating, and obtain the address of the destination host for this communication. The DNS server in the ADSS network responds to the request and sends a response packet to the control center. The control center replaces the real address information carried in the corresponding data packet with virtual address information, and answers the domain name resolution request and issues a flow rule. In the communication process, the address conversion switch modifies the source IP address and destination IP address of the data packet according to the flow rule, and realizes end information conversion.

[0037] The control center writes a smaller value into the TTL value in the domain name request response, so as to ensure that the host accesses again , the domain name resolution must be performed again. In the entire process, and the real IP do not need to be changed, and both parties only know the conversion end information of the other party, and the transmission network is responsible for the conversion of and . In each such access process, the control center randomly allocates to the host , so that the destination IP of the host when accessing changes every time.

[0038] In order to prevent the problem of data flow unreachable caused by inconsistent flow table updates in the address conversion process, the ADSS adopts the update method of "adding in reverse order and deleting in order", and the flow table update rule is as follows: : It means that the current address conversion switch does not belong to the forwarding switch set in the current time period, nor does it belong to the forwarding switch set in the next time period. Therefore, it will not receive any data packet.

[0039] : It means that the current address conversion switch only belongs to the forwarding switch set in the next time period. Therefore, such switches will only forward data packets in the next time period according to the updated flow table rule.

[0040] : It means that the current address conversion switch belongs to both the forwarding switch in the current time period and the forwarding switch set in the next time period. Therefore, such address conversion switches will forward according to the corresponding routing table item.

[0041] It indicates that the current address conversion switch is only a forwarding switch set belonging to the current time period. Therefore, the address conversion switch only receives the data packets in the current time period and forwards them according to the original routing table. In addition, when the address conversion switch does not receive data packets after a network loop time, it is proved that all data packets in the current window period have been forwarded.

[0042] The network security operation module includes a static analysis layer and a dynamic analysis layer. The static analysis layer includes a network security check module that acquires a router operation strategy and analyzes network security, and sends an alarm and executes the operation strategy when network intrusion occurs. The dynamic analysis layer includes a network security check module that sends an attack behavior to a router to block the connection between a host and the outside and generates an attack behavior log when the attack behavior is found.

[0043] The network security antivirus module includes a data cooperative virus detection layer and a response cooperative antivirus layer. The data cooperative virus detection layer includes a network security check module that sends a large number of test data segments to a host and receives the response state of the host. The response cooperative antivirus layer includes a network security check module that acquires and executes a host original system forced start program when the host executes an antivirus instruction, and the network security check module sends a large number of RST packets to block the established connection. The intrusion detection and honeypot cooperative unit includes a network security check module that detects data segments with a similarity of 90-100% at a detection point of the network security check module based on decoy data shared by a network security management module, and sends a detection event to a network security analysis module in time, and the network security check module blocks the established connection.

[0044] The network security management module is used for storing security event types and IP addresses corresponding to each network security check module and controlling system operation. The network security management module is connected with a network security analysis module and a network security cooperative module.

[0045] The above-described large-scale network security defense system based on cooperative intrusion detection collects data from multiple IP addresses in multiple networks through the setting of a network security check module, a network security analysis module, a network security cooperative module, and a network security management module, compares and cooperatively processes the collected data, effectively collects dynamic network data packets, and performs security protection through data interaction of multiple IP addresses when an alarm event occurs, thereby effectively improving the large-scale network security defense performance.

[0046] The above only describes the preferred embodiments of the present application and is not used to limit the present application. For those skilled in the art, the present application can have various modifications and changes. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application.

Claims

1. A network security terminal, characterized in that, include: The network security inspection module, network security analysis module, network security collaboration module, network security operation module, network security antivirus module, and network security management module are all included. The network security inspection module detects the data and obtains the address before sending it to the network security analysis module. The network security analysis module processes and analyzes the data to obtain the data analysis results, which are then sent to the network security collaboration module. The network security collaboration module defends based on network security situational awareness and sends defense commands to the network security operation module; the network security operation module obtains the operation policy, issues an alarm and executes the operation policy when a network intrusion occurs; the network security antivirus module performs antivirus processing on data with a high risk factor; and the network security management module supervises and manages the operation of each module.

2. A network security terminal as described in claim 1, characterized in that, The network security inspection module is set up in multiple different locations in the network to perform collaborative data collection and send the IP address corresponding to the type of detection event and the detection location.

3. A network security terminal as described in claim 2, characterized in that, The network security inspection module includes an interconnected collaborative data acquisition module and an intrusion detection management module. The collaborative data acquisition module is used to collaboratively collect intrusion detection data and vulnerability scanning system data, and collaboratively collect intrusion detection data and virus scanning system data. The intrusion detection management module includes a communication unit and a response and testing unit. The communication unit receives alarm events from the collaborative data acquisition unit and sends the alarm events to the network security analysis module. The response and testing unit is used to obtain the IP address of the current location, acquire real-time and historical operating data under that IP address, and transmit them to the network security analysis module through the communication unit. At the same time, it receives and executes response instructions issued by the network security collaboration module.

4. A network security terminal as described in claim 1, characterized in that, The network security analysis module, connected to the network security inspection module, is used to aggregate data collected by multiple network security inspection modules and perform collaborative analysis.

5. A network security terminal as described in claim 4, characterized in that, The network security analysis module includes a learning unit for deep learning of various intrusion events, a detection data acquisition unit for acquiring detection events and IP addresses, a detection point data comparison unit for comparing the acquired detection event data with the security events corresponding to the IP addresses, a hybrid list unit for creating a list of the acquired detection events and corresponding security events and generating network logs, and an error correction and anomaly detection unit for checking the contents of the created list based on the deep learning content of the learning unit. The detection data acquisition unit is communicatively connected to the network security inspection module, the detection point data comparison unit is connected to the detection data acquisition unit and the network security management module, the hybrid list unit is connected to the detection point data comparison unit, and the error correction and anomaly detection unit is connected to the hybrid list unit and the network security collaboration module.

6. A network security terminal as described in claim 1, characterized in that, The network security collaboration module is connected to the network security analysis module to obtain the analysis results from the network security analysis module and to control the operation of the network security module in a timely manner.

7. A network security terminal as described in claim 6, characterized in that, The network security collaboration module includes an intrusion detection and firewall collaboration unit, a network security operation module, an intrusion detection and switch collaboration unit, a network security antivirus module, and an intrusion detection and honeypot collaboration unit, which performs defense based on network security situational awareness.