Method and apparatus for managing security policies based on PaC
Through PaC management of security policies, abstract business requirements to generate policy plans and conduct test evaluation and version management, it solves the problem that traditional security policies cannot be changed simultaneously, and improves security operation and maintenance efficiency and business continuity.
Patent Information
- Application Number
- CN202111575937.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-21
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2041-12-21
AI Technical Summary
In the existing security operation and maintenance technology, traditional security policies are separated from applications, resulting in the inability to change security policies simultaneously, increasing the probability of false interception and manual operation failure, and high management complexity in heterogeneous environments.
PaC is used to manage security policies, generate business rules through abstract business requirements, form policy plans, and conduct test evaluation and version management through policy agents, and use code management to unify security policies.
It improves security operation and maintenance efficiency, reduces failure rate and misoperation, and realizes unified management of security policies and business continuity.
Smart Images

Figure CN114254301B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of cloud computing technology, specifically to the field of security operation and maintenance technology, and more specifically to a method, device, equipment, medium and program product for managing security policies based on PaC. Background Art
[0002] With the advent of the information age and the implementation of cloud computing technology in various fields, traditional security operation and maintenance has also entered a new era of automation and coding. Existing devices or software such as firewalls, wafs, and IDSs all provide a large and complex graphical user interface (GUI), which improves usability and is friendly to security administrators.
[0003] Since the devices of each manufacturer are different, the graphical user interfaces (GUIs) are also different. Especially in a heterogeneous environment, that is, there are multiple and multi-vendor security devices. As the quantity and heterogeneity increase, it adds complexity to management and operation and maintenance.
[0004] In addition, since traditional technology security policies and application programs are separated, dedicated security devices manage security policies, and application programs apply to security devices for open access permissions. When application programs change and iterate, the original security access policies for this application program are often ignored, and the security policies cannot be changed synchronously, resulting in misinterception. Moreover, traditional security policies are managed by humans, which are not easy to version and repeat, increasing the probability of manual operation failure. Summary of the Invention
[0005] In view of the above problems, the present disclosure provides a method, device, equipment, medium and program product for managing security policies based on PaC.
[0006] According to a first aspect of the present disclosure, there is provided a method for managing security policies based on PaC, including: determining at least one business rule according to the business requirement information of the application program;
[0007] Generating a policy plan according to the business rule;
[0008] Matching a policy agent according to the business rule and the policy plan;
[0009] Testing and evaluating the policy plan according to the matched policy agent; and
[0010] When it is determined that the policy plan test is successful, performing version management on the application program and the policy plan.
[0011] According to an embodiment of the present disclosure, the method further includes:
[0012] Generating at least one policy agent according to the device type and API documentation;
[0013] Define the resource scope of the policy agent to form a resource scope definition code, where the resource scope includes bandwidth volume, number of users, and response time; and
[0014] Write the resource scope definition code into the resource configuration database.
[0015] According to an embodiment of the present disclosure, the generating a policy plan according to the service rule includes:
[0016] Abstract and aggregate the service rules to form a service rule set; and
[0017] Generate a policy plan code according to the service rule set in accordance with the PaC standard.
[0018] According to an embodiment of the present disclosure, the matching a policy agent according to the service rule and the policy plan includes:
[0019] Obtain the resource scope definition code; and
[0020] Match the resource scope definition code according to the service rule and the policy plan to determine the policy agent.
[0021] According to an embodiment of the present disclosure, the version management of the application program and the policy plan includes:
[0022] Obtain the application program identification information and obtain at least one policy plan code corresponding to the application program;
[0023] Save the application program identification information and the policy plan code into the code library.
[0024] A second aspect of the present disclosure provides a device for managing security policies based on PaC, including:
[0025] A service rule determination module, configured to determine at least one service rule according to the service requirement information of the application program;
[0026] A policy plan generation module, configured to generate a policy plan according to the service rule;
[0027] A matching module, configured to match a policy agent according to the service rule and the policy plan;
[0028] A test and evaluation module, configured to test and evaluate the policy plan according to the matched policy agent; and
[0029] A version management module, configured to perform version management on the application program and the policy plan when it is determined that the policy plan test is successful.
[0030] According to an embodiment of the present disclosure, a policy agent generation module is configured to generate at least one policy agent according to the device type and API documentation.
[0031] A resource scope definition module is configured to define the resource scope of the policy agent to form a resource scope definition code, where the resource scope includes bandwidth amount, number of users, and response time.
[0032] A third aspect of the present disclosure provides an electronic device, including: one or more processors; a memory for storing one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors are caused to execute the method for managing security policies based on PaC as described above.
[0033] A fourth aspect of the present disclosure further provides a computer-readable storage medium, on which executable instructions are stored, and when the instructions are executed by a processor, the processor is caused to execute the method for managing security policies based on PaC as described above.
[0034] A fifth aspect of the present disclosure further provides a computer program product, including a computer program, and when the computer program is executed by a processor, the method for managing security policies based on PaC as described above is implemented.
[0035] Through the method for managing security policies based on PaC provided by the embodiments of the present disclosure, by performing adaptation development on traditional security device APIs or automation scripts, multiple policy agents are obtained, business requirements are abstracted to generate business rules, and multiple business rules are formed into a policy plan; and the policy plan code is tested to improve the success rate of code execution, and version management is performed on the policy plan code that passes the test. Using code management, unified management of security policies can be achieved, the efficiency of security operation and maintenance and business continuity are improved, and the failure rate and misoperation are reduced. Description of the Drawings
[0036] Through the following description of the embodiments of the present disclosure with reference to the drawings, the above content and other objects, features, and advantages of the present disclosure will become clearer. In the drawings:
[0037] Figure 1 Schematically shows a flowchart of a method for managing security policies based on PaC according to an embodiment of the present disclosure;
[0038] Figure 2 Schematically shows a flowchart of a method for generating a policy agent according to an embodiment of the present disclosure;
[0039] Figure 3 Schematically shows a flowchart of another method for managing security policies based on PaC according to an embodiment of the present disclosure;
[0040] Figure 4Schematically shows a structural block diagram of an apparatus for managing security policies based on PaC according to an embodiment of the present disclosure; and
[0041] Figure 5 Schematically shows a block diagram of an electronic device suitable for implementing a method for managing security policies based on PaC according to an embodiment of the present disclosure. Detailed implementation manners
[0042] Hereinafter, embodiments of the present disclosure will be described with reference to the accompanying drawings. However, it should be understood that these descriptions are merely exemplary and are not intended to limit the scope of the present disclosure. In the following detailed description, for the sake of explanation, many specific details are set forth in order to provide a comprehensive understanding of the embodiments of the present disclosure. However, obviously, one or more embodiments can also be implemented without these specific details. In addition, in the following description, descriptions of well-known structures and technologies are omitted to avoid unnecessarily obscuring the concepts of the present disclosure.
[0043] The terms used herein are merely for describing specific embodiments and are not intended to limit the present disclosure. The terms "including", "comprising", etc. used herein indicate the presence of the described features, steps, operations, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, or components.
[0044] All terms used herein (including technical and scientific terms) have the meanings commonly understood by those skilled in the art, unless otherwise defined. It should be noted that the terms used herein should be interpreted as having a meaning consistent with the context of this specification and should not be interpreted in an idealized or overly rigid manner.
[0045] In the case of using expressions such as "at least one of A, B, and C", generally, it should be interpreted according to the meaning usually understood by those skilled in the art (for example, "a system having at least one of A, B, and C" should include, but is not limited to, a system having only A, only B, only C, having A and B, having A and C, having B and C, and / or having A, B, and C).
[0046] First, the terms appearing in the embodiments of the present disclosure are explained:
[0047] WAF (Web Application Firewall, WAF): A web application firewall, a product that specifically provides protection for web applications by executing a series of security policies for HTTP / HTTPS. Based on a deep understanding of the business and logic of web applications, WAF performs content detection and verification on various requests from the clients of web applications to ensure their security and legality, and blocks illegal requests in real time, thereby effectively protecting various website sites.
[0048] IaC (Infrastructure as Code, IaC), that is, infrastructure as code, creates, configures, and deploys infrastructure components by writing code. These infrastructure components include various types of cloud resources, such as networks, computing, databases, security controls, and management tools, etc.
[0049] DevOps: The combination of people, processes, and products that can continuously deliver value to end users.
[0050] PaC (Policy as Code, PaC) policy as code, codifies policies and manages policies using code management methods.
[0051] Based on the above technical problems, embodiments of the present disclosure provide a method for managing security policies based on PaC. The method includes: determining at least one business rule according to the business requirement information of the application; generating a policy plan according to the business rule; matching a policy agent according to the business rule and the policy plan; testing and evaluating the policy plan according to the matched policy agent; and when it is determined that the policy plan test is successful, performing version management on the application and the policy plan.
[0052] Through the method for managing security policies based on PaC provided by the embodiments of the present disclosure, by adapting and developing traditional security device APIs or automation scripts, multiple policy agents are obtained, business requirements are abstracted to generate business rules, and multiple business rules form a policy plan; and the policy plan code is tested to improve the success rate of code execution, and version management is performed on the policy plan code that passes the test. Using code management, security policies can be uniformly managed, improving the efficiency of security operation and maintenance and business continuity, and reducing failure rates and misoperations.
[0053] The application scenario of the method for managing security policies based on PaC provided in this embodiment can be a security operation and maintenance scenario. Developers obtain the business requirements of the application. For example, for an application, it is required to enable http and https services, that is, ports 80 and 443; it is required to prohibit IP addresses with source address A from accessing port 80 of this application from 21:20:15 to 22:20:15 every day, and a firewall of brand B of a certain manufacturer of security devices. Abstract the business requirements into multiple business rules, that is, open ports 80 and 443 for application A, and it is required to prohibit IP addresses with source address A from accessing port 80 of this application from 21:00 to 22:00 every day. Aggregate multiple business rules into a policy plan code, allocate it to the corresponding developed policy agent, and after the execution of the policy plan code is successful in the test, implement it in the production environment, and include the application and the policy plan in version management together.
[0054] The following will be throughFigures 1 to 3 A method for managing security policies based on PaC for publicly disclosed embodiments is described in detail.
[0055] Figure 1 A flowchart of a method for managing security policies based on PaC according to an embodiment of the present disclosure is schematically shown.
[0056] As Figure 1 shown, the method for managing security policies based on PaC in this embodiment includes operations S210 to S250, and this method can be executed by a server or other computing devices.
[0057] In operation S210, at least one business rule is determined according to the business requirement information of the application.
[0058] In one example, first, the business requirement information of the application is obtained. The business requirement information in the embodiments of the present disclosure generally refers to the security requirements of business personnel. Generally speaking, the business requirement information of the application can be abstracted into multiple business rules. Combining with the application scenario, for example, for a certain application, it is necessary to open the http and https services, that is, ports 80 and 443, and it is necessary to prohibit IP addresses with source address A from accessing port 80 of this application during a specific time period (21:00 - 22:00), and a firewall of brand B of a certain manufacturer of security devices. According to the above business requirement information, the business rules are determined: open ports 80 and 443 for application A; prohibit IP addresses with source address A from accessing port 80 of this application every day during the specific time period.
[0059] In operation S220, a policy plan is generated according to the business rules.
[0060] In one example, a policy plan is generated according to the business rules obtained in operation S210. The policy plan is usually declarative code and is represented in json format.
[0061] For example, it can be:
[0062] with_items:
[0063] -http
[0064] -deny 21:00:00 - 22:00:00
[0065] -https
[0066] In operation S230, a policy agent is matched according to the business rules and the policy plan.
[0067] In a practical environment, developers develop multiple policy agents according to information such as device type and manufacturer API. Each policy agent corresponds to a physical device of a different manufacturer. According to business rules, the security device for the application is determined to be a firewall of brand B of a certain manufacturer, and then the policy agent matching the policy plan is determined.
[0068] In operation S240, test and evaluate the policy plan according to the matching policy agent.
[0069] In one example, in this operation, the policy plan obtained in operation S230 needs to be assigned to the matching policy agent for test and evaluation. Each policy agent has a predefined resource range, and these resource ranges characterize the capabilities of the policy agent, such as capacity (bandwidth amount, number of users), speed (response time), Mac address, etc. Evaluate the resources in the policy agent by comparing the attributes of these resources with business rules. These resources can also be, for example, firewall rules, the supported situations of firewall products, attributes such as five-tuples, time, and statistical ratios. Execute the policy plan and confirm the execution situation of the policy plan to improve the success rate of policy plan execution.
[0070] In operation S250, when it is determined that the policy plan test is successful, perform version management on the application and the policy plan.
[0071] In one example, when it is determined that the policy plan test is successful, where the sign of successful test is based on the effective implementation of the security device policy plan, that is, the current policy plan can be normally executed and take effect, then the application and the policy plan are incorporated into git for version management together. Different applications correspond to one or more policy plans (policy codes), and the relationship between policy codes and applications is many-to-one; when it is determined that the policy plan test fails, that is, the current policy plan cannot be normally executed and take effect, then it is necessary to re-execute operations S210 to S240, modify the policy plan and the policy agent, and retest.
[0072] Through the method for managing security policies based on PaC provided by the embodiments of the present disclosure, business requirements are abstracted to generate business rules, and multiple business rules are formed into a policy plan; and the policy plan code is tested to improve the success rate of code execution. Version management is performed on the successfully tested policy plan code. Using code management, unified management of security policies can be achieved, improving the efficiency of security operation and maintenance and business continuity, and reducing failure rates and misoperations.
[0073] Next, in combination with Figure 2 introduce the generation process of the policy agent, Figure 2 The flowchart of the policy agent generation method according to the embodiments of the present disclosure is schematically shown.
[0074] AsFigure 2 As shown, it includes operations S310 to S330.
[0075] In operation S310, at least one policy agent is generated according to the device type and API documentation.
[0076] In one example, since existing security device manufacturers provide their own unique graphical user interfaces (GUIs), and different devices have different GUIs, in a large infrastructure environment, multiple multi-vendor security devices form a heterogeneous environment, resulting in disadvantages such as numerous and chaotic security policies, high management costs, and lack of flexibility. Therefore, in this operation, first, adaptation development is carried out according to the device type, the API provided by the manufacturer, or the automation tool script (such as the playbook for different devices in Ansible) to obtain the policy agent for heterogeneous devices. In an actual environment, multiple policy agents can be developed, and each policy agent corresponds to a physical device of a different manufacturer.
[0077] In operation S320, the resource scope of the policy agent is defined to form a resource scope definition code. In operation S330, the resource scope definition code is written into the resource configuration database.
[0078] In operation S320, after obtaining the policy agent for the heterogeneous environment, in order to enable the policy plan to run normally, it is necessary to define the resource scope of the policy agent according to the capabilities of the policy agent. The resource scope includes parameters such as bandwidth, number of users, and response time, etc., to form a resource scope definition code. And the resource definition code rules obtained in the above steps are written into the resource configuration database for storage.
[0079] Figure 3 Schematically shows a flowchart of another method for managing security policies based on PaC according to an embodiment of the present disclosure. As Figure 3 shown, it mainly includes operations S410 to S470.
[0080] In operation S410, at least one business rule is determined according to the business requirement information of the application.
[0081] This operation is Figure 1 the same as the technical solution and principle of operation S210 shown, and will not be elaborated here.
[0082] In operation S420, a policy plan is generated according to the business rule.
[0083] The steps from business rules to a strategic plan are as follows. First, abstract and aggregate the business rules to form a set of business rules. To achieve generality, the policy access code in the embodiments of the present disclosure adopts the JSON format and complies with the mainstream PaC standard in the industry, and generates a strategic plan code from the set of business rules according to the PaC standard.
[0084] After generating the strategic plan, it is necessary to match the corresponding policy agent for execution according to the strategic plan, which specifically includes operation S430 and operation S440.
[0085] In operation S430, obtain the resource scope definition code. In operation S440, match the resource scope definition code according to the business rules and the strategic plan to determine the policy agent.
[0086] In one example, operation S430 and operation S440 are the processes of matching the strategic plan with the policy agent, obtaining the resource scope definition code from the resource configuration database, and determining the policy agent that can execute the strategic plan according to the device type required in the business rules.
[0087] In operation S450, test and evaluate the strategic plan according to the matched policy agent.
[0088] This operation is the same as Figure 1 the technical solution and principle of operation S240 shown, and will not be elaborated here.
[0089] In operation S460, when it is determined that the strategic plan test is successful, perform version management on the application program and the strategic plan.
[0090] In one example, when it is determined that the strategic plan test is successful, for example, whether the firewall device in the above example supports the time dimension (prohibiting IP addresses with source address A from accessing port 80 from 21:00 to 22:00), after the test is successful, it is implemented in the formal environment and managed in the git code library. The above version management includes the management of application programs and policy codes. Different application programs correspond to one or more policy codes, and the relationship between policy codes and application programs is many-to-one. Obtain the application program identification information and obtain at least one strategic plan code corresponding to the application program; save the application program identification information and the strategic plan code to the code library. By using the code to uniformly manage traditional physical devices, replacing the inefficiency and uncertainty of manual management, making security operation and maintenance no longer depend on personal capabilities and experience, and combining with the current cloud computing PaC standard, improving the manageability of traditional devices.
[0091] Figure 4 Schematically shows a structural block diagram of a device for managing security policies based on PaC according to an embodiment of the present disclosure.
[0092] As Figure 4As shown, the process instance generation device 500 based on a structured process template in this embodiment includes a business rule determination module 510, a policy plan generation module 520, a matching module 530, a test evaluation module 540, and a version management module 550.
[0093] The business rule determination module 510 is used to determine at least one business rule according to the business requirement information of the application. In one embodiment, the business rule determination module 510 can be used to perform the operation S210 described above, which will not be elaborated here.
[0094] The policy plan generation module 520 is used to generate a policy plan according to the business rule. In one embodiment, the policy plan generation module 520 can be used to perform the operation S220 described above, which will not be elaborated here.
[0095] The matching module 530 is used to match a policy agent according to the business rule and the policy plan. In one embodiment, the matching module 530 can be used to perform the operation S230 described above, which will not be elaborated here.
[0096] The test evaluation module 540 is used to test and evaluate the policy plan according to the matched policy agent. In one embodiment, the test evaluation module 540 can be used to perform the operation S240 described above, which will not be elaborated here.
[0097] The version management module 550 is used to perform version management on the application and the policy plan when it is determined that the policy plan test is successful. In one embodiment, the version management module 550 can be used to perform the operation S250 described above, which will not be elaborated here.
[0098] According to an embodiment of the present disclosure, it further includes:
[0099] A policy agent generation module 560, which is used to generate at least one policy agent according to the device type and the API document. In one embodiment, the policy agent generation module 560 can be used to perform the operation S310 described above, which will not be elaborated here.
[0100] A resource scope definition module 570, which defines the resource scope of the policy agent to form a resource scope definition code. The resource scope includes bandwidth amount, number of users, and response time. In one embodiment, the resource scope definition module 570 can be used to perform the operation S320 described above, which will not be elaborated here.
[0101] According to an embodiment of the present disclosure, any combination of the service rule determination module 510, the policy plan generation module 520, the matching module 530, the test and evaluation module 540, the version management module 550, the policy agent generation module 560, and the resource scope definition module 570 may be combined and implemented in one module, or any one of them may be split into multiple modules. Alternatively, at least part of the functions of one or more of these modules may be combined with at least part of the functions of other modules and implemented in one module. According to an embodiment of the present disclosure, at least one of the service rule determination module 510, the policy plan generation module 520, the matching module 530, the test and evaluation module 540, the version management module 550, the policy agent generation module 560, and the resource scope definition module 570 may be at least partially implemented as a hardware circuit, such as a field programmable gate array (FPGA), a programmable logic array (PLA), a system on chip, a system on substrate, a system on package, an application specific integrated circuit (ASIC), or any other reasonable way of integrating or packaging circuits, etc., implemented by hardware or firmware, or implemented in any one of the three implementation manners of software, hardware, and firmware, or in any appropriate combination of several of them. Alternatively, at least one of the service rule determination module 510, the policy plan generation module 520, the matching module 530, the test and evaluation module 540, the version management module 550, the policy agent generation module 560, and the resource scope definition module 570 may be at least partially implemented as a computer program module, which can perform corresponding functions when the computer program module is run.
[0102] Figure 5 Schematically shows a block diagram of an electronic device suitable for implementing a method for managing a security policy based on PaC according to an embodiment of the present disclosure.
[0103] As Figure 5 shown, the electronic device 900 according to an embodiment of the present disclosure includes a processor 901, which can perform various appropriate actions and processes according to a program stored in a read only memory (ROM) 902 or a program loaded from a storage section 908 into a random access memory (RAM) 903. The processor 901 may include, for example, a general microprocessor (such as a CPU), an instruction set processor, and / or a related chipset, and / or a dedicated microprocessor (such as an application specific integrated circuit (ASIC)), etc. The processor 901 may also include on-board memory for caching purposes. The processor 901 may include a single processing unit or multiple processing units for performing different actions of the method flow according to an embodiment of the present disclosure.
[0104] In the RAM 903, various programs and data required for the operation of the electronic device 900 are stored. The processor 901, the ROM 902, and the RAM 903 are connected to each other via a bus 904. The processor 901 performs various operations of the method flow according to the embodiments of the present disclosure by executing the programs in the ROM 902 and / or the RAM 903. It should be noted that the programs can also be stored in one or more memories other than the ROM 902 and the RAM 903. The processor 901 can also perform various operations of the method flow according to the embodiments of the present disclosure by executing the programs stored in one or more memories.
[0105] According to an embodiment of the present disclosure, the electronic device 900 may further include an input / output (I / O) interface 905, and the input / output (I / O) interface 905 is also connected to the bus 904. The electronic device 900 may further include one or more of the following components connected to the I / O interface 905: an input portion 906 including a keyboard, a mouse, etc.; an output portion 907 including a cathode ray tube (CRT), a liquid crystal display (LCD), etc. and a speaker, etc.; a storage portion 908 including a hard disk, etc.; and a communication portion 909 including a network interface card such as a LAN card, a modem, etc. The communication portion 909 performs communication processing via a network such as the Internet. A drive 910 is also connected to the I / O interface 905 as needed. A removable medium 911, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 910 as needed so that a computer program read from it can be installed into the storage portion 908 as needed.
[0106] The present disclosure also provides a computer-readable storage medium, which may be included in the device / device / system described in the above embodiments; or may exist separately without being assembled into the device / device / system. The above computer-readable storage medium carries one or more programs, and when the one or more programs are executed, the method according to the embodiments of the present disclosure is implemented.
[0107] According to an embodiment of the present disclosure, the computer-readable storage medium may be a non-volatile computer-readable storage medium, which may include, for example, but not limited to: portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the above. In the present disclosure, the computer-readable storage medium may be any tangible medium that contains or stores a program, and this program can be used by or in conjunction with an instruction execution system, apparatus, or device. For example, according to an embodiment of the present disclosure, the computer-readable storage medium may include the above-described ROM 902 and / or RAM 903 and / or one or more memories other than ROM 902 and RAM 903.
[0108] An embodiment of the present disclosure further includes a computer program product, which includes a computer program that contains program code for executing the method shown in the flowchart. When the computer program product runs in a computer system, the program code is used to enable the computer system to implement the method for managing security policies based on PaC provided by the embodiments of the present disclosure.
[0109] When the computer program is executed by the processor 901, it executes the above functions defined in the system / apparatus of the embodiments of the present disclosure. According to an embodiment of the present disclosure, the above-described systems, apparatuses, modules, units, etc. can be implemented by computer program modules.
[0110] In one embodiment, the computer program may rely on tangible storage media such as optical storage devices and magnetic storage devices. In another embodiment, the computer program may also be transmitted and distributed in the form of a signal on a network medium, and be downloaded and installed through the communication part 909, and / or be installed from the removable medium 911. The program code contained in the computer program can be transmitted by any suitable network medium, including but not limited to: wireless, wired, etc., or any suitable combination of the above.
[0111] In such an embodiment, the computer program can be downloaded and installed from the network through the communication part 909, and / or be installed from the removable medium 911. When the computer program is executed by the processor 901, it executes the above functions defined in the system of the embodiments of the present disclosure. According to an embodiment of the present disclosure, the above-described systems, devices, apparatuses, modules, units, etc. can be implemented by computer program modules.
[0112] According to embodiments of the present disclosure, program code for executing the computer programs provided by the embodiments of the present disclosure can be written in any combination of one or more programming languages. Specifically, these computing programs can be implemented using high-level procedural and / or object-oriented programming languages, and / or assembly / machine languages. Programming languages include, but are not limited to, such as Java, C++, Python, the "C" language, or similar programming languages. The program code can be executed entirely on the user's computing device, partially on the user's device, partially on a remote computing device, or entirely on a remote computing device or server. In cases involving a remote computing device, the remote computing device can be connected to the user's computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computing device (e.g., by using an Internet service provider to connect through the Internet).
[0113] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present disclosure. In this regard, each block in the flowchart or block diagram can represent a module, a program segment, or a part of code that contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks can occur in a different order than marked in the accompanying drawings. For example, two consecutive blocks shown can actually be executed substantially in parallel, and they can sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram or flowchart, and combinations of blocks in the block diagram or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.
[0114] Those skilled in the art can understand that the features recited in the various embodiments and / or claims of the present disclosure can be combined or / and combined in various ways, even if such combinations or combinations are not explicitly recited in the present disclosure. In particular, without departing from the spirit and teachings of the present disclosure, the features recited in the various embodiments and / or claims of the present disclosure can be combined and / or combined in various ways. All such combinations and / or combinations fall within the scope of the present disclosure.
[0115] The embodiments of the present disclosure have been described above. However, these embodiments are for illustrative purposes only and are not intended to limit the scope of the present disclosure. Although the embodiments have been described separately above, this does not mean that the measures in each embodiment cannot be used advantageously in combination. The scope of the present disclosure is defined by the appended claims and their equivalents. Without departing from the scope of the present disclosure, those skilled in the art can make various substitutions and modifications, and these substitutions and modifications should fall within the scope of the present disclosure.
Claims
1. A method for managing security policies based on PaC, characterized in that, The method includes: Determining at least one business rule according to the business requirement information of the application program; Generating a policy plan according to the business rule; Matching a policy agent according to the business rule and the policy plan; Testing and evaluating the policy plan according to the matched policy agent; and When it is determined that the policy plan test is successful, performing version management on the application program and the policy plan. The method further includes: Generating at least one policy agent according to the device type and API documentation; Defining the resource scope of the policy agent to form a resource scope definition code, where the resource scope includes bandwidth volume, number of users, and response time; and Writing the resource scope definition code into the resource configuration database.
2. The method according to claim 1, wherein The generating a policy plan according to the business rule includes: Abstracting and aggregating business rules to form a business rule set; and Generating a policy plan code according to the business rule set in accordance with the PaC standard.
3. The method according to claim 1, wherein The matching a policy agent according to the business rule and the policy plan includes: Obtaining a resource scope definition code; and Matching the resource scope definition code according to the business rule and the policy plan to determine a policy agent.
4. The method according to claim 2, wherein The performing version management on the application program and the policy plan includes: Obtaining application program identification information and obtaining at least one policy plan code corresponding to the application program; Saving the application program identification information and the policy plan code into a code library.
5. An apparatus for managing security policies based on PaC, characterized in that, including: A business rule determination module, configured to determine at least one business rule according to the business requirement information of the application program; A policy plan generation module, configured to generate a policy plan according to the business rule; A matching module, configured to match a policy agent according to the business rule and the policy plan; A test evaluation module, configured to test and evaluate the policy plan according to the matched policy agent; and A version management module, configured to perform version management on the application program and the policy plan when it is determined that the policy plan test is successful: A policy agent generation module, configured to generate at least one policy agent according to the device type and API documentation; A resource scope definition module, configured to define the resource scope of the policy agent to form a resource scope definition code, where the resource scope includes bandwidth volume, number of users, and response time.
6. An electronic device, including: One or more processors; A storage device, configured to store one or more programs, wherein, when the one or more programs are executed by the one or more processors, the one or more processors are caused to execute the method according to any one of claims 1 to 4.
7. A computer-readable storage medium, on which executable instructions are stored, and when the instructions are executed by a processor, the processor is caused to execute the method according to any one of claims 1 to 4.
8. A computer program product, including a computer program, and when the computer program is executed by a processor, the method according to any one of claims 1 to 4 is implemented.