WO2014040571A1 - 控制客户端访问网络的检测方法、装置和系统 - Google Patents

控制客户端访问网络的检测方法、装置和系统 Download PDF

Info

Publication number
WO2014040571A1
WO2014040571A1 PCT/CN2013/083629 CN2013083629W WO2014040571A1 WO 2014040571 A1 WO2014040571 A1 WO 2014040571A1 CN 2013083629 W CN2013083629 W CN 2013083629W WO 2014040571 A1 WO2014040571 A1 WO 2014040571A1
Authority
WO
WIPO (PCT)
Prior art keywords
network
communication
client
address
detection
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2013/083629
Other languages
English (en)
French (fr)
Inventor
江爱军
谭合力
张波
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Beijing Qihoo Technology Co Ltd
Qizhi Software Beijing Co Ltd
Original Assignee
Beijing Qihoo Technology Co Ltd
Qizhi Software Beijing Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Beijing Qihoo Technology Co Ltd, Qizhi Software Beijing Co Ltd filed Critical Beijing Qihoo Technology Co Ltd
Publication of WO2014040571A1 publication Critical patent/WO2014040571A1/zh
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/10Network architectures or network communication protocols for network security for controlling access to devices or network resources

Definitions

  • the present invention relates to the field of communications technologies, and in particular, to a method, an apparatus, and a system for detecting a client access network. Background of the invention
  • the current security software will improve the Trojan killing function by means of a web server in order to reduce the resource consumption of the client.
  • the client security software accesses the server of the cloud security center, transmits the characteristics of the suspicious file to the server of the cloud security center, and the cloud security center determines its security, and then the client security software according to the cloud
  • the information returned by the Security Center reports and processes the Trojan.
  • the Trojan virus and some other malicious programs will try to destroy the network communication between the client security software and the network server, and prevent the client security software from accessing the network server, resulting in the client not being able to upgrade the network server.
  • Virus database unable to identify and clean up new Trojans, weakens the security protection of client security software.
  • some client security software detects and repairs Host files or DNS (Domain Name System), which is a poor Trojan killing solution for a certain point of detection. , now the solution. Summary of the content
  • the present invention has been made in order to provide a method, apparatus and system for detecting a client access network that overcomes the above problems or at least partially solves the above problems.
  • a method for controlling a client access network including:
  • the system setting detection item is repaired, and when the detection result indicates that the communication is normal, the client application is allowed to access the network object;
  • the selected driving detection item is detected, when When the detection result of the driving detection item indicates that the communication is abnormal, the driving detection item is repaired, and when the detection result of the driving detection item indicates that the communication is normal, the client application is allowed to access the network object.
  • the above communication information includes a domain name and an IP address of the network object.
  • the system setting detection items include a network protocol security setting of the client system, a system firewall setting, a local IP address, a routing item, a domain name system DNS setting, and/or a host file.
  • the communication between the client application and the network object is detected by using the system setting detection item and the communication information of the network object that the client application needs to access, including: detecting whether the network exists in the block list of the network protocol security setting of the client system.
  • the communication information of the object if yes, the detection result indicates that the communication is abnormal, and if not, the detection result indicates that the communication is normal; and/or,
  • the detection result indicates that the communication is abnormal. If not, the detection result indicates that the communication is normal; and/or,
  • the repair system setting detection items include:
  • the communication information of the network object exists in the block list of the network protocol security setting of the client system, the communication information of the network object is cleared from the block list of the network protocol security setting; and/or,
  • the rule entry of the IP address of the network object or the client application name is included from the system. Cleared in the block list of the firewall settings; and/or,
  • the local IP address of the client system in the same network segment as the IP address of the network object is cleared;
  • the routing entry of the IP address of the network object in the same network segment as the IP address of the network object is cleared in the client system; and / or,
  • the IP address in the DNS setting of the client system is in the banned DNS list
  • the IP address in the DNS setting is modified to a trusted DNS server address
  • the entry of the host file including the domain name of the network object in the client system is cleared.
  • the selected driving detection item is a network filtering driver, and the method for detecting the selected driving detection item includes:
  • the network filtering driver is repaired to make the detection result indicate that the communication is normal, and when the detection result indicates that the communication is normal, the client application is allowed to access the network object.
  • the above repair network filtering driver includes: after the network filtering driver in the blacklist is backed up, the network filtering driver is cleared, the detection result indicates that the communication is normal, and the client application is allowed to access the network object.
  • the method further includes: when the client application accesses the network object If the client application cannot successfully access the trusted third-party network object, the client application cannot access the network. If the client application can successfully access the trusted third-party network object, determine whether the client application does not exist in the blacklist. And the network filtering driver in the whitelist, if not, confirm that the client application cannot access the network. If yes, the network filtering driver is backed up and cleared, allowing the client application to access the network object.
  • a detecting apparatus for controlling a client to access a network comprising:
  • the detection item selection unit is adapted to select a system setting detection item according to the client system setting; the detecting unit is adapted to use the system to set the detection item and the communication information of the network object that the client application needs to access, to the client application and the Communication between network objects is detected;
  • the access control unit is adapted to: when the detection result of the detection item of the system indicates that the communication is abnormal, repair the system setting detection item, and when the detection result indicates that the communication is normal, allow the client application to access the network object;
  • the detection item selection unit is further adapted to select a driving detection item for detection; the detecting unit, It is further adapted to detect the selected driving detection item when the system setting detection item fails to be repaired; the access control unit is further adapted to repair the driving detection when the detection result of the driving detection item indicates a communication abnormality Item, when the detection result of the driving detection item indicates that the communication is normal, the client application is allowed to access the network object.
  • the above communication information includes a domain name and an IP address of the network object.
  • the above system setting detection items include network protocol security settings of the client system, system firewall settings, local IP addresses, routing items, domain name system DNS settings, and/or host files, and detection.
  • the unit is specifically adapted to detect whether the communication information of the network object exists in the block list of the network protocol security setting of the client system, and if yes, the detection result indicates that the communication is abnormal, and if not, the detection result indicates that the communication is normal; and/or,
  • the detection result indicates that the communication is abnormal. If not, the detection result indicates that the communication is normal; and/or,
  • the above access control unit is adapted to repair the system setting detection item by the following method when the detection result indicates that the communication is abnormal:
  • the communication information of the network object exists in the block list of the network protocol security setting of the client system, the communication information of the network object is cleared from the block list of the network protocol security setting; and/or,
  • the rule entry of the IP address of the network object and the client application name is included from the system. Cleared in the block list of the firewall settings; and/or,
  • the local IP address of the client system in the same network segment as the IP address of the network object is cleared;
  • the routing entry having the same IP address as the IP address of the network object in the client system is cleared;
  • the IP address in the DNS setting of the client system is in the banned DNS list
  • the IP address in the DNS setting is modified to a trusted DNS server address
  • the entry of the host file including the domain name of the network object in the client system is cleared.
  • the detection item selection unit is further adapted to select a network filtering driver of the client system as a system setting detection item;
  • the detecting unit is further adapted to: when the access control unit allows the client application to access the network object, when the client application fails to access the network object, detecting whether the network filtering driver exists in the blacklist, and if yes, the detection result indicates that the communication is abnormal; , the test result indicates that the communication is normal;
  • the access control unit is further adapted to: when the detection result indicates that the communication is abnormal, repair the network filtering driver to make the detection result indicate that the communication is normal, and when the detection result indicates that the communication is normal, allow the client application to access the network object.
  • the above access control unit is adapted to repair the network filtering driver in the following manner:
  • the network filtering driver in the blacklist is backed up, the network filtering driver is cleared, and the detection result indicates that the communication is normal, and the client application is allowed to access the network object.
  • the access control unit is further configured to: after the network filtering driver in the blacklist is backed up, clear the network filtering driver from the blacklist, and the detection result indicates that the communication is normal, and after the client application is allowed to access the network object, the client application is used. If the client application fails to access the trusted third-party network object, the client application cannot access the network. If the client application can successfully access the trusted third-party network object, determine whether the client application does not exist. The network filtering driver in the blacklist and whitelist, if not, confirms that the client application cannot access the network. If yes, the network filtering driver is backed up and cleared, allowing the client application to access the network object.
  • a communication system provided by an embodiment of the present invention includes a client device, where the client device includes the foregoing detecting device for controlling a client to access a network,
  • the network object that the client application running on the client device needs to access is the cloud security center server;
  • the client application When the detecting device that controls the client accessing the network allows the client application to access the cloud security center server, the client application is adapted to send the information of the suspicious file to the cloud security center server, and receive Analysis of the information sent by the Cloud Security Center server for suspicious files.
  • a computer program comprising computer readable code, when the computer readable code is run on a client, causing the client to execute the control client described in any of the above End detection network detection method.
  • a computer readable medium wherein the computer program as described above is stored.
  • the embodiment of the present invention selects the system to set the detection item and the drive detection item, and uses the system to set the detection item, the driving detection item and the communication information of the network object to perform the access control technical means, and can be set from the system kernel to the system setting.
  • Multiple dimensions detect the damage of the malicious program to the client application accessing the system network, effectively repairing the damage caused by the malicious program to the communication between the client application and the network object, and ensuring the normal access of the client application to the network object.
  • FIG. 1 is a flow chart showing a method for detecting a client access network according to an embodiment of the present invention
  • FIG. 2 is a flow chart showing a method for repairing a malicious application of a client application to access a network object based on a network filter driver according to still another embodiment of the present invention
  • FIG. 3 is a schematic structural diagram of a detecting apparatus for controlling a client to access a network according to an embodiment of the present invention
  • FIG. 4 is a schematic structural diagram of a communication system according to an embodiment of the present invention. Mode for carrying out the invention
  • the application can be applied to a computer system/server that can operate with numerous other general purpose or special purpose computing system environments or configurations.
  • Examples of well-known computing systems, environments, and/or configurations suitable for use with a computer system/server include, but are not limited to: a personal computer system, a server computer system, a client, a thick client, a handheld or a laptop, based on Microprocessor systems, set-top boxes, programmable consumer electronics, networked personal computers, small computer systems, large computer systems, and distributed cloud computing technology environments including any of the above, and the like.
  • the computer system/server can be described in the general context of computer system executable instructions (such as program modules) being executed by a computer system.
  • program modules may include routines, programs, target programs, components, logic, data structures, and the like that perform particular tasks or implement particular abstract data types.
  • the computer system/server can be implemented in a distributed cloud computing environment where tasks are performed by remote processing devices that are linked through a communication network.
  • program modules may be located on a local or remote computing system storage medium including storage devices.
  • the computer system/server can also communicate with one or more external devices, such as a keyboard, pointing device, display, etc., in one or more devices that enable the user to interact with the computer system/server, and/or Any device (eg, a network card, modem, etc.) that enables a computer system/server to communicate with one or more other computing devices. This communication can be done via an input/output (I/O) interface.
  • the computer system/server can communicate with one or more networks, such as a local area network (LAN), a wide area network (WAN), and/or a public network (e.g., the Internet) through a network adapter. As shown, the network adapter communicates with other modules of the computer system/server via the bus.
  • LAN local area network
  • WAN wide area network
  • public network e.g., the Internet
  • a method for detecting a client access network is provided by an embodiment of the present invention. Referring to FIG. 1, the method includes:
  • S100 Select a system setting detection item according to the client system, where the system setting detection item includes a network protocol security (Internet Protocol Security, IPSec) setting of the client system, a system firewall setting, a local IP address, a routing item, a DNS setting, and One or more of the host files.
  • IPSec Internet Protocol Security
  • the communication between the client application and the network object is detected by using the system to set the detection item and the communication information of the network object that the client application needs to access.
  • the system setting detection item selected in the above step S100 is generally used as a basic detection item, and all the system setting detection items are detected in this step. It can be understood that in this step, only the Some of the above communication detection items are detected.
  • the solution can detect and repair the client application access system network from the dimension set by the system.
  • the above network object is a network device or system to be accessed by the client application, for example, the network object may be
  • S104 Allow the client application to access the network object when the detection result of the detection item of the system indicates that the communication is normal.
  • step S108 When the repairing the system setting detection item fails, detecting the selected driving detection item, proceeding to step S110, when repairing the system setting detection item is successful, indicating that the communication is normal, allowing the client application to access the network object .
  • the solution can detect and repair the client application access system network from the dimension of the system kernel.
  • the embodiment of the invention detects the malicious program by using the system setting detection item and the driving detection item, and using the system to set the detection item, the driving detection item and the communication information of the network object to perform access control, and can detect the malicious program from multiple dimensions such as the system kernel to the system setting.
  • the damage to the client application accessing the system network effectively repairs the damage caused by the malicious program to the communication between the client application and the network object, and ensures the normal access of the client application to the network object.
  • a scenario in which a client application is a client security application for securing a client network, and a network object to be accessed by a client application is a cloud security center server is taken as an example.
  • a cloud computing environment includes one or more cloud computing nodes with which a computing device used by a cloud computing consumer can communicate, such as a personal digital assistant (PDA) or a mobile phone, a desktop computer, a laptop computer, and/or Or a car computer system.
  • Nodes can communicate with each other. Can be in one or more networks - such as private clouds, community clouds, public as described above In a cloud or hybrid cloud or a combination thereof, nodes are physically or virtually grouped (not shown). This allows the cloud computing environment to provide infrastructure as a service, platform as a service, and/or software as a service that cloud consumers can request without maintaining resources on the local computing device.
  • the compute nodes and cloud computing environments can communicate with any type of computing device (e.g., using a web browser) on any type of network and/or network addressable connection.
  • the cloud security architecture is implemented in a cloud computing environment. It connects all the cloud security clients to the cloud security server in real time. The client continuously collects and reports updates, forms a huge malicious program database on the server side, and compares the analysis of active defenses. The operation is done on the server side, making the entire cloud security network a proactive defense tool; collecting and storing the threated program behavior in the server's database, and supporting the direct use of program behavior for malicious purposes when performing malware analysis on the server side Program decision
  • the program behavior is collected by the client and associated with the program feature, thereby recording the program feature and its corresponding program behavior in the database, and according to the collected relationship between the program behavior and the program feature, the database may be in the database.
  • the sample is analyzed and summarized, which helps to classify the software or program in black and white. It can also set corresponding clearance or recovery measures for malware in the blacklist.
  • the Trojan virus and some other malicious programs will try to destroy the network security between the client security software and the network server, for example, the cloud security server, and prevent the client security software from accessing the network server, resulting in the client.
  • the virus database on the network server side cannot be upgraded, and the new Trojan cannot be identified and cleared.
  • IP CloudSecCentre
  • the detection of the communication between the client application and the network object may include the following:
  • a malicious program such as a Trojan
  • the detection of the client system's network protocol security setting is prevented. Whether there is communication information of the network object in the list. If yes, the detection result indicates that the communication is abnormal. If not, the detection result indicates that the communication is normal. For example, read the IPSec settings of the client system, check whether there is a cloud security center domain name CloudSecCentre (Domain) and an IP address CloudSecCentre (IP) in the block list of the setting item. If it exists, clear it. If it does not exist, it is incorrect. The IPSec settings are modified.
  • all the information in the IPSec setting may be directly detected to determine whether the communication information of the network object is in the IPSec setting. If the communication information of the network object is cleared from the IPSec setting, if not, Keep the IPSec settings unchanged.
  • the rule entry containing the cloud security center server IP address or the client security application name is added to the block list to destroy the network communication.
  • the client is detected. Whether the IP address of the network object or the name of the client application exists in the rule entry of the block list set by the system firewall of the system. If yes, the detection result indicates that the communication is abnormal. If not, the detection result indicates that the communication is normal.
  • this embodiment detects whether the client system exists. The local IP address on the same network segment as the IP address of the network object. If yes, the detection result indicates that the communication is abnormal. If not, the detection result indicates that the communication is normal.
  • IP IP address
  • the address entry is the local IP address of the client network that is on the same network segment as the IP address of the network object. If it does not exist, keep the IP address setting of the client system.
  • the client application cannot access the cloud security center server IP address to destroy the communication.
  • This embodiment detects whether the routing entry of the client system has an IP address on the same network segment as the IP address of the network object. Address, if yes, the test result indicates that the communication is abnormal. If not, the test result indicates that the communication is normal. For example, read all routing entries of the client system, and check whether the network address of the routing entry is the same as the network address in the cloud security center server IP address CloudSecCentre (IP). If they are the same, the routing entry is cleared, that is, in the client system. The routing entry of the IP address of the same network segment as the IP address of the network object is cleared. If it is different, the original routing entry is maintained.
  • IP CloudSecCentre
  • the domain name of the cloud security center cannot be resolved, and communication cannot be performed normally.
  • the DNS setting of the client system is detected, When the IP address is in the DNS list, the IP address in the DNS settings is changed to a trusted DNS server address.
  • the banned DNS list consists of a known illegal IP address or an IP address that is prohibited from being accessed by the client application. It can also be called a black DNS list.
  • read the network DNS settings of the client system check whether the DNS IP address is in the prohibited DNS list, and if so, change the IP address in the DNS settings to a trusted DNS server address, such as correcting the DNS to pre- Set the DNS server address: 8.8.8.8 and 8.8.4.4, if not, keep the network DNS settings of the client system unchanged.
  • a trusted DNS server address such as correcting the DNS to pre- Set the DNS server address: 8.8.8.8 and 8.8.4.4
  • this embodiment detects that the entries of the host file of the client system include the network object.
  • the entry of the host file in the client system including the domain name of the network object is cleared.
  • the host file usually consists of multiple lines of information, each line of information can be regarded as an entry, and the domain name information is set in the entry.
  • the host file is usually located in the c: ⁇ windows ⁇ system32 ⁇ drivers ⁇ etc directory of the client system, and the host file of the client system is read.
  • the manner of repairing in this embodiment includes at least one of the following or a combination thereof: when the communication information of the network object exists in the block list of the IPSec setting of the client system is detected, the network object is The communication information is cleared from the block list set by IPSec;
  • IP address of the network object or the client application name when the IP address of the network object or the name of the client application exists in the rule entry of the block list of the system firewall setting of the client system is detected. Rule entries are cleared from the block list set by the system firewall;
  • the local IP address of the client system in the same network segment as the IP address of the network object is cleared; when the client system is detected If there is an IP address in the same network segment as the IP address of the network object in the routing entry, the routing entry of the IP address of the same network segment as the IP address of the network object in the client system is cleared.
  • the IP address in the DNS setting of the client system is in the banned DNS list, the IP address in the DNS setting is modified to a trusted DNS server address;
  • the entry of the host file including the domain name of the network object in the client system is cleared.
  • the selection of the detection items of the above system, and the specific manner of detecting and repairing are summarized in the confrontation practice with the Trojan (such as the typical "Hurricane Trojan"), which can effectively repair the Trojan to the cloud security center.
  • the Trojan such as the typical "Hurricane Trojan”
  • the damage caused by network communication to ensure the normal communication between the client security software and the cloud security center, to provide a reliable network environment for the subsequent Trojan killing, so that the security software can play the best Trojan killing effect.
  • the embodiment further includes selecting the network filtering driver of the client system as the driving detection item, based on the NDIS ( Network Driver Interface Specification, network filter driver for Trojan horse killing.
  • NDIS Network Driver Interface Specification, network filter driver for Trojan horse killing.
  • the network filtering driver usually includes a network filtering driver file and registry information. In this embodiment, it is detected whether the network filtering driver exists in the blacklist. If yes, the detection result indicates that the communication is abnormal; if not, the detection result indicates that the communication is normal;
  • the network filtering driver is repaired to make the detection result indicate that the communication is normal, and when the detection result indicates that the communication is normal, the client application is allowed to access the network object.
  • FIG. 2 a flow chart of a method for repairing a malicious application to a client application to access a network object based on a network filtering driver is illustrated.
  • the specific processing is as follows: S200: Determine whether the client application can access the network object.
  • the client application can access the network object after the detection and repair of the above six key points, the communication is normal, the detection ends.
  • step S202 is performed.
  • the identification information of the network filtering driver includes signature information and/or version information of the network filtering driver.
  • the configuration interface reads all network filter drivers in the system.
  • the identification information of the allowed network filtering driver is recorded in the whitelist, and the identification information of the forbidden network filtering driver is recorded in the blacklist.
  • the status of the network filter driver that is not in the whitelist is set to gray, and gray indicates unknown.
  • step S206 is performed.
  • step S208 Determine whether the client application at this time can access the network object. If yes, the communication is normal, and the operation ends. If no, step S210 is performed.
  • step S210 Determine whether the client can access the trusted third-party network object in the current user environment. If yes, go to step S212. If not, the client itself cannot access the network and the operation ends.
  • the solution also detects and repairs the client application access system network from the user mode dimension.
  • the solution can comprehensively detect the damage of the malicious program to the client application access system network from the system kernel to the user state and the system setting, and ensure a reliable network communication environment before the malicious program is detected and killed. .
  • step S212 Determine whether the client application has a network filtering drive that does not exist in the blacklist and the whitelist. If there is no gray network filter driver, it is confirmed that the client application cannot access the network. If yes, go to step S214.
  • the embodiment of the present invention selects the system to set the detection item and the drive detection item, and uses the system to set the detection item, the driving detection item and the communication information of the network object to perform the access control technical means, and can be set from the system kernel to the system setting. Multiple dimensions detect the damage of the malicious program to the client application accessing the system network, effectively repairing the damage caused by the malicious program to the communication between the client application and the network object, and ensuring the normal access of the client application to the network object.
  • An embodiment of the present invention further provides a detecting device for controlling a client to access a network.
  • the device includes:
  • the detection item selecting unit 300 is adapted to select a system setting detection item according to the client system, wherein the system setting detection item includes a network protocol security setting of the client system, a system firewall setting, a local IP address, a routing item, and a domain name system DNS setting. And/or host files;
  • the detecting unit 302 is adapted to detect the communication between the client application and the network object by using the system setting detection item and the communication information of the network object that the client application needs to access;
  • the access control unit 304 is configured to: when the detection result of the detection item of the system is set to indicate that the communication is abnormal, repair the system setting detection item, and when the detection result indicates that the communication is normal, allow the client application to access the network object;
  • the detection item selection unit 300 is further adapted to select a driving detection item for detecting; the detecting unit 302 is further adapted to: when the system setting detection item fails to repair, select the selected driving detection item;
  • the access control unit 304 is further configured to: when the detection result of the driving detection item indicates a communication abnormality, repair the driving detection item, and when the detection result of the driving detection item indicates that the communication is normal, allow the client application to access the network object. .
  • the foregoing communication information includes a domain name and an IP address of the network object
  • the detecting unit 302 is specifically configured to detect whether the communication information of the network object exists in the block list of the network protocol security setting of the client system, and if yes, the detection result indicates that the communication is abnormal. , if not, the test result indicates that the communication is normal; and / or,
  • the detection result indicates that the communication is abnormal. If not, the detection result indicates that the communication is normal; and/or,
  • the access control unit 304 is adapted to: when the detection result indicates that the communication is abnormal, repair the system setting detection item by:
  • the communication information of the network object exists in the block list of the network protocol security setting of the client system, the communication information of the network object is cleared from the block list of the network protocol security setting; and/or,
  • the rule entry containing the IP address of the network object or the client application name is set from the system firewall. Cleared in the block list; and/or,
  • the local IP address of the client system in the same network segment as the IP address of the network object is cleared;
  • the routing entry of the client system When it is detected that the routing entry of the client system has an IP address in the same network segment as the IP address of the network object, the routing entry having the same IP address as the IP address of the network object in the client system is cleared; and/or ,
  • the IP address in the DNS setting of the client system is in the banned DNS list
  • the IP address in the DNS setting is modified to a trusted DNS server address
  • the entry of the host file including the domain name of the network object in the client system is cleared.
  • the detection item selection unit 300 is specifically adapted to select a network filtering driver as the driving detection item;
  • the detecting unit 302 is further configured to detect whether the network filtering driver exists in the blacklist, and if yes, detect The result indicates that the communication is abnormal; if not, the detection result indicates that the communication is normal;
  • the access control unit 304 is further adapted to: when the detection result indicates that the communication is abnormal, repair the network filtering driver to make the detection result indicate that the communication is normal, and when the detection result indicates that the communication is normal, allow the client application to access the network object.
  • the detecting unit 302 is specifically configured to detect whether the network filtering driver exists in the blacklist by: obtaining the signature information and version information of the network filtering driver from the registry and the network configuration interface of the client system; When the signature information and version information of the filter driver are in the blacklist, it is confirmed that the network filter driver exists in the blacklist. When the signature information and version information of the network filter driver are not in the blacklist, it is confirmed that the network filter driver does not exist in the blacklist. In the blacklist.
  • the access control unit 304 is adapted to repair the network filtering driver by: after the network filtering driver in the blacklist is backed up, the network filtering driver is cleared, and the detection result indicates that the communication is normal, and the client application is allowed to access the network object.
  • the access control unit 304 is further configured to: after the network filtering driver in the blacklist is backed up, clear the network filtering driver from the blacklist, and the detection result indicates that the communication is normal, and after the client application is allowed to access the network object,
  • the client application fails to access the network object, if the client application cannot successfully access the trusted third-party network object, it is confirmed that the client application cannot access the network, and if the client application can successfully access the trusted third-party network object, the client system Obtaining the signature information and/or version information of the network filtering driver in the registry and the network configuration interface, and determining whether the client application has network filtering that does not exist in the blacklist and the whitelist according to the signature information and/or the version information of the network filtering driver.
  • Driver if not, confirm that the client application cannot access the network. If it has, clear the network filter driver and then clear it, allowing the client application to access the network object.
  • the detecting unit 302 is specifically configured to detect whether the network filtering driver exists in the blacklist by: obtaining the signature information and/or version information of the network filtering driver from the registry and the network configuration interface of the client system; When the signature information and/or version information of the driver is in the blacklist, it is confirmed that the network filtering driver exists in the blacklist. When the signature information and/or version information of the network filtering driver is not in the blacklist, the network filtering driver is confirmed. Does not exist on the blacklist;
  • the detecting unit 302 is specifically configured to determine, by using the following manner, whether the client application has a network filtering driver that does not exist in the blacklist and the whitelist:
  • the client application has a network filtering driver that does not exist in the blacklist and the whitelist. Otherwise, it is confirmed that the client application does not have Network filter drivers that do not exist in the blacklist and whitelist.
  • the embodiment of the present invention uses the network protocol security setting, the system firewall setting, the local IP address, the routing item, the DNS setting, and the host file as system setting detection items, and uses the system to set the communication information between the detection item and the network object.
  • the technical means of access control can detect the damage of the malicious program to the client application accessing the Windows system network from the system kernel to the user state and the system setting, and effectively repair the communication between the client application and the network object by the malicious program. The damage caused ensures the normal access of the client application to the network object.
  • the embodiment of the present invention further provides a communication system.
  • the communication system includes a client device 400.
  • the client device 400 includes at least one detection device 402 for controlling a client access network, as provided in the foregoing embodiment.
  • the network object that the client application 406 running on the client device 400 needs to access is the cloud security center server 404;
  • the client application 406 is adapted to send the information of the suspicious file to the cloud security center server 404, and receive the cloud security center server 404. The result of the analysis of the information on the suspicious file.
  • the embodiment of the present invention uses the network protocol security setting, the system firewall setting, the local IP address, the routing item, the DNS setting, and the host file as system setting detection items, and uses the system to set the communication information between the detection item and the network object.
  • the technical means of access control can detect the damage of the malicious program to the client application accessing the Windows system network from the system kernel to the user state and the system setting, and effectively repair the communication between the client application and the network object by the malicious program. The damage caused ensures the normal access of the client application to the network object.
  • modules in the devices of the embodiments can be adaptively changed and placed in one or more devices different from the embodiment.
  • the modules or units or components in the embodiments may be combined into one module or unit or component, and further they may be divided into a plurality of sub-modules or sub-units or sub-components.
  • any combination of the features disclosed in the specification, including the accompanying claims, the abstract and the drawings, and any methods so disclosed may be employed. Or combine all the processes or units of the device.
  • Each feature disclosed in the specification (including the accompanying claims, the abstract and the drawings) may be replaced by alternative features that provide the same, equivalent or similar purpose, unless otherwise stated.
  • the various component embodiments of the present invention may be implemented in hardware, or in software modules running on one or more processors, or in a combination thereof.
  • a microprocessor or digital signal processor may be used in practice to implement some or all of some or all of the components of the detection device that controls the client access network in accordance with an embodiment of the present invention.
  • the invention can also be implemented as a device or device program (e.g., a computer program and a computer program product) for performing some or all of the methods described herein.
  • a program implementing the present invention may be stored on a computer readable medium or may be in the form of one or more signals. Such signals can be downloaded from the Internet website, either on the carrier signal or in any other form.
  • the computer program includes computer readable code when the computer readable code is in the guest When the client is running, it causes the client to perform the detection method described above to control the client access to the network.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Hardware Design (AREA)
  • Computer Security & Cryptography (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)
  • Computer And Data Communications (AREA)

Description

控制客户端访问网络的检测方法、 装置和系统 技术领域 本发明涉及通信技术领域, 特别涉及一种控制客户端访问网络的检测方法、 装置和系统。 发明背景
当前安全防护软件为了快速地识别和查杀新木马, 同时为了减轻客户端的 资源消耗, 会借助于网络服务器提高木马查杀功能。 例如, 在云安全技术下, 客户端安全软件访问云安全中心的服务器, 将可疑文件的特征传给云安全中心 的服务器, 由云安全中心对其安全做出判定, 然后客户端安全软件根据云安全 中心传回的信息对木马进行报告和处理。
然而, 木马病毒以及一些其他的恶意程序为了躲避安全软件的检测, 会想 方设法破坏客户端安全软件与网络服务器之间的网络通讯, 阻止客户端安全软 件访问网络服务器, 导致客户端无法升级网络服务器端的病毒库, 无法识别和 清除新木马, 削弱了客户端安全软件的安全防护性能。 针对这种问题, 一些客 户端安全软件对主机 ( Host )文件或 DNS ( (Domain Name System, 域名系统 ) 进行检测和修复, 这种仅针对某个点进行检测的方案的木马查杀效果较差, 现 解决方案。 发明内容
鉴于上述问题, 提出了本发明以便提供一种克服上述问题或者至少部分地 解决上述问题的一种控制客户端访问网络的检测方法、 装置和系统。
依据本发明的一个方面, 提供了一种控制客户端访问网络的检测方法, 包 括:
根据客户端系统设置选取系统设置检测项;
利用所述系统设置检测项和客户端应用需要访问的网络对象的通讯信息, 对客户端应用与所述网络对象之间的通讯进行检测;
当对系统设置检测项的检测结果指示通讯异常时, 修复所述系统设置检测 项, 当检测结果指示通讯正常时, 允许客户端应用访问所述网络对象;
当修复所述系统设置检测项失败时, 对选取的驱动检测项进行检测, 当对 驱动检测项的检测结果指示通讯异常时, 修复所述驱动检测项, 当对驱动检测 项的检测结果指示通讯正常时, 允许客户端应用访问所述网络对象。
上述通讯信息包括网络对象的域名和 IP地址, 上述系统设置检测项包括客 户端系统的网络协议安全性设置、 系统防火墙设置、 本地 IP地址、 路由项、 域 名系统 DNS设置和 /或主机文件,上述利用系统设置检测项和客户端应用需要访 问的网络对象的通讯信息, 对客户端应用与网络对象之间的通讯进行检测包括: 检测客户端系统的网络协议安全性设置的阻止列表中是否存在网络对象的 通讯信息, 若是, 检测结果指示通讯异常, 若否, 检测结果指示通讯正常; 和 /或,
检测客户端系统的系统防火墙设置的阻止列表的规则条目中是否存在网络 对象的 IP地址和客户端应用的名称, 若是, 检测结果指示通讯异常, 若否, 检 测结果指示通讯正常; 和 /或,
检测客户端系统是否存在与网络对象的 IP地址在同一网段的本地 IP地址, 若是, 检测结果指示通讯异常, 若否, 检测结果指示通讯正常; 和 /或,
检测客户端系统的路由项中是否存在与网络对象的 IP地址在同一网段的 IP 地址, 若是, 检测结果指示通讯异常, 若否, 检测结果指示通讯正常;
和 /或,
检测客户端系统的 DNS设置中的 IP地址是否在禁止 DNS列表中, 若是, 检测结果指示通讯异常, 若否, 检测结果指示通讯正常; 和 /或,
检测客户端系统的主机文件的各条目中是否包括网络对象的域名, 若是, 检测结果指示通讯异常, 若否, 检测结果指示通讯正常。
当检测结果指示通讯异常时, 修复系统设置检测项包括:
当检测到客户端系统的网络协议安全性设置的阻止列表中存在网络对象的 通讯信息时, 将网络对象的通讯信息从网络协议安全性设置的阻止列表中清除; 和 /或,
当检测到客户端系统的系统防火墙设置的阻止列表的规则条目中存在网络 对象的 IP地址和客户端应用的名称时,将包含了网络对象的 IP地址或客户端应 用名称的该规则条目从系统防火墙设置的阻止列表中清除; 和 /或,
当检测到客户端系统存在与网络对象的 IP地址在同一网段的本地 IP地址 时, 将客户端系统中与网络对象的 IP地址在同一网段的本地 IP地址清除;
和 /或, 当检测到客户端系统的路由项中存在与网络对象的 IP地址在同一网段的 IP 地址时,将客户端系统中存在与网络对象的 IP地址在同一网段的 IP地址的路由 项清除; 和 /或,
当检测到客户端系统的 DNS设置中的 IP地址在禁止 DNS列表中时,将 DNS 设置中的 IP地址修改为可信赖的 DNS服务器地址; 和 /或,
当检测到客户端系统的主机文件的各条目中包括网络对象的域名时, 将客 户端系统中包括网络对象的域名的主机文件的条目清除。
上述选取的驱动检测项为网络过滤驱动, 本方法对选取的驱动检测项进行 检测包括:
检测网络过滤驱动是否存在于黑名单中, 若是, 检测结果指示通讯异常; 若否, 检测结果指示通讯正常;
当检测结果指示通讯异常时, 修复网络过滤驱动使检测结果指示通讯正常, 当检测结果指示通讯正常时, 允许客户端应用访问网络对象。
上述修复网络过滤驱动包括: 将黑名单中的网络过滤驱动备份后, 将该网 络过滤驱动清除, 检测结果指示通讯正常, 允许客户端应用访问网络对象。
在将黑名单中的网络过滤驱动备份后, 将该网络过滤驱动从黑名单中清除, 检测结果指示通讯正常, 允许客户端应用访问网络对象之后, 本方法还包括: 当客户端应用访问网络对象失败时, 若客户端应用不能成功访问信赖的第 三方网络对象, 确认客户端应用无法访问网络, 若客户端应用能够成功访问信 赖的第三方网络对象, 判断客户端应用是否具有不存在于黑名单和白名单中的 网络过滤驱动, 若不具有, 确认客户端应用无法访问网络, 若具有, 将该网络 过滤驱动备份后清除, 允许客户端应用访问网络对象。
根据本发明的另一方面, 提供了一种控制客户端访问网络的检测装置, 该 装置包括:
检测项选取单元, 适于根据客户端系统设置选取系统设置检测项; 检测单元, 适于利用所述系统设置检测项和客户端应用需要访问的网络对 象的通讯信息, 对客户端应用与所述网络对象之间的通讯进行检测;
访问控制单元, 适于当对系统设置检测项的检测结果指示通讯异常时, 修 复所述系统设置检测项, 当检测结果指示通讯正常时, 允许客户端应用访问所 述网络对象;
所述检测项选取单元, 还适于选取驱动检测项进行检测; 所述检测单元, 还适于当修复所述系统设置检测项失败时, 对选取的驱动检测项进行检测; 所述访问控制单元, 还适于当对驱动检测项的检测结果指示通讯异常时, 修复所述驱动检测项, 当对驱动检测项的检测结果指示通讯正常时, 允许客户 端应用访问所述网络对象。
上述通讯信息包括网络对象的域名和 IP地址, 上述系统设置检测项包括客 户端系统的网络协议安全性设置、 系统防火墙设置、 本地 IP地址、 路由项、 域 名系统 DNS设置和 /或主机文件,检测单元, 具体适于检测客户端系统的网络协 议安全性设置的阻止列表中是否存在网络对象的通讯信息, 若是, 检测结果指 示通讯异常, 若否, 检测结果指示通讯正常; 和 /或,
检测客户端系统的系统防火墙设置的阻止列表的规则条目中是否存在网络 对象的 IP地址和客户端应用的名称, 若是, 检测结果指示通讯异常, 若否, 检 测结果指示通讯正常; 和 /或,
检测客户端系统是否存在与网络对象的 IP地址在同一网段的本地 IP地址, 若是, 检测结果指示通讯异常, 若否, 检测结果指示通讯正常; 和 /或,
检测客户端系统的路由项中是否存在与网络对象的 IP地址在同一网段的 IP 地址, 若是, 检测结果指示通讯异常, 若否, 检测结果指示通讯正常;
和 /或,
检测客户端系统的 DNS设置中的 IP地址是否在禁止 DNS列表中, 若是, 检测结果指示通讯异常, 若否, 检测结果指示通讯正常; 和 /或,
检测客户端系统的主机文件的各条目中是否包括网络对象的域名, 若是, 检测结果指示通讯异常, 若否, 检测结果指示通讯正常。
上述访问控制单元, 适于当检测结果指示通讯异常时, 通过下述方式修复 系统设置检测项:
当检测到客户端系统的网络协议安全性设置的阻止列表中存在网络对象的 通讯信息时, 将网络对象的通讯信息从网络协议安全性设置的阻止列表中清除; 和 /或,
当检测到客户端系统的系统防火墙设置的阻止列表的规则条目中存在网络 对象的 IP地址和客户端应用的名称时,将包含了网络对象的 IP地址和客户端应 用名称的该规则条目从系统防火墙设置的阻止列表中清除; 和 /或,
当检测到客户端系统存在与网络对象的 IP地址在同一网段的本地 IP地址 时, 将客户端系统中与网络对象的 IP地址在同一网段的本地 IP地址清除; 当检测到客户端系统的路由项中存在与网络对象的 IP地址在同一网段的 IP 地址时 ,将客户端系统中存在与网络对象的 IP地址相同的 IP地址的路由项清除; 和 /或,
当检测到客户端系统的 DNS设置中的 IP地址在禁止 DNS列表中时,将 DNS 设置中的 IP地址修改为可信赖的 DNS服务器地址; 和 /或,
当检测到客户端系统的主机文件的各条目中包括网络对象的域名时, 将客 户端系统中包括网络对象的域名的主机文件的条目清除。
上述检测项选取单元, 还适于选取客户端系统的网络过滤驱动作为系统设 置检测项;
检测单元, 还适于在访问控制单元允许客户端应用访问网络对象之后, 当 客户端应用访问网络对象失败时, 检测网络过滤驱动是否存在于黑名单中, 若 是, 检测结果指示通讯异常; 若否, 检测结果指示通讯正常;
访问控制单元, 还适于当检测结果指示通讯异常时, 修复网络过滤驱动使 检测结果指示通讯正常, 当检测结果指示通讯正常时, 允许客户端应用访问网 络对象。
上述访问控制单元, 适于通过下述方式修复网络过滤驱动:
将黑名单中的网络过滤驱动备份后, 将该网络过滤驱动清除, 检测结果指 示通讯正常, 允许客户端应用访问网络对象。
上述访问控制单元, 还适于在将黑名单中的网络过滤驱动备份后, 将该网 络过滤驱动从黑名单中清除, 检测结果指示通讯正常, 允许客户端应用访问网 络对象之后, 当客户端应用访问网络对象失败时, 若客户端应用不能成功访问 信赖的第三方网络对象, 确认客户端应用无法访问网络, 若客户端应用能够成 功访问信赖的第三方网络对象, 判断客户端应用是否具有不存在于黑名单和白 名单中的网络过滤驱动, 若不具有, 确认客户端应用无法访问网络, 若具有, 将该网络过滤驱动备份后清除, 允许客户端应用访问网络对象。
本发明实施例提供的一种通信系统包括客户端设备, 所述客户端设备包括 上述的控制客户端访问网络的检测装置,
客户端设备上运行的客户端应用需要访问的网络对象为云安全中心服务 器;
控制客户端访问网络的检测装置允许客户端应用访问云安全中心服务器 时, 该客户端应用, 适于将可疑文件的信息发送至云安全中心服务器, 并接收 云安全中心服务器下发的对可疑文件的信息的分析结果。
根据本发明的又一个方面, 提供了一种计算机程序, 包括计算机 可读代码, 当所述计算机可读代码在客户端上运行时, 导致所述客户 端执行上述任一项所述的控制客户端访问网络的检测方法。
根据本发明的再一个方面, 提供了一种计算机可读介质, 其中存 储了如上所述的计算机程序。
由上所述, 本发明实施例通过选取系统设置检测项和驱动检测项, 利用系 统设置检测项、 驱动检测项与网络对象的通讯信息进行访问控制的技术手段, 能够从系统内核到系统设置等多个维度检测恶意程序对客户端应用访问系统网 络的破坏, 有效地修复恶意程序对客户端应用与网络对象之间通讯造成的破坏, 保证了客户端应用对网络对象的正常访问。
上述说明仅是本发明技术方案的概述, 为了能够更清楚了解本发明的技术 手段, 而可依照说明书的内容予以实施, 并且为了让本发明的上述和其它目的、 特征和优点能够更明显易懂, 以下特举本发明的具体实施方式。
附图简要说明
通过阅读下文优选实施方式的详细描述, 各种其他的优点和益处对于本领 域普通技术人员将变得清楚明了。 附图仅用于示出优选实施方式的目的, 而并 不认为是对本发明的限制。 而且在整个附图中, 用相同的参考符号表示相同的 部件。 在附图中:
图 1 示出了根据本发明一个实施例的一种控制客户端访问网络的检测方法 流程图;
图 2示出了根据本发明又一个实施例的基于网络过滤驱动的修复恶意程序 对客户端应用访问网络对象的破坏的方法流程图;以及
图 3 示出了根据本发明一个实施例的一种控制客户端访问网络的检测装置 结构示意图;
图 4示出了本发明实施例提供的一种通信系统的结构示意图。 实施本发明的方式
下面将参照附图更详细地描述本公开的示例性实施例。 虽然附图中显示了 本公开的示例性实施例, 然而应当理解, 可以以各种形式实现本公开而不应被 这里阐述的实施例所限制。 相反, 提供这些实施例是为了能够更透彻地理解本 公开, 并且能够将本公开的范围完整的传达给本领域的技术人员。
本申请可以应用于计算机系统 /服务器, 其可与众多其它通用或专用计算系 统环境或配置一起操作。 适于与计算机系统 /服务器一起使用的众所周知的计算 系统、 环境和 /或配置的例子包括但不限于: 个人计算机系统、 服务器计算机系 统、 痩客户机、 厚客户机、 手持或膝上设备、 基于微处理器的系统、 机顶盒、 可编程消费电子产品、 网络个人电脑、 小型计算机系统、 大型计算机系统和包 括上述任何系统的分布式云计算技术环境, 等等。
计算机系统 /服务器可以在由计算机系统执行的计算机系统可执行指令 (诸 如程序模块) 的一般语境下描述。 通常, 程序模块可以包括例程、 程序、 目标 程序、 组件、 逻辑、 数据结构等等, 它们执行特定的任务或者实现特定的抽象 数据类型。 计算机系统 /服务器可以在分布式云计算环境中实施, 分布式云计算 环境中, 任务是由通过通信网络链接的远程处理设备执行的。 在分布式云计算 环境中, 程序模块可以位于包括存储设备的本地或远程计算系统存储介质上。
计算机系统 /服务器也可以与一个或多个外部设备一一诸如键盘、指向设备、 显示器等等一一通信, 与一个或者多个使用户能与计算机系统 /服务器交互的设 备通信, 和 /或与使计算机系统 /服务器能与一个或多个其它计算设备通信的任何 设备(例如网卡, 调制解调器等等)通信。 这种通信可以通过输入 /输出 (I/O ) 接口进行。 并且, 计算机系统 /服务器还可以通过网络适配器与一个或者多个网 络——诸如局域网 (LAN ), 广域网 (WAN ) 和 /或公共网络(例如因特网) 一 一通信。如图所示, 网络适配器通过总线与计算机系统 /服务器的其它模块通信。 应当明白, 其它硬件和 /或软件模块可以与计算机系统 /服务器一起使用。 例子包 括但不限于: 微代码、 设备驱动器、 冗余处理单元、 外部磁盘驱动阵列、 RAID 系统、 磁带驱动器以及数据备份存储系统, 等等。
本发明一个实施例提供的一种控制客户端访问网络的检测方法, 参见图 1 , 所述方法包括:
S100: 根据客户端系统选取系统设置检测项, 所述系统设置检测项包括客 户端系统的网络协议安全性( Internet Protocol Security, IPSec )设置、 系统防火 墙设置、 本地 IP地址、 路由项、 DNS设置和主机文件中的一项或多项。
S102: 利用所述系统设置检测项和客户端应用需要访问的网络对象的通讯 信息, 对客户端应用与所述网络对象之间的通讯进行检测。 本实施例中, 通常将上述步骤 S100中选取的系统设置检测项作为基础的检 测项, 并在本步骤中对上述所有的系统设置检测项进行检测, 可以理解, 在本 步骤中也可以仅对上述的部分通讯检测项进行检测。 通过对系统设置检测项的 检测, 本方案能够从系统设置的维度对客户端应用访问系统网络进行检测和修 复。
上述网络对象为客户端应用要访问的网络设备或系统, 如网络对象可以为
Windows系统下的云安全中心服务器等。
S104: 当对系统设置检测项的检测结果指示通讯正常时, 允许客户端应用 访问所述网络对象。
S106: 当对系统设置检测项的检测结果指示通讯异常时, 修复所述系统设 置检测项使检测结果指示通讯正常, 当通讯正常时允许客户端应用访问所述网 络对象。
S108: 当修复所述系统设置检测项失败时, 对选取的驱动检测项进行检测, 进入步骤 S110, 当修复所述系统设置检测项成功时, 表明通讯正常, 允许客户 端应用访问所述网络对象。 通过对驱动检测项的检测, 本方案能够从系统内核 的维度对客户端应用访问系统网络进行检测和修复。
S110: 当对驱动检测项的检测结果指示通讯异常时, 修复所述驱动检测项, 当对驱动检测项的检测结果指示通讯正常时, 允许客户端应用访问所述网络对 由上所述, 本发明实施例通过选取系统设置检测项和驱动检测项, 利用系 统设置检测项、 驱动检测项与网络对象的通讯信息进行访问控制的技术手段, 能够从系统内核到系统设置等多个维度检测恶意程序对客户端应用访问系统网 络的破坏, 有效地修复恶意程序对客户端应用与网络对象之间通讯造成的破坏, 保证了客户端应用对网络对象的正常访问。
本发明又一个实施例以客户端应用为用于保证客户端网络安全的客户端安 全应用、 客户端应用需要访问的网络对象为云安全中心服务器的场景为例进行 说明。
云计算环境包括云计算消费者使用的本地计算设备可以与其相通信的一个 或者多个云计算节点, 本地计算设备诸如个人数字辅助设备 ( PDA )或者是移 动电话, 台式电脑, 笔记本电脑, 和 /或汽车计算机系统。 节点之间可以相互通 信。 可以在在一个或者多个网络——诸如如上所述的私有云、 共同体云、 公共 云或混合云或者它们的组合——中, 将节点进行物理或者虚拟分组(图中未示 出)。 这允许云计算环境提供云消费者无需在本地计算设备上维护资源就能请求 的基础架构即服务、 平台即服务和 /或软件即服务。 应当明白,计算节点以及云计 算环境可以与任何类型的网络上的和 /或网络可寻址的连接上的任何类型的计算 设备(例如使用网络浏览器)通信。
云安全架构基于云计算环境实现, 是将所有云安全客户端与云安全服务器 实时连接, 客户端不断釆集上报更新, 在服务器端组成一庞大的恶意程序数据 库, 并将主动防御的分析比对操作放在服务器端完成, 从而使整个云安全网络 成为一主动防御工具; 针对具有威胁的程序行为进行收集并保存在服务器的数 据库中, 在服务器端进行恶意软件分析时支持直接使用程序行为进行恶意程序 判定;
另外, 本发明实施例通过客户端收集程序行为并关联到程序特征, 从而在 数据库中记录程序特征及其对应的程序行为, 根据收集到的程序行为和程序特 征的关联关系, 可以在数据库中对样本进行分析归纳, 从而有助于对软件或程 序进行黑白的分类判别, 还可以针对黑名单中的恶意软件制定相应的清除或恢 复措施 。
然而, 木马病毒以及一些其他的恶意程序为了躲避安全软件的检测, 会想 方设法破坏客户端安全软件与网络服务器, 例如, 云安全服务器之间的网络通 讯, 阻止客户端安全软件访问网络服务器, 导致客户端无法升级网络服务器端 的病毒库, 无法识别和清除新木马。
网络对象的通讯信息包括网络对象的域名和 IP地址, 如云安全中心服务器 的多个域名构成的域名列表和多个 IP地址构成的 IP地址列表,该域名列表可以 表示为 CloudSecCentre (Domain)={Dl,D2, ... ,Dn}, 该 IP 地址列表可以表示为 CloudSecCentre (IP)= {IP 1 ,IP2, . - . ,ΙΡη}。
则利用系统设置检测项和客户端应用需要访问的网络对象的通讯信息, 对 客户端应用与所述网络对象之间的通讯进行的检测可以包括如下:
( 1 ) IPSec设置
考虑到恶意程序 (如木马)会将安全厂商的云安全中心服务器 IP地址或域 名加入到 IPSec设置的阻止列表中来破坏网络通讯,本实施例中检测客户端系统 的网络协议安全性设置的阻止列表中是否存在网络对象的通讯信息, 若是, 检 测结果指示通讯异常, 若否, 检测结果指示通讯正常。 例如,读取客户端系统的 IPSec设置,检查设置项的阻止列表中是否存在云 安全中心的域名 CloudSecCentre (Domain)和 IP地址 CloudSecCentre (IP)的项目, 如果存在则予以清除, 如果不存在, 不对 IPSec设置进行修改。 可选的, 本实施 例中也可以直接对 IPSec设置中的所有信息进行检测,判断网络对象的通讯信息 是否在 IPSec设置中,若在将网络对象的通讯信息从 IPSec设置中清除,若不在, 保持 IPSec设置不变。
( 2 ) 系统防火墙设置
考虑到木马会修改 Vista及以上平台的系统防火墙的出入站规则, 把包含云 安全中心服务器 IP地址或客户端安全应用名称的规则条目加入阻止列表中来破 坏网络通讯, 本实施例中检测客户端系统的系统防火墙设置的阻止列表的规则 条目中是否存在网络对象的 IP地址或客户端应用的名称, 若是, 检测结果指示 通讯异常, 若否, 检测结果指示通讯正常。
例如, 读取客户端系统的系统防火墙设置, 逐一检查系统防火墙的阻止列 表中的规则条目是否存在云安全中心 IP地址 CloudSecCentre(IP)或客户端安全应 用的名称, 若存在则予以清除, 即将网络对象的 IP地址或客户端应用名称的规 则条目从系统防火墙设置的阻止列表中清除, 若不存在, 保持原系统防火墙的 设置。
( 3 )本地 IP地址
考虑到木马会通过在客户端添加与云安全中心服务器在同一网段的 IP地址 及无效网关地址, 使得客户端应用无法访问云安全中心服务器 IP来破坏通讯, 本实施例检测客户端系统是否存在与网络对象的 IP地址在同一网段的本地 IP地 址, 若是, 检测结果指示通讯异常, 若否, 检测结果指示通讯正常。
例如,读取客户端系统的所有 IP地址设置, 逐一检查是否存在有 IP地址与 云安全中心服务器 IP地址 CloudSecCentre(IP)中的某一 IP在同一网段内, 如果 存在则清除客户端的此 IP地址项,即将客户端系统中与网络对象的 IP地址在同 一网段的本地 IP地址清除, 如果不存在, 保持客户端系统的 IP地址设置。
( 4 )路由项
考虑到木马会设置错误的路由项导致客户端应用无法访问云安全中心服务 器 IP地址来破坏通讯, 本实施例检测客户端系统的路由项中是否存在与网络对 象的 IP地址在同一网段的 IP地址, 若是, 检测结果指示通讯异常, 若否, 检测 结果指示通讯正常。 例如, 读取客户端系统的所有路由项, 逐一检查路由项的网络地址是否与 云安全中心服务器 IP地址 CloudSecCentre(IP)中的网络地址相同,如果相同则清 除此路由项,即将客户端系统中存在与网络对象的 IP地址在同一网段的 IP地址 的路由项清除, 如果不同, 保持原路由项。
( 5 ) DNS设置
考虑到木马会修改客户端系统的 DNS设置, 将客户端指向木马作者控制的 黑 DNS服务器, 导致无法解析云安全中心域名, 从而无法正常通讯, 本实施例 当检测到客户端系统的 DNS设置中的 IP地址在禁止 DNS列表中时, 将 DNS 设置中的 IP地址修改为可信赖的 DNS服务器地址。 该禁止 DNS列表由已获知 的非法 IP地址或者禁止客户端应用访问的 IP地址构成, 也可以称之为黑 DNS 列表。
例如, 读取客户端系统的网络 DNS设置, 检查 DNS的 IP地址是否在禁止 DNS列表中, 如果在, 则将 DNS设置中的 IP地址修改为可信赖的 DNS服务器 地址, 如将 DNS修正为预置的 DNS服务器地址: 8.8.8.8和 8.8.4.4, 如果不在, 保持客户端系统的网络 DNS设置不变。
( 6 )主机文件(Hosts )
考虑到木马会在客户端系统的主机文件中添加云安全中心服务器域名并使 其指向错误的 IP地址来破坏通讯, 本实施例当检测到客户端系统的主机文件的 各条目中包括网络对象的域名时, 将客户端系统中包括网络对象的域名的主机 文件的条目清除。 主机文件通常由多行的信息构成, 每行信息可视为一个条目, 条目中设置有域名信息等。
例如,主机文件通常位于客户端系统的 c:\windows\system32\drivers\etc目录 下, 读取客户端系统的主机文件, 逐一检查其中的每一条目中的域名是否包含 云安全中心的域名 CloudSecCentre (Domain), 如果包含, 则将客户端系统中包 括网络对象的域名的主机文件的条目清除, 如果不包含, 则保持主机文件的条 目不变。
由上可见, 本实施例中釆用的修复的方式包括下述的至少一种或其组合: 当检测到客户端系统的 IPSec设置的阻止列表中存在网络对象的通讯信息 时, 将网络对象的通讯信息从 IPSec设置的阻止列表中清除;
当检测到客户端系统的系统防火墙设置的阻止列表的规则条目中存在网络 对象的 IP地址或客户端应用的名称时,将网络对象的 IP地址或客户端应用名称 的规则条目从系统防火墙设置的阻止列表中清除;
当检测到客户端系统存在与网络对象的 IP地址在同一网段的本地 IP地址 时, 将客户端系统中与网络对象的 IP地址在同一网段的本地 IP地址清除; 当检测到客户端系统的路由项中存在与网络对象的 IP地址在同一网段的 IP 地址时,将客户端系统中存在与网络对象的 IP地址在同一网段的 IP地址的路由 项清除;
当检测到客户端系统的 DNS设置中的 IP地址在禁止 DNS列表中时,将 DNS 设置中的 IP地址修改为可信赖的 DNS服务器地址;
当检测到客户端系统的主机文件的各条目中包括网络对象的域名时, 将客 户端系统中包括网络对象的域名的主机文件的条目清除。
本实施例中上述系统设置检测项的选取, 以及检测和修复的具体方式等是 在与木马 (如典型的 "飓风木马")对抗实践过程中总结出来的, 能有效地修复 木马对云安全中心网络通讯造成的破坏, 以保证客户端安全软件与云安全中心 的正常通讯, 为后面的木马查杀提供可靠的网络环境, 使得安全软件发挥最好 的木马查杀效果。
由于多数情况下, 在执行完上述六个关键点的操作后, 已经能够检测出并 修复完恶意程序对客户端应用访问 Windows系统网络的破坏, 则此时允许客户 端安全应用访问云安全中心服务器, 从而能够保证客户端及时快速地将可疑文 件上报云安全中心服务器。
若在执行完上述六个关键点的木马检测和修复后, 客户端安全应用还无法 访问云安全中心服务器, 则本实施例还包括选取客户端系统的网络过滤驱动作 为驱动检测项, 基于 NDIS ( Network Driver Interface Specification, 网络驱动接 口规范) 网络过滤驱动进行木马查杀。
( 7 ) 网络过滤驱动
网络过滤驱动通常包括网络过滤驱动文件和注册表信息, 本实施例检测网 络过滤驱动是否存在于黑名单中, 若是, 检测结果指示通讯异常; 若否, 检测 结果指示通讯正常;
当检测结果指示通讯异常时, 修复所述网络过滤驱动使检测结果指示通讯 正常, 当检测结果指示通讯正常时, 允许客户端应用访问所述网络对象。 参见 图 2,示出了基于网络过滤驱动的修复恶意程序对客户端应用访问网络对象的破 坏的方法流程图, 具体处理如下: S200: 判断客户端应用能否访问网络对象。
若在执行完上述六个关键点的检测和修复后, 客户端应用能访问网络对象, 通讯正常, 则检测结束。
若在执行完上述六个关键点的检测和修复后, 客户端应用还不能访问网络 对象, 执行步骤 S202。
S202: 获取客户端系统中的所有网络过滤驱动的标识信息。
网络过滤驱动的标识信息包括网络过滤驱动的签名信息和 /或版本信息。 通 配置接口读取系统中所有网络过滤驱动。
S204: 检查网络过滤驱动是否在黑名单和白名单中。
白名单中记录了允许的网络过滤驱动的标识信息, 黑名单中记录了禁止的 网络过滤驱动的标识信息。
将位于黑名单中的网络过滤驱动的状态设置为黑, 其中, 黑代表不可信, 将位于白名单中的网络过滤驱动的状态设置为白, 白代表可信, 将既不位于黑 名单中也不位于白名单中的网络过滤驱动的状态设置为灰, 灰代表未知。
若客户端系统中的所有网络过滤驱动都位于白名单中, 则不在进行后续处 理, 检测结束, 否则, 执行步骤 S206。
S206: 若客户端系统中存在黑的网络过滤驱动, 则将黑名单中的网络过滤 驱动备份后, 将黑名单中的网络过滤驱动清除, 此时的检测结果指示通讯正常, 允许客户端应用访问所述网络对象, 执行步骤 S208。
S208: 判断此时的客户端应用能否访问网络对象, 若是, 通讯正常, 结束 操作, 若否, 执行步骤 S210。
S210: 判断客户端在当前的用户环境下是否能够访问信赖的第三方网络对 象, 若能够, 执行步骤 S212 , 若不能, 说明客户端本身的访问出现问题, 客户 端无法访问网络, 结束操作。 通过上述在用户环境下检测客户端应用对网络对 象的访问, 本方案还从用户态的维度对客户端应用访问系统网络进行了检测和 修复。
由上可知, 本方案能够从系统内核到用户态以及系统设置等多个维度全面 检测恶意程序对客户端应用访问系统网络的破坏, 保证在进行恶意程序的查杀 之前有一个可靠的网络通讯环境。
S212: 判断客户端应用是否具有不存在于黑名单和白名单中的网络过滤驱 动, 即是否存在灰的网络过滤驱动, 若不具有灰的网络过滤驱动, 确认客户端 应用无法访问网络, 若具有, 执行步骤 S214。
S214: 将该灰的网络过滤驱动备份后清除, 允许客户端应用访问所述网络 对象。
可以理解, 对网络过滤驱动的检测也可以和上述六个关键点同时执行。 由上所述, 本发明实施例通过选取系统设置检测项和驱动检测项, 利用系 统设置检测项、 驱动检测项与网络对象的通讯信息进行访问控制的技术手段, 能够从系统内核到系统设置等多个维度检测恶意程序对客户端应用访问系统网 络的破坏, 有效地修复恶意程序对客户端应用与网络对象之间通讯造成的破坏, 保证了客户端应用对网络对象的正常访问。
本发明一个实施例还提供了一种控制客户端访问网络的检测装置, 参见图 3 , 该装置包括:
检测项选取单元 300 , 适于根据客户端系统选取系统设置检测项, 其中该系 统设置检测项包括客户端系统的网络协议安全性设置、 系统防火墙设置、 本地 IP地址、 路由项、 域名系统 DNS设置和 /或主机文件;
检测单元 302,适于利用系统设置检测项和客户端应用需要访问的网络对象 的通讯信息, 对客户端应用与网络对象之间的通讯进行检测;
访问控制单元 304, 适于当对系统设置检测项的检测结果指示通讯异常时, 修复所述系统设置检测项, 当检测结果指示通讯正常时, 允许客户端应用访问 所述网络对象;
检测项选取单元 300, 还适于选取驱动检测项进行检测; 检测单元 302, 还 适于当修复所述系统设置检测项失败时, 对选取的驱动检测项进行检测;
访问控制单元 304, 还适于当对驱动检测项的检测结果指示通讯异常时,修 复所述驱动检测项, 当对驱动检测项的检测结果指示通讯正常时, 允许客户端 应用访问所述网络对象。
其中, 上述通讯信息包括网络对象的域名和 IP地址, 检测单元 302, 具体 适于检测客户端系统的网络协议安全性设置的阻止列表中是否存在网络对象的 通讯信息, 若是, 检测结果指示通讯异常, 若否, 检测结果指示通讯正常; 和 / 或,
检测客户端系统的系统防火墙设置的阻止列表的规则条目中是否存在网络 对象的 IP地址或客户端应用的名称, 若是, 检测结果指示通讯异常, 若否, 检 测结果指示通讯正常; 和 /或,
检测客户端系统是否存在与网络对象的 IP地址在同一网段的本地 IP地址, 若是, 检测结果指示通讯异常, 若否, 检测结果指示通讯正常; 和 /或,
检测客户端系统的路由项中是否存在与网络对象的 IP地址在同一网段的 IP 地址, 若是, 检测结果指示通讯异常, 若否, 检测结果指示通讯正常;
和 /或,
检测客户端系统的 DNS设置中的 IP地址是否在禁止 DNS列表中, 若是, 检测结果指示通讯异常, 若否, 检测结果指示通讯正常; 和 /或,
检测客户端系统的主机文件的各条目中是否包括网络对象的域名, 若是, 检测结果指示通讯异常, 若否, 检测结果指示通讯正常。
其中, 访问控制单元 304, 适于当检测结果指示通讯异常时, 通过下述方式 修复系统设置检测项:
当检测到客户端系统的网络协议安全性设置的阻止列表中存在网络对象的 通讯信息时, 将网络对象的通讯信息从网络协议安全性设置的阻止列表中清除; 和 /或,
当检测到客户端系统的系统防火墙设置的阻止列表的规则条目中存在网络 对象的 IP地址或客户端应用的名称时,将包含网络对象的 IP地址或客户端应用 名称的规则条目从系统防火墙设置的阻止列表中清除; 和 /或,
当检测到客户端系统存在与网络对象的 IP地址在同一网段的本地 IP地址 时, 将客户端系统中与网络对象的 IP地址在同一网段的本地 IP地址清除;
和 /或,
当检测到客户端系统的路由项中存在与网络对象的 IP地址在同一网段的 IP 地址时 ,将客户端系统中存在与网络对象的 IP地址相同的 IP地址的路由项清除; 和 /或,
当检测到客户端系统的 DNS设置中的 IP地址在禁止 DNS列表中时,将 DNS 设置中的 IP地址修改为可信赖的 DNS服务器地址; 和 /或,
当检测到客户端系统的主机文件的各条目中包括网络对象的域名时, 将客 户端系统中包括网络对象的域名的主机文件的条目清除。
可选的,检测项选取单元 300, 具体适于选取网络过滤驱动作为所述驱动检 测项;
检测单元 302, 还适于检测网络过滤驱动是否存在于黑名单中, 若是, 检测 结果指示通讯异常; 若否, 检测结果指示通讯正常;
访问控制单元 304, 还适于当检测结果指示通讯异常时,修复网络过滤驱动 使检测结果指示通讯正常, 当检测结果指示通讯正常时, 允许客户端应用访问 网络对象。
其中, 上述检测单元 302, 具体适于通过下列方式, 检测网络过滤驱动是否 存在于黑名单中: 从客户端系统的注册表和网络配置接口中获取网络过滤驱动 的签名信息和版本信息; 当网络过滤驱动的签名信息和版本信息位于黑名单中 时, 确认该网络过滤驱动存在于黑名单中, 当网络过滤驱动的签名信息和版本 信息不位于黑名单中时, 确认该网络过滤驱动不存在于黑名单中。
其中, 访问控制单元 304, 适于通过下述方式修复网络过滤驱动: 将黑名单 中的网络过滤驱动备份后, 将该网络过滤驱动清除, 检测结果指示通讯正常, 允许客户端应用访问网络对象。
进一步的 ,访问控制单元 304,还适于在将黑名单中的网络过滤驱动备份后, 将该网络过滤驱动从黑名单中清除, 检测结果指示通讯正常, 允许客户端应用 访问网络对象之后, 当客户端应用访问网络对象失败时, 若客户端应用不能成 功访问信赖的第三方网络对象, 确认客户端应用无法访问网络, 若客户端应用 能够成功访问信赖的第三方网络对象, 从客户端系统的注册表和网络配置接口 中获取网络过滤驱动的签名信息和 /或版本信息, 根据网络过滤驱动的签名信息 和 /或版本信息判断客户端应用是否具有不存在于黑名单和白名单中的网络过滤 驱动, 若不具有, 确认客户端应用无法访问网络, 若具有, 将该网络过滤驱动 备份后清除, 允许客户端应用访问网络对象。
检测单元 302, 具体适于通过下列方式,检测网络过滤驱动是否存在于黑名 单中: 从客户端系统的注册表和网络配置接口中获取网络过滤驱动的签名信息 和 /或版本信息; 当网络过滤驱动的签名信息和 /或版本信息位于黑名单中时, 确 认该网络过滤驱动存在于黑名单中, 当网络过滤驱动的签名信息和 /或版本信息 不位于黑名单中时, 确认该网络过滤驱动不存在于黑名单中;
检测单元 302, 具体适于通过下列方式, 判断客户端应用是否具有不存在于 黑名单和白名单中的网络过滤驱动:
当网络过滤驱动的签名信息和 /或版本信息不存在于黑名单和白名单中时, 确认客户端应用具有不存在于黑名单和白名单中的网络过滤驱动, 否则, 确认 客户端应用不具有不存在于黑名单和白名单中的网络过滤驱动。 本发明装置实施例中各单元的具体工作方式可以参见本发明的方法实施 例, 在此不再赘述。
由上所述, 本发明实施例通过选取网络协议安全性设置、 系统防火墙设置、 本地 IP地址、 路由项、 DNS设置和主机文件作为系统设置检测项, 利用系统设 置检测项与网络对象的通讯信息进行访问控制的技术手段, 能够从系统内核到 用户态以及系统设置等多个维度检测恶意程序对客户端应用访问 Windows系统 网络的破坏, 有效地修复恶意程序对客户端应用与网络对象之间通讯造成的破 坏, 保证了客户端应用对网络对象的正常访问。
本发明实施例还提供了一种通信系统, 参见图 4, 该通信系统包括客户端设 备 400,客户端设备 400包括如上述实施例提供的至少一种的控制客户端访问网 络的检测装置 402,
客户端设备 400上运行的客户端应用 406需要访问的网络对象为云安全中 心服务器 404;
控制客户端访问网络的检测装置 402允许客户端应用访问云安全中心服务 器 404 时, 客户端应用 406, 适于将可疑文件的信息发送至云安全中心服务器 404, 并接收云安全中心服务器 404下发的对该可疑文件的信息的分析结果。
由上所述, 本发明实施例通过选取网络协议安全性设置、 系统防火墙设置、 本地 IP地址、 路由项、 DNS设置和主机文件作为系统设置检测项, 利用系统设 置检测项与网络对象的通讯信息进行访问控制的技术手段, 能够从系统内核到 用户态以及系统设置等多个维度检测恶意程序对客户端应用访问 Windows系统 网络的破坏, 有效地修复恶意程序对客户端应用与网络对象之间通讯造成的破 坏, 保证了客户端应用对网络对象的正常访问。
在此提供的算法和显示不与任何特定计算机、 虚拟系统或者其它设备固有 相关。 各种通用系统也可以与基于在此的示教一起使用。 根据上面的描述, 构 造这类系统所要求的结构是显而易见的。 此外, 本发明也不针对任何特定编程 语言。 应当明白, 可以利用各种编程语言实现在此描述的本发明的内容, 并且 上面对特定语言所做的描述是为了披露本发明的最佳实施方式。
在此处所提供的说明书中, 说明了大量具体细节。 然而, 能够理解, 本发 明的实施例可以在没有这些具体细节的情况下实践。 在一些实例中, 并未详细 示出公知的方法、 结构和技术, 以便不模糊对本说明书的理解。
类似地, 应当理解, 为了精简本公开并帮助理解各个发明方面中的一个或 多个, 在上面对本发明的示例性实施例的描述中, 本发明的各个特征有时被一 起分组到单个实施例、 图、 或者对其的描述中。 然而, 并不应将该公开的方法 解译成反映如下意图: 即所要求保护的本发明要求比在每个权利要求中所明确 记载的特征更多的特征。 更确切地说, 如下面的权利要求书所反映的那样, 发 明方面在于少于前面公开的单个实施例的所有特征。 因此, 遵循具体实施方式 的权利要求书由此明确地并入该具体实施方式, 其中每个权利要求本身都作为 本发明的单独实施例。
本领域那些技术人员可以理解, 可以对实施例中的设备中的模块进行自适 应性地改变并且把它们设置在与该实施例不同的一个或多个设备中。 可以把实 施例中的模块或单元或组件组合成一个模块或单元或组件, 以及此外可以把它 们分成多个子模块或子单元或子组件。 除了这样的特征和 /或过程或者单元中的 至少一些是相互排斥之外, 可以釆用任何组合对本说明书 (包括伴随的权利要 求、 摘要和附图) 中公开的所有特征以及如此公开的任何方法或者设备的所有 过程或单元进行组合。 除非另外明确陈述, 本说明书 (包括伴随的权利要求、 摘要和附图) 中公开的每个特征可以由提供相同、 等同或相似目的的替代特征 来代替。
此外, 本领域的技术人员能够理解, 尽管在此所述的一些实施例包括其它 实施例中所包括的某些特征而不是其它特征, 但是不同实施例的特征的组合意 味着处于本发明的范围之内并且形成不同的实施例。 例如, 在下面的权利要求 书中, 所要求保护的实施例的任意之一都可以以任意的组合方式来使用。
本发明的各个部件实施例可以以硬件实现, 或者以在一个或者多个处理器 上运行的软件模块实现, 或者以它们的组合实现。 本领域的技术人员应当理解, 可以在实践中使用微处理器或者数字信号处理器 ( DSP )来实现根据本发明实施 例的控制客户端访问网络的检测装置中的一些或者全部部件的一些或者全部功 能。 本发明还可以实现为用于执行这里所描述的方法的一部分或者全部的设备 或者装置程序 (例如, 计算机程序和计算机程序产品)。 这样的实现本发明的程 序可以存储在计算机可读介质上, 或者可以具有一个或者多个信号的形式。 这 样的信号可以从因特网网站上下载得到, 或者在载体信号上提供, 或者以任何 其他形式提供。
当本发明可以实现为用于执行这里所描述的方法的一部分或者全部的计算 机程序时, 该计算机程序包括计算机可读代码, 当该计算机可读代码在客 户端上运行时, 导致客户端执行这里所述的控制客户端访问网络的检测方 法。
应该注意的是上述实施例对本发明进行说明而不是对本发明进行限制, 并 且本领域技术人员在不脱离所附权利要求的范围的情况下可设计出替换实施 例。 在权利要求中, 不应将位于括号之间的任何参考符号构造成对权利要求的 限制。 单词 "包含" 不排除存在未列在权利要求中的元件或步骤。 位于元件之 前的单词 "一" 或 "一个" 不排除存在多个这样的元件。 本发明可以借助于包 括有若干不同元件的硬件以及借助于适当编程的计算机来实现。 在列举了若干 装置的单元权利要求中, 这些装置中的若干个可以是通过同一个硬件项来具体 体现。 单词第一、 第二、 以及第三等的使用不表示任何顺序。 可将这些单词解 释为名称。

Claims

权利要求书
1、 一种控制客户端访问网络的检测方法, 所述方法包括:
根据客户端系统设置选取系统设置检测项;
利用所述系统设置检测项和客户端应用需要访问的网络对象的通讯信息, 对客户端应用与所述网络对象之间的通讯进行检测;
当对系统设置检测项的检测结果指示通讯异常时, 修复所述系统设置检测 项, 当检测结果指示通讯正常时, 允许客户端应用访问所述网络对象;
当修复所述系统设置检测项失败时, 对选取的驱动检测项进行检测, 当对 驱动检测项的检测结果指示通讯异常时, 修复所述驱动检测项, 当对驱动检测 项的检测结果指示通讯正常时, 允许客户端应用访问所述网络对象。
2、 根据权利要求 1所述的方法, 其中, 所述系统设置检测项包括客户端系 统的网络协议安全性设置、 系统防火墙设置、 本地 IP地址、 路由项、 域名系统 DNS设置和 /或主机文件。
3、 根据权利要求 2所述的方法, 其中, 所述通讯信息包括网络对象的域名 和 IP地址, 所述利用所述系统设置检测项和客户端应用需要访问的网络对象的 通讯信息, 对客户端应用与所述网络对象之间的通讯进行检测包括:
检测客户端系统的网络协议安全性设置的阻止列表中是否存在网络对象的 通讯信息, 若是, 检测结果指示通讯异常, 若否, 检测结果指示通讯正常; 和 /或,
检测客户端系统的系统防火墙设置的阻止列表的规则条目中是否存在网络 对象的 IP地址或客户端应用的名称, 若是, 检测结果指示通讯异常, 若否, 检 测结果指示通讯正常; 和 /或,
检测客户端系统是否存在与网络对象的 IP地址在同一网段的本地 IP地址, 若是, 检测结果指示通讯异常, 若否, 检测结果指示通讯正常; 和 /或,
检测客户端系统的路由项中是否存在与网络对象的 IP地址在同一网段的 IP 地址, 若是, 检测结果指示通讯异常, 若否, 检测结果指示通讯正常;
和 /或,
检测客户端系统的 DNS设置中的 IP地址是否在禁止 DNS列表中, 若是, 检测结果指示通讯异常, 若否, 检测结果指示通讯正常; 和 /或,
检测客户端系统的主机文件的各条目中是否包括网络对象的域名, 若是, 检测结果指示通讯异常, 若否, 检测结果指示通讯正常。
4、 根据权利要求 3所述的方法, 其中, 所述当检测结果指示通讯异常时, 修复所述系统设置检测项包括:
当检测到客户端系统的网络协议安全性设置的阻止列表中存在网络对象的 通讯信息时, 将网络对象的通讯信息从网络协议安全性设置的阻止列表中清除; 和 /或,
当检测到客户端系统的系统防火墙设置的阻止列表的规则条目中存在网络 对象的 IP地址或客户端应用的名称时, 将该规则条目从系统防火墙设置的阻止 列表中清除; 和 /或,
当检测到客户端系统存在与网络对象的 IP地址在同一网段的本地 IP地址 时, 将客户端系统中与网络对象的 IP地址在同一网段的本地 IP地址清除;
和 /或,
当检测到客户端系统的路由项中存在与网络对象的 IP地址在同一网段的 IP 地址时,将客户端系统中存在与网络对象的 IP地址在同一网段的 IP地址的路由 项清除; 和 /或,
当检测到客户端系统的 DNS设置中的 IP地址在禁止 DNS列表中时,将 DNS 设置中的 IP地址修改为可信赖的 DNS服务器地址; 和 /或,
当检测到客户端系统的主机文件的各条目中包括网络对象的域名时, 将客 户端系统中包括网络对象的域名的主机文件的条目清除。
5、根据权利要求 1所述的方法, 其中,选取的驱动检测项为网络过滤驱动, 所述对选取的驱动检测项进行检测包括:
检测网络过滤驱动是否存在于黑名单中, 若是, 对网络过滤驱动的检测结 果指示通讯异常; 若否, 对网络过滤驱动的检测结果指示通讯正常。
6、 根据权利要求 5所述的方法, 其中, 所述修复所述网络过滤驱动包括: 将黑名单中的网络过滤驱动备份后, 将该网络过滤驱动清除, 检测结果指 示通讯正常时, 允许客户端应用访问所述网络对象。
7、 根据权利要求 6所述的方法, 其中, 在所述将黑名单中的网络过滤驱动 备份后, 将该网络过滤驱动从黑名单中清除, 检测结果指示通讯正常, 允许客 户端应用访问所述网络对象之后, 所述方法还包括:
当客户端应用访问网络对象失败时, 若客户端应用不能成功访问信赖的第 三方网络对象, 确认客户端应用无法访问网络, 若客户端应用能够成功访问信 赖的第三方网络对象, 判断客户端应用是否具有不存在于黑名单和白名单中的 网络过滤驱动, 若不具有, 确认客户端应用无法访问网络, 若具有, 将该网络 过滤驱动备份后清除, 允许客户端应用访问所述网络对象。
8、 根据权利要求 7所述的方法, 其特征在于,
所述检测网络过滤驱动是否存在于黑名单中包括:
从客户端系统的注册表和网络配置接口中获取网络过滤驱动的签名信息和 / 或版本信息;
当网络过滤驱动的签名信息和 /或版本信息位于黑名单中时, 确认该网络过 滤驱动存在于黑名单中, 当网络过滤驱动的签名信息和 /或版本信息不位于黑名 单中时, 确认该网络过滤驱动不存在于黑名单中;
所述判断客户端应用是否具有不存在于黑名单和白名单中的网络过滤驱动 包括:
当网络过滤驱动的签名信息和 /或版本信息不存在于黑名单和白名单中时, 确认客户端应用具有不存在于黑名单和白名单中的网络过滤驱动, 否则, 确认 客户端应用不具有不存在于黑名单和白名单中的网络过滤驱动。
9、 一种控制客户端访问网络的检测装置, 所述装置包括:
检测项选取单元, 适于根据客户端系统设置选取系统设置检测项; 检测单元, 适于利用所述系统设置检测项和客户端应用需要访问的网络对 象的通讯信息, 对客户端应用与所述网络对象之间的通讯进行检测;
访问控制单元, 适于当对系统设置检测项的检测结果指示通讯异常时, 修 复所述系统设置检测项, 当检测结果指示通讯正常时, 允许客户端应用访问所 述网络对象;
所述检测项选取单元, 还适于选取驱动检测项进行检测; 所述检测单元, 还适于当修复所述系统设置检测项失败时, 对选取的驱动检测项进行检测; 所述访问控制单元, 还适于当对驱动检测项的检测结果指示通讯异常时, 修复所述驱动检测项, 当对驱动检测项的检测结果指示通讯正常时, 允许客户 端应用访问所述网络对象。
10、 根据权利要求 9所述的装置, 其中, 所述系统设置检测项包括客户端 系统的网络协议安全性设置、 系统防火墙设置、 本地 IP地址、 路由项、 域名系 统 DNS设置和 /或主机文件, 所述通讯信息包括网络对象的域名和 IP地址, 所述检测单元, 具体适于检测客户端系统的网络协议安全性设置的阻止列 表中是否存在网络对象的通讯信息, 若是, 检测结果指示通讯异常, 若否, 检 测结果指示通讯正常; 和 /或,
检测客户端系统的系统防火墙设置的阻止列表中的规则条目中是否存在网 络对象的 IP地址或客户端应用的名称, 若是, 检测结果指示通讯异常, 若否, 检测结果指示通讯正常; 和 /或,
检测客户端系统是否存在与网络对象的 IP地址在同一网段的本地 IP地址, 若是, 检测结果指示通讯异常, 若否, 检测结果指示通讯正常; 和 /或,
检测客户端系统的路由项中是否存在与网络对象的 IP地址在同一网段的 IP 地址, 若是, 检测结果指示通讯异常, 若否, 检测结果指示通讯正常;
和 /或,
检测客户端系统的 DNS设置中的 IP地址是否在禁止 DNS列表中, 若是, 检测结果指示通讯异常, 若否, 检测结果指示通讯正常; 和 /或,
检测客户端系统的主机文件的各条目中是否包括网络对象的域名, 若是, 检测结果指示通讯异常, 若否, 检测结果指示通讯正常。
11、 根据权利要求 9 所述的装置, 其中, 所述访问控制单元, 适于当检测 结果指示通讯异常时, 通过下述方式修复所述系统设置检测项:
当检测到客户端系统的网络协议安全性设置的阻止列表中存在网络对象的 通讯信息时, 将网络对象的通讯信息从网络协议安全性设置的阻止列表中清除; 和 /或,
当检测到客户端系统的系统防火墙设置的阻止列表中的规则条目中存在网 络对象的 IP地址或客户端应用的名称时, 将该规则条目从系统防火墙设置的阻 止列表中清除; 和 /或,
当检测到客户端系统存在与网络对象的 IP地址在同一网段的本地 IP地址 时, 将客户端系统中与网络对象的 IP地址在同一网段的本地 IP地址清除;
和 /或,
当检测到客户端系统的路由项中存在与网络对象的 IP地址在同一网段的 IP 地址时,将客户端系统中存在与网络对象的 IP地址在同一网段的 IP地址的路由 项清除; 和 /或,
当检测到客户端系统的 DNS设置中的 IP地址在禁止 DNS列表中时,将 DNS 设置中的 IP地址修改为可信赖的 DNS服务器地址; 和 /或,
当检测到客户端系统的主机文件的各条目中包括网络对象的域名时, 将客 户端系统中包括网络对象的域名的主机文件的条目清除。
12、 根据权利要求 9所述的装置, 其中, 所述检测单元, 还适于检测网络过滤驱动是否存在于黑名单中, 若是, 对 网络过滤驱动的检测结果指示通讯异常; 若否, 对网络过滤驱动的检测结果指 示通讯正常。
13、 根据权利要求 12所述的装置, 其中,
所述访问控制单元, 适于通过下述方式修复所述网络过滤驱动: 将黑名单 中的网络过滤驱动备份后, 将该网络过滤驱动清除, 检测结果指示通讯正常, 允许客户端应用访问所述网络对象。
14、 根据权利要求 13所述的装置, 其中, 所述访问控制单元, 还适于在所 述将黑名单中的网络过滤驱动备份后, 将该网络过滤驱动从黑名单中清除, 检 测结果指示通讯正常, 允许客户端应用访问所述网络对象之后, 当客户端应用 访问网络对象失败时, 若客户端应用不能成功访问信赖的第三方网络对象, 确 认客户端应用无法访问网络, 若客户端应用能够成功访问信赖的第三方网络对 象, 判断客户端应用是否具有不存在于黑名单和白名单中的网络过滤驱动, 若 不具有, 确认客户端应用无法访问网络, 若具有, 将该网络过滤驱动备份后清 除, 允许客户端应用访问所述网络对象。
15、 根据权利要求 14所述的装置, 其中,
所述检测单元, 具体适于通过下列方式, 检测网络过滤驱动是否存在于黑 名单中: 从客户端系统的注册表和网络配置接口中获取网络过滤驱动的签名信 息和 /或版本信息; 当网络过滤驱动的签名信息和 /或版本信息位于黑名单中时, 确认该网络过滤驱动存在于黑名单中, 当网络过滤驱动的签名信息和 /或版本信 息不位于黑名单中时, 确认该网络过滤驱动不存在于黑名单中;
所述检测单元, 具体适于通过下列方式, 判断客户端应用是否具有不存在 于黑名单和白名单中的网络过滤驱动:
当网络过滤驱动的签名信息和 /或版本信息不存在于黑名单和白名单中时, 确认客户端应用具有不存在于黑名单和白名单中的网络过滤驱动, 否则, 确认 客户端应用不具有不存在于黑名单和白名单中的网络过滤驱动。
16、 一种通信系统, 所述系统包括客户端设备, 所述客户端设备包括如上 述权利要求 9至 15任一项所述的控制客户端访问网络的检测装置, 所述客户端设备上运行的客户端应用需要访问的网络对象为云安全中心服 务器;
所述控制客户端访问网络的检测装置允许客户端应用访问云安全 中心服务器时, 所述客户端应用, 适于将可疑文件的信息发送至云安 全中心服务器, 并接收云安全中心服务器下发的对所述可疑文件的信 息的分析结果。
17、 一种计算机程序, 包括计算机可读代码, 当所述计算机可读 代码在客户端上运行时, 导致所述客户端执行根据权利要求 1 -8 中的 任一项所述的控制客户端访问网络的检测方法。
18、 一种计算机可读介质, 其中存储了如权利要求 17所述的计算 机程序。
PCT/CN2013/083629 2012-09-17 2013-09-17 控制客户端访问网络的检测方法、装置和系统 Ceased WO2014040571A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201210345506.7A CN102868694B (zh) 2012-09-17 2012-09-17 控制客户端访问网络的检测方法、装置和系统
CN201210345506.7 2012-09-17

Publications (1)

Publication Number Publication Date
WO2014040571A1 true WO2014040571A1 (zh) 2014-03-20

Family

ID=47447285

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2013/083629 Ceased WO2014040571A1 (zh) 2012-09-17 2013-09-17 控制客户端访问网络的检测方法、装置和系统

Country Status (2)

Country Link
CN (2) CN105100092B (zh)
WO (1) WO2014040571A1 (zh)

Families Citing this family (12)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN105100092B (zh) * 2012-09-17 2018-06-12 北京奇虎科技有限公司 控制客户端访问网络的检测方法、装置和系统
CN104144063B (zh) * 2013-05-08 2018-08-10 朱烨 基于日志分析和防火墙安全矩阵的网站安全监控报警系统
CN103269389B (zh) * 2013-06-03 2016-05-25 北京奇虎科技有限公司 检查和修复恶意dns设置的方法和装置
CN105868632B (zh) * 2016-04-20 2018-11-16 北京金山安全软件有限公司 一种拦截释放dhcp的方法及装置
CN105791033A (zh) * 2016-05-09 2016-07-20 浪潮电子信息产业股份有限公司 一种调控服务器运行状态的方法、装置及系统
CN106411860B (zh) * 2016-09-07 2019-09-17 微梦创科网络科技(中国)有限公司 一种网络互连协议ip检测的方法及装置
CN107995152B (zh) * 2016-10-27 2020-07-03 腾讯科技(深圳)有限公司 一种恶意访问检测方法、装置及检测服务器
US11005871B2 (en) * 2018-01-10 2021-05-11 AVAST Software s.r.o. Cloud-based anomalous traffic detection and protection in a remote network via DNS properties
CN108566643A (zh) * 2018-04-24 2018-09-21 深信服科技股份有限公司 App访问控制方法、系统、终端设备及存储介质
CN109858236A (zh) * 2018-12-29 2019-06-07 北京奇安信科技有限公司 一种驱动加载监管方法及客户端
CN112311626A (zh) * 2020-10-29 2021-02-02 山东大学 一种计算机网络异常检测的方法
CN112565447B (zh) * 2020-12-17 2022-09-09 南京维拓科技股份有限公司 云环境下上传下载配合加解密方法、系统及web文件管理器

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101141243A (zh) * 2006-09-08 2008-03-12 飞塔信息科技(北京)有限公司 一种对通信数据进行安全检查和内容过滤的装置和方法
US20100037321A1 (en) * 2008-08-04 2010-02-11 Yoggie Security Systems Ltd. Systems and Methods for Providing Security Services During Power Management Mode
CN102436560A (zh) * 2011-08-22 2012-05-02 高振宇 计算机自防御系统及方法
CN102868694A (zh) * 2012-09-17 2013-01-09 北京奇虎科技有限公司 控制客户端访问网络的检测方法、装置和系统

Family Cites Families (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20070061818A1 (en) * 2005-09-12 2007-03-15 Microsoft Corporation Detection of devices during operating system setup
CN102064979B (zh) * 2010-12-15 2013-04-03 刘俊 网络故障修复系统及其装置和方法
CN102436402B (zh) * 2011-03-29 2014-12-10 奇智软件(北京)有限公司 一种软件中的模块修复方法及该软件设备

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101141243A (zh) * 2006-09-08 2008-03-12 飞塔信息科技(北京)有限公司 一种对通信数据进行安全检查和内容过滤的装置和方法
US20100037321A1 (en) * 2008-08-04 2010-02-11 Yoggie Security Systems Ltd. Systems and Methods for Providing Security Services During Power Management Mode
CN102436560A (zh) * 2011-08-22 2012-05-02 高振宇 计算机自防御系统及方法
CN102868694A (zh) * 2012-09-17 2013-01-09 北京奇虎科技有限公司 控制客户端访问网络的检测方法、装置和系统

Also Published As

Publication number Publication date
CN105100092A (zh) 2015-11-25
CN102868694B (zh) 2015-08-19
CN105100092B (zh) 2018-06-12
CN102868694A (zh) 2013-01-09

Similar Documents

Publication Publication Date Title
CN105100092B (zh) 控制客户端访问网络的检测方法、装置和系统
US11489855B2 (en) System and method of adding tags for use in detecting computer attacks
US10282548B1 (en) Method for detecting malware within network content
US8539582B1 (en) Malware containment and security analysis on connection
US10587647B1 (en) Technique for malware detection capability comparison of network security devices
JP6086968B2 (ja) 悪意のあるソフトウェアに対するローカル保護をするシステム及び方法
US10068091B1 (en) System and method for malware containment
US11381578B1 (en) Network-based binary file extraction and analysis for malware detection
US9223978B2 (en) Security policy deployment and enforcement system for the detection and control of polymorphic and targeted malware
US20150244730A1 (en) System And Method For Verifying And Detecting Malware
JP6458135B2 (ja) ブランドの不正使用を処理するためのシステム及び方法
US20120117650A1 (en) Ip-based blocking of malware
US20090077631A1 (en) Allowing a device access to a network in a trusted network connect environment
CN104468632A (zh) 防御漏洞攻击的方法、设备及系统
CN108293044A (zh) 用于经由域名服务流量分析来检测恶意软件感染的系统和方法
US10225284B1 (en) Techniques of obfuscation for enterprise data center services
CN106797375A (zh) 恶意软件代理的行为检测
US8978139B1 (en) Method and apparatus for detecting malicious software activity based on an internet resource information database
CN112583841B (zh) 虚拟机安全防护方法及系统、电子设备和存储介质
CN107341396B (zh) 入侵检测方法、装置及服务器
TWI764618B (zh) 網路資安威脅防護系統及相關的前攝性可疑網域示警系統
JP6286314B2 (ja) マルウェア通信制御装置

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 13837515

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 13837515

Country of ref document: EP

Kind code of ref document: A1