A method and system for defining security boundaries based on switches

By combining the physical and logical topology of the network, defining the strategic level of nodes and adjusting security zones, the problem of poor security boundary accuracy in existing technologies is solved, achieving higher network security and adaptability.

CN116827599BActive Publication Date: 2025-12-02HUANENG ZHONGDIAN WEIHAI WIND POWER CO LTD +3
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310583765.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-05-19
Publication Date
2025-12-02
Estimated Expiration
2043-05-19

AI Technical Summary

Technical Problem

In existing technologies, the security boundary based on switches is set only according to the network logical topology, resulting in poor security boundary accuracy and affecting network security.

Method used

By acquiring the physical and logical topology of the network, and considering influencing factors and the company's development strategy, the strategic level of nodes is defined. Based on the strategic level, security zones are adjusted, access rules are set, and switch interface information is configured, and then testing and updates are performed.

Benefits of technology

It improves the precision and accuracy of security boundaries, ensuring the complex adaptability of network security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116827599B_ABST
    Figure CN116827599B_ABST
Patent Text Reader

Abstract

This invention discloses a method and system for defining security boundaries based on switches, relating to the field of data processing technology. The method includes: determining initial regions in the network based on the network's physical and logical topology; determining the influence of nodes based on influencing factors; defining the strategic level of nodes based on enterprise development strategy priorities and the influence of nodes; adjusting the initial regions into multiple strategic regions according to the strategic levels of nodes within the initial regions, setting access rules between these strategic regions, and configuring switch interface information based on the access rules; testing and verifying the access rules between the multiple strategic regions, and adjusting the access rules accordingly; obtaining the effect of the access rules over a period of time, and updating the access rules based on the effect. This improves the precision and accuracy of security boundaries and ensures the complex adaptability of security boundaries to network security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of data processing technology, and more specifically, to a method and system for defining security boundaries based on switches. Background Technology

[0002] Security boundary definition based on switches refers to dividing a network into different security zones by configuring and managing network switches, and setting strict access control rules between zones to limit the spread of network traffic and protect sensitive information from unauthorized access. This achieves control and protection of network resources. This method primarily relies on the VLAN technology of switches, and through the configuration of switch ports, it achieves isolation between hosts with different security levels, thereby improving network security.

[0003] In existing technologies, security boundaries are set or defined solely based on the network's logical topology, resulting in poor accuracy of security boundaries and thus affecting network security.

[0004] Therefore, improving the accuracy of security boundaries and network security are technical problems that need to be solved. Summary of the Invention

[0005] This invention provides a security boundary definition method based on a switch, to solve the technical problems of low security boundary accuracy and poor network security in existing technologies. The method includes:

[0006] Obtain the physical and logical topology of the network, and determine the initial regions in the network based on the physical and logical topology.

[0007] Obtain the influencing factors of each node within each initial region, and determine the influence of each node based on these factors.

[0008] Obtain the strategic focus of the enterprise's development strategy, and define the strategic level of the node based on the strategic focus of the enterprise's development strategy and the influence of the node;

[0009] The initial region is adjusted into multiple strategic regions based on the strategic level of the nodes within the initial region, and access rules are set between the multiple strategic regions. The interface information of the switch is then configured based on the access rules.

[0010] Test and validate access rules across multiple strategic zones, and adjust the access rules accordingly;

[0011] Get the effect of the access rules over a period of time, and update the access rules based on the effect.

[0012] In some embodiments of this application, the influence of a node is determined based on influencing factors, including:

[0013] Influencing factors include security requirements, business traffic, management complexity, and scalability.

[0014] A first set is constructed based on factors influencing security requirements, a second set is constructed based on factors influencing business traffic, a third set is constructed based on factors influencing management complexity, and a fourth set is constructed based on factors influencing scalability. Different weights are assigned to the first, second, third, and fourth sets.

[0015] Determine the intersection of the first set, the second set, the third set, and the fourth set. The intersection can be either a two-way intersection or a three-way intersection. A two-way intersection is when two sets intersect, and a three-way intersection is when all three sets intersect.

[0016] If two intersections exist, their intersection is denoted as the first intersection. The relationship between the sum of the weights of the two sets involved in the first intersection and the sum of the weights of the remaining sets is determined. The difference between the sum of the weights of the two sets involved in the first intersection and the first weight is calculated and denoted as the first weight difference. Based on the relationship and the first weight difference, the first correction amount is determined. The remaining sets are the two sets other than the two sets involved in the first intersection, and the first weight is a preset weight.

[0017] If there is a triple intersection, then the intersection is denoted as the second intersection. The relationship between the sum of the weights of the three sets involved in the second intersection and the constant multiple of the weight of the remaining set is determined. The difference between the sum of the weights of the three sets involved in the second intersection and the second weight is calculated and denoted as the second weight difference. Based on the relationship and the second weight difference, the second correction amount is determined. The remaining set is a set other than the three sets involved in the first intersection. The second weight is a preset weight and is greater than the first weight.

[0018] In some embodiments of this application, determining the influence of a node based on influencing factors further includes:

[0019] The influencing factors include security requirements, business traffic, management complexity, and scalability, which correspond to the influencing factors of security requirements, business traffic, management complexity, and scalability, respectively.

[0020] The amount of influence is determined based on either the first or the second correction amount;

[0021] ;

[0022] Where L represents the security requirement, business traffic, management complexity, or scalability, and n represents the total number of factors influencing security requirements, business traffic, management complexity, or scalability. Let i be the weight corresponding to the i-th influencing factor. Let be the parameter magnitude of the i-th influencing factor, and exp be the exponential function. This is the first correction amount. This is the second correction amount. This is the preset correction amount.

[0023] In some embodiments of this application, the strategic level of a node is defined by the enterprise's development strategy emphasis and the node's influence, including:

[0024] The corporate development strategy emphasizes the respective weighting of security requirements, business volume, management complexity, and scalability.

[0025] Based on the enterprise's development strategy emphasis and the impact of nodes, the respective weights of security requirements, business traffic, management complexity, and scalability are determined, and the weights are divided into first weights and second weights based on the respective weight ratios of security requirements, business traffic, management complexity, and scalability.

[0026] The total off-weight is calculated based on the first off-weight and the second off-weight.

[0027] ;

[0028] Where P is the total off-center weight. Let be the conversion factor corresponding to the first partial weight, and n be the number of first partial weights. The weight corresponding to the i-th first bias weight. For the i-th first bias weight, Here, represents the conversion factor corresponding to the second partial weight, and m represents the number of second partial weights. For the j-th second partial weight, For the j-th second partial weight;

[0029] The strategic level of a node is determined based on its total partial weight, where different strategic levels of nodes correspond to different ranges of total partial weight.

[0030] In some embodiments of this application, the initial region is adjusted into multiple strategic regions based on the strategic level of nodes within the initial region, including:

[0031] The strategic level of the node with the largest number of nodes of the same strategic level is defined as the initial strategic region level of the initial region.

[0032] If any of the remaining nodes matches the level of the adjacent initial strategic region, then that node is assigned to the adjacent strategic region. The remaining nodes are those other than the node with the largest number of nodes of the same strategic level in that initial region.

[0033] After the nodes are divided, multiple strategic regions are formed.

[0034] In some embodiments of this application, access rules are set between multiple strategic zones, including:

[0035] Access rules include access actions and access interfaces;

[0036] If the difference in strategic level between two communicating strategic regions does not exceed a preset difference, then an access action is specified, and the access interface is determined based on the average strategic level between the two communicating strategic regions.

[0037] If the difference in strategic level between two communicating strategic regions exceeds a preset difference, then the rule-based access action determines the access interface based on the larger of the strategic levels between the two communicating strategic regions.

[0038] In some embodiments of this application, access rules between multiple strategic zones are tested and verified, and the access rules are adjusted, including:

[0039] Simulate attacks, conduct traffic tests, and detect rule conflicts for access rules across multiple strategic zones;

[0040] The access rules were adjusted based on the test and verification results.

[0041] In some embodiments of this application, the effects of obtaining access rules over a period of time include:

[0042] Retrieve log records over a period of time, inspect the log records, and filter out abnormal data;

[0043] Calculate the relevance of each abnormal data point to the access rule, and retain abnormal data whose relevance exceeds a preset relevance threshold as the effect of the access rule.

[0044] In some embodiments of this application, the access rules are updated based on their effectiveness, including:

[0045] If the access rules achieve the expected results, then the access rules will not be updated.

[0046] If the access rule does not perform as expected, the access rule will be updated based on the difference between the actual performance and the expected performance.

[0047] Correspondingly, this application also provides a security boundary definition system based on a switch, the system comprising:

[0048] The first module is used to obtain the physical and logical topology of the network, and determine the initial regions in the network based on the physical and logical topology.

[0049] The second module is used to obtain the influencing factors of nodes in each initial region and determine the influence of nodes based on the influencing factors.

[0050] The third module is used to obtain the enterprise's strategic focus and to define the strategic level of a node based on the enterprise's strategic focus and the node's influence.

[0051] The fourth module is used to adjust the initial region into multiple strategic regions based on the strategic level of the nodes in the initial region, set access rules between multiple strategic regions, and configure the interface information of the switch based on the access rules.

[0052] The fifth module is used to test and verify access rules between multiple strategic zones, and to adjust the access rules accordingly.

[0053] The sixth module is used to obtain the effect of the access rules over a period of time and update the access rules based on the effect.

[0054] By applying the above technical solutions, the physical and logical topologies of the network are obtained, and initial regions within the network are determined based on these topologies. Influencing factors on nodes within each initial region are acquired, and the influence of each node is determined based on these factors. The strategic priorities of the enterprise development strategy are identified, and the strategic level of each node is defined based on these priorities and the node's influence. The initial regions are then adjusted into multiple strategic regions according to their strategic levels, and access rules are set between these strategic regions. Switch interface information is configured based on these access rules. The access rules between the multiple strategic regions are tested and verified, and adjustments are made accordingly. The effectiveness of the access rules over a period of time is obtained, and the access rules are updated based on their effectiveness. This application determines multiple influence quantities of nodes through influencing factors, thereby defining the strategic level of nodes and dividing the network into multiple strategic regions. This allows for the setting of access rules between multiple strategic regions, improving the precision and accuracy of security boundaries and ensuring the complex adaptability of security boundaries and network security. Attached Figure Description

[0055] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0056] Figure 1 A flowchart illustrating a security boundary definition method based on a switch, as proposed in an embodiment of the present invention, is shown.

[0057] Figure 2A schematic diagram of a security boundary definition system based on a switch, as proposed in an embodiment of the present invention, is shown. Detailed Implementation

[0058] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0059] This application provides a method for defining security boundaries based on switches, such as... Figure 1 As shown, the method includes the following steps:

[0060] Step S101: Obtain the physical topology and logical topology of the network, and determine each initial region in the network based on the physical topology and logical topology of the network.

[0061] In this embodiment, the physical topology refers to the actual physical connections between different devices in the network, such as network cables, optical fibers, and switches. These physical connections form the basic architecture of the network and determine the communication paths and data transmission methods between network devices.

[0062] In this embodiment, the logical topology is as follows: a logical connection refers to the logical relationship between different devices in the network, a connection implemented through network protocols and configurations. A logical connection defines the communication rules, protocols, and methods between devices in the network, such as configuration parameters like IP addresses, subnet masks, routing tables, and VLANs. A logical connection acts as a logical bridge for communication between network devices.

[0063] Step S102: Obtain the influencing factors of each node within the initial region, and determine the influence of the node based on the influencing factors.

[0064] In this embodiment, the influence of each node is determined by influencing factors, thereby enabling node planning.

[0065] In some embodiments of this application, the influence of a node is determined based on influencing factors, including:

[0066] Influencing factors include security requirements, business traffic, management complexity, and scalability.

[0067] A first set is constructed based on factors influencing security requirements, a second set is constructed based on factors influencing business traffic, a third set is constructed based on factors influencing management complexity, and a fourth set is constructed based on factors influencing scalability. Different weights are assigned to the first, second, third, and fourth sets.

[0068] Determine the intersection of the first set, the second set, the third set, and the fourth set. The intersection can be either a two-way intersection or a three-way intersection. A two-way intersection is when two sets intersect, and a three-way intersection is when all three sets intersect.

[0069] If two intersections exist, their intersection is denoted as the first intersection. The relationship between the sum of the weights of the two sets involved in the first intersection and the sum of the weights of the remaining sets is determined. The difference between the sum of the weights of the two sets involved in the first intersection and the first weight is calculated and denoted as the first weight difference. Based on the relationship and the first weight difference, the first correction amount is determined. The remaining sets are the two sets other than the two sets involved in the first intersection, and the first weight is a preset weight.

[0070] If there is a triple intersection, then the intersection is denoted as the second intersection. The relationship between the sum of the weights of the three sets involved in the second intersection and the constant multiple of the weight of the remaining set is determined. The difference between the sum of the weights of the three sets involved in the second intersection and the second weight is calculated and denoted as the second weight difference. Based on the relationship and the second weight difference, the second correction amount is determined. The remaining set is a set other than the three sets involved in the first intersection. The second weight is a preset weight and is greater than the first weight.

[0071] In this embodiment, the influencing factors are divided into four categories: security requirement influencing factors include risk level and compliance requirements; business traffic influencing factors include network applications, bandwidth requirements and user access patterns; management complexity influencing factors include personnel resources and management requirements; and scalability influencing factors include business growth and technological changes.

[0072] It should be noted that among the influencing factors mentioned above, there may be non-parametric factors. These will be converted into standardized parameters before subsequent calculations.

[0073] In this embodiment, determining the relationship between the sum of the weights of the two sets involved in the first intersection and the sum of the weights of the remaining sets means calculating the sum of the weights of the two sets involved in the first intersection and comparing it with the sum of the weights of the remaining two sets. Determining the first correction amount based on the relationship and the first weight difference means that different relationships and first weight differences correspond to a single first correction amount. This is because the same factor may affect two or more categories. The same principle applies to three intersections.

[0074] It should be noted that this solution only considers the case where three or two intersections exist individually, and does not consider the case where both exist simultaneously.

[0075] In some embodiments of this application, determining the influence of a node based on influencing factors further includes:

[0076] The influencing factors include security requirements, business traffic, management complexity, and scalability, which correspond to the influencing factors of security requirements, business traffic, management complexity, and scalability, respectively.

[0077] The amount of influence is determined based on either the first or the second correction amount;

[0078] ;

[0079] Where L represents the security requirement, business traffic, management complexity, or scalability, and n represents the total number of factors influencing security requirements, business traffic, management complexity, or scalability. Let i be the weight corresponding to the i-th influencing factor. Let be the parameter magnitude of the i-th influencing factor, and exp be the exponential function. This is the first correction amount. This is the second correction amount. This is the preset correction amount.

[0080] In this embodiment, L represents one of the following: security requirement, business traffic, management complexity, or scalability. The influencing factors include four types: security requirement, business traffic, management complexity, and scalability.

[0081] In this embodiment, To correct for the sum of the effects, The value ranges from 0.1 to 0.16. The value ranges from 0.1 to 0.21.

[0082] Step S103: Obtain the enterprise's strategic focus and define the strategic level of the node based on the enterprise's strategic focus and the node's influence.

[0083] In this embodiment, the enterprise development strategy emphasis refers to the degree of emphasis the enterprise places on four aspects: security needs, business traffic, management complexity, and scalability. The strategic level of a node is determined by these four actual influencing factors.

[0084] In some embodiments of this application, the strategic level of a node is defined by the enterprise's development strategy emphasis and the node's influence, including:

[0085] The corporate development strategy emphasizes the respective weighting of security requirements, business volume, management complexity, and scalability.

[0086] Based on the enterprise's development strategy emphasis and the impact of nodes, the respective weights of security requirements, business traffic, management complexity, and scalability are determined, and the weights are divided into first weights and second weights based on the respective weight ratios of security requirements, business traffic, management complexity, and scalability.

[0087] The total off-weight is calculated based on the first off-weight and the second off-weight.

[0088] ;

[0089] Where P is the total off-center weight. Let be the conversion factor corresponding to the first partial weight, and n be the number of first partial weights. The weight corresponding to the i-th first bias weight. For the i-th first bias weight, Here, represents the conversion factor corresponding to the second partial weight, and m represents the number of second partial weights. For the j-th second partial weight, For the j-th second partial weight;

[0090] The strategic level of a node is determined based on its total partial weight, where different strategic levels of nodes correspond to different ranges of total partial weight.

[0091] In this embodiment, the weight of each of the following parameters—security requirement, business traffic, management complexity, and scalability—is determined based on the enterprise's development strategy and the impact of each node. This weight is the product of the impact and the weight ratio. For example, the weight corresponding to scalability = the weight ratio of scalability * scalability.

[0092] In this embodiment, the weighting is divided into a first weighting and a second weighting based on the respective weighting ratios of security requirements, business traffic, management complexity, and scalability. If the weighting ratios of these four aspects of the enterprise's development strategy are all 0.25, it indicates that the enterprise is developing evenly in these four directions without any bias. The weighting corresponding to a weighting ratio exceeding 0.25 is defined as the first weighting, and the weighting corresponding to a weighting ratio below 0.25 is defined as the second weighting.

[0093] In this embodiment, the first bias weight and the second bias weight are calculated in different ways, thereby calculating the total bias weight.

[0094] Step S104: Adjust the initial region into multiple strategic regions according to the strategic level of the nodes in the initial region, set access rules between the multiple strategic regions, and configure the interface information of the switch based on the access rules.

[0095] In this embodiment, the VLAN, port security, ACLs, 802.1X authentication, secure connection and other features of the switch are configured based on access rules.

[0096] In some embodiments of this application, the initial region is adjusted into multiple strategic regions based on the strategic level of nodes within the initial region, including:

[0097] The strategic level of the node with the largest number of nodes of the same strategic level is defined as the initial strategic region level of the initial region.

[0098] If any of the remaining nodes matches the level of the adjacent initial strategic region, then that node is assigned to the adjacent strategic region. The remaining nodes are those other than the node with the largest number of nodes of the same strategic level in that initial region.

[0099] After the nodes are divided, multiple strategic regions are formed.

[0100] In this embodiment, the strategic region refers to the comprehensive strategic level (multiple levels) of the node.

[0101] In this embodiment, the situation where there are other nodes that match the level of the adjacent initial strategic region means, for example, if the level of the first initial strategic region is 3 and the level of the second initial strategic region adjacent to the first initial strategic region is 5, then if there is a node with a level of 5 in the first initial strategic region that matches the situation, then that node will be assigned to the second initial strategic region.

[0102] Step S105: Test and verify the access rules between multiple strategic zones, and adjust the access rules accordingly.

[0103] In this embodiment, the access rules include access actions, access interfaces, the scope of the rules, and the purpose of the rules.

[0104] In some embodiments of this application, access rules are set between multiple strategic zones, including:

[0105] Access rules include access actions and access interfaces;

[0106] If the difference in strategic level between two communicating strategic regions does not exceed a preset difference, then an access action is specified, and the access interface is determined based on the average strategic level between the two communicating strategic regions.

[0107] If the difference in strategic level between two communicating strategic regions exceeds a preset difference, then the rule-based access action determines the access interface based on the larger of the strategic levels between the two communicating strategic regions.

[0108] In this embodiment, access rules are set based on the strategic level difference between the two communication strategic zones. Different differences are set in different ways.

[0109] In this embodiment, different strategic levels correspond to different access rules. The higher the strategic level, the more categories of access actions are allowed, and the fewer access interfaces are available.

[0110] In this embodiment, if the difference in strategic levels exceeds a certain level, the access interface is determined by the larger strategic level. The higher-level access interface only opens the necessary interfaces, while the lower-level access interface can open the non-essential interfaces to meet the requirements of strategic adaptability.

[0111] Step S106: Obtain the effect of the access rules over a period of time, and update the access rules based on the effect of the access rules.

[0112] In some embodiments of this application, access rules between multiple strategic zones are tested and verified, and the access rules are adjusted, including:

[0113] Simulate attacks, conduct traffic tests, and detect rule conflicts for access rules across multiple strategic zones;

[0114] The access rules were adjusted based on the test and verification results.

[0115] This embodiment includes simulated attacks, traffic testing, and rule conflict detection. Penetration testing tools or vulnerability scanning tools can be used to simulate attacks and verify whether the rules can effectively defend against different types of attacks. For example, simulating access to prohibited resources or unauthorized access to specific protocols or ports. By generating traffic in the network that conforms to the rule conditions, the system tests whether the rules restrict network traffic access as expected. Network traffic generation tools can be used to simulate traffic from different protocols, ports, and IP addresses to verify the filtering effect of the rules. Finally, the system checks for conflicts or overlaps between rules.

[0116] In some embodiments of this application, the effects of obtaining access rules over a period of time include:

[0117] Retrieve log records over a period of time, inspect the log records, and filter out abnormal data;

[0118] Calculate the relevance of each abnormal data point to the access rule, and retain abnormal data whose relevance exceeds a preset relevance threshold as the effect of the access rule.

[0119] In some embodiments of this application, the access rules are updated based on their effectiveness, including:

[0120] If the access rules achieve the expected results, then the access rules will not be updated.

[0121] If the access rule does not perform as expected, the access rule will be updated based on the difference between the actual performance and the expected performance.

[0122] In this embodiment, updating the access rules based on the difference between the effect and the expected effect means updating the access rules based on the degree to which the effect is not met.

[0123] By applying the above technical solutions, the physical and logical topologies of the network are obtained, and initial regions within the network are determined based on these topologies. Influencing factors on nodes within each initial region are acquired, and the influence of each node is determined based on these factors. The strategic priorities of the enterprise development strategy are identified, and the strategic level of each node is defined based on these priorities and the node's influence. The initial regions are then adjusted into multiple strategic regions according to their strategic levels, and access rules are set between these strategic regions. Switch interface information is configured based on these access rules. The access rules between the multiple strategic regions are tested and verified, and adjustments are made accordingly. The effectiveness of the access rules over a period of time is obtained, and the access rules are updated based on their effectiveness. This application determines multiple influence quantities of nodes through influencing factors, thereby defining the strategic level of nodes and dividing the network into multiple strategic regions. This allows for the setting of access rules between multiple strategic regions, improving the precision and accuracy of security boundaries and ensuring the complex adaptability of security boundaries and network security.

[0124] Through the above description of the embodiments, those skilled in the art can clearly understand that the present invention can be implemented in hardware or by means of software plus necessary general-purpose hardware platforms. Based on this understanding, the technical solution of the present invention can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (such as a CD-ROM, USB flash drive, external hard drive, etc.) and includes several instructions to cause a computer device (such as a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments of the present invention.

[0125] To further illustrate the technical concept of this invention, the technical solution of this invention will now be described in conjunction with specific application scenarios.

[0126] Correspondingly, this application also provides a security boundary definition system based on a switch, such as Figure 2 As shown, the system includes:

[0127] The first module 201 is used to obtain the physical topology and logical topology of the network, and to determine each initial region in the network based on the physical topology and logical topology of the network.

[0128] The second module 202 is used to obtain the influencing factors of nodes in each initial region and determine the influence of nodes based on the influencing factors.

[0129] The third module 203 is used to obtain the enterprise's strategic focus and to define the strategic level of the node by the enterprise's strategic focus and the influence of the node.

[0130] The fourth module 204 is used to adjust the initial region into multiple strategic regions according to the strategic level of the nodes in the initial region, set access rules between multiple strategic regions, and configure the interface information of the switch based on the access rules.

[0131] Module 5, 205, is used to test and verify access rules between multiple strategic zones and to adjust the access rules.

[0132] Module 6, 206, is used to obtain the effect of access rules over a period of time and update the access rules based on the effect of the access rules.

[0133] In some embodiments of this application, the second module 202 is used for:

[0134] Influencing factors include security requirements, business traffic, management complexity, and scalability.

[0135] A first set is constructed based on factors influencing security requirements, a second set is constructed based on factors influencing business traffic, a third set is constructed based on factors influencing management complexity, and a fourth set is constructed based on factors influencing scalability. Different weights are assigned to the first, second, third, and fourth sets.

[0136] Determine the intersection of the first set, the second set, the third set, and the fourth set. The intersection can be either a two-way intersection or a three-way intersection. A two-way intersection is when two sets intersect, and a three-way intersection is when all three sets intersect.

[0137] If two intersections exist, their intersection is denoted as the first intersection. The relationship between the sum of the weights of the two sets involved in the first intersection and the sum of the weights of the remaining sets is determined. The difference between the sum of the weights of the two sets involved in the first intersection and the first weight is calculated and denoted as the first weight difference. Based on the relationship and the first weight difference, the first correction amount is determined. The remaining sets are the two sets other than the two sets involved in the first intersection, and the first weight is a preset weight.

[0138] If there is a triple intersection, then the intersection is denoted as the second intersection. The relationship between the sum of the weights of the three sets involved in the second intersection and the constant multiple of the weight of the remaining set is determined. The difference between the sum of the weights of the three sets involved in the second intersection and the second weight is calculated and denoted as the second weight difference. Based on the relationship and the second weight difference, the second correction amount is determined. The remaining set is a set other than the three sets involved in the first intersection. The second weight is a preset weight and is greater than the first weight.

[0139] In some embodiments of this application, the second module 202 is used for:

[0140] The influencing factors include security requirements, business traffic, management complexity, and scalability, which correspond to the influencing factors of security requirements, business traffic, management complexity, and scalability, respectively.

[0141] The amount of influence is determined based on either the first or the second correction amount;

[0142] ;

[0143] Where L represents the security requirement, business traffic, management complexity, or scalability, and n represents the total number of factors influencing security requirements, business traffic, management complexity, or scalability. Let i be the weight corresponding to the i-th influencing factor. Let be the parameter magnitude of the i-th influencing factor, and exp be the exponential function. This is the first correction amount. This is the second correction amount. This is the preset correction amount.

[0144] In some embodiments of this application, the third module 203 is used for:

[0145] The corporate development strategy emphasizes the respective weighting of security requirements, business volume, management complexity, and scalability.

[0146] Based on the enterprise's development strategy emphasis and the impact of nodes, the respective weights of security requirements, business traffic, management complexity, and scalability are determined, and the weights are divided into first weights and second weights based on the respective weight ratios of security requirements, business traffic, management complexity, and scalability.

[0147] The total off-weight is calculated based on the first off-weight and the second off-weight.

[0148] ;

[0149] Where P is the total off-center weight. Let be the conversion factor corresponding to the first partial weight, and n be the number of first partial weights. The weight corresponding to the i-th first bias weight. For the i-th first bias weight, Here, represents the conversion factor corresponding to the second partial weight, and m represents the number of second partial weights. For the j-th second partial weight, For the j-th second partial weight;

[0150] The strategic level of a node is determined based on its total partial weight, where different strategic levels of nodes correspond to different ranges of total partial weight.

[0151] In some embodiments of this application, the fourth module 204 is used for:

[0152] The strategic level of the node with the largest number of nodes of the same strategic level is defined as the initial strategic region level of the initial region.

[0153] If any of the remaining nodes matches the level of the adjacent initial strategic region, then that node is assigned to the adjacent strategic region. The remaining nodes are those other than the node with the largest number of nodes of the same strategic level in that initial region.

[0154] After the nodes are divided, multiple strategic regions are formed.

[0155] In some embodiments of this application, the fourth module 204 is used for:

[0156] Access rules include access actions and access interfaces;

[0157] If the difference in strategic level between two communicating strategic regions does not exceed a preset difference, then an access action is specified, and the access interface is determined based on the average strategic level between the two communicating strategic regions.

[0158] If the difference in strategic level between two communicating strategic regions exceeds a preset difference, then the rule-based access action determines the access interface based on the larger of the strategic levels between the two communicating strategic regions.

[0159] In some embodiments of this application, the fifth module 205 is used for:

[0160] Simulate attacks, conduct traffic tests, and detect rule conflicts for access rules across multiple strategic zones;

[0161] The access rules were adjusted based on the test and verification results.

[0162] In some embodiments of this application, the sixth module 206 is used for:

[0163] Retrieve log records over a period of time, inspect the log records, and filter out abnormal data;

[0164] Calculate the relevance of each abnormal data point to the access rule, and retain abnormal data whose relevance exceeds a preset relevance threshold as the effect of the access rule.

[0165] In some embodiments of this application, the sixth module 206 is used for:

[0166] If the access rules achieve the expected results, then the access rules will not be updated.

[0167] If the access rule does not perform as expected, the access rule will be updated based on the difference between the actual performance and the expected performance.

[0168] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application.

Claims

1. A method for defining security boundaries based on switches, characterized in that, The method includes: Obtain the physical and logical topology of the network, and determine the initial regions in the network based on the physical and logical topology. Obtain the influencing factors of each node within each initial region, and determine the influence quantity of the node based on the influencing factors. The influence quantity includes security requirements, business traffic, management complexity, and scalability. Obtain the strategic focus of the enterprise's development strategy, and define the strategic level of the node based on the strategic focus of the enterprise's development strategy and the influence of the node; The initial region is adjusted into multiple strategic regions based on the strategic level of the nodes within the initial region, and access rules are set between the multiple strategic regions. The interface information of the switch is then configured based on the access rules. Test and validate access rules across multiple strategic zones, and adjust the access rules accordingly; Obtain the effect of access rules over a period of time, and update the access rules based on the effect of the access rules; The specific impact of a node is determined based on the influencing factors as follows: Influencing factors include various types; Different sets are constructed based on different influencing factors and assigned different weights; Determine the intersection between sets. The intersection includes two-way intersection and three-way intersection. Two-way intersection means that two sets intersect, and three-way intersection means that three sets intersect. If two intersections exist, their intersection is denoted as the first intersection. The relationship between the sum of the weights of the two sets involved in the first intersection and the sum of the weights of the remaining sets is determined. The difference between the sum of the weights of the two sets involved in the first intersection and the first weight is calculated and denoted as the first weight difference. Based on the relationship and the first weight difference, the first correction amount is determined. The remaining sets are the two sets other than the two sets involved in the first intersection, and the first weight is a preset weight. If there is a triple intersection, then the intersection is denoted as the second intersection. The relationship between the sum of the weights of the three sets involved in the second intersection and the constant multiple of the weight of the remaining set is determined. The difference between the sum of the weights of the three sets involved in the second intersection and the second weight is calculated and denoted as the second weight difference. Based on the relationship and the second weight difference, the second correction amount is determined. The remaining set is a set other than the three sets involved in the second intersection. The second weight is a preset weight and the second weight is greater than the first weight. The magnitude of influence includes various types, corresponding to the influencing factors; The amount of influence is determined based on either the first or the second correction amount; The formulas for calculating the impact of two-way and three-way intersections are as follows: Where L is the influence quantity, and n is the total number of influencing factors. Let i be the weight corresponding to the i-th influencing factor. Let be the parameter magnitude of the i-th influencing factor, and exp be the exponential function. This is the first correction amount. This is the second correction amount. This is the preset correction amount.

2. The security boundary definition method based on a switch as described in claim 1, characterized in that, The strategic level of a node is defined by the enterprise's development strategy priorities and the node's influence, including: The corporate development strategy emphasizes the respective weighting of security requirements, business volume, management complexity, and scalability. Based on the enterprise's development strategy emphasis and the impact of nodes, the respective weights of security requirements, business traffic, management complexity, and scalability are determined, and the weights are divided into first weights and second weights based on the respective weight ratios of security requirements, business traffic, management complexity, and scalability. The total off-weight is calculated based on the first off-weight and the second off-weight. Where P is the total off-center weight. Let be the conversion factor corresponding to the first partial weight, and n be the number of first partial weights. The weight corresponding to the i-th first bias weight. For the i-th first bias weight, Here, represents the conversion factor corresponding to the second partial weight, and m represents the number of second partial weights. The weight corresponding to the j-th second partial weight. For the j-th second partial weight; The strategic level of a node is determined based on its total partial weight, where different strategic levels of nodes correspond to different ranges of total partial weight.

3. The security boundary definition method based on a switch as described in claim 2, characterized in that, The initial region is adjusted into multiple strategic regions based on the strategic level of the nodes within the initial region, including: The strategic level of the node with the largest number of nodes of the same strategic level is defined as the initial strategic region level of the initial region. If any of the remaining nodes matches the level of the adjacent initial strategic region, then that node is assigned to the adjacent strategic region. The remaining nodes are those other than the node with the largest number of nodes of the same strategic level in that initial region. After the nodes are divided, multiple strategic regions are formed.

4. The security boundary definition method based on a switch as described in claim 3, characterized in that, And set access rules between multiple strategic zones, including: Access rules include access actions and access interfaces; If the difference in strategic level between two communicating strategic regions does not exceed a preset difference, then an access action is specified, and the access interface is determined based on the average strategic level between the two communicating strategic regions. If the difference in strategic level between two communicating strategic regions exceeds a preset difference, then the rule-based access action determines the access interface based on the larger of the strategic levels between the two communicating strategic regions.

5. The security boundary definition method based on a switch as described in claim 1, characterized in that, Test and validate access rules across multiple strategic zones, and adjust the access rules accordingly, including: Simulate attacks, conduct traffic tests, and detect rule conflicts for access rules across multiple strategic zones; The access rules were adjusted based on the test and verification results.

6. The security boundary definition method based on a switch as described in claim 5, characterized in that, The effect of obtaining access rules over a period of time includes: Retrieve log records over a period of time, inspect the log records, and filter out abnormal data; Calculate the relevance of each abnormal data point to the access rule, and retain abnormal data whose relevance exceeds a preset relevance threshold as the effect of the access rule.

7. The security boundary definition method based on a switch as described in claim 6, characterized in that, And update the access rules based on their effects, including: If the access rules achieve the expected results, then the access rules will not be updated. If the access rule does not perform as expected, the access rule will be updated based on the difference between the actual performance and the expected performance.

8. A security boundary definition system based on a switch, characterized in that, The system includes: The first module is used to obtain the physical and logical topology of the network, and determine the initial regions in the network based on the physical and logical topology. The second module obtains the influencing factors of each node in each initial region, and determines the influence of the node based on the influencing factors. The influence includes security requirements, business traffic, management complexity, and scalability. The third module is used to obtain the enterprise's strategic focus and to define the strategic level of a node based on the enterprise's strategic focus and the node's influence. The fourth module is used to adjust the initial region into multiple strategic regions based on the strategic level of the nodes in the initial region, set access rules between multiple strategic regions, and configure the interface information of the switch based on the access rules. The fifth module is used to test and verify access rules between multiple strategic zones, and to adjust the access rules accordingly. The sixth module retrieves the effect of the access rules over a period of time and updates the access rules based on the effect. The specific impact of a node is determined based on the influencing factors as follows: Influencing factors include various types; Different sets are constructed based on different influencing factors and assigned different weights; Determine the intersection between sets. The intersection includes two-way intersection and three-way intersection. Two-way intersection means that two sets intersect, and three-way intersection means that three sets intersect. If two intersections exist, their intersection is denoted as the first intersection. The relationship between the sum of the weights of the two sets involved in the first intersection and the sum of the weights of the remaining sets is determined. The difference between the sum of the weights of the two sets involved in the first intersection and the first weight is calculated and denoted as the first weight difference. Based on the relationship and the first weight difference, the first correction amount is determined. The remaining sets are the two sets other than the two sets involved in the first intersection, and the first weight is a preset weight. If there is a triple intersection, then the intersection is denoted as the second intersection. The relationship between the sum of the weights of the three sets involved in the second intersection and the constant multiple of the weight of the remaining set is determined. The difference between the sum of the weights of the three sets involved in the second intersection and the second weight is calculated and denoted as the second weight difference. Based on the relationship and the second weight difference, the second correction amount is determined. The remaining set is a set other than the three sets involved in the second intersection. The second weight is a preset weight and the second weight is greater than the first weight. The magnitude of influence includes various types, corresponding to the influencing factors; The amount of influence is determined based on either the first or the second correction amount; The formulas for calculating the impact of two-way and three-way intersections are as follows: Where L is the influence quantity, and n is the total number of influencing factors. Let i be the weight corresponding to the i-th influencing factor. Let be the parameter magnitude of the i-th influencing factor, and exp be the exponential function. This is the first correction amount. This is the second correction amount. This is the preset correction amount.

Citation Information

Patent Citations

  • Industrial network boundary protection method and system based on industrial control terminal feature recognition

    CN113079186A

  • Terminal trust management and trusted access system and method

    CN114553554A