Packet filtering strategy management method and data packet filtering method and device
By splitting the policy templates and policy trees, new packet filtering policies are generated and assigned to the corresponding templates. This solves the problem that policy templates in traditional solutions cannot adapt to diverse configurations, and improves the matching efficiency and real-time protection capabilities of packet filtering policies.
Patent Information
- Application Number
- CN202511293220.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-10
- Publication Date
- 2025-12-09
- Estimated Expiration
- 2045-09-10
AI Technical Summary
In traditional packet filtering policy management solutions, the combination of policy templates and policy trees is limited by the hardware performance and design architecture of the device, making it difficult to adapt to the diverse policy configuration needs of customers. This results in a large number of policies not being assigned to policy templates, leading to decreased matching efficiency and failing to meet the real-time protection needs in large-scale network environments.
By splitting candidate packet filtering strategies that cannot be directly matched with the strategy template, extracting the parts that overlap with the configuration parameter range of the strategy template, generating new packet filtering strategies and classifying them into the corresponding strategy template, the number of strategies flowing into the strategy tree is reduced, and matching efficiency is improved.
It significantly improves the efficiency of policy matching in the packet filtering process, reduces the storage pressure on the policy tree, and ensures real-time protection capabilities in large-scale network environments.
Smart Images

Figure CN121098583A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field, and in particular to a packet filtering strategy management method, a data packet filtering method, and an apparatus. Background Technology
[0002] With the rapid development of network technology and the emergence of various network applications, network attacks are becoming increasingly complex, making network security a core guarantee for the stable operation of information systems. Packet filtering technology, as a key means of resisting network threats, uses preset packet filtering strategies to detect the legitimacy of data packet headers and payloads, precisely controlling the inflow and outflow of data, thereby achieving security protection for user networks.
[0003] To address the increasingly complex spread of viruses and cyberattacks, the number of packet filtering policies continues to expand, and their configuration dimensions are becoming increasingly diverse. However, the increase in the number and dimensions of policies directly leads to a significant decrease in the efficiency of traditional matching mechanisms. Relying solely on a single storage and matching method makes it difficult to balance the needs of large-scale policy management and efficient real-time matching. Therefore, the industry generally adopts a combined approach of "policy templates + policy trees" to optimize the policy storage and matching process.
[0004] In this combined approach, policy templates and policy trees play different management roles: policy templates categorize and store packet filtering policies with the same or similar configuration characteristics based on predefined parameter configuration rules. Since policies belonging to the same template all conform to the preset rules, the matching phase does not need to traverse all policies one by one; it only needs to determine whether the parameters of the traffic to be matched conform to the template rules to quickly locate the target policy set, making the matching efficiency significantly higher than that of the policy tree. The policy tree is used to store the remaining policies that cannot satisfy any policy template rules. It adopts a binary tree structure, splitting the policies extracted from the kernel space into intermediate nodes and leaf nodes according to different dimensions. The intermediate nodes record the dimension attributes and child node identifiers, while the leaf nodes store the offset information and data size of the parsed policy. During matching, it is necessary to start from the root node and traverse the intermediate nodes layer by layer according to the dimension parameters of the traffic to be matched until the corresponding leaf node is found. Then, the matching is determined by comparing the policies mapped to the leaf nodes. The entire process relies on hierarchical traversal and is relatively time-consuming.
[0005] However, the above solutions have significant limitations in practical applications: due to limitations in device hardware performance and design architecture, the currently configurable policy template combination types are typically fixed at four, making it difficult to adapt to diverse customer policy configuration needs. This results in a large number of policies not being assigned to policy templates and instead being distributed to policy tree storage. As the number of policies in the policy tree continues to increase, its hierarchical depth expands: on the one hand, the policy compilation stage needs to handle more node splitting and construction operations, significantly extending parsing time; on the other hand, the matching stage needs to traverse deeper tree structures, searching for intermediate and leaf nodes layer by layer, further increasing matching time costs. Ultimately, this leads to a significant decrease in the overall packet filtering policy matching efficiency, failing to meet the real-time protection needs of large-scale network environments. Summary of the Invention
[0006] To overcome the problems existing in related technologies, this application provides a packet filtering strategy management method, a data packet filtering method, and an apparatus.
[0007] According to a first aspect of the embodiments of this application, a method for managing packet filtering policies is provided, wherein each packet filtering policy is configured with a range of values for parameters of multiple dimensions for data packets, the method comprising:
[0008] The packet filtering strategy is matched with a pre-built strategy template, and the matched packet filtering strategy is stored in the corresponding category of the strategy template; wherein, each category of strategy template is configured with the value range of at least two dimensions of parameters, and the combination of the dimensions of parameters represented by different strategy templates is different;
[0009] Candidate packet filtering strategies are selected from the packet filtering strategies that do not match the strategy template. The candidate packet filtering strategies are packet filtering strategies whose value ranges overlap with the parameters configured in the strategy template.
[0010] Extract the value range of parameters that overlap with the policy template from the candidate packet filtering strategy, generate a new packet filtering strategy, and store the new packet filtering strategy in the corresponding policy template;
[0011] The remaining parameter values in the candidate packet filtering strategy that do not overlap with the strategy template are taken as another new packet filtering strategy, and the other new packet filtering strategy and other packet filtering strategies that do not match the strategy template are stored in the strategy tree.
[0012] According to a second aspect of the embodiments of this application, a data packet filtering method is provided, the method comprising:
[0013] Retrieve the data packets to be filtered;
[0014] The data packet is matched with the policy template described in the first aspect;
[0015] If a target policy template that matches the data packet exists, then the packet filtering policy in the target policy template that matches the data packet is executed;
[0016] If no target policy template matches the data packet, then the packet filtering policy in the policy tree described in the first aspect that matches the data packet is executed.
[0017] According to a third aspect of the embodiments of this application, a packet filtering policy management device is provided, wherein each packet filtering policy is configured with a range of values for parameters of multiple dimensions for data packets, the device comprising:
[0018] The strategy template matching module is used to match the packet filtering strategy with a pre-built strategy template and store the matched packet filtering strategy in the corresponding category of the strategy template; wherein, each category of strategy template is configured with the value range of at least two dimensions of parameters, and different strategy templates represent different combinations of the dimensions of the parameters.
[0019] The candidate packet filtering strategy screening module is used to filter out candidate packet filtering strategies from the packet filtering strategies that do not match the strategy template. The candidate packet filtering strategies are packet filtering strategies that overlap with the value range of the parameters configured in the strategy template.
[0020] The candidate packet filtering strategy splitting module is used to split the value range of parameters that overlap with the strategy template from the candidate packet filtering strategy, generate a new packet filtering strategy, and store the new packet filtering strategy into the corresponding strategy template.
[0021] The strategy tree storage module is used to take the value range of the remaining parameters in the candidate packet filtering strategy that do not overlap with the strategy template as another new packet filtering strategy, and store the other new packet filtering strategy and other packet filtering strategies that do not match the strategy template into the strategy tree.
[0022] According to a fourth aspect of the embodiments of this application, a data packet filtering apparatus is provided, the apparatus comprising:
[0023] The data packet acquisition module is used to acquire the data packets to be filtered.
[0024] A template matching module is used to match the data packet with the policy template described in the first aspect;
[0025] The template policy matching module is used to execute the packet filtering policy in the target policy template that matches the data packet when a target policy template that matches the data packet exists.
[0026] The tree policy matching module is used to execute the packet filtering policy in the policy tree that matches the data packet in the first aspect when there is no target policy template that matches the data packet.
[0027] According to a fifth aspect of the embodiments of this application, a computer device is provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the method described in the first aspect or the second aspect.
[0028] The technical solutions provided in this application embodiment may include the following beneficial effects:
[0029] In this embodiment, candidate packet filtering strategies that cannot be directly matched with the strategy template are split and the parts that overlap with the configuration parameter range of the strategy template are extracted. New packet filtering strategies are generated and assigned to the corresponding strategy template. This allows more strategies to be managed through efficient template matching, reducing the number of strategies flowing into the strategy tree and thus effectively improving the strategy matching efficiency in the subsequent packet filtering process.
[0030] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and do not limit this application. Attached Figure Description
[0031] The accompanying drawings, which are incorporated in and form part of this application, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.
[0032] Figure 1 This is a flowchart illustrating a packet filtering strategy management method according to an exemplary embodiment of this application.
[0033] Figure 2 This is a schematic flowchart illustrating a packet filtering method according to an exemplary embodiment of this application.
[0034] Figure 3 This is a schematic diagram of the structure of a packet filtering strategy management device according to an exemplary embodiment of this application.
[0035] Figure 4 This is a schematic flowchart of a packet filtering device according to an exemplary embodiment of this application.
[0036] Figure 5 This is a schematic diagram of the structure of a computer device according to an exemplary embodiment of this application. Detailed Implementation
[0037] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.
[0038] The terminology used in this application is for the purpose of describing particular embodiments only and is not intended to be limiting of the application. The singular forms “a,” “the,” and “the” used in this application and the appended claims are also intended to include the plural forms unless the context clearly indicates otherwise. It should also be understood that the term “and / or” as used herein refers to and includes any or all possible combinations of one or more of the associated listed items.
[0039] It should be understood that although the terms first, second, third, etc., may be used in this application to describe various information, such information should not be limited to these terms. These terms are only used to distinguish information of the same type from one another. For example, without departing from the scope of this application, first information may also be referred to as second information, and similarly, second information may also be referred to as first information. Depending on the context, the word "if" as used herein may be interpreted as "when," "when," or "in response to determination."
[0040] With the rapid development of network technology and the emergence of various network applications, network attacks are becoming increasingly complex, making network security a core guarantee for the stable operation of information systems. Packet filtering technology, as a key means of resisting network threats, uses preset packet filtering strategies to detect the legitimacy of data packet headers and payloads, precisely controlling the inflow and outflow of data, thereby achieving security protection for user networks.
[0041] To address the increasingly complex spread of viruses and cyberattacks, the number of packet filtering policies continues to expand, and their configuration dimensions are becoming increasingly diverse. However, the increase in the number and dimensions of policies directly leads to a significant decrease in the efficiency of traditional matching mechanisms. Relying solely on a single storage and matching method makes it difficult to balance the needs of large-scale policy management and efficient real-time matching. Therefore, the industry generally adopts a combined approach of "policy templates + policy trees" to optimize the policy storage and matching process.
[0042] In this combined approach, policy templates and policy trees play different management roles: policy templates categorize and store packet filtering policies with the same or similar configuration characteristics based on predefined parameter configuration rules. Since policies belonging to the same template all conform to the preset rules, the matching phase does not need to traverse all policies one by one; it only needs to determine whether the parameters of the traffic to be matched conform to the template rules to quickly locate the target policy set, making the matching efficiency significantly higher than that of the policy tree. The policy tree is used to store the remaining policies that cannot satisfy any policy template rules. It adopts a binary tree structure, splitting the policies extracted from the kernel space into intermediate nodes and leaf nodes according to different dimensions. The intermediate nodes record the dimension attributes and child node identifiers, while the leaf nodes store the offset information and data size of the parsed policy. During matching, it is necessary to start from the root node and traverse the intermediate nodes layer by layer according to the dimension parameters of the traffic to be matched until the corresponding leaf node is found. Then, the matching is determined by comparing the policies mapped to the leaf nodes. The entire process relies on hierarchical traversal and is relatively time-consuming.
[0043] However, the above solutions have significant limitations in practical applications: due to limitations in device hardware performance and design architecture, the currently configurable policy template combination types are typically fixed at four, making it difficult to adapt to diverse customer policy configuration needs. This results in a large number of policies not being assigned to policy templates and instead being distributed to policy tree storage. As the number of policies in the policy tree continues to increase, its hierarchical depth expands: on the one hand, the policy compilation stage needs to handle more node splitting and construction operations, significantly extending parsing time; on the other hand, the matching stage needs to traverse deeper tree structures, searching for intermediate and leaf nodes layer by layer, further increasing matching time costs. Ultimately, this leads to a significant decrease in the overall packet filtering policy matching efficiency, failing to meet the real-time protection needs of large-scale network environments.
[0044] Based on this, and to address the problems existing in related technologies, embodiments of this application provide a method for managing packet filtering strategies. This method splits candidate packet filtering strategies that cannot directly match a strategy template, extracts the portions that overlap with the strategy template's configuration parameter range, generates new packet filtering strategies, and assigns them to the corresponding strategy template. This allows more strategies to be managed through efficient template matching, reducing the number of strategies flowing into the strategy tree and effectively improving the strategy matching efficiency in subsequent packet filtering processes.
[0045] The embodiments of this application will now be described in detail with reference to the accompanying drawings.
[0046] Figure 1 This is a flowchart illustrating a packet filtering strategy management method according to an exemplary embodiment of this application. Figure 1 As shown, the management method includes the following steps S101 to S104.
[0047] Step S101: Match the packet filtering strategy with the pre-built strategy template, and store the matched packet filtering strategy in the corresponding category of strategy template; wherein, each category of strategy template is configured with the value range of parameters in at least two dimensions, and the combination of the dimensions of parameters represented by different strategy templates is different.
[0048] In step S101, each packet filtering policy is configured with a range of values for parameters of multiple dimensions for the data packet. These dimension parameters can cover various core identification information of the data packet in network transmission, such as source IP address, destination IP address, virtual system ID, transport protocol type (such as TCP, UDP, ICMP), source port number, destination port number, source security domain, destination security domain, etc. The range of values for parameters of different dimensions jointly defines the protection rules of the policy, that is, only data packets that meet the range of values of all dimensions are subjected to filtering operations such as allowing, blocking or auditing. For example, a packet filtering policy used to protect an internal office network might have the following dimensional parameter configurations: source IP address range of "192.168.1.0 / 24", destination IP address range of "203.0.113.0 / 24", virtual system ID range of "1" (the virtual system corresponding to the office network), protocol type range of "TCP", and destination port number range of "80, 443". This policy only applies to TCP packets originating from the "192.168.1.0 / 24" network segment and sent to ports 80 or 443 of the "203.0.113.0 / 24" network segment.
[0049] The pre-built policy templates can be policy classification frameworks formed by combining parameter dimensions based on common policy configuration features in the network. For high-frequency combinations of policy dimensions in different business scenarios, fixed parameter value range rules are configured for each combination, so that policies with the same combination features can be managed in a unified manner. Specifically, each type of policy template contains at least two dimensions of parameter value range configuration, and the combination of the parameter dimensions represented by different policy templates is different. For example, the dimension combination of template A is "source IP address + destination IP address + virtual system ID", and its value range rules limit that the parameters of these three dimensions must simultaneously meet specific network segment or identification requirements (such as source IP address "10.0.0.0 / 8", destination IP address "172.16.0.0 / 12", and virtual system ID "1-4"); the dimension combination of template B is "source IP address + protocol type + virtual system ID", and its value range focuses on the matching of source IP network segment, protocol type and virtual system ID; the dimension combination of template C is "destination IP address + destination port number + virtual system ID", and the value range rules revolve around destination IP network segment, port number range and virtual system ID.
[0050] During the matching operation in step S101, the value ranges of all dimension parameters of each packet filtering policy can be compared one by one with the dimension combinations and value ranges of each policy template. If the dimension combination of a policy can cover the dimension combination of a policy template (or is completely consistent with the template dimension combination), and the value ranges of the parameters of each dimension of the policy fall within the value range rules of the corresponding template, then the policy is determined to match the template. For example, if the dimension combination of a policy is "source IP address + destination IP address + virtual system ID", and the source IP address is "10.1.0.0 / 24" (belonging to the "10.0.0.0 / 8" range of template A), the destination IP address is "172.16.1.0 / 24" (belonging to the "172.16.0.0 / 12" range of template A), and the virtual system ID is "2" (belonging to the "1-4" range of template A), then the policy matches template A.
[0051] For successfully matched packet filtering strategies, they can be stored in the corresponding category of strategy templates. This means each matching strategy can be assigned to a template that perfectly matches it, avoiding management confusion caused by storing strategies across templates. Through this process, a large number of strategies with common dimensional combinations are centrally incorporated into their corresponding strategy templates. Subsequently, when filtering packets, the target strategy can be quickly located directly based on the template, significantly reducing invalid traversals and providing a foundation for improving matching efficiency.
[0052] Step S102: Select candidate packet filtering strategies from the packet filtering strategies that do not match the strategy template. The candidate packet filtering strategies are those whose value ranges overlap with the parameters configured in the strategy template.
[0053] Step S103: Extract the value range of parameters that overlap with the policy template from the candidate packet filtering strategy, generate a new packet filtering strategy, and store the new packet filtering strategy in the corresponding policy template.
[0054] In step S102, packet filtering policies that do not match the policy template can be mainly divided into two categories: The first category is "dimensional combination mismatch", that is, the parameter dimensions of the packet filtering policy have no overlap with the dimension combinations of all policy templates. For example, a policy only configures two dimensions, "source port number + destination port number", while the dimension combinations of the preset templates all include the dimension parameter "IP address + virtual system ID" (such as "source IP + destination IP + virtual system ID" in template A and "source IP + protocol type + virtual system ID" in template B). Since the dimension composition does not overlap, this type of policy cannot be adapted to the template by adjusting the parameter value range. The second category is "dimensional combination match but value range mismatch", that is, the parameter dimensions of the policy include all the dimensions of a certain template (or are completely consistent with the dimension combination of the template), but the value range of at least one dimension does not completely fall within the parameter value range of the template.
[0055] The second type of strategy, "mismatch in value range," can be further divided into two cases: "completely non-overlapping" and "partially overlapping." The former refers to situations where the value range of a certain dimension of the strategy has no overlap with the value range of the corresponding dimension of the template (for example, the source IP address value range of template D is "192.168.0.0 / 24," and the source IP address of a certain strategy is "10.0.0.0 / 24," with no overlap in their network segments). Such strategies lack a basis for adaptation and cannot be adapted to the template by adjusting the parameter value range. The latter refers to situations where the value range of parameters in the same dimension of the strategy and the template partially overlaps (for example, the source IP address mask of template D is 24 bits, and the source IP address mask of a certain strategy is 23 bits, and the 23-bit network segment includes the 24-bit network segment of template D). This indicates that such strategies have the potential to be adapted to the template by splitting them. Therefore, they can be used as candidate packet filtering strategies so that they can be split later to generate new strategies and be incorporated into the template. This splitting allows more strategies to be managed through an efficient template matching mechanism, avoiding the direct inflow of a large number of strategies that cannot match templates into the strategy tree, thereby reducing the pressure on strategy tree construction and matching.
[0056] To ensure the effectiveness and efficiency of strategy splitting, in addition to meeting the core condition of "overlapping value ranges" when screening candidate packet filtering strategies, an additional "overlapping range threshold" restriction can be set. That is, a strategy is only judged as a candidate packet filtering strategy when the overlap between the parameter value ranges of the strategy and the template meets the preset range threshold, thereby avoiding resource waste caused by splitting too many low-overlapping strategies. Taking the IP address mask dimension as an example, a preset range threshold of "mask bit difference ≤ 5" can be set: Assuming that the source IP address mask requirement of template D is 24 bits (such as "192.168.1.0 / 24"), and the source IP address mask of a certain unmatched policy is 23 bits (such as "192.168.0.0 / 23"), the difference in the number of bits between the two masks is 1 (≤ 5), and the 23-bit network segment exactly contains "192.168.1.0 / 24" (overlapping part) and "192.168.0.0 / 24" (non-overlapping part), then the policy can be determined as a candidate packet filtering policy.
[0057] When proceeding to the splitting stage in step S103, the overlapping portion of the candidate packet filtering strategies and the strategy template can be precisely split to generate new packet filtering strategies that can be directly incorporated into the strategy template. Again, taking the aforementioned 23-bit mask strategy as an example, according to the 24-bit mask address value range of template D, the strategy "192.168.0.0 / 23" can be split into two independent 24-bit mask network segments: "192.168.0.0 / 24" and "192.168.1.0 / 24". "192.168.1.0 / 24" fully conforms to the address value range of template D, so it can be used as a new packet filtering strategy (retaining other dimension parameters of the original strategy besides the source IP address, such as destination IP and protocol type), and stored in template D. "192.168.0.0 / 24", however, does not meet the address value range of any template, so it can be temporarily listed as a strategy to be processed and proceed to subsequent steps.
[0058] Through precise filtering and splitting in steps S102 and S103, a large number of packet filtering policies that originally could not match the policy template can be transformed into new policies that conform to the policy template rules, which significantly improves the coverage of the policy template, reduces the number of policies entering the policy tree, and lays the foundation for improving the efficiency of subsequent policy matching.
[0059] Step S104: Take the value range of the remaining parameters in the candidate packet filtering strategy that do not overlap with the strategy template as another new packet filtering strategy, and store this new packet filtering strategy and other packet filtering strategies that do not match the strategy template into the strategy tree.
[0060] In the splitting operation of step S103, the candidate packet filtering policy is split into "the part that overlaps with the template" and "the part that does not overlap with the template". The "overlapping part" has been included in the corresponding template as a new policy, while the "non-overlapping part" is the value range of the remaining parameters in the candidate packet filtering policy that do not overlap with the policy template. Although it does not meet the rules of any template, it still needs to be effective as an independent protection rule. Therefore, it can be encapsulated into another new packet filtering policy. For example, the candidate packet filtering policy with the 23-bit mask (192.168.0.0 / 23) mentioned above, after splitting, the remaining "192.168.0.0 / 24" network segment part that does not overlap with the policy template will be encapsulated into a new policy. Its dimension combination, virtual system ID, protocol type and other configurations are consistent with the original candidate packet policy, only the source IP address value range is updated to "192.168.0.0 / 24".
[0061] Besides the aforementioned "new strategies remaining after splitting," there are two other types of strategies that consistently fail to match the strategy templates: one type is the "dimension combination mismatch" strategy selected in step S102 (e.g., configuring only "source port number + destination port number," which has no overlap with the "IP address + virtual system ID" type dimension combination of all templates); the other type is the "completely non-overlapping value range" strategy (e.g., template D's source IP is "192.168.0.0 / 24," and a certain strategy's source IP is "10.0.0.0 / 24," with no overlap and a mask difference exceeding the threshold). These two types of strategies, together with the "new strategies remaining after splitting," constitute all the strategies that need to be stored in the strategy tree.
[0062] When storing policies in the policy tree, these policies can be structured according to the construction rules of the policy tree (binary tree): First, extract the multi-dimensional parameters of each policy from the kernel space (such as source IP, destination IP, port number, protocol, etc.), and use these dimensions as the basis for splitting the binary tree. The intermediate nodes of the tree record the attributes of a single dimension (such as "source IP address mask", "destination port number range", etc.) and the identifier of whether there are child nodes. The leaf nodes store the memory offset address and data size of the parsed policy. For example, for a policy with the dimension combination of "source port number + destination port number", when constructing the tree, first generate an intermediate node with "source port number range" as the first splitting dimension, then split the node into child intermediate nodes according to "destination port number range", and finally store the policy information in the corresponding leaf node.
[0063] Through this process, all policies not covered by templates are systematically incorporated into the policy tree, ensuring the integrity of packet filtering policies and providing a unified traversal query path for subsequent matching steps. When a data packet cannot match any policy template, matching can be completed by traversing the intermediate nodes of the policy tree and comparing the policy information of the leaf nodes, ensuring that network protection is thorough.
[0064] The pre-built policy templates in the above embodiments are not fixed configurations, but can be dynamically generated based on the configuration features of the actual packet filtering policies. This ensures that the policy templates can cover most frequently used policy dimension combinations, maximizing the efficiency of template matching. Specifically, in one embodiment, the step of building a policy template may include:
[0065] First, determine the combination methods for parameters of different dimensions of the packet filtering policy. Dimensional parameters of a packet filtering policy typically include source IP address, destination IP address, virtual system ID, protocol type, source port number, and destination port number. Based on common policy configuration logic in network protection scenarios, at least two dimensions are selected from these and combined to form multiple dimension combination methods. Then, a corresponding basic policy template is generated for each combination method. In this embodiment, to cover most configuration scenarios, 16 basic policy templates can be generated, covering core combination logics such as "source IP address + destination IP address + virtual system ID", "source IP address + virtual system ID", and "destination IP address + virtual system ID", avoiding the omission of high-frequency policy combinations due to insufficient basic template types.
[0066] Subsequently, the number of matches between each packet filtering policy and the basic policy template was counted. All packet filtering policies in the current system were traversed, and it was determined whether the dimension combination of each policy matched the dimension combination of a certain basic template. The number of matching policies corresponding to each basic template was recorded. For example, the statistics showed that the basic template "source IP address + destination IP address + virtual system ID" matched 2800 policies, "source IP address + virtual system ID" matched 2200, "destination IP address + virtual system ID" matched 1900, "source IP address + protocol type + virtual system ID" matched 1700, and the number of matches for the remaining basic templates was less than 1500.
[0067] Finally, a preset number of basic policy templates are selected as the final policy templates based on the number of matches, from highest to lowest. For example, considering device storage and matching performance requirements, the preset selection number can be 4. From the 16 basic templates, the top 4 templates with the highest number of matches are selected as the core templates for subsequent policy matching. Taking the above statistical data as an example, the following templates are selected as the final policy templates: "Source IP address + Destination IP address + Virtual System ID", "Source IP address + Virtual System ID", "Destination IP address + Virtual System ID", and "Source IP address + Protocol type + Virtual System ID". Specific parameter value ranges (such as IP address mask, port number range, etc.) are added to each template to complete the construction of the policy templates.
[0068] By adopting this construction method of "first covering high-frequency combinations and then filtering on demand", it can be ensured that the final policy template can be adapted to most package filtering policies, thereby improving the matching rate between policies and templates from the source and reducing the pressure of subsequent splitting and policy tree storage.
[0069] More specifically, in step S101, when storing the matched packet filtering policies into the corresponding category of policy templates, to further improve the efficiency of policy query during subsequent packet filtering, a hash value association storage method can be used to bind the policies and templates. The specific implementation process is as follows:
[0070] Once a packet filtering policy is confirmed to match a policy template, a unique hash value can be calculated based on the value range of the parameters for each dimension of the policy, using a preset hash algorithm (such as SHA-1, MD5, or a custom hash function, which can be selected according to device performance and security requirements). The generation of this hash value must cover the core configuration information of the policy. For example, if the policy's dimension combination is "source IP address + destination IP address + virtual system ID," and the value ranges are "192.168.1.0 / 24," "203.0.113.0 / 24," and "2," respectively, then the hash calculation will take the specific value ranges of these three dimensions as input, and after algorithm processing, obtain a fixed-length hash value. This hash value can uniquely identify the dimensional configuration characteristics of this policy.
[0071] Subsequently, the complete information of the packet filtering policy (including the value range of each dimension, filtering action, effective time, etc.) is associated with the calculated hash value and stored in the corresponding policy template. For example, the policy template can maintain a "hash value-policy" mapping table, with the hash value as the index and the policy information as the corresponding stored content. The core advantage of this storage method is its rapid location: when a data packet needs to match a policy within the template, it is only necessary to extract the corresponding dimension parameters of the data packet (such as source IP, destination IP, virtual system ID), calculate its hash value, and then directly query the corresponding policy in the template's mapping table using the hash value, without having to traverse all policies within the template for dimension comparison.
[0072] For example, if a data packet has a source IP of "192.168.1.10" (belonging to "192.168.1.0 / 24"), a destination IP of "203.0.113.5" (belonging to "203.0.113.0 / 24"), and a virtual system ID of "2", when matching the "source IP + destination IP + virtual system ID" template, the hash value of the corresponding dimension of the data packet is calculated first. Then, the template's mapping table is queried using this hash value as an index. This instantly locates the previously stored packet filtering policy with the same hash value, significantly reducing matching time. Compared to the traditional "traversal comparison" method, hash-associative storage effectively shortens policy query time. Even if a policy template stores thousands of policies, it still ensures a high-efficiency query response speed, further enhancing the efficiency advantage of policy templates in packet filtering matching.
[0073] In addition to the conventional policy templates built for policy dimension combinations mentioned above, policy templates for specific addresses can also be pre-built based on policy management needs in special address scenarios. These templates are used to store packet filtering policies for specific addresses. Specific addresses mainly refer to address types in the network with special functions or high-frequency usage scenarios, such as wildcard addresses (e.g., "0.0.0.0 / 0", representing any IP address) and small-range addresses within specific network segments (e.g., "192.168.0.1-192.168.0.2" containing only 1-2 IPs). Packet filtering policies corresponding to these addresses often have strong generality (e.g., default protection rules for any IP) or high specificity (e.g., dedicated protection rules for core device IPs). If these are included in ordinary policy templates along with conventional policies, differences in dimension combinations or value ranges may lead to reduced matching efficiency or even rule conflicts.
[0074] Meanwhile, to avoid interference with the storage and matching process of regular policy templates, the policy template at the specified address and the aforementioned regular policy template can be stored in different storage areas (such as different partitions in the device memory or different storage files), and independent matching query entries can be assigned to the two types of templates.
[0075] For example, a network may be configured with a protection policy against "any IP accessing the core server's port 8080," with address parameters "0.0.0.0 / 0" (source IP) and "10.0.1.10" (destination IP, core server). Such policies will be categorized into "policy templates for specified addresses" and stored in a separate memory partition. When a data packet is sent from any IP (such as "202.100.5.3") to "10.0.1.10:8080," the matching process will first query the "policy templates for specified addresses" storage area to quickly locate the protection policy without having to traverse and query the regular templates. This further improves the policy matching efficiency in special scenarios and also ensures the management independence of regular policy templates and policy templates for specified addresses, reducing the complexity of rule maintenance.
[0076] Furthermore, in practical applications of packet filtering policies, there are often scenarios where multiple policies match the same data packet simultaneously. For example, a data packet may meet both the policy of "allowing the 192.168.1.0 / 24 network segment to access the public network" and the policy of "blocking the 192.168.1.10-192.168.1.20 network segment from accessing the public network." In such cases, priority must be used to determine which policy to execute. If the priority logic is confused, it may lead to the protection rules becoming ineffective or being falsely blocked. Traditional methods for determining policy priorities often rely on traversing all policies to build an inclusion relationship linked list. However, when the number of policies reaches millions and the dimensions exceed ten, the traversal process requires comparing multi-dimensional parameters one by one, which is extremely time-consuming and error-prone, severely impacting the efficiency of policy implementation. Therefore, in one embodiment, the inclusion relationship detection process can be optimized by performing multiple checks on a single dimension, thereby accurately determining the policy priority. The specific implementation process is as follows:
[0077] First, the inclusion relationship between each packet filtering policy is determined based on the value range of parameters for each individual dimension. For each packet filtering policy, all configured dimensions are selected, and the inclusion relationship of parameter value ranges for different policies under each single dimension is analyzed one by one. For example, in the "source IP address" dimension, the value range of policy A is "192.168.1.0 / 24", and the value range of policy B is "192.168.1.10 / 32" (single IP). Since "192.168.1.10" belongs to the "192.168.1.0 / 24" network segment, it can be determined that policy B is included by policy A in the "source IP address" dimension. Similarly, in the "destination port number" dimension, the value range of policy C is "1-1024", and the value range of policy D is "80-443". Therefore, policy D is included by policy C in this dimension. In this process, the inclusion relationship determination for each dimension is performed independently without the need to associate with other dimensions, which greatly reduces the complexity of single-step calculation.
[0078] Secondly, by comprehensively considering the inclusion relationships across all dimensions, the overall inclusion relationship between each packet filtering strategy is determined. After completing the inclusion relationship detection for all individual dimensions, an overall judgment needs to be made based on the dimensional combination features of the strategies: if a strategy X is included by strategy Y in all dimensions (i.e., the value range of each dimension of strategy X falls within the value range of the corresponding dimension of strategy Y), then strategy X and strategy Y are determined to have an "overall inclusion relationship," and strategy X has a finer granularity (targeting a smaller range of data packets); if strategy X is only included by strategy Y in some dimensions, and there is no inclusion relationship or they are independent of each other in other dimensions, then there is no overall inclusion relationship between the two. For example, if policy E is configured with the dimension "Source IP: 192.168.1.0 / 24, Destination Port: 80" and policy F is configured with the dimension "Source IP: 192.168.1.10 / 32, Destination Port: 80", then policy F is included by policy E in the "Source IP" dimension and is completely consistent with policy E in the "Destination Port" dimension. Therefore, it can be determined that policy F is included by policy E as a whole. If the destination port of policy F is "443", then only the "Source IP" dimension is included and the "Destination Port" dimension is independent. There is no overall inclusion relationship between the two.
[0079] Finally, based on the overall inclusion relationship, the priority of packet filtering policies is determined according to preset priority rules. These preset priority rules can be set according to actual user needs. For example, the preset priority rule can be set so that finer-grained policies have higher priority; that is, included policies (such as policies F, B, and D above) have higher priority than policies that include them (such as policies E, A, and C). This makes fine-grained policies more suitable for the protection needs of specific scenarios and prioritizes their execution to avoid coarse-grained policies overriding precise rules. For example, when the source IP of a data packet is "192.168.1.10" and the destination port is "80", if both policy E (coarse-grained, allowing 192.168.1.0 / 24 to access port 80) and policy F (fine-grained, if policy F is "block 192.168.1.10 from accessing port 80") are matched, policy F, with its higher priority, will be executed first, meeting the requirements for precise protection. The priority determined by this rule can be marked in the corresponding packet filtering policy. When filtering subsequent packets, the higher priority policy can be executed first to ensure the effectiveness and accuracy of the protection rule.
[0080] On the other hand, this application also provides a packet filtering method, which utilizes the policy template and policy tree constructed in the above packet filtering policy management method to achieve efficient filtering of packets in the network and ensure that the protection rules take effect accurately.
[0081] Figure 2 This is a schematic flowchart illustrating a packet filtering method according to an exemplary embodiment of this application. Figure 2 As shown, the filtering method includes the following steps S201 to S204.
[0082] Step S201: Obtain the data packets to be filtered.
[0083] During network data transmission, network devices with packet filtering capabilities (such as firewalls and intrusion prevention systems) use techniques like port mirroring and traffic capture to acquire all data packets flowing through the device in real time and extract their core characteristic parameters. These parameters correspond one-to-one with the configuration dimensions of the packet filtering policy, including but not limited to source IP address, destination IP address, virtual system ID, transmission protocol type, source port number, destination port number, source security domain identifier, and destination security domain identifier, providing a basis for subsequent policy matching. For example, a data packet sent from the internal office network to an external business server, after parsing, extracts the following characteristic parameters: source IP "192.168.1.15", destination IP "203.0.113.8", virtual system ID "2" (the virtual system corresponding to the office network), protocol "TCP", destination port "443", source security domain "office domain", and destination security domain "Internet domain". These parameters will serve as the core basis for subsequent matching policies.
[0084] Step S202: Match the data packet with the policy template described in the above embodiments.
[0085] The core of this step is to quickly filter data packets using policy templates, reducing the number of packets that need to be matched in the policy tree and improving overall filtering efficiency. The device can compare the feature parameters of each data packet with the dimension combinations and parameter value ranges of each policy template according to a preset template matching order (the matching order can be set based on the number of policies stored in the template and the priority of business scenarios, such as prioritizing the template with the most stored policies or prioritizing templates corresponding to businesses with high security levels). If the feature parameter dimensions of the data packet cover the dimension combination of a certain policy template (or are completely consistent with the template's dimension combination), and the parameter values of all corresponding dimensions of the data packet fall within the value range of that template, then the data packet is determined to match that template, and that template is the "target policy template." If, after traversing all policy templates, no template meets the above comparison conditions (e.g., the data packet dimensions have no intersection with all template dimension combinations, or the parameter values exceed the range of all templates), then it is determined that there is no target policy template, and the process proceeds to step S204 for policy tree matching.
[0086] Taking the extracted data packet as an example, if the policy template contains a template with the dimension combination of "source IP + destination IP + virtual system ID + protocol + destination port", and the value range rule of the template is "source IP: 192.168.1.0 / 24, destination IP: 203.0.113.0 / 24, virtual system ID: 2, protocol: TCP, destination port: 443", then the characteristic parameters of the data packet completely match the dimension combination and value range of the template, and the template is determined to be the target policy template; if the destination IP of the data packet is "203.0.114.8" (which exceeds the range of "203.0.113.0 / 24" of the template), then the template does not match, and other templates need to be compared.
[0087] Step S203: If a target policy template that matches the data packet exists, then execute the packet filtering policy in the target policy template that matches the data packet.
[0088] Once the target policy template is determined, it is necessary to further locate the specific policy within the template that completely matches the data packet, and execute the action in conjunction with priority rules to ensure the accuracy of protection. Since the packet filtering policies within the target policy template are stored using hash value association, the device can first calculate the corresponding hash value based on the characteristic parameters of the data packet (consistent with the hash calculation dimension when storing the policy) using the same hash algorithm; then, using this hash value as an index, it can quickly query the "hash value-policy" mapping table of the target policy template to directly locate the packet filtering policy that matches the data packet characteristics, without having to traverse all policies within the template one by one, greatly reducing the query time.
[0089] Specifically, when executing a policy, the packet filtering policy that matches the data packet and is marked as high priority in the target policy template is executed first. The device first determines whether the located policy is marked as high priority: if it is a high-priority policy, the corresponding filtering action is executed immediately (such as allowing the data packet to pass, blocking the data packet transmission, logging the data packet and issuing an alarm, etc.), and the matching process of all subsequent templates is terminated to avoid redundant matching operations; if the located policy is not high priority, it is not executed immediately, but the next policy template that may match the data packet is polled, and the process of "parameter comparison-hash query-priority determination" is repeated until all policy templates are traversed. If only a non-high-priority policy is matched after the traversal, the last matched non-high-priority policy can be selected to be executed; if a high-priority policy is matched during the process, it is executed immediately and the process is terminated.
[0090] For example, when the above data packet matches the template "source IP + destination IP + virtual system ID + protocol + destination port", it is located to Policy 1 (not high priority, rule: "allow the 192.168.1.0 / 24 network segment to access port 443 of the 203.0.113.0 / 24 network segment via TCP protocol"); when it continues to match the template "source IP + destination IP + virtual system ID + source security domain + destination security domain", it is located to Policy 2 (high priority, rule: "allow TCP port 443 data packets sent from the office domain (192.168.1.0 / 24) to the Internet domain (203.0.113.0 / 24) to pass through, and log the access"). At this time, because Policy 2 is high priority, the device immediately executes the "allow passage + log recording" action and stops matching all subsequent templates, which ensures the accuracy of the protection rules and avoids invalid matching waste.
[0091] It should be noted that the priority determination process of the packet filtering strategy in this step is consistent with the implementation process of the corresponding step in the packet filtering strategy management method described above, and will not be repeated here.
[0092] Step S204: If there is no target policy template that matches the data packet, then execute the packet filtering policy that matches the data packet in the policy tree described in the above embodiment.
[0093] When packet feature parameters do not match any policy templates, the policy tree acts as a fallback matching mechanism to ensure that all flowing packets are covered by protection rules, preventing security vulnerabilities. The device can follow the binary tree structure of the policy tree, starting from the root node and traversing intermediate nodes layer by layer based on packet feature parameters. The traversal logic corresponds to the policy tree construction logic. For example, it first matches the corresponding intermediate node based on the "source IP address mask" dimension, then matches child intermediate nodes under that intermediate node based on the "destination port number range" dimension, and so on, until the leaf node of the tree is reached. After finding the corresponding leaf node, the device can extract the policy memory offset address and data size stored in the leaf node, retrieve the packet filtering policy corresponding to that address, and finally compare the policy's dimension parameter value range with the packet feature parameters. If they match completely, the filtering action of that policy is executed; if they do not match, the device returns to the previous intermediate node and continues traversing other child nodes until a matching policy is found or it is confirmed that no matching policy exists (at this point, the default policy can be executed, such as blocking all unmatched packets).
[0094] For example, a data packet with a source IP of "10.0.0.5" (no corresponding template) enters the policy tree for matching. Starting from the root node, it first matches the intermediate node with "source IP address mask" of "10.0.0.0 / 24", then matches the child intermediate node with "protocol type = UDP" under that node, and finally locates the "block UDP protocol data packets of 10.0.0.0 / 24 network segment" policy stored in the leaf node. After comparing the data packet characteristics and finding a complete match, the blocking action is executed.
[0095] In the packet filtering process described above, the priority of packet filtering policies is not fixed but may be updated in real time as network services change. For example, adding, deleting, or modifying packet filtering policies will change the inclusion relationship between policies, thus requiring dynamic priority updates. If the priority update process and the packet filtering policy execution process share the same process or thread, when the number of policies reaches millions, the computation time of priority updates will block policy execution, leading to packet matching delays and even network congestion.
[0096] To address this issue, in one embodiment, an asynchronous update mechanism can be employed. This involves deploying the process of determining the priority of packet filtering policies and the process of executing packet filtering policies that match data packets in the target policy template, respectively, in different processes or threads within the device. For example, a priority management thread and a policy execution thread can be created within the device system. The priority management thread is only responsible for real-time monitoring of policy additions, modifications, and deletions. When a policy change is detected, it re-determines the priority using a single-dimensional, multiple-detection approach and updates the policy's priority flag. This entire process does not participate in any data packet matching or filtering. The policy execution thread, on the other hand, focuses on data packet feature extraction, template matching, policy querying, and filtering actions. Only when a policy priority needs to be determined does it directly read the priority flag updated by the priority management thread, without waiting for the priority calculation to complete.
[0097] This asynchronous update and independent process / thread design ensures that priority updates and policy execution do not interfere with each other: on the one hand, real-time priority adjustment will not block the packet filtering process, ensuring the real-time nature of network protection; on the other hand, the policy execution process does not need to bear the resource consumption of priority calculation, further improving matching and execution efficiency, which is especially suitable for large-scale network scenarios with frequent policy changes and large packet traffic.
[0098] Corresponding to the aforementioned embodiments of the packet filtering policy management method, this application also provides a packet filtering policy management device. Figure 3 This is a schematic diagram illustrating the structure of a packet filtering policy management device according to an exemplary embodiment of this application. Figure 3 As shown, the device includes:
[0099] The strategy template matching module 301 is used to match the packet filtering strategy with the pre-built strategy template and store the matched packet filtering strategy in the corresponding category of the strategy template; wherein, each category of strategy template is configured with the value range of at least two dimensions of parameters, and the combination of the dimensions of the parameters represented by different strategy templates is different.
[0100] The candidate packet filtering strategy screening module 302 is used to filter candidate packet filtering strategies from packet filtering strategies that do not match the strategy template. The candidate packet filtering strategy is a packet filtering strategy whose value range overlaps with the parameter configured in the strategy template.
[0101] The candidate packet filtering strategy splitting module 303 is used to split the value range of parameters that overlap with the strategy template from the candidate packet filtering strategy, generate a new packet filtering strategy, and store the new packet filtering strategy into the corresponding strategy template.
[0102] The policy tree storage module 304 is used to take the value range of the remaining parameters in the candidate packet filtering policy that do not overlap with the policy template as another new packet filtering policy, and store the other new packet filtering policy and other packet filtering policies that do not match the policy template into the policy tree.
[0103] The specific implementation process of the functions and roles of each module in the above-mentioned device can be found in the implementation process of the corresponding steps in the above-mentioned packet filtering strategy management method, and will not be repeated here.
[0104] Corresponding to the embodiments of the aforementioned packet filtering method, this application also provides a packet filtering device. Figure 4 This is a schematic diagram illustrating the structure of a data packet filtering device according to an exemplary embodiment of this application. Figure 4 As shown, the device includes:
[0105] The data packet acquisition module 401 is used to acquire the data packets to be filtered;
[0106] Template matching module 402 is used to match data packets with the policy templates described in any of the foregoing embodiments;
[0107] The template policy matching module 403 is used to execute the packet filtering policy in the target policy template that matches the data packet when a target policy template that matches the data packet exists.
[0108] The tree policy matching module 404 is used to execute the packet filtering policy that matches the packet in the policy tree described in any of the foregoing embodiments when there is no target policy template that matches the packet.
[0109] The specific implementation process of the functions and roles of each module in the above-mentioned device can be found in the implementation process of the corresponding steps in the above-mentioned data packet filtering method, and will not be repeated here.
[0110] For the device embodiments, since they basically correspond to the method embodiments, the relevant parts can be referred to in the description of the method embodiments. The device embodiments described above are merely illustrative. The modules described as separate components may or may not be physically separate, and the components shown as modules may or may not be physical modules, that is, they may be located in one place or distributed across multiple network modules. Some or all of the modules can be selected to achieve the purpose of this application according to actual needs. Those skilled in the art can understand and implement this without creative effort.
[0111] Corresponding to the aforementioned embodiments of packet filtering policy management method and data packet filtering method, this application also provides a computer device, including a memory, a processor, and a computer program stored in the memory and executable on the processor; wherein, when the processor executes the computer program, it implements the steps of the packet filtering policy management method or data packet filtering method described in any of the above embodiments.
[0112] For example, processors include, but are not limited to, central processing units (CPUs), graphics processing units (GPUs), digital signal processors (DSPs), application-specific integrated circuits (ASICs), or field-programmable gate arrays (FPGAs).
[0113] For example, the memory may include at least one type of storage medium, including flash memory, hard disk, multimedia card, card-type memory (e.g., SD or DX memory, etc.), random access memory (RAM), static random access memory (SRAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), programmable read-only memory (PROM), magnetic memory, disk, optical disk, etc.
[0114] Figure 5 This is a schematic diagram illustrating the structure of a computer device according to an exemplary embodiment of this application. Figure 5As shown, at the hardware level, the computer device includes a processor 501, an internal bus 502, a network interface 503, memory 504, and non-volatile memory 505, and may also include other hardware required for business operations. One or more embodiments of this application can be implemented in software, for example, the processor 501 reads the corresponding computer program from the non-volatile memory 505 into memory 504 and then runs it. Of course, in addition to software implementation, one or more embodiments of this application do not exclude other implementation methods, such as logic devices or a combination of hardware and software, etc. That is to say, the execution subject of the above processing flow is not limited to each logic unit, but can also be hardware or logic devices.
[0115] Corresponding to the embodiments of the foregoing methods, this application also provides a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the steps of the packet filtering strategy management method or data packet filtering method described in any of the above embodiments.
[0116] Corresponding to the embodiments of the foregoing methods, this application also provides a computer program product, including a computer program that, when executed by a processor, implements the steps of the packet filtering strategy management method or data packet filtering method described in any of the above embodiments.
[0117] The foregoing has described specific embodiments of this application. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims may be performed in a different order than that shown in the embodiments and may still achieve the desired results. Furthermore, the processes depicted in the drawings do not necessarily require the specific or sequential order shown to achieve the desired results. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0118] Other embodiments of this application will readily occur to those skilled in the art upon consideration of the specification and practice of the invention filed herein. This application is intended to cover any variations, uses, or adaptations of this application that follow the general principles of this application and include common knowledge or customary techniques in the art not claimed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of this application are indicated by the foregoing claims.
[0119] It should be understood that this application is not limited to the precise structure described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of this application is limited only by the appended claims.
[0120] The above description is merely a preferred embodiment of this application and is not intended to limit this application. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of protection of this application.
Claims
1. A method for managing packet filtering strategies, characterized in that, Each packet filtering policy is configured with a range of values for multiple dimensions of parameters targeting data packets. The method includes: The packet filtering strategy is matched with a pre-built strategy template, and the matched packet filtering strategy is stored in the corresponding category of the strategy template; wherein, each category of strategy template is configured with the value range of at least two dimensions of parameters, and the combination of the dimensions of parameters represented by different strategy templates is different; Candidate packet filtering strategies are selected from the packet filtering strategies that do not match the strategy template. The candidate packet filtering strategies are packet filtering strategies whose value ranges overlap with the parameters configured in the strategy template. Extract the value range of parameters that overlap with the policy template from the candidate packet filtering strategy, generate a new packet filtering strategy, and store the new packet filtering strategy in the corresponding policy template; The remaining parameter values in the candidate packet filtering strategy that do not overlap with the strategy template are taken as another new packet filtering strategy, and the other new packet filtering strategy and other packet filtering strategies that do not match the strategy template are stored in the strategy tree.
2. The method according to claim 1, characterized in that, The steps to build a strategy template include: Determine the combination of parameters for different dimensions of the packet filtering strategy, and generate a corresponding basic strategy template for each combination. The number of matches between each packet filtering strategy and the basic strategy template is counted, and a preset number of basic strategy templates are selected as the strategy templates according to the number of matches from high to low.
3. The method according to claim 1, characterized in that, The matched packet filtering policies are stored in the corresponding category of the policy template, specifically including: Based on the value range of the parameters of each dimension of the matched packet filtering strategy, the hash value of the matched packet filtering strategy is calculated, and the matched packet filtering strategy and the corresponding hash value are associated and stored in the corresponding strategy template.
4. The method according to claim 1, characterized in that, Also includes: A policy template for a specified address is pre-built to store the filtering policy for that address; the policy template for the specified address and the policy template are stored in different storage areas.
5. The method according to any one of claims 1-4, characterized in that, Also includes: The inclusion relationship between each packet filtering strategy is determined based on the value range of the parameters in a single dimension. The inclusion relationship is determined by considering the range of values for parameters across all dimensions, and the overall inclusion relationship between each packet filtering strategy is then determined. Based on the overall inclusion relationship, the priority of the packet filtering strategy is determined according to the preset priority rules, so that the packet filtering strategy marked as high priority is executed first when filtering data packets.
6. A data packet filtering method, characterized in that, The method includes: Retrieve the data packets to be filtered; The data packet is matched with the policy template described in any one of claims 1-5; If a target policy template that matches the data packet exists, then the packet filtering policy in the target policy template that matches the data packet is executed; If no target policy template matches the data packet, then the packet filtering policy that matches the data packet in the policy tree according to any one of claims 1-5 shall be executed.
7. The method according to claim 6, characterized in that, Executing the packet filtering policy in the target policy template that matches the data packet includes: Execute the packet filtering policy in the target policy template that matches the data packet and is marked as high priority, wherein the priority of the packet filtering policy is determined in the following way: The inclusion relationship between each packet filtering strategy is determined based on the value range of the parameters in a single dimension. The inclusion relationship is determined by considering the range of values for parameters across all dimensions, and the overall inclusion relationship between each packet filtering strategy is then determined. Based on the overall inclusion relationship, the priority of the packet filtering strategy is determined according to a preset priority rule; The process of determining the priority of the packet filtering policy and the process of executing the packet filtering policy in the target policy template that matches the data packet are performed in different processes or threads.
8. A management device for a packet filtering strategy, characterized in that, Each packet filtering policy is configured with a range of values for multiple dimensions of parameters targeting data packets. The device includes: The strategy template matching module is used to match the packet filtering strategy with a pre-built strategy template and store the matched packet filtering strategy in the corresponding category of the strategy template; wherein, each category of strategy template is configured with the value range of at least two dimensions of parameters, and different strategy templates represent different combinations of the dimensions of the parameters. The candidate packet filtering strategy screening module is used to filter out candidate packet filtering strategies from the packet filtering strategies that do not match the strategy template. The candidate packet filtering strategies are packet filtering strategies that overlap with the value range of the parameters configured in the strategy template. The candidate packet filtering strategy splitting module is used to split the value range of parameters that overlap with the strategy template from the candidate packet filtering strategy, generate a new packet filtering strategy, and store the new packet filtering strategy into the corresponding strategy template. The strategy tree storage module is used to take the value range of the remaining parameters in the candidate packet filtering strategy that do not overlap with the strategy template as another new packet filtering strategy, and store the other new packet filtering strategy and other packet filtering strategies that do not match the strategy template into the strategy tree.
9. A data packet filtering device, characterized in that, The device includes: The data packet acquisition module is used to acquire the data packets to be filtered. A template matching module is used to match the data packet with the policy template described in any one of claims 1-5; The template policy matching module is used to execute the packet filtering policy in the target policy template that matches the data packet when a target policy template that matches the data packet exists. The tree policy matching module is used to execute the packet filtering policy that matches the data packet in the policy tree as described in any one of claims 1-5 when there is no target policy template that matches the data packet.
10. A computer device, characterized in that, The method includes a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor, when executing the computer program, implements the method according to any one of claims 1 to 7.
Citation Information
Patent Citations
Filtering strategy management system and method
CN111131197A
Verification device and method for packet filtering strategy
CN114143079A
Firewall policy conflict detection method and device
CN116094777A
Data packet filtering method and device
CN120110738A
Cited By
Security policy tree construction method and device, storage medium and computing equipment
CN121509107A
TCP connection filtering method and device, equipment and storage medium
CN121887460A