Network device optimization method and apparatus, computer device and storage medium
By identifying and optimizing policy relationships in network devices and merging or deleting redundant policies, the problem of low network device management efficiency is solved, and efficient and accurate network device optimization is achieved.
Patent Information
- Application Number
- CN202511013488.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-23
- Publication Date
- 2025-10-10
- Estimated Expiration
- 2045-07-23
AI Technical Summary
Existing network equipment optimization methods have low management efficiency and it is difficult to improve management efficiency while ensuring management accuracy.
By obtaining the policy action, policy virtual wall and communication quintuple information in the network security policy table, the network security policy group with policy relationship is determined, and the policy table is optimized based on this information, including merging and deleting redundant policies, and constructing an optimized network security policy table, and finally optimizing the target network device.
It achieves accurate optimization of network security strategies without human intervention, improves management efficiency, and ensures management accuracy.
Smart Images

Figure CN120528701B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of network security, and in particular to a network device optimization method and device, computer equipment and a storage medium. BACKGROUND
[0002] With the expansion of the network and the scale of business, the security policy configured on the device based on network security has exploded, which easily reaches the upper limit of the device capacity, accompanied by a decline in device performance, causing great distress to network operation and security operation. To solve the above problems, the operation and maintenance personnel face thousands of policies in the traditional manual way, and the combing and optimization work is not easy. The existing network device optimization method has the problem of low management efficiency.
[0003] Therefore, how to provide a network device optimization method that guarantees management accuracy while taking into account management efficiency has become a problem to be solved. SUMMARY
[0004] Therefore, it is necessary to provide a network device optimization method, device, computer equipment and storage medium to solve the problem of low management efficiency and accuracy of the traditional method.
[0005] A network device optimization method, the method comprising:
[0006] Obtaining a network security policy table of a target network device, the network security policy table including at least one network security policy, each network security policy including a policy action, a policy virtual wall and communication quintuple information;
[0007] Based on the policy action, the policy virtual wall and the communication quintuple information, determining a network security policy group with a policy relationship in the network security policy table;
[0008] Optimizing the network security policy table based on the policy relationship of the network security policy group to obtain an optimized network security policy table;
[0009] Optimizing the target network device based on the optimized network security policy table to obtain an optimized target network device.
[0010] Optionally, before obtaining the network security policy table of the target network device, the method further comprises:
[0011] Logging into the target network device through a preset protocol to obtain configuration information of the target network device;
[0012] Extracting at least one group of security policy information from the configuration information;
[0013] Format the security policy information in each group uniformly to obtain a network security policy corresponding to each group of security policy information;
[0014] Based on the network security policy, a network security policy table of the target network device is constructed.
[0015] Optionally, the network security policy table of the target network device is constructed based on the network security policy, including:
[0016] Obtain the hit number information of each network security policy;
[0017] Based on the hit number information, determine the adding order of each network security policy;
[0018] According to the adding order, the network security policies are added to a preset empty table in sequence to obtain the network security policy table.
[0019] Optionally, based on the policy action, the policy virtual wall, and the communication five tuple information, the network security policy group with a policy relationship in the network security policy table is determined, including:
[0020] In the network security policy table, at least two network security policies with the same policy action and policy virtual wall are determined as a network security policy group to be processed;
[0021] Based on the communication five tuple information, the network security policy with a policy relationship in the network security policy group to be processed is determined as the network security policy group.
[0022] Optionally, the communication five tuple information includes source address, destination address, and protocol port information, and based on the communication five tuple information, the network security policy with a policy relationship in the network security policy group to be processed is determined as the network security policy group, including:
[0023] If the source address, destination address, and protocol port information of a first network security policy in the network security policy group to be processed all contain the source address, destination address, and protocol port information of a second network security policy in the network security policy group to be processed, the policy relationship between the first network security policy and the second network security policy is a containing relationship;
[0024] If any two of the source address, the destination address and the protocol port information of the first network security policy in the group of network security policies to be processed are the same as any two of the source address, the destination address and the protocol port information of the second network security policy in the group of network security policies to be processed, and the policy relationship between the first network security policy and the second network security policy is not the containing relationship, the policy relationship between the first network security policy and the second network security policy is the merging relationship.
[0025] Optionally, the policy relationship is the containing relationship or the merging relationship, the network security policy further comprises security domain information and a policy name, and the optimization processing of the network security policy table based on the policy relationship of the group of network security policies comprises:
[0026] In the network security policy table, a group of network security policies with the containing relationship is determined, a network security policy with a smaller policy coverage range is determined in the group of network security policies, and a deletion mark is added to the network security policy with the smaller policy coverage range in the network security policy table, so as to obtain a network security policy table to be merged;
[0027] In the network security policy table to be merged, a group of network security policies with the merging relationship is determined, and the network security policies in the group of network security policies are merged in the network security policy table to be merged, so as to obtain the optimized network security policy table, and the merging processing comprises merging and deduplicating the policy action, the policy virtual wall, the communication five-tuple information and the security domain information, and retaining the policy name with a higher ranking.
[0028] Optionally, the method further comprises:
[0029] obtaining hit number information of each of the network security policies;
[0030] adding a zero hit mark to the network security policy with the hit number information of zero in the optimized network security policy table;
[0031] if the hit number information corresponding to the network security policy with the zero hit mark is not zero within a preset time, the zero hit mark is removed in the optimized network security policy table;
[0032] if the hit number information corresponding to the network security policy with the zero hit mark is still zero after the preset time ends, a deletion mark is added to the network security policy with the zero hit mark in the optimized network security policy table.
[0033] A network device optimization apparatus, the apparatus comprising:
[0034] a first obtaining module, configured to obtain a network security policy table of a target network device, the network security policy table comprising at least one network security policy, each network security policy comprising a policy action, a policy virtual wall, and communication quintuple information;
[0035] a first determining module, configured to determine, based on the policy action, the policy virtual wall, and the communication quintuple information, a network security policy group with policy relationship in the network security policy table;
[0036] a first optimization module, configured to perform optimization processing on the network security policy table based on the policy relationship of the network security policy group, to obtain an optimized network security policy table;
[0037] a second optimization module, configured to perform optimization processing on the target network device based on the optimized network security policy table, to obtain an optimized target network device.
[0038] A computer device comprising a memory, a processor, and computer readable instructions stored in the memory and executable on the processor, the processor implementing the network device optimization method when executing the computer readable instructions.
[0039] A readable storage medium having computer readable instructions stored thereon, the computer readable instructions being executable by a processor to implement the network device optimization method.
[0040] The network device optimization method, device, computer device and storage medium, comprising: obtaining a network security policy table of a target network device, the network security policy table comprising at least one network security policy, each network security policy comprising a policy action, a policy virtual wall and communication quintuple information; determining a network security policy group having a policy relationship in the network security policy table based on the policy action, the policy virtual wall and the communication quintuple information; performing optimization processing on the network security policy table based on the policy relationship of the network security policy group to obtain an optimized network security policy table; and performing optimization processing on the target network device based on the optimized network security policy table. The policy action, the policy virtual wall and the communication quintuple information can be used to accurately determine the network security policy group having a policy relationship in the network security policy table, and the network security policy table can be optimized based on the policy relationship to obtain an optimized network security policy table. The target network device can be optimized based on the optimized network security policy table, which can effectively sort and optimize the network security policy of the target network device. Since no human intervention is required throughout the process, the management accuracy is ensured, and the management efficiency is effectively improved. BRIEF DESCRIPTION OF DRAWINGS
[0041] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following will briefly introduce the drawings needed to be used in the description of the embodiments of the present application. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor.
[0042] Figure 1 is a flow diagram of a network device optimization method provided by an embodiment of the present application;
[0043] Figure 2 is a flow diagram of a second network device optimization method provided by an embodiment of the present application;
[0044] Figure 3 is a flow diagram of a third network device optimization method provided by an embodiment of the present application;
[0045] Figure 4 is a structural diagram of a network device optimization device provided by an embodiment of the present application;
[0046] Figure 5 is a schematic diagram of a computer device provided by an embodiment of the present application. DETAILED DESCRIPTION
[0047] With reference to the accompanying drawings, the technical solutions in the embodiments of the present application will be described clearly and completely. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments of the present application. Based on the embodiments of the present application, all the other embodiments obtained by those of ordinary skill in the art without creative work fall within the scope of the present application.
[0048] In an embodiment, as shown in Figure 1 A network device optimization method is provided, comprising the following steps:
[0049] 101. Obtain a network security policy table of a target network device.
[0050] In the embodiments of the present application, the network device optimization method described above can be applied to a network device optimization platform, and the network device optimization platform can be constructed by a server or a server cluster. The server or the server cluster can be any electronic device with functions of data processing, data analysis, data transmission, data storage, etc. The network device optimization platform can communicate with any network device through the data transmission function, and then implement the network device optimization method to optimize the network device.
[0051] The target network device can be any network device that can be communicatively connected to the network device optimization platform. Specifically, it can be a device with functions of network data flow control, protection, detection and audit, used to realize the security management and policy execution of network communication behavior. Typical network devices include, but are not limited to, firewalls, intrusion detection and prevention systems (IDS / IPS), unified threat management devices (UTM), next-generation firewalls (NGFW), security gateways, security proxy devices, virtual firewalls, and intelligent switches or security routers with access control capabilities, etc. By configuring security policies, network devices can accurately identify and control different sources, targets and communication behaviors, prevent illegal access, data leakage and network attacks, and ensure the safe and stable operation of the network environment.
[0052] The network security policy table includes at least one network security policy, each network security policy includes a policy action, a policy virtual wall, and communication quintuple information, and can further include a policy name and security domain information. The order of the policy name can be set according to the hit number of the network security policy. The more the hit number is, the higher the order is. The less the hit number is, the lower the order is. The security domain information can include a source security domain and a destination security domain. The policy action can be a processing behavior performed by the network security policy after matching a specific communication condition (such as communication quintuple information). Common policy actions include allowing, rejecting, recording, redirecting, and the like, which are used to control the processing mode of a data packet in a network device. The policy virtual wall can be a policy scope or a policy container used for logical classification and isolation of network security policies. It usually represents different security domains, security area pairs, or policy configuration sets in a network device, so as to establish a structured management relationship between different policy instances, and realize fine control and matching analysis of policy rules.
[0053] The communication quintuple information includes a source address, a destination address, and protocol port information. The protocol port information can include communication protocol and port information. The port information can include a source port and a destination port.
[0054] The target network device can be any network device that needs to be optimized for network security policies. The brand of the target network device can be any brand. The configuration information of the target network device can be obtained by logging in the target network device through a preset protocol. Then, a plurality of network security policies can be parsed from the configuration information, and the network security policy table can be constructed according to the plurality of network security policies.
[0055] 102. Based on the policy action, the policy virtual wall, and the communication quintuple information, determine a network security policy group with a policy relationship in the network security policy table.
[0056] In the embodiment of the application, the policy relationship can be a containing relationship or a merging relationship. The merging relationship can be simply understood as an intersection between network security policies, but not exactly the same. The containing relationship can be understood as one policy containing all information of another network security policy. The network security policy group with a policy relationship includes at least two network security policies with a policy relationship.
[0057] Specifically, the containing relationship of the policy can be defined as follows: under the premise that the values of the policy virtual wall and the policy action are completely the same, if the source address, the destination address, and the service range of a policy A completely cover the source address, the destination address, and the service range of another policy B, respectively, then the policy A contains the policy B.
[0058] Correspondingly, the merging relationship of the policies can be defined as: on the premise that the "policy virtual wall" and "policy action" values are completely same, if two of the source address, destination address and service range of a policy A completely cover two of the source address, destination address and service range of another policy B, then the policy A and the policy B are in the merging relationship.
[0059] It should be noted that the service range can be understood as the protocol port information, and the service ranges are same, that is, the protocol port information between the two policies is same.
[0060] 103. The network security policy table is optimized based on the policy relationship of the network security policy group, and an optimized network security policy table is obtained.
[0061] In the embodiment of the application, the policy relationship is a merging relationship or a containing relationship, and when the policy relationship of the network security policy group is a containing relationship, the policy with a large range is retained, and the policy with a small range is marked for deletion; for the policy marked for deletion, all subsequent comparisons are not performed.
[0062] When the policy relationship of the network security policy group is a merging relationship, it is indicated that two of the source address, destination address and service range are same, so the remaining different one can be merged, and the "source security domain" and "destination security domain" information of the network security policies in the network security policy group are merged and de-duplicated to obtain a merged policy, and finally the positions of the two network security policies in the policy table are compared, the policy in the front is modified as the merged policy, and the other one is marked for deletion. Correspondingly, for the two policies that cannot be merged, the original data is retained.
[0063] By traversing the policy relationship of the network security policy group in the network security policy table and performing corresponding marking deletion, modification and other optimization processing through the policy relationship, after the optimization processing of all network security policy groups with the policy relationship is completed, the optimized network security policy table can be obtained.
[0064] In another embodiment, for each network security policy, the source address and the destination address can also be merged in the policy; that is, if multiple address elements belong to the same network segment and are continuous in one address set, the address merging is performed.
[0065] 104. The target network device is optimized based on the optimized network security policy table, and an optimized target network device is obtained.
[0066] In the embodiment of the present application, after the above-mentioned optimized network security policy table is obtained, the above-mentioned target network device can be logged in. Specifically, the configuration information in the above-mentioned target network device can be first modified according to the modification and marked deletion processing corresponding to the network security policy groups with a merge relationship in the above-mentioned optimized network security policy table, and then the configuration information in the above-mentioned target network device can be secondly modified according to the marked deletion processing corresponding to the network security policy groups with a containing relationship. After all the policy relationships are completed, the above-mentioned optimized target network device can be obtained.
[0067] In the embodiment of the present application, a network security policy table of a target network device is obtained, the network security policy table includes at least one network security policy, each network security policy includes a policy action, a policy virtual wall, and communication quintuple information; based on the policy action, the policy virtual wall, and the communication quintuple information, network security policy groups with policy relationships in the network security policy table are determined; the network security policy table is optimized based on the policy relationships of the network security policy groups, and an optimized network security policy table is obtained; and the target network device is optimized based on the optimized network security policy table, and an optimized target network device is obtained. Through the policy action, the policy virtual wall, and the communication quintuple information, network security policy groups with policy relationships in the network security policy table can be accurately determined, and then the network security policy table can be optimized based on the policy relationships, and an optimized network security policy table is obtained. The target network device is optimized based on the optimized network security policy table, which can effectively sort and optimize the network security policy of the target network device. At the same time, since no human intervention is required throughout the process, the management accuracy is guaranteed, and the management efficiency is effectively improved.
[0068] It can be understood that in the specific embodiments of the present application, data related to network security policy tables, policy names, policy actions, policy virtual walls, communication quintuple information, security domain information, configuration information, security policy information, hit number information, etc. are involved. When the embodiments in the present application are applied to specific products or technologies, the user's permission or consent needs to be obtained, and the collection, use, and processing of related data, as well as the related processing of network device protocols, login, optimization, etc. need to comply with relevant laws, regulations, and standards of relevant countries and regions.
[0069] Optionally, before the step of obtaining the network security policy table of the target network device, the target network device can be logged in through a preset protocol to obtain configuration information of the target network device; at least one set of security policy information is extracted from the configuration information; each set of security policy information is subjected to format uniform processing to obtain a network security policy corresponding to each set of security policy information; and the network security policy table of the target network device is constructed based on the network security policy.
[0070] In the embodiment of the application, the preset protocol can be an ssh protocol. Specifically, the ssh protocol can be used to log in the target network device to obtain complete configuration information, which is usually saved in a txt file format. Security policy information can be extracted from the configuration information, which can specifically include address group, address object, port group, port object information, security policy, ACL information, etc.
[0071] Further, the address group, address object, port group, and port object contained in the security policy and ACL can be parsed into IP addresses or ports, and the key data contained in the policy can be formatted to form a unified data format for the difference data of multiple brands.
[0072] For example, part of the configuration of a certain brand of firewall is as follows:
[0073] Virtual wall:
[0074] switch vsys GDYDXWJ
[0075] Address object configuration:
[0076] ip address-set zxfw_dmz_184 type object
[0077] address 0 range 172.17.20.65 172.17.20.67
[0078] address 1 172.17.20.36 0
[0079] Port object configuration:
[0080] ip service-set tcp_d_eq_20011 type object
[0081] service 0 protocol tcp destination-port 20011
[0082] Security policy configuration:
[0083] rule name 1749_563
[0084] description dmz_to_untrust dmz_untrust_outbound
[0085] source-zone dmz
[0086] destination-zone untrust
[0087] source-address address-set zxfw_dmz_184
[0088] destination-address 117.159.206.246 mask 255.255.255.255
[0089] service tcp_d_eq_20011
[0090] action permit
[0091] After parsing the above information, we get a set of security policy information:
[0092] rule name 1749_563
[0093] description dmz_to_untrust dmz_untrust_outbound
[0094] source-zone dmz
[0095] destination-zone untrust
[0096] source-address range 172.17.20.65 172.17.20.67
[0097] source-address 172.17.20.36 mask 255.255.255.255
[0098] destination-address 117.159.206.246 mask 255.255.255.255
[0099] service protocol tcp destination-port 20011
[0100] action permit
[0101] The security policy information of each group is uniformly formatted, and the network security policy corresponding to each group of security policy information is obtained. Specifically, the key data can be formatted, so that the difference data of different brands of network devices form a unified data format.
[0102] The above-mentioned uniform data format can be exemplarily illustrated by the uniform format network security policy provided in Table One:
[0103] Table One
[0104]
[0105] Among them, "1749_563" represents the name of the network security policy, "dmz" represents the source security domain of the network security policy, "untrust" represents the destination security domain of the network security policy, "172.17.20.65-64 172.17.20.36" represents the source address of the network security policy, "117.159.206.246" represents the destination address of the network security policy, "tcp: 20011" represents the service range of the network security policy, that is, the above-mentioned protocol port information, "permit" represents the policy action of the network security policy, and "GDYDXWJ" represents the policy virtual wall of the network security policy. Specifically, a plurality of the above network security policies are collected to construct the network security policy table.
[0106] It can be understood that the uniform data format makes the network device optimization method provided by the application applicable to different types and different brands of network devices.
[0107] Optionally, in the step of constructing the network security policy table of the target network device based on the network security policy, the hit number information of each network security policy can also be obtained; based on the hit number information, the adding order of each network security policy is determined; and the network security policy is added to the preset empty table in sequence according to the adding order, to obtain the network security policy table.
[0108] In the embodiment of the application, the above-mentioned hit number information can be understood as the matching statistical result of each network security policy in the running process of the network device, which is used to reflect the number of times that the policy is triggered or hit in the actual communication traffic. The hit number information can represent the activity or frequency of the policy to a certain extent, thereby providing data support for subsequent policy sorting and optimization processing. Through the acquisition and analysis of the hit number information, the adding order of each network security policy in the policy table can be determined, so that the high-frequency hit policy is arranged in priority, the policy matching efficiency is improved, and the influence of invalid policies on the system performance is avoided.
[0109] Optionally, in the step of determining the network security policy group with policy relationship in the network security policy table based on the policy action, the policy virtual wall and the communication five tuple information, at least two network security policies with the same policy action and policy virtual wall in the network security policy table can be determined as the network security policy group to be processed; and the network security policy with policy relationship in the network security policy group to be processed can be determined as the network security policy group based on the communication five tuple information.
[0110] In the embodiment of the present application, the policy relationship is used to describe the logical association of two network security policies in the communication control range, and can specifically include the containing relationship or the merging relationship. When the policy action and the policy virtual wall of at least two network security policies are the same, the at least two network security policies are determined as the network security policy group to be processed, and the communication five tuple information (including the source address, the destination address, the source port, the destination port and the communication protocol) corresponding to the network security policy group to be processed is compared and analyzed. If the communication five tuple information of one policy completely contains the communication five tuple information of another policy, the containing relationship exists between the two policies. If the two policies partially overlap and the control boundary can be merged to form a more extensive but non-conflicting control boundary, the merging relationship exists between the two policies. The identification of the policy relationship provides a basis for the subsequent policy optimization operations such as the policy de-duplication and the rule merging, and helps to improve the overall efficiency and manageability of the network security policy table.
[0111] It should be noted that when the communication five tuple information of one network security policy completely contains the communication five tuple information of multiple other policies, the containing relationship exists between the policy and the multiple policies. At this time, the above policy set can be defined as the network security policy group with the containing relationship, and the number of members depends on the number of policy entries satisfying the containing relationship. When only one policy completely contains another policy, the network security policy group with the containing relationship contains two policies. Similarly, for the network security policy group with the merging relationship, if two or more policies satisfy the merging condition, they can be grouped together. The number of members of the policy group also depends on the number of policies satisfying the merging relationship condition. Therefore, the number of policies in the containing relationship group and the merging relationship group is determined by the number of policy entries actually satisfying the corresponding policy relationship.
[0112] Optionally, in the step of determining the network security policies with policy relationship in the network security policy group to be processed based on the communication five tuple information, if the source address, the destination address and the protocol port information of the first network security policy in the network security policy group to be processed all contain the source address, the destination address and the protocol port information of the second network security policy in the network security policy group to be processed, the policy relationship between the first network security policy and the second network security policy is a containing relationship; if any two of the source address, the destination address and the protocol port information of the first network security policy in the network security policy group to be processed are the same as any two of the source address, the destination address and the protocol port information of the second network security policy in the network security policy group to be processed, and the policy relationship between the first network security policy and the second network security policy is not a containing relationship, the policy relationship between the first network security policy and the second network security policy is a merging relationship.
[0113] In the embodiment of the application, the communication five tuple information at least includes the source address, the destination address and the protocol port information (i.e. the range of the following service, or the service is understood).
[0114] The containing relationship of the source address, the destination address and the service is defined as: for address or service sets a and b, if any element in set a can be contained by an element in set b, set a is contained by set b (or set b contains set a).
[0115] The containing relationship of the address element is defined as: if the address represented by address element c can be contained by the address range represented by address element d, c is contained by d (or d contains c).
[0116] The containing relationship of the service element is defined as: if the combination of the protocol, the source port and the destination port of service element e can be contained by the combination of the protocol, the source port and the destination port of service element f, e is contained by f (or f contains e). That is, the containing relationship of the service can be understood as the containing relationship of the protocol port information.
[0117] The format of the service element (i.e. the format of the protocol port information) can be the format of protocol: source port ~ destination port, that is, e can be written as: tcp: 1-65535 ~ 22; f can be written as: tcp: 1-65535 ~ 22, 2222; and usually, if the port is 1-65535, it can be omitted, that is, e can be written as: tcp: 22; f can be written as: tcp: 22, 2222; if the source port and the destination port are both 1-65535, only the protocol can be written, such as: tcp: 1-65535 ~ 1-65535, which can be written as: tcp.
[0118] The inclusion relationship of the protocol is defined as: IP protocol includes ICMP protocol, TCP protocol of all ports, and UDP protocol of all ports, like any.
[0119] All the inclusion relationships defined above, when compared with two network security policies X and Y, if X = Y, it can be said that X includes Y, and also Y includes X.
[0120] Correspondingly, the merging relationship of source address, destination address, and service is defined as: for address or service sets a and b, if any two elements of the source address, destination address, and service of set a are the same as any two elements of the source address, destination address, and service of b, then a and b are in a merging relationship.
[0121] Further, the above inclusion relationship can be further illustrated by the following examples of inclusion relationship:
[0122] Suppose the network security policy group to be processed contains the following three network security policies provided in Table Two:
[0123] Table Two
[0124]
[0125] Among them, the policy Cloud_840812000 contains another two policies.
[0126] The inclusion relationship of source address, destination address, and service (i.e. protocol port information) is defined as: for address or service sets a and b, if any element in set a can be included by an element in b, then address set a is included by b (or b includes a).
[0127] For example:
[0128] Address set a: 10.250.10.122 / 32; 10.250.10.123 / 32;
[0129] Address set b: 10.250.10.0 / 24;
[0130] In this example, a is included by b;
[0131] The inclusion relationship of address elements is defined as: if the address represented by address element c can be included by the address range represented by address element d, then c is included by d (or d includes c);
[0132] For example:
[0133] Address element c: 10.250.10.122 / 32;
[0134] Address element d: 10.250.10.0 / 24;
[0135] In this example, the address range represented by address element d is 256 addresses of 10.250.10.0-10.250.10.255, and 10.250.10.122 / 32 is contained in d, so c is contained in d;
[0136] The containment relationship of service elements is defined as: if the combination of the protocol, source port, and destination port of service element e is contained in the combination of the protocol, source port, and destination port of service element f, then e is contained in f (or f contains e);
[0137] For example:
[0138] Service element e: protocol tcp, source port 1-655535, destination port 22;
[0139] Service element f: protocol tcp, source port 1-655535, destination port 22, 2222;
[0140] In this example, service element e is contained in service element f;
[0141] It should be noted that service elements can be written in the format of protocol: source port ~ destination port, i.e. e can be written as tcp: 1-65535 ~ 22, and f can be written as tcp: 1-65535 ~ 22, 2222. Usually, if the port is 1-65535, it can be omitted, i.e. e can be written as tcp: 22, and f can be written as tcp: 22, 2222. If the source and destination ports are both 1-65535, only the protocol can be written, such as tcp: 1-65535 ~ 1-65535, which can be written as tcp.
[0142] The containment relationship of protocols is defined as: IP protocol contains ICMP protocol, TCP protocol for all ports, and UDP protocol for all ports, like any;
[0143] For example:
[0144] Service element g: ip (or written as any);
[0145] Service element h: tcp: 100-10000; udp;
[0146] In this example, service element h is contained in service element g;
[0147] All the containment relationships defined above, when comparing two elements X and Y, if X = Y, it can be said that X contains Y, or Y contains X;
[0148] For example:
[0149] X: 10.187.7.128 / 26;
[0150] Y: 10.187.7.128 / 26;
[0151] In this example, X contains Y, and it can also be said that Y contains X.
[0152] Optionally, in the step of optimizing the network security policy table based on the policy relationship of the network security policy group, the network security policy group with a containing relationship in the network security policy table is determined, the network security policy with a smaller policy coverage range in the network security policy group is determined, and a deletion mark is added to the network security policy with a smaller policy coverage range in the network security policy table to obtain a network security policy table to be merged; the network security policy group with a merging relationship in the network security policy table to be merged is determined, and the network security policies in the network security policy group are merged in the network security policy table to be merged to obtain the optimized network security policy table, the merging processing includes merging and deduplication processing of the policy action, the policy virtual wall, the communication five-tuple information and the security domain information, and the policy name with a higher ranking is retained.
[0153] In the embodiment of the application, the policy relationship is a containing relationship or a merging relationship, the network security policy further includes security domain information and a policy name. In the process of optimizing the network security policy table based on the policy relationship of the network security policy group, the different processing modes are preferably performed according to the policy relationship type. First, for the network security policy group with a containing relationship, the communication control range (i.e. the address range, the port range and the protocol type represented by the communication five-tuple information) of one policy is considered to be completely covered by another policy. At this time, in order to reduce redundancy and avoid repeated matching, the network security policy with a smaller policy coverage range can be determined, and a deletion mark is added to it in the policy table. Such a policy will be filtered or removed by the system in the subsequent policy table publishing or deployment process, so as to avoid the waste of execution performance caused by rule overlap.
[0154] Then, in the obtained network security policy table to be merged, further identify the network security policy group with a merging relationship. The merging relationship usually indicates that two policies have a partial intersection or a union set in the fields of source address, destination address, or port range, and their policy actions and policy virtual walls are the same, and have the feasibility of being merged into one wider policy. During the merging process, the policy action, policy virtual wall, communication quintuple information, and security domain information can be merged and de-duplicated, and the top-ranked policy name is retained, so as to merge the two policies into a new policy to replace the original policy pair. Specifically, the network security policy ranked first in the network security policy table in the network security policy group can be replaced, and the network security policy ranked second can be deleted.
[0155] Through the above fine processing corresponding to the inclusion relationship and the merging relationship, redundant policy entries can be effectively eliminated, the policy table volume can be compressed, policy conflicts and matching paths can be reduced, the efficiency and maintainability of the network device when executing the policy can be improved, and the accuracy of policy optimization and business continuity can be ensured.
[0156] It should be noted that the policy coverage range refers to the communication flow range that can be identified and controlled by the communication quintuple information (source address, destination address, source port, destination port, and communication protocol) in the network security policy. The larger the coverage range, the more network data streams the policy can apply to; the smaller the coverage range, the more targeted the control object is.
[0157] Further, the above merging process can be further illustrated by the following examples:
[0158] Suppose that the network security policy group to be processed includes the following two network security policies provided in Table Three:
[0159] Table Three
[0160]
[0161] The two policies in this example can be merged (i.e., the policy relationship is a merging relationship), and after merging, a new policy provided in Table Four is obtained:
[0162] Table Four
[0163]
[0164] After obtaining the above new policy, the network security policy ranked first in the network security policy table in the network security policy group can be replaced.
[0165] In another embodiment, for each network security policy, the source address and the destination address can be merged respectively within the policy; that is, in one address set, if multiple address elements belong to the same network segment and are continuous, address merging is performed. That is, it can be understood as policy-internal merging of a single policy. The policy-internal merging can be further illustrated by the following examples:
[0166] Suppose that the network security policy table contains the network security policies provided in Table Five:
[0167] Table Five
[0168]
[0169] In the source address set of the above network security policy, multiple address elements belong to one network segment and are continuous, so address merging is performed to obtain the optimized network security policy table provided in Table Six:
[0170] Table Six
[0171]
[0172] As can be seen, the address set of the source address in the optimized network security policy table has been subjected to address merging.
[0173] Optionally, the network device optimization method can also obtain the hit number information of each network security policy; add a zero-hit mark to the network security policy with zero hit number information in the optimized network security policy table; if the hit number information corresponding to the network security policy with the zero-hit mark is not zero within a preset time, the zero-hit mark is removed in the optimized network security policy table; if the hit number information corresponding to the network security policy with the zero-hit mark is still zero after the end of the preset time, the network security policy with the zero-hit mark is added with a deletion mark in the optimized network security policy table.
[0174] In the embodiment of the application, the network device optimization method can also obtain the hit number information of each network security policy and evaluate and dynamically manage the policy usage based on the information. The hit number information can be obtained through a web interface or by logging into the target network device using the SSH protocol. The device usually records the number of times each configured network security policy is triggered (i.e., matched) within a certain time window. The hit number information of this type can be extracted through a command or interface call and integrated into the data structure of each network security policy to form a statistical field that can be used for subsequent judgment.
[0175] Further, in the optimized network security policy table, if the hit number information of a certain policy is zero, it is marked as a "zero-hit" state and enters an observation period (such as a preset time of one week). During the observation period, the system continuously monitors the change of the hit number of the policy:
[0176] If the number of hits becomes non-zero in the observation period, it means that the strategy has actually been used, and the "zero hit" label can be automatically removed.
[0177] If the number of hits is still zero after the end of the observation period, it means that the strategy has not been called in the current business scenario, and a "deletion label" can be added to it for policy table refinement.
[0178] This processing mechanism enables the network security policy table to have a "self-cleaning" capability, effectively reducing the number of redundant strategies that exist for a long time but are not actually hit, thereby optimizing the policy matching path and improving the resource utilization and response performance of the network device during operation. At the same time, it avoids the potential business interruption risk caused by blindly deleting non-hit strategies, ensuring that the optimization process has rollbackability and observation period buffer.
[0179] In an embodiment, as shown in Figure 2 a second network device optimization method is provided, including the following steps:
[0180] First, through the policy extraction and analysis module, the network security policies in the configuration information of the network device are extracted, and the network security policy table is constructed;
[0181] Second, the network security policy groups with inclusion relationship in the network security policy table are combed and optimized for repeated strategies;
[0182] Third, the network security policy groups with merging relationship in the network security policy table are combed and optimized for strategy merging;
[0183] Fourth, the hit number information of each network security policy is extracted through the hit number extraction module, and the network security policy table is combed and optimized for hit number strategies according to the hit number information;
[0184] After the above second to fourth steps, the optimized network security policy table is obtained;
[0185] Fifth, the above network device is optimized by using the above optimized network security policy table, and the optimized network device is obtained.
[0186] In an embodiment, as shown in Figure 3 a third network device optimization method is provided, including the following steps:
[0187] First, the device configuration, i.e., the configuration information of the network device, is obtained;
[0188] Second step, network security policy extraction and analysis of multi-brand equipment, that is, at least one set of security policy information is extracted in the configuration information; each set of security policy information is uniformly processed in format to obtain the network security policy corresponding to each set of security policy information; the network security policy table of the target network device is constructed based on the network security policy, which can be applied to different brands and different types of network devices, and a unified format network security policy table is obtained;
[0189] Third step, based on the policy relationship of the network security policy group, the network security policy table is sorted and optimized to obtain the optimized network security policy table;
[0190] Fourth step, log in to the network device and optimize the network device through the optimized network security policy table to obtain the optimized network device.
[0191] It should be understood that the size of the serial number of each step in the above embodiment does not mean the order of execution, and the execution order of each process should be determined according to its function and internal logic, and should not constitute any limitation on the implementation process of the embodiment of the application.
[0192] In an embodiment, a network device optimization apparatus is provided, which corresponds to the network device optimization method in the above embodiment. As shown in the figure, the network device optimization apparatus includes a first acquisition module 401, a first determination module 402, a first optimization module 403, and a second optimization module 404. The detailed description of each functional module is as follows: Figure 4
[0193] The first acquisition module 401 is configured to acquire the network security policy table of the target network device, wherein the network security policy table includes at least one network security policy, and each network security policy includes a policy action, a policy virtual wall, and communication quintuple information;
[0194] The first determination module 402 is configured to determine, based on the policy action, the policy virtual wall, and the communication quintuple information, a network security policy group with a policy relationship in the network security policy table;
[0195] The first optimization module 403 is configured to perform optimization processing on the network security policy table based on the policy relationship of the network security policy group to obtain an optimized network security policy table;
[0196] The second optimization module 404 is configured to perform optimization processing on the target network device based on the optimized network security policy table to obtain an optimized target network device.
[0197] The specific limitations of the network device optimization apparatus can refer to the limitations of the network device optimization method described above, which will not be repeated here. Each module in the network device optimization apparatus described above can be implemented by software, hardware, and a combination thereof, in whole or in part. The above-mentioned modules can be embedded in or independent of the processor in the computer device in hardware form, or can be stored in the memory in the computer device in software form, so as to be called and executed by the processor to perform the operations corresponding to each module.
[0198] In one embodiment, a computer device is provided, which can be a terminal device, and an internal structure diagram thereof can be as shown in Figure 5 The computer device includes a processor, a memory, and a network interface connected through a system bus. The processor of the computer device is configured to provide computing and control capabilities. The memory of the computer device includes a readable storage medium. The readable storage medium stores computer readable instructions. The network interface of the computer device is configured to communicate with an external terminal through a network connection. The computer readable instructions are executed by the processor to implement a network device optimization method. The readable storage medium provided in the embodiment includes a non-volatile readable storage medium and a volatile readable storage medium.
[0199] In the embodiments of the present application, a computer device is provided, which includes a memory, a processor, and computer readable instructions stored in the memory and executable on the processor, and the processor executes the computer readable instructions to implement the steps of the network device optimization method described above.
[0200] In the embodiments of the present application, a readable storage medium is provided, which stores computer readable instructions, and the computer readable instructions are executed by the processor to implement the steps of the network device optimization method described above.
[0201] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing relevant hardware through computer readable instructions, and the computer readable instructions can be stored in a non-volatile readable storage medium or a volatile readable storage medium. When the computer readable instructions are executed, the processes of the above-mentioned embodiments of the methods can be included. Any reference to memory, storage, database or other medium used in the embodiments provided in the present application can include non-volatile and / or volatile memory. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM) or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. As an illustration but not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link (Synchlink) DRAM (SLDRAM), memory bus (Rambus) direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM), etc.
[0202] Those skilled in the art can clearly understand that, for the convenience and brevity of description, only the above-mentioned division of functional units and modules is exemplified, and in actual application, the above-mentioned functions can be completed by different functional units and modules according to needs, that is, the internal structure of the device is divided into different functional units or modules to complete all or part of the functions described above.
[0203] The above embodiments are only used to illustrate the technical solutions of the present application, but not to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or make equivalent replacement for part of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present application, and should be included in the protection scope of the present application.
Claims
1. A network device optimization method, characterized in that: The method comprises: Obtaining a network security policy table of a target network device, wherein the network security policy table includes at least one network security policy, and each network security policy includes a policy action, a policy virtual wall, and communication quintuple information; Determining, based on the policy action, the policy virtual wall, and the communication quintuple information, a network security policy group having a policy relationship in the network security policy table; Optimizing the network security policy table based on the policy relationship of the network security policy group to obtain an optimized network security policy table; Optimizing the target network device based on the optimized network security policy table to obtain an optimized target network device; The policy relationship is an inclusion relationship or a merger relationship, the network security policy also includes security domain information and a policy name, and the network security policy table is optimized based on the policy relationship of the network security policy group to obtain an optimized network security policy table, including: In the network security policy table, determining a network security policy group whose policy relationship is an inclusion relationship, determining a network security policy with a smaller policy coverage in the network security policy group, and adding a deletion mark to the network security policy with the smaller policy coverage in the network security policy table to obtain a network security policy table to be merged; In the network security policy table to be merged, a network security policy group whose policy relationship is a merge relationship is determined, and the network security policies in the network security policy group are merged in the network security policy table to be merged to obtain the optimized network security policy table. The merging process includes merging and deduplicating the policy actions, policy virtual walls, communication quintuple information and security domain information, and retaining the policy names with higher rankings.
2. The network device optimization method according to claim 1, wherein: Before obtaining the network security policy table of the target network device, the method further includes: Logging into the target network device through a preset protocol to obtain configuration information of the target network device; extracting at least one set of security policy information from the configuration information; Performing unified formatting on each set of security policy information to obtain a network security policy corresponding to each set of security policy information; A network security policy table of the target network device is obtained based on the network security policy.
3. The network device optimization method according to claim 2, wherein: The step of constructing a network security policy table for the target network device based on the network security policy includes: Obtaining hit count information for each of the network security policies; Based on the hit count information, determining the order in which each of the network security policies is added; The network security policies are added to a preset empty table in sequence according to the adding order to obtain the network security policy table.
4. The network device optimization method according to claim 1, wherein: The determining, based on the policy action, the policy virtual wall, and the communication quintuple information, of a network security policy group having a policy relationship in the network security policy table includes: In the network security policy table, determining at least two network security policies having the same policy actions and policy virtual walls as a network security policy group to be processed; Based on the communication quintuple information, network security policies with policy relationships are determined in the network security policy group to be processed as the network security policy group.
5. The network device optimization method according to claim 4, wherein: The communication quintuple information includes a source address, a destination address, and protocol port information. Based on the communication quintuple information, determining a network security policy having a policy relationship in the network security policy group to be processed as the network security policy group includes: If the source address, destination address, and protocol port information of the first network security policy in the network security policy group to be processed all contain the source address, destination address, and protocol port information of the second network security policy in the network security policy group to be processed, then the policy relationship between the first network security policy and the second network security policy is an inclusion relationship; If any two of the source address, destination address, and protocol port information of the first network security policy in the network security policy group to be processed are the same as any two of the source address, destination address, and protocol port information of the second network security policy in the network security policy group to be processed, and the policy relationship between the first network security policy and the second network security policy is not an inclusion relationship, then the policy relationship between the first network security policy and the second network security policy is a merge relationship.
6. The network device optimization method according to claim 1, wherein: The method further comprises: Obtaining hit count information for each of the network security policies; In the optimized network security policy table, adding a zero hit mark for the network security policy whose hit count information is zero; If within a preset time, the hit count information corresponding to the network security policy with a zero hit mark is not zero, then the zero hit mark is removed from the optimized network security policy table; If, after the preset time expires, the hit count information corresponding to the network security policy mark with the zero hit mark is still zero, a deletion mark is added to the network security policy with the zero hit mark in the optimized network security policy table.
7. A network equipment optimization device, characterized in that: The device comprises: A first acquisition module is configured to acquire a network security policy table of a target network device, wherein the network security policy table includes at least one network security policy, and each network security policy includes a policy action, a policy virtual wall, and communication quintuple information; A first determining module is configured to determine, based on the policy action, the policy virtual wall, and the communication quintuple information, a network security policy group having a policy relationship in the network security policy table; A first optimization module, configured to optimize the network security policy table based on the policy relationship of the network security policy group to obtain an optimized network security policy table; A second optimization module is configured to optimize the target network device based on the optimized network security policy table to obtain an optimized target network device; The policy relationship is an inclusion relationship or a merger relationship, the network security policy also includes security domain information and a policy name, and the network security policy table is optimized based on the policy relationship of the network security policy group to obtain an optimized network security policy table, including: In the network security policy table, determining a network security policy group whose policy relationship is an inclusion relationship, determining a network security policy with a smaller policy coverage in the network security policy group, and adding a deletion mark to the network security policy with the smaller policy coverage in the network security policy table to obtain a network security policy table to be merged; In the network security policy table to be merged, a network security policy group whose policy relationship is a merge relationship is determined, and the network security policies in the network security policy group are merged in the network security policy table to be merged to obtain the optimized network security policy table. The merging process includes merging and deduplicating the policy actions, policy virtual walls, communication quintuple information and security domain information, and retaining the policy names with higher rankings.
8. A computer device comprising a memory, a processor, and computer-readable instructions stored in the memory and executed on the processor, wherein: When the processor executes the computer-readable instructions, the network device optimization method according to any one of claims 1 to 6 is implemented.
9. A computer-readable storage medium having computer-readable instructions stored thereon, characterized in that: When the computer-readable instructions are executed by a processor, the network device optimization method according to any one of claims 1 to 6 is implemented.
Citation Information
Patent Citations
Access gateway distribution method and device
CN105376309A
Strategy identification method and device
CN112788059A