Internet firewall security policy setting method

By conducting detailed statistics and classification of the access needs of intranet users of enterprises and institutions and Internet applications in DMZ area, security strategies for different types of users and applications are set up on the Internet firewall, the Internet security threats faced by enterprises and institutions are solved and the security guarantee of information resources is achieved.

CN120185899APending Publication Date: 2025-06-20TANGSHAN IRON & STEEL GROUP +3
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510392882.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-31
Publication Date
2025-06-20

AI Technical Summary

Technical Problem

Enterprises and institutions are facing an increase in security threats from the Internet. How to ensure that employees use the Internet safely, prevent intranet users from being infected with viruses, Trojans, and phishing, and prevent Internet applications from being attacked by external networks.

Method used

By conducting detailed statistics and classification of the Internet access needs of intranet users of enterprises and institutions and the service objects of Internet applications in DMZ area, different security policies are set on the Internet firewall for different types of users and Internet applications. The specific steps include: counting the access needs of users and applications, dividing them into four categories of users and four categories of applications, and setting corresponding security policies on the firewall, such as point-to-point communication, domestic or overseas IP address access permissions, etc.

Benefits of technology

Minimize the possibility of intranet users being infected with viruses, Trojans, and being phished, while reducing the possibility of Internet applications being attacked by external networks, ensuring the security of information resources of enterprises and institutions, and achieving the overall security of park networks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120185899A_ABST
    Figure CN120185899A_ABST
Patent Text Reader

Abstract

The invention relates to an Internet firewall security policy setting method, and belongs to the technical field of network information security control methods. According to the technical scheme, statistics and classification are carried out on internet access requirements of enterprise and public intranet users and service objects of DMZ area internet applications, and different security policies are set on an internet firewall according to different types of users and internet applications. The method has the advantages that the possibility that intranet users are infected with viruses and Trojan horses and are phished is reduced to the maximum extent, meanwhile, the possibility that Internet application is attacked by an external network is reduced, on the premise that normal Internet application of enterprises and public institutions is met, the safety of enterprise and public institution information resources is guaranteed, and the safety of enterprises and public institutions is guaranteed. And finally, the management and control target of enterprise and public institution park network overall security is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a method for setting security policies of an Internet firewall, belonging to the technical field of network information security control methods. Background Art

[0002] With the development and in-depth application of the Internet, the security threats faced by enterprises and institutions from the Internet are increasing day by day. How to ensure that the employees of enterprises and institutions can safely use the Internet, and the Internet applications released by enterprises and institutions are not or less attacked by network attacks and can operate safely and stably has become a security problem that enterprises and institutions must face and solve. Summary of the Invention

[0003] The object of the present invention is to provide a method for setting security policies of an Internet firewall. By detailed statistics and classification of the Internet access requirements of the internal network users of enterprises and institutions and the service objects of Internet applications in the DMZ area, different security policies are set on the Internet firewall for different types of users and Internet applications to minimize the possibility of internal network users being infected with viruses, trojans, and phished, and at the same time reduce the possibility of Internet applications being attacked by external networks. On the premise of meeting the normal Internet applications of enterprises and institutions, the security of enterprise information resources is guaranteed, and finally the overall security control goal of the enterprise and institution campus network is realized, effectively solving the above problems existing in the background art.

[0004] The technical solution of the present invention is: a method for setting security policies of an Internet firewall, comprising the following steps: Step S1, the Internet firewall in an enterprise or institution provides secure Internet access services for the Internet users of the unit and protects the security of the Internet applications of the unit to provide services externally; Step S2, statistically analyze the secure access requirements of Internet users. According to the statistical results, the users are divided into four categories, including those who only have access requirements for fixed government departments and company branch applications, those who only have access requirements for uncertain applications within the territory, those who only have access requirements for fixed applications outside the territory, and those who only have access requirements for uncertain applications outside the territory; Step S3, set security policies for each type of user on the Internet firewall. For type 1 users: set point-to-point communication security policies for users to government and branch applications; for type 2 users: set security policies that only allow access to the address range within the territory; for type 3 users: set security policies that only allow access to fixed applications outside the territory; for type 4 users: set full access permissions outside the territory, and at the same time add known attack and vulnerability protection security policies; Step S4: Statistically classify the service scopes of enterprise Internet applications. The statistical results classify Internet applications into four categories, including providing access services only to fixed government departments and company branches, providing services only to indefinite domestic customers, providing services only to designated overseas customers, and providing services only to indefinite overseas customers. Step S5: Set four types of security policies for each type of Internet application on the Internet firewall. Type 1 application: Set a point-to-point communication security policy for the application to the fixed IP addresses of the government and branches. Type 2 application: Set a security policy that only allows access from domestic IP addresses for the application. Type 3 application: Set a security policy that only allows access from the fixed customer IP addresses overseas for the application. Type 4 application: Set full overseas access permissions for the application and add security policies for known attacks and vulnerabilities.

[0005] In the said step S1, the following steps are included: Step S101: The connection mode of the Internet firewall consists of three areas, namely the external network area and Internet access area, the demilitarized zone and the external network application release area of enterprises and institutions, and the internal network area and the campus network of enterprises and institutions. Step S102: In the external network area, enterprises and institutions connect to the Internet by renting lines from Internet operators. Step S103: In the demilitarized zone, it is the network area where enterprises and institutions provide services to specific or non-specific Internet users. Step S104: The internal network area is the area connecting the internal campus network of enterprises and institutions, providing services for internal employees to access specific and non-specific network applications on the Internet. In the said step S2, it is default that employees of enterprises and institutions need to access the Internet according to work needs, and these needs are legitimate, reasonable and can be clearly expressed. The following steps are included: Step S201: Statistically analyze the IP addresses of employees' terminal computers and the Internet applications to be accessed according to work needs, and locate the domain names and IP addresses of these Internet applications. Step S202: The IP addresses of employees' terminal computers are fixed. If obtained through DHCP, set a longer lease period. If the IP address changes, update the corresponding firewall access policy in a timely manner. Step S203: If there are more than one IP addresses available for the Internet applications that employees need to access, use the command "nslookup + domain name" in the cmd command line mode to obtain more than one Internet IP address for the application. When setting the firewall policy, add all IP addresses to the list of allowed access. In the said step S3, the following steps are included: Step S301, the first type of users refers to employees who need to access the websites of some government departments or the applications or websites of company branches to handle some affairs and have no access requirements for other Internet applications. Set point-to-point or multi-point-to-multi-point access permissions for these employees on the firewall, and prohibit access to other addresses; Step S302, the second type of employees refers to those who need to collect relevant information required for work through the Internet. It is not possible to determine specifically from which websites to obtain it, but it can be determined that it only involves domestic websites and does not involve foreign websites. Develop access permissions for domestic Internet IPs for these users and prohibit their access permissions to foreign IP addresses; Step S303, the third type of employees refers to those with access requirements for specific foreign websites or applications. Locate the domain names and IP addresses of the foreign websites or applications, and set access permissions on the firewall that only allow access to the specific domain names and IPs for such users, and prohibit their access permissions to other IP addresses; Step S304, the fourth type of employees refers to those with the need to access uncertain foreign networks or applications. Set access permissions for these employees that allow them to access all Internet IP addresses, and at the same time add security policies for known attacks and vulnerabilities. Use this policy only after confirming that the websites and applications to be accessed cannot be exhausted; In step S4 mentioned above, the following steps are included: Step S401, the applications published by enterprises and institutions on the Internet specify the specific service objects and the IP addresses or IP address ranges of the service objects; Step S402, the first type of Internet applications refers to those where enterprises need to provide specific services for specific government departments or branches through the Internet, such as developing email or OA office automation services for branches, registering the Internet IP addresses of government agencies and branches, and using them when setting firewall policies; Step S403, the second type of Internet applications refers to those whose service objects are domestic uncertain users but do not have foreign users; Step S404, the third type of Internet applications refers to those whose service objects are one or several fixed foreign customers, and register the IP addresses or IP address ranges of the fixed customers; Step S405, the fourth type of Internet applications refers to those whose service objects are foreign uncertain users, and can only be used when it is confirmed that the service objects cannot be exhausted; In step S5 mentioned above, the following steps are included: Step S501, set an access policy on the firewall for the first type of Internet applications that allows access from the IP address of the application to the government department or branch point-to-point or one-to-multi-point, and does not allow anything else; Step S502: Set a security policy on the firewall for the second type of Internet applications, which does not allow access from foreign IP addresses to the application IP addresses. Step S503: Set a security policy on the firewall for the third type of Internet applications, which only allows access to the application IP addresses from specific foreign IP addresses or IP addresses for access, and does not allow access to other IP addresses. Step S504: Set a security policy on the firewall for the fourth type of Internet applications, which only allows access to the application IP addresses from all foreign IP addresses, and at the same time add security policies for known attacks and vulnerabilities protection.

[0006] The beneficial effects of the present invention are as follows: By conducting detailed statistics and classification on the Internet access requirements of the intranet users in enterprises and institutions and the service objects of the Internet applications in the DMZ area, different security policies are set on the Internet firewall for different types of users and Internet applications, so as to minimize the possibility of the intranet users being infected with viruses, Trojans, and phished, and at the same time reduce the possibility of the Internet applications being attacked by external networks. On the premise of meeting the normal Internet applications of enterprises and institutions, the security of enterprise and institution information resources is guaranteed, and finally the overall security control goal of the enterprise and institution campus network is achieved. Description of the Drawings

[0007] Figure 1 is the flowchart of the present invention; Figure 2 is the network connection structure block diagram of the present invention. Detailed Embodiments

[0008] In order to make the purpose, technical solutions and advantages of the embodiments of the invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments. Obviously, the described embodiments are only a small part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative work belong to the protection scope of the present invention.

[0009] A method for setting security policies of an Internet firewall includes the following steps: Step S1: The Internet firewall in an enterprise or institution provides secure Internet access services for the unit's Internet users and protects the security of the unit's Internet applications to provide services externally. Step S2: Statistically analyze the secure access requirements of Internet users. According to the statistical results, the users are divided into four categories, including those who only have access requirements for fixed government departments and company branch applications, those who only have access requirements for uncertain applications within the country, those who only have access requirements for fixed applications outside the country, and those who only have access requirements for uncertain applications outside the country. Step S3, set security policies for each type of user on the Internet firewall. For type 1 users: set a point-to-point communication security policy for users to access the government and branch offices. For type 2 users: set a security policy that only allows access to the domestic address range. For type 3 users: set a security policy that only allows access to fixed overseas applications. For type 4 users: set full overseas access rights and add security policies for known attacks and vulnerabilities. Step S4, statistically classify the service scope of the unit's Internet applications. The statistical results classify Internet applications into four categories, including providing access services only to fixed government departments and company branch offices, providing services only to uncertain domestic customers, providing services only to designated overseas customers, and providing services only to uncertain overseas customers. Step S5, set four types of security policies for each type of Internet application on the Internet firewall. For type 1 applications: set a point-to-point communication security policy for the application to access the fixed IP addresses of the government and branch offices. For type 2 applications: set a security policy that only allows access from domestic IP addresses. For type 3 applications: set a security policy that only allows access from the fixed customer IP addresses overseas. For type 4 applications: set full overseas access rights and add security policies for known attacks and vulnerabilities.

[0010] In the said step S1, the following steps are included: Step S101, the connection mode of the Internet firewall consists of three areas: the external network area and Internet access area, the demilitarized zone and the enterprise and institution external network application release area, and the internal network area and the enterprise and institution campus network. In step S102, in the external network area, enterprises and institutions connect to the Internet by leasing lines from Internet operators. In step S103, in the demilitarized zone, it is the network area where enterprises and institutions provide services to specific or non-specific Internet users. In step S104, the internal network area is the area connecting the internal campus network of enterprises and institutions, providing services for internal employees to access specific and non-specific network applications on the Internet. In the said step S2, it is default that the employees of enterprises and institutions need to access the Internet according to work needs, and these needs are legitimate, reasonable and can be clearly expressed. The following steps are included: Step S201, statistically count the IP addresses of employees' terminal computers and the Internet applications they need to access according to work needs, and locate the domain names and IP addresses of these Internet applications. In step S202, the IP addresses of employees' terminal computers are fixed. If obtained through DHCP, set a longer lease period. If the IP address changes, update the corresponding firewall access policy in a timely manner. Step S203, if the Internet application that the employee needs to access has more than one IP address available for access, use the command "nslookup + domain name" in the cmd command line mode to obtain more than one Internet IP address for the application. When setting the firewall policy, add all the IP addresses to the list of allowed access; In step S3, the following steps are included: Step S301, the first type of users refers to employees who need to access the websites of some government departments or the applications or websites of company branches to handle some affairs and have no access requirements for other Internet applications. Set point-to-point or multi-point-to-multi-point access permissions for these employees on the firewall, and prohibit access to other addresses; Step S302, the second type of employees refers to those who need to collect relevant information required for work through the Internet. It is not possible to determine specifically from which websites to obtain it, but it can be determined that it only involves domestic websites and does not involve foreign websites. Develop access permissions for domestic Internet IPs for these users and prohibit their access permissions to foreign IP addresses; Step S303, the third type of employees refers to those with access requirements for specific foreign websites or applications. Locate the domain name and IP address of the foreign website or application, and set access permissions on the firewall that only allow access to the specific domain name and IP for such users, and prohibit their access permissions to other IP addresses; Step S304, the fourth type of employees refers to those with the need to access uncertain foreign networks or applications. Set access permissions for these employees that allow access to all Internet IP addresses, and at the same time add known attack and vulnerability protection security policies. Use this policy only after confirming that the websites and applications to be accessed cannot be exhausted; In step S4, the following steps are included: Step S401, the applications published by enterprises and institutions on the Internet specify the specific service objects and the IP addresses or IP address ranges of the service objects; The first type of Internet application refers to that enterprises need to provide specific services for specific government departments or branches through the Internet, develop email or OA office automation services for branches, etc., and register the Internet IP addresses of government agencies and branches for use when setting firewall policies; The second type of Internet application refers to the type whose service objects are uncertain domestic users but there are no foreign users; The third type of Internet application refers to that the service objects are one or several fixed foreign customers, and register the IP addresses or IP address ranges of the fixed customers; The fourth type of Internet application refers to that the service objects are uncertain foreign users, and it can only be used when it is confirmed that the service objects cannot be exhausted; In step S5, the following steps are included: Step S501: Set an access policy on the firewall for the first type of Internet application, allowing point-to-point or one-to-many access from the application's IP address to government departments or branches, and disallowing all other access. Step S502: Set an access security policy on the firewall for the second type of Internet application, disallowing access from foreign IP addresses to the application's IP address. Step S503: Set an access security policy on the firewall for the third type of Internet application, allowing access only from specific foreign IP addresses or IP addresses for access to the application's IP address, and disallowing all other access. Step S504: Set an access security policy on the firewall for the fourth type of Internet application, allowing access only from all foreign IP addresses to the application's IP address, and at the same time adding known attack and vulnerability protection security policies.

[0011] In practical applications, the following steps are included: Step S1, as Figure 1 shown, in enterprises and institutions, the Internet firewall generally undertakes the functions of providing secure Internet access services for the unit's Internet users and protecting the security of the unit's Internet applications for external services. The present invention will be described from two directions: the setting of Internet user security policies and the setting of Internet application security policies; Step S2: Statistically analyze the secure access requirements of Internet users. The statistical results classify users into four categories: 1. Those with access requirements only for fixed government departments and company branches; 2. Those with access requirements only for uncertain applications within the country; 3. Those with access requirements only for fixed applications outside the country; 4. Those providing services for access to uncertain applications outside the country; Step S3: According to the four major categories of results statistically obtained in step 2, set four types of security policies for each category of users on the Internet firewall: For category 1 users: Set point-to-point communication security policies for users to government and branch applications; For category 2 users: Set security policies that only allow access to the domestic address range for users; For category 3 users: Set security policies that only allow access to fixed applications outside the country for users; For category 4 users: Set full access permissions outside the country, and at the same time add known attack and vulnerability protection security policies; The setting process is as Figure 2 shown, to complete the setting of Internet user security policies for the Internet firewall; Step S4: Statistically classify the service scopes of the unit's Internet applications. The statistical results classify Internet applications into four categories: 1. Those providing access services only for fixed government departments and company branches; 2. Those providing services only for uncertain customers within the country; 3. Those providing services only for designated customers outside the country; 4. Those providing services for uncertain customers outside the country; Step S5: According to the statistical results of the four major categories in Step 4, set four types of security policies for each type of Internet application on the Internet firewall: Type 1 application: Set a point-to-point communication security policy for the application to the fixed IP addresses of the government and branch offices; Type 2 application: Set a security policy that only allows access from domestic IP addresses for the application; Type 3 application: Set a security policy that only allows access from fixed overseas customer IP addresses for the application; Type 4 application: Set full overseas access permissions for the application, and at the same time add security policies for known attacks and vulnerabilities; The setting process is as Figure 1 shown, and complete the setting of the security policies for Internet applications on the Internet firewall; In the said Step S1, the following steps are included: Step S101: The connection method of the Internet firewall involved in this method is as Figure 1 shown, including: an external network area and Internet access area, a DMZ (demilitarized zone) and enterprise and institution external network application publishing area, and an internal network area and enterprise and institution campus network, which are composed of three areas; Step S102: Among them, the external network area is where enterprises and institutions connect to the Internet through leased lines of Internet operators (such as Telecom, Unicom, Mobile, etc.); Step S103: Among them, the DMZ (demilitarized zone) is a network area where enterprises and institutions provide services to specific or non-specific Internet users, generally including: email services, e-commerce services, portal websites, WEB application services, etc.; Step S104: The internal network area refers to the area connecting the internal campus network of enterprises and institutions, mainly providing services for internal employees to access specific and non-specific network applications on the Internet; In the said Step S2, it is default that employees of enterprises and institutions need to access the Internet according to work needs, and these needs are legitimate, reasonable and can be clearly expressed. The following steps are included: Step S201: According to work needs, count the IP addresses of employees' terminal computers and the Internet applications to be accessed, and accurately locate the domain names and IP addresses of these Internet applications; Step S202: The premise of this method is that the IP address of the employee's terminal computer is fixed. If it is obtained through DHCP, a longer lease period needs to be set to ensure that it remains unchanged for a long time. If the IP address changes, the corresponding firewall access policy needs to be updated in time; Step S203: Generally, there are multiple IP addresses available for the Internet applications that employees need to access. The command "nslookup + domain name" can be used in the cmd command line mode to obtain multiple Internet IP addresses of the application. When setting the firewall policy, all the multiple IP addresses need to be added to the list of allowed access; In step S3, the following steps are included: Step S301: The first type of users mainly refers to employees who need to access the websites of some government departments or the applications or websites of company branches to handle some affairs. For employees who have no need to access other Internet applications, point-to-point or multi-point-to-multi-point access permissions can be set for these employees on the firewall, and access to other addresses is prohibited; Step S302: The second type of employees mainly refers to those who need to collect relevant information required for work through the Internet. It is not possible to determine specifically which websites to obtain information from, but it can be determined that it only involves domestic websites and does not involve foreign websites. Then, access permissions for domestic Internet IPs can be developed for these users, and access permissions for their foreign IP addresses are prohibited; Step S303: The third type of employees mainly refers to those with access requirements for specific foreign websites or applications. Then, it is necessary to accurately locate the domain names and IP addresses of the foreign websites or applications, and set access permissions on the firewall that only allow access to the specific domain names and IPs for such users, and prohibit their access to other IP addresses; Step S304: The fourth type of employees refers to those who have the need to access uncertain foreign networks or applications. Then, access permissions that allow them to access all Internet IP addresses need to be set for such employees, and at the same time, security policies for known attacks and vulnerabilities are added. Note that the security policy risk for this type of employees is the highest, and it must be fully demonstrated and confirmed that the websites and applications to be accessed cannot be exhausted before using this policy; In step S4, the following steps are included: Step S401: The applications published by enterprises and institutions on the Internet should clearly define the specific service objects and the IP addresses or IP address ranges of the service objects; Step S402: The first type of Internet application refers to the situation where an enterprise needs to provide specific services for specific government departments or branches through the Internet. For example, it is necessary to provide video surveillance services to the government environmental protection department; it is necessary to develop email or OA office automation services for branches; it is necessary to accurately register the Internet IP addresses of government agencies and branches for use when setting firewall policies; Step S403: The second type of Internet application refers to the type where the service objects are domestic uncertain users but there are no foreign users; Step S404: The third type of Internet application refers to the situation where the service objects are one or several fixed foreign customers, and it is necessary to register the IP addresses or IP address ranges of the fixed customers; Step S405: The fourth type of Internet application refers to the situation where the service objects are uncertain foreign users. Since this type of application is highly dangerous, it can only be used when it is determined that the service objects cannot be exhausted; In step S5, the following steps are included: Step S501: Set an access policy on the firewall for the first type of Internet applications, allowing point-to-point or one-to-many access from the IP address of the application to government departments or branches, and disallowing all other access. Step S502: Set an access security policy on the firewall for the second type of Internet applications, disallowing access from foreign IP addresses to the IP address of the application. Step S503: Set an access security policy on the firewall for the third type of Internet applications, allowing access only from specific foreign IP addresses or IP addresses for access, and disallowing all other access. Step S504: Set an access security policy on the firewall for the fourth type of Internet applications, allowing access only from all foreign IP addresses, and at the same time adding security policies for known attacks and vulnerability protection. In practical applications, the specific implementation content of the present invention includes the following five parts: The first part, as Figure 2 shown, in enterprises and institutions, the Internet firewall generally shoulders the functions of providing secure Internet access services for the Internet users of the unit and protecting the security of the Internet applications of the unit when providing services externally. The present invention will be described from two directions: the setting of Internet user security policies and the setting of Internet application security policies; the specific implementation steps are as follows: Step S101: The connection method of the Internet firewall involved in this method is as Figure 2 shown, including: an external network area, i.e., the Internet access area; a DMZ (demilitarized zone), i.e., the external network application release area of enterprises and institutions; and an internal network area, i.e., the campus network of enterprises and institutions, consisting of three areas. Step S102: Among them, the external network area is where enterprises and institutions connect to the Internet through leased lines from Internet operators (such as Telecom, Unicom, Mobile, etc.). Step S103: Among them, the DMZ (demilitarized zone) is a network area where enterprises and institutions provide services to specific or non-specific Internet users, generally including: email services, e-commerce services, portal websites, WEB application services, etc. Step S104: The internal network area refers to the area connecting the internal campus network of enterprises and institutions, mainly providing services for internal employees to access specific and non-specific network applications on the Internet. The second part: Statistically analyze the secure access requirements of Internet users. The statistical results classify users into four categories: 1. Those with access requirements only for fixed government departments and company branches; 2. Those with access requirements only for uncertain applications within the country; 3. Those with access requirements only for fixed applications outside the country; 4. Those providing services for access to uncertain applications outside the country. The specific implementation steps are as follows; Step S201: According to the work requirements, count the IP addresses of employees' terminal computers and the Internet applications to be accessed, and accurately locate the domain names and IP addresses of these Internet applications. Step S202: The premise of this method is that the IP address of the employee's terminal computer is fixed. If it is obtained through DHCP, a longer lease period needs to be set to ensure that it remains unchanged for a long time. If the IP address changes, the corresponding firewall access policy needs to be updated in a timely manner. Step S203: Generally, there are multiple IP addresses available for the Internet applications that employees need to access. The command "nslookup + domain name" can be used in the cmd command line mode to obtain multiple Internet IP addresses of the application. When setting the firewall policy, all these IP addresses need to be added to the list of allowed access. Part three: According to the four major types of results counted in step 2, set four types of security policies for each type of user on the Internet firewall: Type 1 users: Set point-to-point communication security policies for users to access government and branch applications; Type 2 users: Set security policies that only allow access to domestic address ranges for users; Type 3 users: Set security policies that only allow access to specific foreign applications for users; Type 4 users: Set full access permissions for foreign countries, and at the same time add known attack and vulnerability protection security policies. The setting process is as Figure 2 shown. Complete the setting of the security policies for Internet users on the Internet firewall. The specific implementation steps are as follows: Step S301: The first type of users mainly refer to employees who need to access the websites of some government departments or the applications or websites of the company's branches to handle some affairs and have no access requirements for other Internet applications. Point-to-point or multi-point-to-multi-point access permissions can be set for these employees on the firewall, and access to other addresses is prohibited. Step S302: The second type of employees mainly refer to those who need to collect relevant information required for work through the Internet. It is not possible to determine specifically from which websites to obtain it, but it can be determined that it only involves domestic websites and does not involve foreign websites. Then, access permissions for domestic Internet IPs can be developed for these users, and access permissions for their foreign IP addresses are prohibited. Step S303: The third type of employees mainly refer to those with access requirements for specific foreign websites or applications. Then, it is necessary to accurately locate the domain names and IP addresses of the foreign websites or applications, and set access permissions on the firewall that only allow access to the specific domain names and IPs for such users, and prohibit their access to other IP addresses. Step S304: The fourth type of employees refers to those who have the need to access uncertain foreign networks or applications. For such employees, access permissions to all Internet IP addresses need to be set, and at the same time, security policies for known attacks and vulnerability protection are added. Note that the security policy risk for this type of employees is the highest, and it requires full demonstration. Only after confirming that the websites and applications to be accessed cannot be exhausted can this policy be used; Part Four: Statistically classify the service scope of the unit's Internet applications. The statistical results classify Internet applications into four categories: 1. Provide access services only to fixed government departments and company branches; 2. Provide services only to uncertain domestic customers; 3. Provide services only to designated foreign customers; 4. Provide services to uncertain foreign customers. The specific implementation steps are as follows: Step S401: Enterprises and institutions should clarify the specific service objects and the IP addresses or IP address ranges of the service objects for the applications published on the Internet; Step S402: The first type of Internet application means that enterprises need to provide specific services for specific government departments or branches through the Internet. For example, they need to provide video surveillance services to the government environmental protection department; they need to develop email or OA office automation services for branches; they need to accurately register the Internet IP addresses of government agencies and branches for use when setting firewall policies; Step S403: The second type of Internet application refers to the type where the service objects are uncertain domestic users but there are no foreign users; Step S404: The third type of Internet application refers to the type where the service objects are one or several fixed foreign customers, and the IP addresses or IP address ranges of the fixed customers need to be registered; Step S405: The fourth type of Internet application refers to the type where the service objects are uncertain foreign users. Since this type of application is highly dangerous, it can only be used when it is confirmed that the service objects cannot be exhausted; Part Five: According to the four major categories of results statistically in Step 4, set four types of security policies for each type of Internet application on the Internet firewall: 1. For the first type of application: Set a point-to-point communication security policy for the application to the fixed IP addresses of the government and branches; 2. For the second type of application: Set a security policy that only allows access from domestic IP addresses for the application; 3. For the third type of application: Set a security policy that only allows access from the IP addresses of fixed foreign customers for the application; 4. For the fourth type of application: Set all foreign access permissions for the application, and at the same time add security policies for known attacks and vulnerability protection; The setting process is as Figure 1 shown. Complete the setting of the security policies for Internet applications on the Internet firewall. The specific implementation steps are as follows: Step S501: Set an access policy on the firewall for the first type of Internet application, which allows point-to-point or one-to-many access from the IP address of this application to government departments or branches, and prohibits all other access. Step S502: Set an access security policy on the firewall for the second type of Internet application, which prohibits access from foreign IP addresses to the IP address of this application. Step S503: Set an access security policy on the firewall for the third type of Internet application, which allows access only from specific foreign IP addresses or IP addresses for access to this application, and prohibits all other access. Step S504: Set an access security policy on the firewall for the fourth type of Internet application, which allows access only from all foreign IP addresses to the IP address of this application, and at the same time add security policies for known attacks and vulnerability protection.

[0012] Through detailed statistics and classification of the Internet access requirements of enterprise and institutional intranet users and the service objects of Internet applications in the DMZ area, the present invention sets different security policies on the Internet firewall for different types of users and Internet applications, so as to minimize the possibility of intranet users being infected with viruses, trojans, and phishing, and at the same time reduce the possibility of Internet applications being attacked by external networks. On the premise of meeting the normal Internet applications of enterprises and institutions, the security of enterprise and institutional information resources is guaranteed, and finally the overall security control goal of the enterprise and institutional campus network is achieved, effectively solving the above problems existing in the background technology.

Claims

1. A method for setting an Internet firewall security policy, characterized in that The following steps are involved: Step S1, the Internet firewall in enterprises and institutions provides secure Internet access services for the Internet users of the enterprise and protects the security of the Internet applications of the enterprise to provide external services; Step S2, statistics are collected on the access security needs of Internet users, and users are divided into four categories according to the statistical results, including users who only have access needs for fixed government departments and company branch applications, users who only have access needs for uncertain applications within the country, users who only have access needs for fixed applications outside the country, and users who only have access needs for uncertain applications outside the country; Step S3, setting security policies for each type of user on the Internet firewall: Type 1 users: set point-to-point communication security policies for users to apply to the government and branches; Type 2 users: set security policies for users to only allow access to domestic address ranges; Type 3 users: set security policies for users to only allow fixed applications outside the country; Type 4 users: set all access rights outside the country, and add known attack and vulnerability protection security policies; Step S4, statistically classifying the service scope of the unit's Internet applications, the statistical results divide the Internet applications into four categories, including providing access services only to fixed government departments and company branches, providing services only to uncertain customers within the country, providing services only to designated customers abroad, and providing services only to uncertain customers abroad; Step S5, set four types of security policies for each type of Internet application on the Internet firewall, Type 1 application: set a point-to-point communication security policy to the fixed IP addresses of the government and branches for the application; Type 2 application: set a security policy that only allows domestic IP addresses to access the application; Type 3 application: set a security policy that only allows overseas fixed customer IP addresses to access the application; Type 4 application: set all overseas access rights for the application, and add known attack and vulnerability protection security policies.

2. The method for setting an Internet firewall security policy according to claim 1, characterized in that: The step S1 includes the following steps: Step S101, the connection mode of the Internet firewall includes three areas: the external network area and the Internet access area, the ceasefire area and the enterprise and institution external network application release area, and the internal network area and the enterprise and institution campus network; Step S102, in the external network area, enterprises and institutions connect to the Internet by renting lines from Internet operators; Step S103, in the ceasefire area, a network area where enterprises and institutions provide services to specific or non-specific Internet users; Step S104, the intranet area is an area connected to the internal campus network of an enterprise or institution, providing services for internal employees to access specific and non-specific network applications on the Internet.

3. The method for setting an Internet firewall security policy according to claim 1, characterized in that: In step S2, it is assumed that employees of enterprises and institutions need to access the Internet according to work needs, and these needs are legitimate and reasonable and can be clearly expressed, which includes the following steps: Step S201, counting the IP addresses of employee terminal computers and the Internet applications that need to be accessed according to work needs, and locating the domain names and IP addresses of these Internet applications; Step S202: The IP address of the employee's terminal computer is fixed. If it is obtained through DHCP, a longer lease period is set. If the IP address changes, the corresponding firewall access policy is updated in time. Step S203: The Internet application that the employee needs to access has one or more IP addresses available for access. In the cmd command line mode, use the command "nslookup + domain name" to obtain one or more Internet IP addresses for the application. When setting the firewall policy, add all IP addresses to the list of allowed access.

4. The method for setting an Internet firewall security policy according to claim 1, characterized in that: The step S3 includes the following steps: Step S301: The first category of users refers to employees who need to access some government websites or company branch applications or websites to handle some affairs, and have no access requirements to other Internet applications. Point-to-point or multipoint-to-multipoint access permissions are set for these employees on the firewall, and access is prohibited to other addresses. Step S302: The second type of employees need to collect relevant information for work through the Internet. It is not certain from which websites they are obtained, but it is certain that they are domestic websites, not foreign websites. For these users, develop access rights for domestic Internet IP addresses, and prohibit their access rights for foreign IP addresses; Step S303: The third type of employees refers to those who have access requirements to specific foreign websites or applications. The domain name and IP address of the foreign website or application are located, and access rights are set on the firewall for such users to only access the specific domain name and IP, and their access rights to other IP addresses are prohibited; Step S304: The fourth category of employees refers to those who have the need to access uncertain foreign networks or applications. Access rights are set for such employees to allow them to access all Internet IP addresses. At the same time, known attack and vulnerability protection security policies are added. The policy is used after confirming that the websites and applications that need to be accessed cannot be exhausted.

5. A method for setting an Internet firewall security policy according to claim 1, characterized in that: The step S4 includes the following steps: Step S401, the application published by the enterprise or institution on the Internet specifies the specific service object, as well as the IP address or IP address range of the service object; Step S402, the first type of Internet application refers to the need for enterprises to provide specific services to specific government departments or branches through the Internet, develop e-mail or OA office automation services for branches, etc., register the Internet IP addresses of government agencies and branches, and use them when setting firewall policies; Step S403, the second type of Internet application refers to the type of service provided to domestic uncertain users but no foreign users; Step S404, the third type of Internet application refers to the service object is one or several fixed customers abroad, and the IP address or IP address range of the fixed customer is registered; Step S405, the fourth type of Internet application refers to a service object that is an uncertain user abroad, and it can only be used when the service object is determined to be impossible to exhaust.

6. The method for setting an Internet firewall security policy according to claim 1, characterized in that: The step S5 includes the following steps: Step S501, for the first type of Internet application, set the access policy on the firewall that the IP address of the application is point-to-point or point-to-multipoint to the government department or branch, and no other access is allowed; Step S502, setting a security policy on the firewall for the second type of Internet application that prohibits the application IP address from being accessed by foreign IP addresses; Step S503, for the third type of Internet application, a security policy is set on the firewall to allow only specific foreign IP addresses or IP addresses to access the application IP address, and no other IP addresses are allowed to access; Step S504, for the fourth type of Internet application, a security policy is set on the firewall to allow only all foreign IP addresses to access the application IP address, and a known attack and vulnerability protection security policy is added.