Linkage method, equipment, medium and program product of security protection system
By achieving linkage between the firewall and vulnerability scanning tools, real-time monitoring of vulnerability scanning data and updating of firewall policies, the problem of lack of linkage between the firewall and vulnerability scanning tools is solved, and the security protection performance of the network system and the flexibility of the policy are improved.
Patent Information
- Application Number
- CN202510687089.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-27
- Publication Date
- 2025-09-16
- Estimated Expiration
- 2045-05-27
AI Technical Summary
The lack of linkage between firewalls and vulnerability scanning tools in network security results in low security protection performance of network systems. Manual adjustment of strategies is labor-intensive and time-consuming.
By real-time monitoring of vulnerability scanning data, generating linkage information and sending it to the firewall, updating the firewall's protection strategy, and obtaining real-time protection status information fed back by the firewall to maintain or switch the security protection linkage function to the enabled state, the linkage flexibility and timeliness of the firewall are improved.
It improves the security protection performance of the network system, enhances the flexibility and timeliness of firewall policies, reduces manual intervention, and improves system security.
Smart Images

Figure CN120223440B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of security protection technology, and more specifically, to a linkage method, device, medium, and program product for a security protection system. Background Art
[0002] A firewall is a network security system that monitors and controls the flow of data across a network to prevent unauthorized access and data leakage. It uses access control lists to allow or deny network traffic based on pre-set rules, ensuring that only authorized devices or users can access internal network resources.
[0003] Vulnerability scanning tools are proactive security tools used to detect vulnerabilities and weaknesses in a network. They are deployed on the system or network to be tested and perform regular or on-demand scans. By simulating attacker behavior, they probe the network or system to identify potential security risks.
[0004] Currently, firewalls and vulnerability scanning tools are deployed in different systems and work independently, lacking linkage between them, resulting in low security protection performance of network systems. Summary of the Invention
[0005] The purpose of the embodiments of the present application is to provide a linkage method, device, medium and program product of a security protection system to improve the security protection performance of the network system.
[0006] In a first aspect, an embodiment of the present application provides a linkage method for a security protection system, comprising:
[0007] When the security protection linkage function of the target system is enabled, the vulnerability scanning data of the target system is monitored in real time;
[0008] In a case where it is determined based on the vulnerability scanning data that a vulnerability discovery event occurs in the target system, generating linkage information based on the vulnerability discovery event;
[0009] Sending the linkage information to a firewall associated with the target system, so that the firewall obtains a current flow control policy corresponding to the vulnerability discovery event based on the linkage information, updates a local protection policy of the firewall based on the current flow control policy, and performs security protection operations according to the updated protection policy;
[0010] The protection status information fed back by the firewall is obtained in real time, and the enabling state of the security protection linkage function is maintained or switched according to the protection status information.
[0011] In an embodiment of the present application, by real-time monitoring of vulnerability scanning conditions, corresponding linkage information is sent to the firewall when new vulnerabilities are discovered, so that the firewall can synchronize security protection strategies in a timely manner, thereby effectively improving the security protection performance of the network system.
[0012] In some possible embodiments, generating linkage information based on the vulnerability discovery event includes:
[0013] Obtain the current vulnerability type corresponding to the vulnerability discovery event;
[0014] When it is determined that the current vulnerability type meets the preset linkage condition, linkage information is generated based on the vulnerability discovery event.
[0015] In the embodiment of the present application, by adding judgment conditions and determining whether to trigger linkage with the firewall based on the type of the current vulnerability, the flexibility of the linkage security protection is further improved.
[0016] In some possible embodiments, sending the linkage information to a firewall associated with the target system so that the firewall obtains a current flow control policy corresponding to the vulnerability discovery event based on the linkage information, updates a local protection policy of the firewall based on the current flow control policy, and performs security protection operations according to the updated protection policy, includes:
[0017] The linkage information is sent to the firewall associated with the target system, so that the firewall obtains the current flow control policy corresponding to the vulnerability discovery event based on the linkage information; when it is determined that the current flow control policy meets the preset protection policy update conditions, the local protection policy of the firewall is updated based on the current flow control policy, and security protection operations are performed according to the updated protection policy.
[0018] In an embodiment of the present application, by configuring judgment conditions on the firewall and determining whether the local protection policy needs to be updated when the flow control rules to be updated are obtained, the flexibility of the linkage security protection is further improved.
[0019] In some possible embodiments, generating linkage information based on the vulnerability discovery event includes:
[0020] Obtaining current vulnerability information corresponding to the vulnerability discovery event, generating a current flow control strategy corresponding to the current vulnerability information, and assembling based on the current flow control strategy to obtain the linkage information;
[0021] The step of sending the linkage information to a firewall associated with the target system so that the firewall obtains a current flow control policy corresponding to the vulnerability discovery event based on the linkage information, updates a local protection policy of the firewall based on the current flow control policy, and performs security protection operations according to the updated protection policy, including:
[0022] The linkage information is sent to the firewall associated with the target system so that the firewall obtains the current flow control policy in the linkage information, updates the local protection policy of the firewall based on the current flow control policy, and performs security protection operations according to the updated protection policy.
[0023] In an embodiment of the present application, by generating corresponding firewall flow control rules based on the newly discovered vulnerabilities on the device where the vulnerability tool is located, and directly sending the flow control rules to the firewall for linkage protection operations, the flexibility of the firewall linkage is further improved.
[0024] In some possible embodiments, generating linkage information based on the vulnerability discovery event includes:
[0025] Obtaining current vulnerability information corresponding to the vulnerability discovery event, and assembling the linkage information based on the current vulnerability information;
[0026] The step of sending the linkage information to a firewall associated with the target system so that the firewall obtains a current flow control policy corresponding to the vulnerability discovery event based on the linkage information, updates a local protection policy of the firewall based on the current flow control policy, and performs security protection operations according to the updated protection policy, including:
[0027] The linkage information is sent to the firewall associated with the target system so that the firewall obtains the current vulnerability information in the linkage information, generates a current flow control policy corresponding to the current vulnerability information, updates the local protection policy of the firewall based on the current flow control policy, and performs security protection operations according to the updated protection policy.
[0028] In an embodiment of the present application, the original vulnerability information of the newly discovered vulnerability is sent directly to the firewall, so that the firewall generates corresponding protection rules based on the original vulnerability information, thereby further improving the flexibility of the firewall linkage.
[0029] In some possible embodiments, the linkage method of the safety protection system further includes:
[0030] Real-time monitoring of vulnerability repair data of the target system;
[0031] In a case where it is determined based on the vulnerability repair data that a vulnerability repair event occurs in the target system, generating second linkage information based on the vulnerability repair event;
[0032] The second linkage information is sent to the firewall associated with the target system, so that the firewall obtains the target flow control policy corresponding to the vulnerability repair event based on the second linkage information, updates the local protection policy of the firewall by eliminating the target flow control policy, and performs security protection operations according to the updated protection policy.
[0033] In an embodiment of the present application, by real-time monitoring of the repair status of discovered vulnerabilities and sending linkage information to the firewall based on the repaired vulnerabilities, the firewall can streamline the protection strategy in a timely manner, thereby further improving the security protection performance of the network system.
[0034] In some possible embodiments, the linkage method of the safety protection system further includes:
[0035] Obtaining in real time traffic interception information fed back by a firewall associated with the target system;
[0036] In the case where it is determined based on the traffic interception information that the target system meets the preset policy adjustment conditions, determining the target vulnerability type that currently requires increased attention based on the traffic interception information;
[0037] Vulnerability scanning rules for the target system are adjusted based on the target vulnerability type.
[0038] In an embodiment of the present application, by monitoring the traffic interception information fed back by the firewall in real time and determining the target vulnerability type that needs to be focused on based on the traffic interception information, the leakage scanning rules of the target vulnerability type are adjusted, thereby further improving the security protection performance of the network system.
[0039] In a second aspect, an embodiment of the present application provides a linkage device for a safety protection system, comprising:
[0040] The data monitoring module is used to monitor the vulnerability scanning data of the target system in real time when the security protection linkage function of the target system is enabled;
[0041] An information generating module, configured to generate linkage information based on a vulnerability discovery event when it is determined based on the vulnerability scanning data that a vulnerability discovery event occurs in the target system;
[0042] an information sending module, configured to send the linkage information to a firewall associated with the target system, so that the firewall obtains a current flow control policy corresponding to the vulnerability discovery event based on the linkage information, updates a local protection policy of the firewall based on the current flow control policy, and performs security protection operations according to the updated protection policy;
[0043] The feedback adjustment module is used to obtain the protection status information fed back by the firewall in real time, and maintain or switch the activation state of the security protection linkage function according to the protection status information.
[0044] In a third aspect, an embodiment of the present application provides an electronic device comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, wherein the processor can implement the method described in any embodiment of the first aspect when executing the program.
[0045] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the method described in any embodiment of the first aspect can be implemented.
[0046] In a fifth aspect, an embodiment of the present application provides a computer program product, which includes a computer program, wherein when the computer program is executed by a processor, it can implement the method described in any embodiment of the first aspect. BRIEF DESCRIPTION OF THE DRAWINGS
[0047] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following is a brief introduction to the drawings required for use in the embodiments of the present application. It should be understood that the following drawings only show certain embodiments of the present application and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other relevant drawings can be obtained based on these drawings without creative work.
[0048] Figure 1 A schematic diagram of a process flow of a linkage method for a security protection system provided in an embodiment of the present application;
[0049] Figure 2 A schematic diagram of the structure of a linkage device of a safety protection system provided in an embodiment of the present application;
[0050] Figure 3 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0051] The technical solutions in the embodiments of the present application will be described below in conjunction with the drawings in the embodiments of the present application.
[0052] It should be noted that similar reference numerals and letters represent similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined or explained in subsequent drawings. At the same time, in the description of this application, the terms "first", "second", etc. are only used to distinguish the description and should not be understood as indicating or implying relative importance.
[0053] It's important to note that firewalls and vulnerability scanning tools are two different security systems. Firewalls operate at the network and transport layers, primarily responsible for monitoring and controlling data packets entering and leaving the network. By setting access control lists, they allow or deny network traffic based on pre-defined rules, ensuring that only authorized devices or users can access internal network resources. Vulnerability scanning, on the other hand, is a proactive security measure that simulates attacker behavior to identify potential security vulnerabilities in the system. Even if a network system has a firewall enabled, vulnerability scanning is still necessary to identify potential security issues and implement appropriate remediation measures.
[0054] Currently, firewalls and vulnerability scanning tools play different roles in network security, and there is a lack of a mechanism for them to work together. For example, when a vulnerability scanning tool discovers a new vulnerability, if the firewall's protection policy needs to be adjusted accordingly, the adjustment can only be done manually. This is not only manpower-consuming, but also has poor timeliness in policy adjustments, resulting in low security protection performance of the system.
[0055] In response to the problems existing in the above-mentioned prior art, an embodiment of the present application provides a linkage method for a security protection system, which improves the protection performance of the security protection system by detecting vulnerability scanning data or the protection status information of the firewall, and automatically triggering the linkage protection between the vulnerability scanning tool (the device where it is located) and the firewall according to needs.
[0056] like Figure 1 As shown, the embodiment of the present application provides a linkage method for a security protection system, which may include the following steps:
[0057] S1. When the security protection linkage function of the target system is enabled, the vulnerability scanning data of the target system is monitored in real time.
[0058] It should be noted that the method of the embodiment of the present application can be executed by a linkage control system in a target system. For example, the target system can be a computer device that needs to be protected, and a vulnerability scanning tool is deployed in the target system.
[0059] For example, the security protection linkage function of the target system can be set to an on state or an off state. If it is in the off state, the vulnerability scanning tool and the firewall will work in a normal mode with each performing their respective functions, and there will be no linkage control between the two; if it is in the on state, monitoring or linkage control will be performed according to the status between the two.
[0060] Specifically, when the security protection linkage function of the target system is turned on, the vulnerability scanning data of the target system is monitored in real time. Based on the vulnerability scanning data, the vulnerability scanning status of the target system can be known, including whether there are vulnerabilities and the specific vulnerability information of the discovered vulnerabilities.
[0061] S2. When it is determined based on the vulnerability scanning data that a vulnerability discovery event occurs in the target system, linkage information is generated based on the vulnerability discovery event.
[0062] Specifically, when vulnerability scanning data indicates that a vulnerability has been detected by a vulnerability scanning tool, it is determined that a vulnerability discovery event has occurred in the target system. In this case, corresponding linkage information is generated according to preset rules based on the specific information of the currently detected vulnerability discovery event.
[0063] Exemplarily, the preset rules can be configured to set corresponding linkage operation information according to different vulnerability types, different vulnerability locations, vulnerability severity levels, etc.; after obtaining the corresponding linkage operation information according to the preset rules based on the specific information of the current vulnerability discovery event, the linkage information is assembled based on the currently obtained linkage operation information.
[0064] S3. Send the linkage information to the firewall associated with the target system, so that the firewall obtains the current flow control policy corresponding to the vulnerability discovery event based on the linkage information, updates the local protection policy of the firewall based on the current flow control policy, and performs security protection operations according to the updated protection policy.
[0065] Specifically, after generating the linkage information corresponding to the current vulnerability discovery event, the linkage information can be sent to the firewall associated with the target system. When the firewall receives the linkage information, it can obtain the current flow control policy corresponding to the vulnerability discovery event based on the current linkage information. For example, it can obtain the current flow control policy based on the linkage job information contained in the linkage information.
[0066] It should be noted that the current flow control policy is the flow control rule for the currently detected vulnerability discovery event. Therefore, the firewall can update the protection policy based on the current flow control policy by adding or replacing it on the basis of its own local original protection policy, and then perform security protection operations according to the updated protection policy.
[0067] S4. Obtain protection status information fed back by the firewall in real time, and maintain or switch the enabled state of the security protection linkage function according to the protection status information.
[0068] It should be noted that the firewall can feed back its own protection status information to the linkage control system in the target system in real time. The linkage control system can determine in real time whether to adjust the switch status of the security protection linkage function based on this protection status information.
[0069] Exemplarily, the protection status information may include information about traffic interception performed by the firewall, such as the interception volume, the interception rate (the ratio of the interception volume to the total traffic), and the like.
[0070] It should be noted that by comparing the real-time protection status information with the preset status threshold, the security protection linkage function of the target system can be switched on or off based on the comparison result. It is understandable that when the security protection linkage function of the target system is in the on state, the security protection effect of the target system is relatively strong. Conversely, when the security protection linkage function of the target system is in the off state, the security protection effect of the target system is relatively weak.
[0071] For example, when the security protection linkage function of the target system is in the on state, if it is determined that the interception amount in the past period is lower than the preset interception amount threshold, or the interception rate in the past period is lower than the preset interception rate threshold, it means that the target system is currently in a relatively safe data traffic environment, then the security protection linkage function of the target system can be switched to the off state to save security protection resource consumption; otherwise, the security protection linkage function is maintained in the on state.
[0072] For example, when the security protection linkage function of the target system is in the off state, if it is determined that the interception amount in the past period of time is higher than the preset interception amount threshold, or the interception rate in the past period of time is higher than the preset interception rate threshold, it means that the target system is currently in a more dangerous data traffic environment, then the security protection linkage function of the target system can be switched to the on state to improve the security protection performance; otherwise, the security protection linkage function is maintained in the on state.
[0073] It should be noted that in some embodiments, the on / off state of the security protection linkage function can also be switched according to a preset period. For example, when the security protection linkage function is in the off state and lasts for more than a preset first period, the security protection linkage function is switched from the off state to the on state; when the security protection linkage function is in the on state and lasts for more than a preset second period, the security protection linkage function is switched from the on state to the off state.
[0074] In an embodiment of the present application, by monitoring the vulnerability scanning situation in real time, a linkage message is sent to the associated firewall when a new vulnerability is detected, so that the firewall can synchronize and update the security protection strategy in a timely manner according to the current vulnerability discovery situation, thereby effectively improving the security protection performance of the network system.
[0075] In some possible embodiments, in step S2, generating linkage information based on the vulnerability discovery event may include:
[0076] S201. Obtain the current vulnerability type corresponding to the vulnerability discovery event;
[0077] S202: When it is determined that the current vulnerability type meets the preset linkage condition, generate linkage information based on the vulnerability discovery event.
[0078] It should be noted that after a vulnerability discovery event occurs and before linkage information is generated, it may be first determined whether the vulnerability type corresponding to the current vulnerability discovery event meets the conditions for triggering linkage protection.
[0079] Specifically, based on the detailed vulnerability information of the vulnerability discovery event, the type of vulnerability scanned (current vulnerability type) can be determined; then, it is determined whether the current vulnerability type meets the preset linkage conditions, for example, whether the current vulnerability type is a preset vulnerability type that needs to trigger linkage protection; if so, linkage information is generated based on the vulnerability discovery event; if not, the subsequent execution steps are omitted.
[0080] Based on this, by adding judgment conditions before generating linkage information, it is possible to determine whether to trigger linkage protection operations with the firewall based on the type of current vulnerability, thereby further improving the flexibility of linkage security protection.
[0081] In some possible embodiments, step S3, sending the linkage information to a firewall associated with the target system so that the firewall obtains a current flow control policy corresponding to the vulnerability discovery event based on the linkage information, updates a local protection policy of the firewall based on the current flow control policy, and performs security protection operations according to the updated protection policy, may include:
[0082] S301. Send the linkage information to the firewall associated with the target system so that the firewall obtains the current flow control policy corresponding to the vulnerability discovery event based on the linkage information. When it is determined that the current flow control policy meets the preset protection policy update conditions, the local protection policy of the firewall is updated based on the current flow control policy, and security protection operations are performed according to the updated protection policy.
[0083] It should be noted that after receiving the linkage information and obtaining the current flow control policy, the firewall can first determine whether the current flow control policy meets the preset protection policy update conditions. If so, it will update the local protection policy of the firewall based on the current flow control policy and perform security protection operations according to the updated protection policy.
[0084] Exemplarily, determining whether the current flow control strategy meets the preset protection strategy update conditions may include at least the following methods: 1. Determining whether the current flow control strategy is repeated with the flow control rules of the original protection strategy. If so, it does not meet the preset protection strategy update conditions; otherwise, it meets the preset protection strategy update conditions; 2. Determining whether the current flow control strategy conflicts with the flow control rules of the original protection strategy. If so, it does not meet the preset protection strategy update conditions; otherwise, it meets the preset protection strategy update conditions.
[0085] Based on this, by configuring judgment conditions on the firewall and first judging whether the current flow control policy meets the conditions before updating the local protection policy, the reliability and flexibility of the linkage security protection can be further improved.
[0086] In some possible embodiments, in step S2, generating linkage information based on the vulnerability discovery event may include:
[0087] S211, obtaining current vulnerability information corresponding to the vulnerability discovery event, generating a current flow control policy corresponding to the current vulnerability information, and assembling linkage information based on the current flow control policy;
[0088] Step S3, sending the linkage information to the firewall associated with the target system, so that the firewall obtains the current flow control policy corresponding to the vulnerability discovery event based on the linkage information, updates the local protection policy of the firewall based on the current flow control policy, and performs security protection operations according to the updated protection policy, which may include:
[0089] S311. Send the linkage information to the firewall associated with the target system so that the firewall obtains the current flow control policy in the linkage information, updates the local protection policy of the firewall based on the current flow control policy, and performs security protection operations according to the updated protection policy.
[0090] It should be noted that when a vulnerability discovery event occurs in the target system, the specific information of the vulnerability discovery event (current vulnerability information) can be obtained based on the vulnerability scanning data. Then, the current flow control policy corresponding to the current vulnerability information can be generated directly on the target system side according to the preset policy generation rules based on the current vulnerability information, and the linkage information can be assembled based on the current flow control policy.
[0091] In this way, when the firewall receives the linkage information, it can directly obtain the current flow control policy generated by the target system side from the linkage information, thereby saving the computing resources of the firewall device and further improving the flexibility of the firewall linkage.
[0092] In some possible embodiments, in step S2, generating linkage information based on the vulnerability discovery event may include:
[0093] S221. Obtain current vulnerability information corresponding to the vulnerability discovery event, and assemble linkage information based on the current vulnerability information;
[0094] Step S3, sending the linkage information to the firewall associated with the target system, so that the firewall obtains the current flow control policy corresponding to the vulnerability discovery event based on the linkage information, updates the local protection policy of the firewall based on the current flow control policy, and performs security protection operations according to the updated protection policy, which may include:
[0095] S321. Send the linkage information to the firewall associated with the target system so that the firewall obtains the current vulnerability information in the linkage information, generates a current flow control policy corresponding to the current vulnerability information, updates the local protection policy of the firewall based on the current flow control policy, and performs security protection operations according to the updated protection policy.
[0096] It should be noted that, in addition to generating a current flow control policy corresponding to the current vulnerability information on the target system side, a current flow control policy corresponding to the current vulnerability information may also be generated on the firewall device side.
[0097] Specifically, policy generation rules can be configured on the firewall device side. When a vulnerability discovery event occurs in the target system, the original vulnerability information (current vulnerability information) of the vulnerability discovery event can be directly assembled into linkage information; when the firewall receives the current vulnerability information contained in the linkage information, it can generate the current flow control policy corresponding to the current vulnerability information according to the policy generation rules configured locally on the firewall.
[0098] In this way, by configuring the policy generation rules on the firewall device side, the policy generation rules can be adaptively set and adjusted according to the characteristics of the firewall device, thereby improving the reliability and flexibility of generating the current flow control policy.
[0099] In some possible embodiments, the linkage method of the security protection system may further include the steps of:
[0100] S501, real-time monitoring of vulnerability repair data of the target system;
[0101] S502: When it is determined based on the vulnerability repair data that a vulnerability repair event occurs in the target system, generate second linkage information based on the vulnerability repair event;
[0102] S503. Send the second linkage information to the firewall associated with the target system, so that the firewall obtains the target flow control policy corresponding to the vulnerability repair event based on the second linkage information, updates the local protection policy of the firewall by eliminating the target flow control policy, and performs security protection operations according to the updated protection policy.
[0103] It should be noted that in addition to real-time monitoring of the target system's vulnerability scanning status (discovery of new vulnerabilities), the target system's vulnerability repair status can also be monitored in real time, and the firewall's linkage protection strategy can be streamlined in a timely manner based on the vulnerability repair status.
[0104] Specifically, real-time monitoring of the target system's vulnerability remediation data reveals information such as the identity / name of the vulnerability being remediated, the progress of the remediation, and other information. Determining a vulnerability remediation event on the target system based on the vulnerability remediation data refers to determining, based on the vulnerability remediation data, that a specific vulnerability or vulnerabilities have been successfully remediated on the target system.
[0105] When it is determined that a vulnerability repair event occurs in the target system, second linkage information may be generated based on the currently occurring vulnerability repair event.
[0106] For example, similar to generating linkage information based on vulnerability discovery events, current vulnerability information corresponding to the vulnerability repair event (currently repaired vulnerability) can also be obtained when generating the second linkage information. According to the same policy generation rules, a target flow control policy corresponding to the vulnerability repair event is generated based on the current vulnerability information (it can also be the current flow control policy corresponding to the current vulnerability information). The difference is that when generating linkage information based on vulnerability discovery events, the purpose is to enable the firewall to add / replace the current flow control policy to the original protection policy according to the linkage information, while the purpose of generating the second linkage information based on the vulnerability repair event is to enable the firewall to remove the target flow control policy from the original protection policy according to the second linkage information. It can be understood that the above two processes are inverse processes of each other.
[0107] In this way, by real-time monitoring of the repair status of discovered vulnerabilities and sending a second linkage message to the firewall based on the repaired vulnerability information, the firewall can promptly streamline the target protection strategy corresponding to the repaired vulnerability, thereby further improving the flexibility of security protection.
[0108] In some possible embodiments, the linkage method of the security protection system may further include the steps of:
[0109] S601, obtaining in real time traffic interception information fed back by a firewall associated with a target system;
[0110] S602: If it is determined based on the traffic interception information that the target system meets the preset policy adjustment conditions, determine the target vulnerability type that currently requires increased attention based on the traffic interception information;
[0111] S603: Adjust vulnerability scanning rules of the target system based on the target vulnerability type.
[0112] It should be noted that, similar to the protection status information, traffic interception information is also used to characterize the situation of traffic interception by the firewall, such as the interception volume (over a period of time), interception rate (the ratio of interception volume to total traffic), etc.
[0113] Specifically, by obtaining real-time traffic interception information from the firewall, it is possible to determine whether the target system meets the preset policy adjustment conditions. For example, if the interception volume over the past period is higher than a preset interception volume threshold, or if the interception rate over the past period is higher than a preset interception rate threshold, it indicates that the target system is currently in a relatively dangerous network environment and is determined to meet the preset policy adjustment conditions.
[0114] If it is determined that the target system meets the preset policy adjustment conditions, the target vulnerability type that currently requires increased attention is determined based on the traffic interception information. For example, information such as the traffic type and protocol type of the currently intercepted traffic can be obtained based on the traffic interception information. A preset type comparison table can be used to determine the target vulnerability type (the vulnerability type that currently requires increased attention) corresponding to the traffic type / protocol type of the currently intercepted traffic.
[0115] Based on the target vulnerability type, the vulnerability scanning rules for the target system can be adjusted accordingly. For example, the scanning frequency of the vulnerability scanning rules for the target vulnerability type can be increased, for example, from once a day to twice a day. For example, the scanning scope of the vulnerability scanning rules for the target vulnerability type can also be increased, for example, from only scanning key areas / key files / key data objects to scanning all areas / files / data objects in the target system.
[0116] Based on this, by monitoring the traffic interception information fed back by the firewall in real time, and determining the target vulnerability types that need to be focused on based on the traffic interception information, the leakage scanning rules of the target vulnerability types can be adjusted to further improve the security protection performance of the network system.
[0117] Please refer to Figure 2 , Figure 2 The following is a block diagram showing the composition of the linkage device of the security protection system provided by some embodiments of the present application. It should be understood that the linkage device of the security protection system is similar to the above-mentioned Figure 1Corresponding to the method embodiment, each step involved in the above method embodiment can be executed. The specific functions of the linkage device of the safety protection system can be found in the description above. To avoid repetition, the detailed description is appropriately omitted here.
[0118] Figure 2 The linkage device of the safety protection system includes at least one software function module that can be stored in a memory in the form of software or firmware or solidified in the linkage device of the safety protection system, and the linkage device of the safety protection system includes:
[0119] The data monitoring module 210 is used to monitor the vulnerability scanning data of the target system in real time when the security protection linkage function of the target system is enabled;
[0120] An information generation module 220 is configured to generate linkage information based on a vulnerability discovery event when it is determined based on the vulnerability scanning data that a vulnerability discovery event has occurred in the target system;
[0121] An information sending module 230 is configured to send the linkage information to a firewall associated with the target system, so that the firewall obtains the current flow control policy corresponding to the vulnerability discovery event based on the linkage information, updates the local protection policy of the firewall based on the current flow control policy, and performs security protection operations according to the updated protection policy;
[0122] The feedback adjustment module 240 is used to obtain the protection status information fed back by the firewall in real time, and maintain or switch the activation state of the security protection linkage function according to the protection status information.
[0123] It can be understood that the above-mentioned device embodiment corresponds to the method embodiment of the present invention. The linkage device of the security protection system provided by the embodiment of the present invention can realize the linkage method of the security protection system provided by any method embodiment of the present invention.
[0124] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working process of the device described above can refer to the corresponding process in the aforementioned method, and will not be described in detail here.
[0125] like Figure 3 As shown, some embodiments of the present application provide an electronic device 300, which includes: a memory 310, a processor 320, and a computer program stored on the memory 310 and executable on the processor 320, wherein the processor 320 reads the program from the memory 310 through the bus 330 and executes the program to implement a method of any embodiment included in the linkage method of the above-mentioned security protection system.
[0126] Processor 320 can process digital signals and can include various computing architectures, such as a complex instruction set computer architecture, a reduced instruction set computer architecture, or an architecture that implements a combination of multiple instruction sets. In some examples, processor 320 can be a microprocessor.
[0127] The memory 310 can be used to store instructions executed by the processor 320 or data related to the execution of instructions. These instructions and / or data may include code for implementing some or all functions of one or more modules described in the embodiments of this application. The processor 320 of the embodiment of the present disclosure can be used to execute the instructions in the memory 310 to implement the method shown above. The memory 310 includes dynamic random access memory, static random access memory, flash memory, optical memory, or other memory known to those skilled in the art.
[0128] Some embodiments of the present application further provide a computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a processor, the method described in the method embodiment is executed.
[0129] Some embodiments of the present application further provide a computer program product, which, when running on a computer, enables the computer to execute the method described in the method embodiment.
[0130] It should be noted that the various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. Similarities between the various embodiments can be referred to in conjunction with each other. For device embodiments, since they are generally similar to method embodiments, their description is relatively simple, and for relevant details, reference can be made to the description of the method embodiments.
[0131] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can also be implemented in other ways. The device embodiments described above are merely illustrative. For example, the flowcharts and block diagrams in the accompanying drawings show the possible architectures, functions, and operations of the devices, methods, and computer program products according to the multiple embodiments of the present application. In this regard, each box in the flowchart or block diagram can represent a module, a program segment, or a portion of code, and the module, program segment, or a portion of code contains one or more executable instructions for implementing the specified logical functions. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in an order different from that marked in the accompanying drawings. For example, two consecutive boxes can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flowchart, and the combination of boxes in the block diagram and / or flowchart, can be implemented using a dedicated hardware-based system that performs the specified function or action, or can be implemented using a combination of dedicated hardware and computer instructions.
[0132] In addition, the functional modules in each embodiment of the present application can be integrated together to form an independent part, or each module can exist independently, or two or more modules can be integrated to form an independent part.
[0133] If the functions are implemented in the form of software function modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes a number of instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as USB flash drives, mobile hard drives, read-only memories (ROM), random access memories (RAM), magnetic disks or optical disks.
[0134] The foregoing is merely an embodiment of the present application and is not intended to limit the scope of protection of the present application. Various modifications and variations are possible for those skilled in the art. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present application shall be included within the scope of protection of the present application. It should be noted that similar reference numerals and letters represent similar items in the following figures. Therefore, once an item is defined in one figure, it does not need to be further defined or explained in subsequent figures.
[0135] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.
[0136] It should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply the existence of any such actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article, or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or device. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of other identical elements in the process, method, article, or device comprising the element.
Claims
1. A linkage method for a safety protection system, characterized in that: include: When the security protection linkage function of the target system is enabled, the vulnerability scanning data of the target system is monitored in real time; In a case where it is determined based on the vulnerability scanning data that a vulnerability discovery event occurs in the target system, generating linkage information based on the vulnerability discovery event; Sending the linkage information to a firewall associated with the target system, so that the firewall obtains a current flow control policy corresponding to the vulnerability discovery event based on the linkage information, updates a local protection policy of the firewall based on the current flow control policy, and performs security protection operations according to the updated protection policy; Acquire protection status information fed back by the firewall in real time, and maintain or switch the activation state of the security protection linkage function according to the protection status information; The method also includes: obtaining in real time traffic interception information fed back by a firewall associated with the target system; determining, based on the traffic interception information, that the target system meets preset policy adjustment conditions, the target vulnerability type that currently requires increased attention based on the traffic interception information; and adjusting vulnerability scanning rules for the target system based on the target vulnerability type, wherein the traffic interception information is used to characterize the situation of traffic interception by the firewall, including the interception amount and interception rate.
2. The linkage method of the safety protection system according to claim 1, characterized in that: Generating linkage information based on the vulnerability discovery event includes: Obtain the current vulnerability type corresponding to the vulnerability discovery event; When it is determined that the current vulnerability type meets the preset linkage condition, linkage information is generated based on the vulnerability discovery event.
3. The linkage method of the safety protection system according to claim 1, characterized in that: The step of sending the linkage information to a firewall associated with the target system so that the firewall obtains a current flow control policy corresponding to the vulnerability discovery event based on the linkage information, updates a local protection policy of the firewall based on the current flow control policy, and performs security protection operations according to the updated protection policy, including: The linkage information is sent to the firewall associated with the target system, so that the firewall obtains the current flow control policy corresponding to the vulnerability discovery event based on the linkage information; when it is determined that the current flow control policy meets the preset protection policy update conditions, the local protection policy of the firewall is updated based on the current flow control policy, and security protection operations are performed according to the updated protection policy.
4. The linkage method of the safety protection system according to claim 1, characterized in that: Generating linkage information based on the vulnerability discovery event includes: Obtaining current vulnerability information corresponding to the vulnerability discovery event, generating a current flow control strategy corresponding to the current vulnerability information, and assembling based on the current flow control strategy to obtain the linkage information; The step of sending the linkage information to a firewall associated with the target system so that the firewall obtains a current flow control policy corresponding to the vulnerability discovery event based on the linkage information, updates a local protection policy of the firewall based on the current flow control policy, and performs security protection operations according to the updated protection policy, including: The linkage information is sent to the firewall associated with the target system so that the firewall obtains the current flow control policy in the linkage information, updates the local protection policy of the firewall based on the current flow control policy, and performs security protection operations according to the updated protection policy.
5. The linkage method of the safety protection system according to claim 1, characterized in that: Generating linkage information based on the vulnerability discovery event includes: Obtaining current vulnerability information corresponding to the vulnerability discovery event, and assembling the linkage information based on the current vulnerability information; The step of sending the linkage information to a firewall associated with the target system so that the firewall obtains a current flow control policy corresponding to the vulnerability discovery event based on the linkage information, updates a local protection policy of the firewall based on the current flow control policy, and performs security protection operations according to the updated protection policy, including: The linkage information is sent to the firewall associated with the target system so that the firewall obtains the current vulnerability information in the linkage information, generates a current flow control policy corresponding to the current vulnerability information, updates the local protection policy of the firewall based on the current flow control policy, and performs security protection operations according to the updated protection policy.
6. The linkage method of the safety protection system according to claim 1, characterized in that: Also includes: Real-time monitoring of vulnerability repair data of the target system; In a case where it is determined based on the vulnerability repair data that a vulnerability repair event occurs in the target system, generating second linkage information based on the vulnerability repair event; The second linkage information is sent to the firewall associated with the target system, so that the firewall obtains the target flow control policy corresponding to the vulnerability repair event based on the second linkage information, updates the local protection policy of the firewall by eliminating the target flow control policy, and performs security protection operations according to the updated protection policy.
7. An electronic device, characterized in that: It includes a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, it can implement the linkage method of the security protection system described in any one of claims 1-6.
8. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the linkage method of the security protection system according to any one of claims 1 to 6 is executed.
9. A computer program product, characterized in that The computer program product includes a computer program, and when the computer program is executed by a processor, the linkage method of the security protection system according to any one of claims 1 to 6 is implemented.
Citation Information
Patent Citations
Network safety protection method, equipment and system thereof
CN102523218A
Information management method and system based on network security
CN119728287A