Network access control policy processing method and device based on traffic learning
By extracting traffic information from network firewall logs, performing data preprocessing and building a deterministic rule base, and combining supervised and unsupervised learning algorithms to train access control policy models, the problems of insufficient real-time performance, high false alarm rate and poor adaptability of traditional methods are solved, and high-reliability and fast-response network access control is achieved.
Patent Information
- Application Number
- CN202411899324.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-20
- Publication Date
- 2025-09-05
- Estimated Expiration
- 2044-12-20
AI Technical Summary
Traditional network traffic learning methods have problems such as lack of real-time performance, high false alarm rate, poor adaptability and excessive need for manual intervention.
By extracting network traffic information from network firewall logs, performing data preprocessing and labeling, building a deterministic rule base, combining supervised and unsupervised learning algorithms to train the access control policy dynamic adjustment model, using regular expressions to identify named entities and extract subject and object relationships, and dynamically adjusting network access control policies.
It achieves timely response to network emergencies, reduces false alarms and missed alarms, improves the stability and credibility of the model, reduces dependence on human intervention, and enhances adaptability.
Smart Images

Figure CN119743307B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of network traffic processing, and in particular relates to a network access control policy processing method and device based on traffic learning. Background Art
[0002] Currently, traditional network traffic learning typically uses a supervised learning model, which involves manually formulating some rules, then learning through supervised learning models such as clustering, and iteratively improving the rules and models through a feedback mechanism based on the learning results. This traditional approach has the following problems:
[0003] First, lack of real-time performance: Traditional methods may not be able to respond to sudden traffic events in the network in a timely manner, resulting in a large deviation between the existing network traffic characteristics and the learned model, causing the model to fail, and it takes a long time to learn a new feature model.
[0004] Second, the false alarm rate is high: Since static rules cannot adapt to all scenarios, a large number of false alarms or missed alarms may occur, affecting the credibility of the system.
[0005] Third, poor adaptability: when network traffic patterns change, rules need to be manually updated, which is not only time-consuming but also error-prone.
[0006] Fourth, excessive manual intervention is required: Traditional methods are often powerless against unknown threats or abnormal behaviors, and typically require highly experienced personnel to input parameters for the initial iteration. If the startup parameters are not set correctly, the model may not converge or may converge very slowly. Summary of the Invention
[0007] To this end, the present invention provides a network access control policy processing method and device based on traffic learning to solve the problems of insufficient real-time performance, high false alarm rate, poor adaptability and excessive manual intervention in traditional technologies.
[0008] To achieve the above objectives, the present invention provides the following technical solution: a network access control policy processing method based on traffic learning, comprising:
[0009] Extracting network traffic information from a network firewall log, and classifying and labeling the network traffic information using set policy tags according to the firewall policy, wherein the set policy tags include valid precise policy, valid imprecise policy, invalid policy, and default policy tags;
[0010] Extract deterministic rules from network traffic logs, firewall access control policies, and application identification results, and build a deterministic rule base based on the extracted deterministic rules;
[0011] Performing data preprocessing on the network traffic information, wherein the data preprocessing uses regular expression-based named entity recognition on the network traffic information and extracting the relationship between the subject and the object in combination with the context;
[0012] Marking the network traffic information after the data preprocessing as a training data set, and using the deterministic rules in the deterministic rule library to mark each traffic record in the training data set with an attribute label;
[0013] An access control policy dynamic adjustment model is constructed, the access control policy dynamic adjustment model is trained using the training data set using a supervised learning algorithm and an unsupervised learning algorithm, and the trained access control policy dynamic adjustment model is used to identify network access control policies.
[0014] As a preferred solution of the network access control policy processing method based on traffic learning, the network traffic information includes source IP address, destination IP address, port number, protocol type, traffic size and timestamp;
[0015] Before classifying and marking the network traffic information by setting policy tags according to the firewall policy, the method also includes removing invalid or incomplete records of the network traffic information.
[0016] As a preferred solution of the network access control policy processing method based on traffic learning, the deterministic rules in the deterministic rule base include application tags, access subject tags, and access control policy IDs;
[0017] Each traffic record in the training data set is marked with an application label, an access subject label, and an access control policy ID.
[0018] As a preferred solution for the network access control policy processing method based on traffic learning, during the data preprocessing of the network traffic information, named entities with specified characteristics of URL addresses and IP addresses are identified, and the subject, object, and access relationship entities are extracted by combining the characteristics of network logs and system access logs.
[0019] As a preferred solution for the network access control policy processing method based on traffic learning, the supervised learning algorithm adopts the K-Means algorithm, and the initial parameter of the K-Means algorithm is set to the number of access control rules of the deterministic rule base that are hit;
[0020] When the cluster center deviation of the K-Means algorithm clustering result exceeds the set threshold, the strategy of increasing the number of clusters is used to adjust the initial parameters.
[0021] As a preferred solution for the network access control policy processing method based on traffic learning, the unsupervised learning algorithm adopts a support vector machine classification algorithm and an association rule analysis algorithm to extract feature data, and converts the extracted feature data into rules and parameters to feed back to the supervised learning algorithm.
[0022] The present invention also provides a network access control policy processing device based on traffic learning, comprising:
[0023] A training data extraction module is used to extract network traffic information from network firewall logs and classify and label the network traffic information using set policy tags according to firewall policies. The set policy tags include valid precise policy, valid imprecise policy, invalid policy, and default policy tags.
[0024] A deterministic rule base construction module is used to extract deterministic rules from network traffic logs, firewall access control policies, and application identification results, and to construct a deterministic rule base based on the extracted deterministic rules;
[0025] A data preprocessing module is used to perform data preprocessing on the network traffic information, wherein the data preprocessing adopts named entity recognition based on regular expressions on the network traffic information and extracts the relationship between subject and object in combination with the context;
[0026] An attribute label marking module, configured to mark the network traffic information after the data preprocessing as a training data set, and to mark each traffic record in the training data set with an attribute label using the deterministic rules in the deterministic rule base;
[0027] The access control policy dynamic adjustment model processing module is used to construct an access control policy dynamic adjustment model, use the training data set to train the access control policy dynamic adjustment model using a supervised learning algorithm and an unsupervised learning algorithm, and use the trained access control policy dynamic adjustment model to identify network access control policies.
[0028] As a preferred solution of the network access control policy processing device based on traffic learning, in the training data extraction module, the network traffic information includes source IP address, destination IP address, port number, protocol type, traffic size and timestamp;
[0029] The training data extraction module also includes removing invalid or incomplete records of the network traffic information.
[0030] As a preferred solution of the network access control policy processing device based on traffic learning, in the deterministic rule base construction module, the deterministic rules include application tags, access subject tags, and access control policy IDs;
[0031] In the attribute label marking module, each flow record in the training data set is marked with an application label, an access subject label, and an access control policy ID;
[0032] In the data preprocessing module, named entities with specified characteristics of URL addresses and IP addresses are identified, and the subject, object, and access relationship entities are extracted in combination with the characteristics of network logs and system access logs.
[0033] As a preferred solution of the network access control policy processing device based on traffic learning, in the access control policy dynamic adjustment model processing module, the supervised learning algorithm adopts the K-Means algorithm, and the initial parameter of the K-Means algorithm is set to the number of access control rules of the deterministic rule base that are hit;
[0034] When the cluster center deviation of the K-Means algorithm exceeds the set threshold, the strategy of increasing the number of clusters is used to adjust the initial parameters;
[0035] The unsupervised learning algorithm uses a support vector machine classification algorithm and an association rule analysis algorithm to extract feature data, and converts the extracted feature data into rules and parameters to feed back to the supervised learning algorithm.
[0036] The beneficial effects of the present invention are as follows: network traffic information is extracted from a network firewall log; the network traffic information is classified and labeled by setting policy tags according to the firewall policy; deterministic rules are extracted from the network traffic log, the firewall access control policy and the application identification result; a deterministic rule library is constructed based on the extracted deterministic rules; data preprocessing is performed on the network traffic information, the data preprocessing adopts named entity recognition based on regular expressions for the network traffic information, and the relationship between the subject and the object is extracted in combination with the context; the network traffic information after the data preprocessing is marked as a training data set, and each traffic record in the training data set is labeled with an attribute tag using the deterministic rules in the deterministic rule library; an access control policy dynamic adjustment model is constructed, the access control policy dynamic adjustment model is trained using the training data set using a supervised learning algorithm and an unsupervised learning algorithm, and the trained access control policy dynamic adjustment model is used to identify the network access control policy. The present invention can respond to sudden traffic events in the network in a timely manner, has a small model deviation and strong stability; is not prone to false positives or false negatives, has high credibility, does not require excessive manual intervention, and has strong adaptability. BRIEF DESCRIPTION OF THE DRAWINGS
[0037] To more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for the embodiments or the description of the prior art. Obviously, the drawings described below are merely exemplary, and those skilled in the art can, without inventive effort, derive other implementation drawings based on the provided drawings.
[0038] The structures, proportions, sizes, etc. illustrated in this specification are intended solely to complement the contents disclosed herein and to facilitate understanding and reading by persons skilled in the art. They are not intended to limit the conditions under which the present invention may be implemented and therefore have no substantive technical significance. Any structural modifications, changes in proportions, or adjustments in sizes, without affecting the efficacy and objectives of the present invention, shall remain within the scope of the technical contents disclosed herein.
[0039] Figure 1 A flow chart of a method for processing network access control policies based on traffic learning provided by an embodiment of the present invention;
[0040] Figure 2 A schematic diagram of the technical architecture of a network access control policy processing method based on traffic learning provided by an embodiment of the present invention;
[0041] Figure 3 A schematic diagram of a network access control policy generation method based on traffic learning provided by an embodiment of the present invention;
[0042] Figure 4 The network access control policy processing method based on traffic learning provided by the embodiment of the present invention has a supervised learning process;
[0043] Figure 5 A schematic diagram of the architecture of a network access control policy processing device based on traffic learning provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0044] The following describes the implementation of the present invention using specific embodiments. Those skilled in the art will readily understand the other advantages and benefits of the present invention from the disclosure herein. Obviously, the embodiments described are only a portion of the present invention, not all of it. All other embodiments derived by persons of ordinary skill in the art based on the embodiments of the present invention without inventive effort are intended to fall within the scope of protection of the present invention.
[0045] Example 1
[0046] See also Figure 1 、 Figure 2 and Figure 3Embodiment 1 of the present invention provides a method for processing a network access control policy based on traffic learning, comprising the following steps:
[0047] S1. Extract network traffic information from the network firewall log, and classify and label the network traffic information by setting policy tags according to the firewall policy, wherein the set policy tags include valid precise policy, valid imprecise policy, invalid policy, and default policy tags;
[0048] S2, extracting deterministic rules from network traffic logs, firewall access control policies, and application identification results, and building a deterministic rule base based on the extracted deterministic rules;
[0049] S3. performing data preprocessing on the network traffic information, wherein the data preprocessing uses regular expression-based named entity recognition on the network traffic information and extracts the relationship between the subject and the object in combination with the context;
[0050] S4, marking the network traffic information after the data preprocessing as a training data set, and using the deterministic rules in the deterministic rule base to mark each traffic record in the training data set with an attribute label;
[0051] S5. Construct an access control policy dynamic adjustment model, train the access control policy dynamic adjustment model using the training data set using a supervised learning algorithm and an unsupervised learning algorithm, and use the trained access control policy dynamic adjustment model to identify network access control policies.
[0052] In this embodiment, in step S1, the crawler captures traffic records from the firewall log, including but not limited to source IP address, destination IP address, port number, protocol type, traffic volume, timestamp, etc., and removes invalid or incomplete records, such as malformed log entries. Simultaneously, a policy tag is assigned to each traffic record based on the existing access control policy, indicating whether it belongs to a valid precise policy, a valid non-precise policy, an invalid policy, or the default policy.
[0053] Effective precise policies are precisely and granularly defined security policies that accurately mark traffic. Traffic matching a policy is highly cohesive. Effective imprecise policies are traffic matching policies, but due to the limitations of traditional descriptive capabilities, traffic matching the same policy may represent a variety of traffic models. For ineffective policies, over time and with business changes, many security policies are no longer likely to be matched by traffic. However, administrators are often hesitant to delete them for fear of disrupting business operations. Default policies are the default actions defined by security devices and serve as the default behavior when no defined policies are matched.
[0054] In this embodiment, in step S2, the deterministic rules in the deterministic rule base include application tags, access subject tags, and access control policy IDs.
[0055] Specifically, the deterministic rule base forms a deterministic rule system by training data network traffic logs based on firewall access control policies, firewall access control logs, and application identification results. This deterministic rule system can be used to accurately label traffic attributes, such as application tags, access subject tags, and access control policy IDs. At the same time, the accuracy of the rules is verified using known traffic data to ensure that the rules correctly label traffic attributes.
[0056] In this embodiment, in step S3, during data preprocessing of the network traffic information, named entities with specified characteristics of URL addresses and IP addresses are identified, and the subject, object, and access relationship entities are extracted in combination with the characteristics of network logs and system access logs.
[0057] Specifically, named entity recognition is mainly completed through data preprocessing. The named entity recognition process comprehensively considers the characteristics of network logs and system access logs, the characteristics of entity recognition and relationship extraction of subjects, objects, access relationships, etc. In the information extraction process, regular expression-based named entity recognition is used to identify named entities with obvious characteristics such as URL addresses and IP addresses.
[0058] Among them, regular expressions are used for named entity recognition to identify named entities with obvious characteristics such as URL addresses and IP addresses. For example, the regular expression "^(http|https): / / [^ / ]+" is used to identify URL addresses.
[0059] Among them, the characteristics of network logs and system access logs are comprehensively considered to extract entities such as subjects, objects, and access relationships. For example, the regular expression "(\d{1,3}\.){3}\d{1,3}" is used to identify IP addresses, and the relationship between subjects and objects is extracted based on the context.
[0060] In this embodiment, in step S4, a process similar to firewall traffic processing is used to further label the pre-processed, initially labeled training data set. This is primarily done by assigning policy tags to the training data according to deterministic rules. Security policies themselves possess highly discriminative properties and can be used as initial parameters for subsequent supervised and unsupervised learning. Network traffic characteristics that match the same security policy can also serve as initial parameters for supervised and unsupervised learning. Deterministic rules are applied to the pre-processed data to label the attributes of each traffic record, generating detailed tags, including application tags, access subject tags, and access control policy IDs.
[0061] In this embodiment, in step S5, the supervised learning algorithm adopts the K-Means algorithm, and the initial parameter of the K-Means algorithm is set to the number of access control rules of the deterministic rule base that are hit;
[0062] When the cluster center deviation of the K-Means algorithm clustering result exceeds the set threshold, the strategy of increasing the number of clusters is used to adjust the initial parameters.
[0063] Specifically, supervised learning is first used to compare the learning results of real traffic with the policy matching results. When a conflict occurs, it may indicate a change in the traffic model, which requires unsupervised learning. Alternatively, if an external system notifies the traffic self-learning module that the subject and object of access have changed, subsequent unsupervised learning is also required. Unsupervised learning is used to learn new traffic models, and new policies are defined through model learning. Supervised learning is then used to iterate and confirm the effectiveness of the new security policy.
[0064] See also Figure 4 The supervised learning algorithm uses a clustering algorithm, and the initial clustering parameter is primarily the number of clusters. Since the training data labels are non-high-dimensional, the classic K-Means algorithm is used for clustering. The most important initial parameter of the clustering algorithm is the number of clusters (n-cluster), which can be initially set to the number of access control rules hit in the "deterministic rules" section. If the clustering algorithm finds that the clustering results produce excessive deviations from the cluster center, this may indicate that the current number of access control rules hit may not be appropriate. In this case, the strategy of increasing the number of clusters is adopted for adjustment. Of course, this adjustment is not unlimited; the total number of access control policies is the upper limit of the adjustment.
[0065] In this embodiment, in step S5, the unsupervised learning algorithm uses a support vector machine classification algorithm and an association rule analysis algorithm to extract feature data, and converts the extracted feature data into rules and parameters to feed back to the supervised learning algorithm.
[0066] Specifically, the training data is labeled after undergoing deterministic rule matching and supervised algorithm training. Unsupervised learning algorithms are used to learn traffic classification features. Support vector machine classification algorithms and association rule analysis algorithms are used to extract feature data. The extracted feature data is converted into rules and parameters, which are then fed back into the supervised learning algorithm.
[0067] In summary, the embodiments of the present invention extract network traffic information from network firewall logs, classify and label the network traffic information by setting policy tags according to firewall policies, extract deterministic rules from network traffic logs, firewall access control policies, and application identification results, and construct a deterministic rule library based on the extracted deterministic rules; perform data preprocessing on the network traffic information, wherein the data preprocessing uses regular expressions to perform named entity recognition on the network traffic information and extracts the relationship between subjects and objects in combination with context; mark the network traffic information after the data preprocessing as a training data set, and use the deterministic rules in the deterministic rule library to label each traffic record in the training data set with attribute tags; construct an access control policy dynamic adjustment model, use the training data set to train the access control policy dynamic adjustment model using supervised learning algorithms and unsupervised learning algorithms, and use the trained access control policy dynamic adjustment model to identify network access control policies. The present invention can respond to sudden traffic events in the network in a timely manner, has low model deviation and strong stability; is not prone to false positives or false negatives, has high credibility, does not require excessive manual intervention, and has strong adaptability.
[0068] It should be noted that the method of the embodiments of the present disclosure can be performed by a single device, such as a computer or server. The method of the embodiments of the present disclosure can also be applied in a distributed scenario, where multiple devices cooperate to perform the method. In such a distributed scenario, one of the multiple devices may only perform one or more steps of the method of the embodiments of the present disclosure, and the multiple devices will interact with each other to complete the method.
[0069] It should be noted that the above description is limited to some embodiments of the present disclosure. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims may be performed in an order different from that described in the above embodiments and still achieve the desired results. Furthermore, the processes depicted in the accompanying drawings do not necessarily require the specific order or sequential order shown to achieve the desired results. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0070] Example 2
[0071] See also Figure 5 Embodiment 2 of the present invention further provides a network access control policy processing device based on traffic learning, comprising:
[0072] The training data extraction module 001 is used to extract network traffic information from the network firewall log and classify and label the network traffic information according to the firewall policy using set policy tags, wherein the set policy tags include valid precise policy, valid imprecise policy, invalid policy, and default policy tags;
[0073] The deterministic rule base construction module 002 is used to extract deterministic rules from network traffic logs, firewall access control policies and application identification results, and to construct a deterministic rule base based on the extracted deterministic rules;
[0074] The data preprocessing module 003 is used to perform data preprocessing on the network traffic information. The data preprocessing adopts named entity recognition based on regular expressions on the network traffic information and extracts the relationship between subject and object in combination with the context;
[0075] An attribute label marking module 004 is used to mark the network traffic information after the data preprocessing as a training data set, and use the deterministic rules in the deterministic rule base to mark each traffic record in the training data set with an attribute label;
[0076] The access control policy dynamic adjustment model processing module 005 is used to construct an access control policy dynamic adjustment model, use the training data set to train the access control policy dynamic adjustment model using a supervised learning algorithm and an unsupervised learning algorithm, and use the trained access control policy dynamic adjustment model to identify network access control policies.
[0077] In this embodiment, in the training data extraction module 001, the network traffic information includes source IP address, destination IP address, port number, protocol type, traffic size and timestamp;
[0078] The training data extraction module 001 also includes removing invalid or incomplete records of the network traffic information.
[0079] In this embodiment, in the deterministic rule base construction module 002, the deterministic rules include application tags, access subject tags, and access control policy IDs;
[0080] In the attribute label marking module 004, each flow record in the training data set is marked with an application label, an access subject label, and an access control policy ID;
[0081] In the data pre-processing module 003, named entities with specified characteristics of URL addresses and IP addresses are identified, and the subject, object, and access relationship entities are extracted in combination with the characteristics of network logs and system access logs.
[0082] In this embodiment, in the access control policy dynamic adjustment model processing module 005, the supervised learning algorithm adopts the K-Means algorithm, and the initial parameter of the K-Means algorithm is set to the number of access control rules in the deterministic rule base that are hit;
[0083] When the cluster center deviation of the K-Means algorithm exceeds the set threshold, the strategy of increasing the number of clusters is used to adjust the initial parameters;
[0084] The unsupervised learning algorithm uses a support vector machine classification algorithm and an association rule analysis algorithm to extract feature data, and converts the extracted feature data into rules and parameters to feed back to the supervised learning algorithm.
[0085] It should be noted that the information interaction, execution process, etc. between the modules of the above-mentioned device are based on the same concept as the method embodiment in Example 1 of the present application, and the technical effects they bring are the same as those of the method embodiment of the present application. For specific contents, please refer to the description in the method embodiment shown above in the present application, and will not be repeated here.
[0086] Example 3
[0087] Embodiment 3 of the present invention provides a non-transitory computer-readable storage medium, in which a program code of a network access control policy processing method based on traffic learning is stored. The program code includes instructions for executing the network access control policy processing method based on traffic learning of embodiment 1 or any possible implementation thereof.
[0088] Computer-readable storage media can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that includes one or more available media. The available media can be magnetic media (e.g., floppy disks, hard disks, magnetic tapes), optical media (e.g., DVDs), or semiconductor media (e.g., solid-state drives (SSDs)).
[0089] Example 4
[0090] Embodiment 4 of the present invention provides an electronic device, including: a memory and a processor;
[0091] The processor and the memory communicate with each other through a bus; the memory stores program instructions that can be executed by the processor, and the processor calls the program instructions to execute the network access control policy processing method based on traffic learning of Example 1 or any possible implementation thereof.
[0092] Specifically, the processor can be implemented by hardware or by software. When implemented by hardware, the processor can be a logic circuit, an integrated circuit, etc.; when implemented by software, the processor can be a general-purpose processor, which is implemented by reading software code stored in a memory. The memory can be integrated into the processor or located outside the processor and exist independently.
[0093] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the process or function described in the embodiment of the present invention is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from a website, computer, server or data center to another website, computer, server or data center via a wired (e.g., coaxial cable, optical fiber, digital consumer customer line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) mode.
[0094] Obviously, those skilled in the art will appreciate that the various modules or steps of the present invention described above can be implemented using a general-purpose computing device, centralized on a single computing device, or distributed across a network of multiple computing devices. Alternatively, they can be implemented using program code executable by a computing device, which can then be stored in a storage device and executed by the computing device. In some cases, the steps shown or described can be performed in a different order than that shown, or can be fabricated as separate integrated circuit modules, or multiple modules or steps can be fabricated as a single integrated circuit module. Thus, the present invention is not limited to any particular combination of hardware and software.
[0095] Although the present invention has been described in detail above using general descriptions and specific embodiments, it will be apparent to those skilled in the art that modifications and improvements may be made thereto. Therefore, such modifications and improvements, without departing from the spirit of the present invention, are intended to be within the scope of protection claimed herein.
Claims
1. A network access control policy processing method based on traffic learning, characterized in that: include: Extracting network traffic information from a network firewall log, and classifying and labeling the network traffic information using set policy tags according to the firewall policy, wherein the set policy tags include valid precise policy, valid imprecise policy, invalid policy, and default policy tags; The network traffic information includes source IP address, destination IP address, port number, protocol type, traffic size and timestamp; Before classifying and marking the network traffic information by setting policy tags according to the firewall policy, the method further includes removing invalid or incomplete records of the network traffic information; Extract deterministic rules from network traffic logs, firewall policies, and application identification results, and build a deterministic rule base based on the extracted deterministic rules; Performing data preprocessing on the network traffic information, wherein the data preprocessing uses regular expressions to perform named entity recognition on the network traffic information and extracts the relationship between the subject and the object in combination with the context; In the process of data preprocessing of the network traffic information, named entities with specified characteristics are identified, and subject, object, and access relationship entities are extracted by combining the characteristics of network traffic logs and system access logs; Marking the network traffic information after the data preprocessing as a training data set, and using the deterministic rules in the deterministic rule library to mark each traffic record in the training data set with an attribute label; The deterministic rules in the deterministic rule base include application tags, access subject tags, and access control policy IDs; Each traffic record in the training data set is marked with an application label, an access subject label, and an access control policy ID; Constructing an access control policy dynamic adjustment model, using the training data set to train the access control policy dynamic adjustment model using a supervised learning algorithm and an unsupervised learning algorithm, and using the trained access control policy dynamic adjustment model to identify network access control policies; The supervised learning algorithm adopts the K-Means algorithm, and the initial parameter of the K-Means algorithm is set to the number of access control rules of the deterministic rule base that are hit; When the cluster center deviation of the K-Means algorithm exceeds the set threshold, the strategy of increasing the number of clusters is used to adjust the initial parameters; The unsupervised learning algorithm uses a support vector machine classification algorithm and an association rule analysis algorithm to extract feature data, and converts the extracted feature data into rules and parameters to feed back to the supervised learning algorithm.
2. A network access control policy processing device based on traffic learning, characterized in that: include: A training data extraction module is used to extract network traffic information from network firewall logs and classify and label the network traffic information using set policy tags according to firewall policies. The set policy tags include valid precise policy, valid imprecise policy, invalid policy, and default policy tags. A deterministic rule base construction module is used to extract deterministic rules from network traffic logs, firewall policies, and application identification results, and to construct a deterministic rule base based on the extracted deterministic rules; A data preprocessing module is used to perform data preprocessing on the network traffic information, wherein the data preprocessing uses regular expressions to perform named entity recognition on the network traffic information and extracts the relationship between the subject and the object in combination with the context; An attribute label marking module is used to mark the network traffic information after the data preprocessing as a training data set, and use the deterministic rules in the deterministic rule base to mark each traffic record in the training data set with an attribute label; mark the attributes of each traffic record and generate detailed labels, including application labels, access subject labels, and access control policy IDs; An access control policy dynamic adjustment model processing module is used to construct an access control policy dynamic adjustment model, train the access control policy dynamic adjustment model using the training data set using a supervised learning algorithm and an unsupervised learning algorithm, and use the trained access control policy dynamic adjustment model to identify network access control policies; In the training data extraction module, the network traffic information includes source IP address, destination IP address, port number, protocol type, traffic size and timestamp; The training data extraction module further includes removing invalid or incomplete records of the network traffic information; In the deterministic rule base construction module, the deterministic rules include application tags, access subject tags, and access control policy IDs; In the data preprocessing module, named entities with specified characteristics are identified, and the subject, object, and access relationship entities are extracted by combining the characteristics of network traffic logs and system access logs; In the access control policy dynamic adjustment model processing module, the supervised learning algorithm adopts the K-Means algorithm, and the initial parameter of the K-Means algorithm is set to the number of access control rules of the deterministic rule base that are hit; When the cluster center deviation of the K-Means algorithm exceeds the set threshold, the strategy of increasing the number of clusters is used to adjust the initial parameters; The unsupervised learning algorithm uses a support vector machine classification algorithm and an association rule analysis algorithm to extract feature data, and converts the extracted feature data into rules and parameters to feed back to the supervised learning algorithm.
Citation Information
Patent Citations
Network access control method and device, equipment and storage medium
CN117499148A
Access control method, device, equipment, medium and program product
CN118018278A