Cloud Host Anti-Cracking System Using Automated Firewall Blocking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud hosts are vulnerable to brute-force cracking attacks due to the lack of systematic security management, requiring high user expertise to identify and block suspicious IP addresses effectively.

Innovation Solution

An anti-cracking method and system that automatically obtains system logs, identifies suspicious IPs based on consecutive login failures, adds blocking rules to the firewall, and tracks attacker IPs to implement timed blocking and alert mechanisms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual log checking and firewall rule setting is used to block suspicious IPs, then security protection against brute-force cracking is achieved, but high user professional ability is required and it is not suitable as a general solution

Engineering Contradiction:
Improvesecurity protectionVSAvoiduser operation complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system automatically monitors login logs, identifies suspicious IP addresses through consecutive failure analysis, and configures firewall blocking rules without requiring user intervention. The anti-cracking system performs self-diagnosis and self-protection, transforming manual security management into an automated self-service process that eliminates the need for user professional knowledge while maintaining reliable security protection

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system continuously monitors login attempts, analyzes failure patterns, and adjusts blocking strategies based on the identified attack behavior. By establishing a feedback loop that tracks login successes and failures, the system dynamically updates its security responses, automatically strengthening protection when cracking attempts are detected and adjusting based on the effectiveness of blocking actions

Inventive Principle:
Principle #23Feedback

2Productivity

If automated tracking and blocking of attacker IPs is implemented, then brute-force cracking is resisted proactively with minimal system resource usage, but system complexity increases

Engineering Contradiction:
Improveattack resistance efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system pre-configures blocking rules and thresholds before attacks occur, establishing automated response mechanisms in advance. By setting up the tracking and blocking framework beforehand with predefined criteria for identifying suspicious activity, the system can immediately respond to brute-force cracking attempts without requiring complex real-time decision-making, thus maintaining low system complexity while achieving high attack resistance efficiency

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The anti-cracking system divides the security monitoring process into distinct functional modules: log acquisition, failure analysis, IP tracking, and blocking rule management. By segmenting the complex security task into smaller, independent components with clear interfaces, the system reduces overall complexity while maintaining high productivity in resisting brute-force cracking attacks

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11470043B2Anti-cracking method and system for a cloud host, as well as terminal device
Publication Date: 2022.10.11 BEIJING BAIDU NETCOM SCI & TECH CO LTD
  • US11470043B2 patent drawing
  • US11470043B2 patent drawing
  • US11470043B2 patent drawing

AI summary

An anti-cracking method and system for a cloud host, as well as a terminal device are provided according to the disclosure. The method includes: obtaining system logs of the cloud host; determining an IP which fails to log in the cloud host according to the system logs as a suspicious IP; tracking and determining the suspicious IP to be an attacker IP according to the number of times of consecutive login failure of the suspicious IP; and adding a first blocking rule to firewall settings of the cloud host; wherein the first blocking rule instructs to block a login operation of the attacker IP during a first preset blocking time. With the anti-cracking method for a cloud host of the disclosure, the brute-force cracking can be prevented proactively in a timely manner with only very few system resources occupied.