CN109922030A - Global network access control system and method based on Android device - Google Patents

Global network access control system and method based on Android device Download PDF

Info

Publication number
CN109922030A
CN109922030A CN201711331344.0A CN201711331344A CN109922030A CN 109922030 A CN109922030 A CN 109922030A CN 201711331344 A CN201711331344 A CN 201711331344A CN 109922030 A CN109922030 A CN 109922030A
Authority
CN
China
Prior art keywords
module
address
network
white list
network access
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Granted
Application number
CN201711331344.0A
Other languages
Chinese (zh)
Other versions
CN109922030B (en
Inventor
席建业
孙超
张泉
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Nanjing Lead Mdt Infotech Ltd
Original Assignee
Nanjing Lead Mdt Infotech Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Nanjing Lead Mdt Infotech Ltd filed Critical Nanjing Lead Mdt Infotech Ltd
Priority to CN201711331344.0A priority Critical patent/CN109922030B/en
Publication of CN109922030A publication Critical patent/CN109922030A/en
Application granted granted Critical
Publication of CN109922030B publication Critical patent/CN109922030B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Landscapes

  • Data Exchanges In Wide-Area Networks (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

The present invention relates to network communication technology fields, more particularly to a kind of global network access control system and method based on Android device, including backstage configuration module inventory, authorization module, interface module, white list writing module, dns resolution redirection module, network request parsing module, network access interception module and data server are issued automatically.The invention enables the automatic acquisition white lists in mobile device backstage, carry out network-control automatically;It supports general domain name to match simultaneously, greatly reduces workload, improve back-stage management working efficiency;Immediately the problem of request parsing immediately, solves performance and efficiency that high-volume concentrates parsing, lowers system resource and occupies, while also making CDN network ip address change is solved.Intervene without administrative staff, efficiently realizes the information security requirement of mobile device global network control.

Description

Global network access control system and method based on Android device
Technical field
The present invention relates to network communication technology field more particularly to a kind of global network access based on Android device Control system and method.
Background technique
With popularizing for mobile Internet, occur a large amount of mobile application usage scenario in every profession and trade, mobile device Use all trades and professions such as quick push and mobile office, mobile government, wisdom education.Using mobile intelligent terminal, can effectively disappear Except place, the limitation of time, the work and study efficiency of government, school, enterprise, and the convenience used are greatly improved;In this Many problems are also brought simultaneously, especially on the Web vector graphic of special equipment, based on the considerations of information security, and prevent from disliking Meaning software corruption, it is more more and more intense for the NS software demand of mobile device, the security management and control of mobile device is mentioned Higher requirement out.
The mobile device NS software of existing market mainstream, there are mainly two types of, one is pass through special browser, control Browser processed accesses network address, and major defect: 1) can only control special browser, can not carry out network control to third party's browser System.2) webpage embedded for other study, job applications can not control.Another kind is simply by operating system Iptables rule carries out global limitation, major defect: 1) being only capable of the setting address ip rule control.2) to the white list of domain name kind Need it is pre- be first converted into ip, inefficiency, and the IP address of variation this kind of for CDN network is had no way of doing it.3) with white name Single increases, and rule write-in execution efficiency is lower and lower.4) Extensive domain name analysis is not supported, back-stage management needs to add a large amount of quasi- True domain name white list address.Two schemes can not all carry out safely and effectively network control for being largely distributed in outer mobile device System can not effectively manage mobile device and access illegal network address.
Summary of the invention
The present invention provides a kind of global network access control system and method based on Android device, can be to shifting The dynamic method that equipment network address white list issues automatically and equipment obtains preservation automatically, can issue pair automatically according to user right The network address white list answered is to remote equipment, and automatic to carry out network request control, reduction repetitive operation burden avoids operating mistake.
In order to achieve the object of the present invention, used technical solution is: the global network access based on Android device Control system, including interface module, white list writing module, dns resolution redirection module are issued automatically, network request parses mould Block, network access interception module and data server issue interface module for the network address white list authorized automatically and are handed down to finger Fixed mobile device;Mobile device is written in the network address white list that white list writing module will acquire;Dns resolution redirection module will The dns resolution of network request is redirected to network request parsing module, and mobile device is requested network by network request parsing module The destination address of access and the white list of acquisition compare, and whether notice network access interception module allows to pass through, data server Save mobile equipment subscriber information and corresponding authorization white list information.
As prioritization scheme of the invention, the global network access control system based on Android device further includes backstage Configuration list module and authorization module, configuration list module offer additions and deletions in backstage, which change, looks into white list list function, authorization module needle Different mobile device models and different user are authorized, backstage configuration list module is stored in data service by authorization module Device issues interface module automatically and reads the inventory saved in data server by authorization module and be handed down to white list write-in mould Block.
As prioritization scheme of the invention, network access interception module is that android system carries iptables function mould Block and iptables add-on module ipset.
In order to achieve the object of the present invention, used technical solution is: utilizing the global network based on Android device The method that access control system is controlled, includes the following steps:
1) start dns resolution redirection module and network request parsing module automatically after mobile device starting;
2) from issuing automatically, interface module obtains newest network address white list and then mobile device is written in classification automatically;
3) mobile device when updating inventory automatically updates network address white list from the background;
4) network request to destination address is initiated in mobile device system or application;
5) dns resolution of network request is redirected to network request parsing module by dns resolution redirection module;
6) destination address and the progress of network address white list that network request parsing module accesses mobile device request network Match, if successful match, network access interception module is written into the address ip after parsing;
7) network access interception module can be reached after network request parsing, network access interception module according to have been written into Allow by rule, judge whether network request can be normal through
As prioritization scheme of the invention, the starting of dns resolution redirection module includes the following steps: in step 1)
S11. network request is redirected to network request parsing module;
S12. iptables environment is initialized, filter table is set, the dns resolution of network request is allowed to pass through;
S13. ipset table is initialized, ip address table and the address ip segment table is respectively created, while adding iptables rule, Address in two tables is allowed to allow to pass through;
S14. allow local loopback;
S15. allow to access the port outer net DNS;
S16. IPset table is created, the address ip is stored;
S17. ipset table is created, ip address field is stored;
S18. allow purpose ip all in ipset table that can access.
As prioritization scheme of the invention, classify in step 2) to network address white list, by the address ip and IP address Section write-in iptables functional module, to domain name kind address, by requesting the method for parsing comparison to be immediately written immediately Iptables functional module.
As prioritization scheme of the invention, the method classified in step 2) to network address white list, including walk as follows It is rapid:
S21. judge whether address is the address ip and IP address section by regular expression;
The address S22.ip and IP address section enter iptables rule;
S23. the white list inventory of network request parsing module (6) is written in the domain name of the non-address ip and IP address section;
S24. it before issuing the network address white list classification write-in that interface module obtains update automatically, is obtained before emptying White list and iptables rule.
As prioritization scheme of the invention, the address ip in step S21 is standard ip address format, and IP address section is standard Network segment format;The domain name of IP address section in step S23 is the Domain Name Form registering sites of standard.
As prioritization scheme of the invention, in step 6), the realization of network request parsing module (6) includes following step It is rapid:
S31. the locally specified port of network request parsing module audiomonitor;
When S32. receiving the network request that dns resolution redirection module is sent, the domain name addresses of request is taken out;
S33. domain name addresses is subjected to general domain name matching with the white list inventory having been written into line by line;
S34. the ipset table created, matching is written in the address ip for returning to the parsing of upstream dns server fitted through It is unacceptable to be not processed.
As prioritization scheme of the invention, general domain name matching includes the following steps:
S41. white list is taken out line by line;
S42. the white list character string domain name string matching of request taken out, is counted from the end of character string, if Successful match, which then compares, to be terminated.
The present invention has the effect of positive: (1) the invention enables white lists to issue automatically, convenient for management, and once-through operation is remote Journey equipment comes into force automatically, can modify at any time.
(2) control method of the invention makes mobile device backstage is automatic to obtain white list, automatic progress network control System;It supports general domain name to match simultaneously, greatly reduces workload, improve back-stage management working efficiency;Immediately request parsing immediately, solution Certainly high-volume concentrates the performance and efficiency of parsing, lowers system resource and occupies, while also making CDN network ip address change Problem is solved.Intervene without administrative staff, efficiently realizes the information security of mobile device global network control It is required that.
(3) present invention lowers systematicness for mobile device setting magnanimity iptabels rule by introducing ipset module Intercepting efficiency, and the influence to network transmission can be greatly improved with the crux of network efficiency.
Detailed description of the invention
The present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments.
Fig. 1 is the overall structure diagram of the automatic sending system of network address white list of the present invention;
Fig. 2 is the network access interception flow chart of global network access control method of the present invention;
Wherein: 1, backstage configuration list module, 2, authorization module, 3, issue interface module automatically, 4, white list mould is written Block, 5, dns resolution redirection module, 6, network request parsing module, 7, network access interception module, 8, data server.
Specific embodiment
The global network access control system based on Android device that the invention discloses a kind of, including issue and connect automatically Mouth mold block 3, white list writing module 4, dns resolution redirection module 5, network request parsing module 6, network access interception module 7 and data server 8, interface module 3 is issued automatically by the network address white list authorized is handed down to specified mobile device;White name Mobile device is written in the network address white list that single writing module 4 will acquire;Dns resolution redirection module 5 solves the DNS of network request Analysis is redirected to network request parsing module 6, the destination address that network request parsing module 6 accesses mobile device request network It is compared with the white list of acquisition, whether notice network access interception module 7 allows to pass through, and data server 8 saves mobile device User information and corresponding authorization white list information.
Global network access control system based on Android device further includes backstage configuration list module 1 and authorization mould Block 2, the offer additions and deletions of backstage configuration list module 1, which change, looks into white list list function, and authorization module 2 is directed to different mobile device models And different user is authorized, backstage configuration list module 1 is stored in data server 8 by authorization module 2, issues interface automatically Module 3 reads the inventory saved in data server 8 by authorization module 2 and is handed down to white list writing module 4.
Network access interception module 7 is that android system carries iptables functional module and iptables add-on module ipset。
The method controlled using the global network access control system based on Android device, is included the following steps:
1) start dns resolution redirection module 5 and network request parsing module 6 automatically after mobile device starting;
2) from issuing automatically, interface module 3 obtains newest network address white list and then mobile device is written in classification automatically;
3) mobile device when updating inventory automatically updates network address white list from the background;
4) network request to destination address is initiated in mobile device system or application;
5) dns resolution of network request is redirected to network request parsing module 6 by dns resolution redirection module 5;
6) destination address and the progress of network address white list that network request parsing module 6 accesses mobile device request network Match, if successful match, network access interception module 7 is written into the address ip after parsing;
7) network access interception module 7 can be reached after network request parsing, network access interception module 7 is according to having been written into With allow by rule, judge whether network request can be normal through.
The starting of dns resolution redirection module 5 includes the following steps: in step 1)
S11. network request is redirected to network request parsing module 6;It can be incited somebody to action by iptables NAT table rule The network request of 53 ports is redirected to network request parsing module 6;Or it is ordered by the ndc resolver that Android is carried Setting network request is enabled to be directed toward network request parsing module 6, (different editions Android command parameter is different).
S12. iptables environment is initialized, filter table is set, the dns resolution of network request is allowed to pass through;It will The OUTPUT chain of filter table is set as DROP.
S13. ipset table is initialized, ip address table and the address ip segment table is respectively created, while adding i ptables rule, Address in two tables is allowed to allow to pass through;
# setting OUTPUT chain is defaulted as DROP
iptables-P OUTPUT DROP
S14. allow local loopback;
iptables-A OUTPUT-s 127.0.0.1-d 127.0.0.1-j
ACCEPT
S15. allow to access the port outer net DNS;
iptables-A OUTPUT-p tcp--dport 53-j ACCEPT
iptables-A OUTPUT-p udp--dport 53-j ACCEPT
S16. IPset table is created, the address ip is stored;
ipset creat iplist hash:ip
S17. ipset table is created, ip address field is stored.
ipset creat netlist hash:net
S18. allow purpose ip all in ipset table that can access
iptables-A OUTPUT-m set--match-set iplist dst-j
ACCEPT
iptables-A OUTPUT-m set--match-set netlist dst-j ACCEPT。
The method classified in step 2) to network address white list, includes the following steps:
S21. judge whether address is the address ip and IP address section by regular expression;
The address S22.ip and IP address section enter iptables rule;
S23. the white list inventory of network request parsing module 6 is written in the domain name of the non-address ip and IP address section;
S24. it before issuing the network address white list classification write-in that interface module 3 obtains update automatically, is obtained before emptying White list and iptables rule.
The ip address format obtained in step S21 is standard ip address format, such as 10.0.123.11;IP address section format For standard network paragraph format, such as 10.0.1.0/24.
The Domain Name Form registering sites obtained in step S21 be standardized domain name format, " " not comprising domain name structure head and the tail, such as 163.com、news.sina.com。
Classify in step 2) to network address white list, iptables function mould is written into the address ip and IP address section Block avoids with for the moment domain name kind address by requesting the method for parsing comparison immediately that iptables functional module is written immediately Between parse a large amount of domain names, the performance and efficiency of NS software is greatly improved, simultaneously as every time parsing all matched, solve Certainly the problem of CDN network ip address change, the network request parsing module in the method supports general domain name matching, greatly reduces The workload of backstage personnel setting white list.And by the way that ipset module is added, solving a large amount of IP address rules causes The problem of attenuating of iptables intercepting efficiency and occupying system resources.
In step 6), the realization of network request parsing module 6 includes the following steps:
S31. the locally specified port of 6 audiomonitor of network request parsing module, audiomonitor local 127.0.0.1 designated ends Mouthful;
When S32. receiving the network request that dns resolution redirection module 5 is sent, the domain name addresses of request is taken out;
S33. domain name addresses is subjected to general domain name matching with the white list inventory having been written into line by line;
S34. the ipset table created, matching is written in the address ip for returning to the parsing of upstream dns server fitted through It is unacceptable to be not processed.
Embodiment 1
As shown in Figure 1, this implementation includes backstage configuration module inventory 1, authorization module 2, issues interface module 3 automatically, is white List writing module 4, dns resolution redirection module 5, network request parsing module 6, network access interception module 7 and data clothes Business device 8.
Backstage configuration module inventory 1 is stored in data service 8 by authorization module 2.Automatically issuing interface module 3 passes through authorization Module 2 reads the inventory that saves in data server 8, is handed down to white list writing module 4, and white list writing module 4 is by white name Single classification write-in network request parsing module 6 and network access interception module 7.Dns resolution redirection module 5 is by network request Dns resolution is redirected to network request parsing module 6, the mesh that network request parsing module 6 accesses mobile device request network Address matched with network address white list, will meet white list parsing return ip write-in network access interception module 7.Network When request eventually arrives at network access interception module 7, the final inventory of the comparison write-in of network access interception module 7 is compared, Decide whether to intercept network request.
Embodiment 2
As shown in Fig. 2, the application method of embodiment 1, comprising the following steps:
(1) mobile device initiates network request;
(2) the domain name kind network request of dns resolution is needed to be redirected to network request solution by dns resolution redirection module 5 Analyse module 6;The request of IP class can directly reach network access interception module 7.
(3) domain name of request and the white list of write-in are carried out general domain name matching by dns resolution module, and will be matched Domain name mapping result ip is written in ipset table, and general domain name matching algorithm is as follows:
S41. white list is taken out line by line;
S42. the white list character string domain name string matching of request taken out, is counted from the end of character string, if Successful match, which then compares, to be terminated.
(4) when network request reaches network access interception module 7 (iptables), network access interception module 7 is according to white The rule that list writing module 4 and dns resolution redirection module 5 are written, allows to pass through, no to the network request of matching rule Matched request will be intercepted.
Particular embodiments described above has carried out further in detail the purpose of the present invention, technical scheme and beneficial effects It describes in detail bright, it should be understood that the above is only a specific embodiment of the present invention, is not intended to restrict the invention, it is all Within the spirit and principles in the present invention, any modification, equivalent substitution, improvement and etc. done should be included in guarantor of the invention Within the scope of shield.

Claims (10)

1. the global network access control system based on Android device, it is characterised in that: including issuing interface module automatically (3), white list writing module (4), dns resolution redirection module (5), network request parsing module (6), network access interception mould Block (7) and data server (8), it is described issue automatically the network address white list that interface module (3) will authorize be handed down to it is specified Mobile device;Mobile device is written in the network address white list that the white list writing module (4) will acquire;Dns resolution is reset The dns resolution of network request is redirected to network request parsing module (6) to module (5), network request parsing module (6) will The destination address of mobile device request network access and the white list of acquisition compare, and whether notice network access interception module (7) Allow to pass through, the data server (8) saves mobile equipment subscriber information and corresponding authorization white list information.
2. the global network access control system according to claim 1 based on Android device, it is characterised in that: institute Stating the global network access control system based on Android device further includes backstage configuration list module (1) and authorization module (2), the backstage configuration list module (1) offer additions and deletions, which change, looks into white list list function, and the authorization module (2) is directed to Different mobile device models and different user are authorized, and backstage configuration list module (1) is stored in data by authorization module (2) Server (8), issue automatically interface module (3) by authorization module (2) read data server (8) in save inventory and under Issue white list writing module (4).
3. the global network access control system according to claim 2 based on Android device, it is characterised in that: institute The network access interception module (7) stated is that android system carries iptables functional module and iptables add-on module ipset。
4. the method controlled using the global network access control system described in claim 2 based on Android device, It is characterized in that: including the following steps:
1) start dns resolution redirection module (5) and network request parsing module (6) automatically after mobile device starting;
2) from the newest network address white list of interface module (3) acquisition is issued automatically, then mobile device is written in classification automatically;
3) mobile device when updating inventory automatically updates network address white list from the background;
4) network request to destination address is initiated in mobile device system or application;
5) dns resolution of network request is redirected to network request parsing module (6) by dns resolution redirection module (5);
6) destination address and the progress of network address white list that network request parsing module (6) accesses mobile device request network Match, if successful match, network access interception module (7) are written into the address ip after parsing;
7) it can be reached network access interception module (7) after network request parsing, network access interception module (7) basis has been written into With allow by rule, judge whether network request can be normal through.
5. the method controlled using the global network access control system described in claim 4 based on Android device, Be characterized in that: dns resolution redirection module (5) starting includes the following steps: in step 1)
S11. network request is redirected to network request parsing module (6);
S12. iptables environment is initialized, filter table is set, the dns resolution of network request is allowed to pass through;
S13. ipset table is initialized, ip address table and the address ip segment table is respectively created, while adding iptables rule, is allowed Address allows to pass through in two tables;
S14. allow local loopback;
S15. allow to access the port outer net DNS;
S16. IPset table is created, the address ip is stored;
S17. ipset table is created, ip address field is stored;
S18. allow purpose ip all in ipset table that can access.
6. the side controlled using the global network access control system described in claim 4 or 5 based on Android device Method, it is characterised in that: classify in step 2) to network address white list, iptables function is written into the address ip and IP address section Energy module passes through to domain name kind address and requests the method for parsing comparison immediately that iptables functional module is written immediately.
7. the method controlled using the global network access control system described in claim 6 based on Android device, Be characterized in that: the method classified in step 2) to network address white list includes the following steps:
S21. judge whether address is the address ip and IP address section by regular expression;
The address S22.ip and IP address section enter iptables rule;
S23. the white list inventory of network request parsing module (6) is written in the domain name of the non-address ip and IP address section;
S24. it before issuing the network address white list classification write-in that interface module (3) obtain update automatically, is obtained before emptying White list and iptables rule.
8. the method controlled using the global network access control system described in claim 7 based on Android device, Be characterized in that: the address ip in step S21 is standard ip address format, and IP address section is standard network paragraph format;In step S23 The domain name of IP address section is the Domain Name Form registering sites of standard.
9. the method controlled using the global network access control system described in claim 6 based on Android device, Be characterized in that: in step 6), the realization of network request parsing module (6) includes the following steps:
S31. network request parsing module (6) the locally specified port of audiomonitor;
When S32. receiving the network request that dns resolution redirection module (5) is sent, the domain name addresses of request is taken out;
S33. domain name addresses is subjected to general domain name matching with the white list inventory having been written into line by line;
S34. the ipset table created is written in the address ip for returning to the parsing of upstream dns server fitted through, matches obstructed That crosses is not processed.
10. the method controlled using the global network access control system described in claim 9 based on Android device, It is characterized by: general domain name matching includes the following steps:
S41. white list is taken out line by line;
S42. the white list character string domain name string matching of request taken out, is counted from the end of character string, if matching Successful then comparison terminates.
CN201711331344.0A 2017-12-13 2017-12-13 Global network access control method based on Android equipment Active CN109922030B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201711331344.0A CN109922030B (en) 2017-12-13 2017-12-13 Global network access control method based on Android equipment

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201711331344.0A CN109922030B (en) 2017-12-13 2017-12-13 Global network access control method based on Android equipment

Publications (2)

Publication Number Publication Date
CN109922030A true CN109922030A (en) 2019-06-21
CN109922030B CN109922030B (en) 2021-11-19

Family

ID=66959042

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201711331344.0A Active CN109922030B (en) 2017-12-13 2017-12-13 Global network access control method based on Android equipment

Country Status (1)

Country Link
CN (1) CN109922030B (en)

Cited By (8)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN111865915A (en) * 2020-06-15 2020-10-30 新浪网技术(中国)有限公司 IP control method and system for accessing server
CN112543238A (en) * 2020-12-08 2021-03-23 光通天下网络科技股份有限公司 Domain name over-white list optimization method, device, equipment and medium
CN113489778A (en) * 2021-07-01 2021-10-08 中国建设银行股份有限公司 Access request processing method and device, electronic equipment and storage medium
CN113904849A (en) * 2021-10-09 2022-01-07 深圳技德智能科技研究院有限公司 Network access method, device, computer equipment and storage medium
CN114125065A (en) * 2021-11-23 2022-03-01 神思智能科技有限公司 Network request framework, creation method, network request method and device
CN114401140A (en) * 2022-01-13 2022-04-26 腾讯科技(深圳)有限公司 Access processing method, related device, storage medium, and program product
CN114938294A (en) * 2022-05-05 2022-08-23 岚图汽车科技有限公司 Control method and control device for network access of vehicle-mounted system
CN115550059A (en) * 2022-11-17 2022-12-30 北京首信科技股份有限公司 WEB access control and redirection system, method and storage medium

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
KR101011987B1 (en) * 2009-09-09 2011-01-31 윤대일 Linux server system literacy json-rpc firewall fixing complement method
CN103581363A (en) * 2013-11-29 2014-02-12 杜跃进 Method and device for controlling baleful domain name and illegal access
CN105592086A (en) * 2015-12-22 2016-05-18 Tcl集团股份有限公司 Method and apparatus of managing firewall specific to Android platform
CN106899711A (en) * 2017-05-09 2017-06-27 南京赢纳信息科技有限公司 A kind of dynamic territory analyzing module and its black and white lists implementation method based on Linux
CN107294962A (en) * 2017-06-14 2017-10-24 福州汇思博信息技术有限公司 A kind of method and terminal for configuring firewall security policy

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
KR101011987B1 (en) * 2009-09-09 2011-01-31 윤대일 Linux server system literacy json-rpc firewall fixing complement method
CN103581363A (en) * 2013-11-29 2014-02-12 杜跃进 Method and device for controlling baleful domain name and illegal access
CN105592086A (en) * 2015-12-22 2016-05-18 Tcl集团股份有限公司 Method and apparatus of managing firewall specific to Android platform
CN106899711A (en) * 2017-05-09 2017-06-27 南京赢纳信息科技有限公司 A kind of dynamic territory analyzing module and its black and white lists implementation method based on Linux
CN107294962A (en) * 2017-06-14 2017-10-24 福州汇思博信息技术有限公司 A kind of method and terminal for configuring firewall security policy

Cited By (12)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN111865915A (en) * 2020-06-15 2020-10-30 新浪网技术(中国)有限公司 IP control method and system for accessing server
CN112543238A (en) * 2020-12-08 2021-03-23 光通天下网络科技股份有限公司 Domain name over-white list optimization method, device, equipment and medium
CN112543238B (en) * 2020-12-08 2022-06-14 光通天下网络科技股份有限公司 Domain name over-white list optimization method, device, equipment and medium
CN113489778A (en) * 2021-07-01 2021-10-08 中国建设银行股份有限公司 Access request processing method and device, electronic equipment and storage medium
CN113489778B (en) * 2021-07-01 2022-12-13 中国建设银行股份有限公司 Access request processing method and device, electronic equipment and storage medium
CN113904849A (en) * 2021-10-09 2022-01-07 深圳技德智能科技研究院有限公司 Network access method, device, computer equipment and storage medium
CN113904849B (en) * 2021-10-09 2024-01-09 深圳技德智能科技研究院有限公司 Access network method, device, computer equipment and storage medium
CN114125065A (en) * 2021-11-23 2022-03-01 神思智能科技有限公司 Network request framework, creation method, network request method and device
CN114401140A (en) * 2022-01-13 2022-04-26 腾讯科技(深圳)有限公司 Access processing method, related device, storage medium, and program product
CN114401140B (en) * 2022-01-13 2022-11-11 腾讯科技(深圳)有限公司 Access processing method, related device and storage medium
CN114938294A (en) * 2022-05-05 2022-08-23 岚图汽车科技有限公司 Control method and control device for network access of vehicle-mounted system
CN115550059A (en) * 2022-11-17 2022-12-30 北京首信科技股份有限公司 WEB access control and redirection system, method and storage medium

Also Published As

Publication number Publication date
CN109922030B (en) 2021-11-19

Similar Documents

Publication Publication Date Title
CN109922030A (en) Global network access control system and method based on Android device
CN109510846A (en) API Calls system, method, apparatus, electronic equipment and storage medium
CN105450780B (en) A kind of CDN system and its return source method
US8135687B2 (en) Rule validator of an attribute rule enforcer for a directory
CN108777699B (en) Application cross-domain access method based on Internet of things multi-domain collaborative architecture
CN104333567B (en) It is the web cachings serviced using safety
CN107241344B (en) Client is intercepted to the method, apparatus and system of the access of hostile network server
CN107454094A (en) A kind of data interactive method and system
CN104714965B (en) Static resource De-weight method, static resource management method and device
CN106603713A (en) Session management method and system
CN103888928A (en) Business strategy control method and system
CN102695167B (en) Mobile subscriber identity management method and apparatus thereof
CN101924785A (en) Data uploading and downloading methods and system
US20210344638A1 (en) Method for network traffic forwarding, request sending, and communication acceleration, forwarding server and node server
JP2016506677A (en) Method and apparatus for preventing unauthorized service access
CN108234639A (en) A kind of data access method and device based on content distributing network CDN
CN105338016B (en) Data high-speed caching method and device and resource request response method and device
CN110430188A (en) A kind of quick url filtering method and device
CN109729183A (en) Request processing method, device, equipment and storage medium
CN105871919A (en) Network application firewall system and realization method thereof
CN109729187A (en) A kind of agent communication method, system, device and storage medium
CN110177015A (en) A kind of method and device of management terminal access network
CN110266799B (en) Method for realizing idempotency based on cache
CN103416027B (en) The system of the method, buffer and cache optimization of cache optimization
CN102164150B (en) Method, device, server and system for delivering strategies

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication
SE01 Entry into force of request for substantive examination
SE01 Entry into force of request for substantive examination
GR01 Patent grant
GR01 Patent grant