Data query method, device, apparatus, and storage medium

By utilizing the order characteristics of address and answer array sets in terminal linkage scenarios, the identifier and structural information of terminal addresses can be determined, solving the problem of low efficiency in traditional firewall policy query and achieving efficient policy distribution.

CN114780572BActive Publication Date: 2025-11-25SANGFOR TECH INC
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202210265605.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-03-17
Publication Date
2025-11-25
Estimated Expiration
2042-03-17

AI Technical Summary

Technical Problem

In terminal-interconnected scenarios, traditional firewall policy query and parsing takes a long time, resulting in extremely low query and distribution efficiency, making it difficult to meet the needs of rapid querying of massive policies.

Method used

The terminal address information is obtained by traversing the array, the identification information is determined by combining the preset address array set, and the answer structure information is determined by using the intermediate structure information in the answer array set to form the target data. Finally, the data is sent to the terminal.

Benefits of technology

It improves the efficiency of querying and distributing massive strategies. By integrating terminal and strategy address information, it optimizes the query process, reduces unnecessary structural information, and improves the accuracy and efficiency of data query.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114780572B_ABST
    Figure CN114780572B_ABST
Patent Text Reader

Abstract

The application provides a data query method, device and equipment and a storage medium, comprising the following steps: obtaining a plurality of terminal address information through traversal, combining address array sets to determine the identification information of the Mth terminal address information; the address array set is an integer set obtained by fusing the known terminal address information and the known strategy address information; using the identification information to determine the answer structure information corresponding to the Mth terminal address information in the preset answer array set to form the current target data; the answer array set is determined by combining the intermediate structure information and the order characteristics of the corresponding strategy data in the address array set; the intermediate structure information is array information representing application and action determined by the corresponding known strategy data; combining the current target data, the remaining terminal address information is continuously traversed until the plurality of terminal address information is traversed to obtain the target data; and the scheme improves the query and delivery efficiency of the mass strategy.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] Embodiments of the present application relate to the technical field of network security, and particularly relate to a data query method and device, equipment and a storage medium. BACKGROUND

[0002] With the diversification of network environment security, it is difficult for a firewall product to meet the needs of customers. Accordingly, there is an urgent need for a firewall + terminal linkage scene strategy to solve complex security problems. In the case of a terminal linkage scene, when a large number of strategies are issued to the corresponding terminal, the server needs to parse and query the strategies one by one and issue them. The traditional merging algorithm consumes a lot of time in strategy query and parsing, which further leads to extremely low query and issuance efficiency. SUMMARY

[0003] The data query method, device, equipment and storage medium provided by the embodiments of the present application can improve the query and issuance efficiency of a large number of strategies.

[0004] The technical solution of the present application is implemented as follows:

[0005] The data query method provided by the embodiments of the present application comprises:

[0006] The acquired plurality of terminal address information is traversed, and the identification information of the Mth terminal address information is determined in combination with a preset address array set; the address array set is an integer set obtained by fusing known terminal address information and known strategy address information; M is an integer greater than or equal to 1;

[0007] The identification information is used to determine the answer structure information corresponding to the Mth terminal address information in a preset answer array set, so as to form a current target data; wherein the answer array set is determined in the order feature in the address array set by combining the corresponding known strategy data with intermediate structure information; the intermediate structure information is array information representing an application and an action determined by the corresponding known strategy data;

[0008] In combination with the current target data, the remaining terminal address information is continuously traversed until the traversal of the plurality of terminal address information is completed, a target data is obtained, and the target data is sent to the terminal corresponding to the plurality of terminal address information.

[0009] In the above solution, before the acquired plurality of terminal address information is traversed and the identification information of the Mth terminal address information is determined in combination with a preset address array set, the method further comprises:

[0010] According to a predetermined order, a plurality of predictive strategy data is traversed, a preset application array set is used, application class and action class information of the Nth predictive strategy data is combined, and the Nth structure information is determined; the application array set represents a sorting set corresponding to a plurality of application class information contained in the plurality of predictive strategy data; N is an integer greater than 1;

[0011] The Nth predictive strategy address information of the Nth predictive strategy data is determined, and the corresponding Nth order feature information in the address array set is determined;

[0012] The Nth order feature information is compared with K order feature information corresponding to the K intermediate structure information respectively, the intermediate structure information is determined according to the comparison result, and the intermediate structure information is listed in the container of the corresponding order of the intermediate answer array set according to the Nth order feature information, until the plurality of predictive strategy data is traversed, and the answer array set is obtained; the intermediate answer array set is a set of empty containers with the same integer number as the address array set; K is an integer greater than or equal to 1 and less than N.

[0013] In the above scheme, before the plurality of predictive strategy data is traversed according to a predetermined order, the preset application array set is used, and the application class and action class information of the Nth predictive strategy data are combined to determine the Nth structure information, the method further comprises:

[0014] The plurality of predictive strategy data and a plurality of predictive terminal data are obtained; each predictive terminal data includes a predictive terminal address information; each predictive strategy data includes a predictive strategy address information;

[0015] The plurality of predictive terminal address information is converted to obtain a plurality of predictive terminal values, and the plurality of predictive strategy address information is converted to obtain a plurality of predictive strategy values;

[0016] The plurality of predictive terminal values and the plurality of predictive strategy values are sorted and merged to obtain a plurality of address values, so as to form the address array set;

[0017] The plurality of application class information contained in the plurality of predictive strategy data is extracted, the preset application identifier corresponding to the plurality of application class information is converted to obtain a plurality of application values, and the plurality of application values are sorted to obtain the application array set.

[0018] In the above scheme, before the plurality of predictive strategy data is traversed according to a predetermined order, the preset application array set is used, and the application class and action class information of the Nth predictive strategy data are combined to determine the Nth structure information, the method further comprises:

[0019] According to the priority information included in the plurality of prediction policy data, the plurality of prediction policy data is sorted; wherein each prediction policy data includes: priority information, prediction policy address information, at least one application class information and at least one action class information corresponding to the at least one application class information;

[0020] According to the predetermined order, the plurality of prediction policy data is traversed, and the application array set is used to determine the Nth structure information according to the application class and the action class information of the Nth prediction policy data, including:

[0021] According to the priority information from low to high, the plurality of prediction policy data is traversed;

[0022] In the application array set, at least one application order information corresponding to the at least one application class information included in the Nth prediction policy data is determined;

[0023] In the pre-constructed array, the original value of the order corresponding to the at least one application order information is replaced by a first value to obtain a first array; the array includes the same number of original values as the number of application values;

[0024] In the array, the original value of the order corresponding to the at least one application order information is replaced by a second value according to the on-off state represented by the at least one action class information to obtain a second array;

[0025] The first array and the second array are combined to obtain the Nth structure information.

[0026] In the above scheme, the prediction policy address information includes: start policy address information and end policy address information;

[0027] The Nth order feature information corresponding to the Nth prediction policy address information of the Nth prediction policy data in the address array set is determined;

[0028] The start policy address information is converted to obtain a start policy value, and the end policy address information is converted to obtain an end policy value;

[0029] The start policy value is compared with the plurality of address values respectively to determine a first address value corresponding to the start policy value, and the end policy value is compared with the plurality of address values respectively to determine a second address value corresponding to the end policy value;

[0030] In the address array set, the first order information of the first address value and the second order information of the second address value are determined;

[0031] The Nth order feature information is determined by combining the first order information and the second order information.

[0032] In the above scheme, the intermediate structure information is determined according to the comparison result, including one of the following:

[0033] If the comparison result indicates that the Nth order feature information is the same as the first order feature information in the K order feature information, the Nth structure information and the first intermediate structure information corresponding to the first order feature information are merged according to a predetermined strategy to obtain the intermediate structure information.

[0034] If the comparison result indicates that the Nth order feature information is different from the K order feature information, the Nth structure information is determined as the intermediate structure information.

[0035] In the above scheme, the first intermediate structure information includes a third array and a fourth array.

[0036] The Nth structure information and the first intermediate structure information corresponding to the first order feature information are merged according to a predetermined strategy to obtain the intermediate structure information, including:

[0037] The first value in the first array is used to cover the value of the corresponding order in the third array to obtain a fifth array.

[0038] The second value in the second array is used to cover the value of the corresponding order in the fourth array to obtain a sixth array.

[0039] The fifth array and the sixth array are combined to obtain the intermediate structure information.

[0040] In the above scheme, the identification information of the Mth terminal address information is determined by combining a preset address array set, including:

[0041] The Mth terminal value is obtained by converting the Mth terminal address information.

[0042] The Mth terminal value and the plurality of address values are compared respectively to determine a third address value corresponding to the Mth terminal value.

[0043] The Mth order information of the third address value is determined in the address array set; and the identification information includes the Mth order information.

[0044] In the above scheme, the answer structure information corresponding to the Mth terminal address information is determined in a preset answer array set by using the identification information to form the current target data, including:

[0045] In the plurality of intermediate structure information in the answer array set, the Mth order information corresponds to the target intermediate structure information, which is the answer structure information; the answer array set comprises: a plurality of intermediate structure information;

[0046] In the plurality of pre-known terminal address information and the plurality of pre-known strategy address information, the third address value corresponds to the target address information;

[0047] The answer structure information, the target address information and the previous current target data are combined to obtain the current target data; the previous current target data is data obtained after traversing M-1 terminal address information.

[0048] The embodiment of the application further provides a data query device, comprising:

[0049] The traversal determination unit is used for traversing the plurality of terminal address information obtained, and determining the identification information of the Mth terminal address information in combination with a preset address array set; the address array set is an integer set obtained by fusing pre-known terminal address information and pre-known strategy address information; M is an integer greater than or equal to 1;

[0050] The processing and sending unit is used for determining the answer structure information corresponding to the Mth terminal address information in a preset answer array set by using the identification information, so as to form current target data; wherein the answer array set is determined by the order feature in the address array set in combination with intermediate structure information and corresponding pre-known strategy data; the intermediate structure information is array information representing application and action determined by the corresponding pre-known strategy data;

[0051] In combination with the current target data, the remaining terminal address information is continuously traversed until the plurality of terminal address information is traversed, target data is obtained, and the target data is sent to the terminal corresponding to the plurality of terminal address information.

[0052] The embodiment of the application further provides a data query device, comprising a memory and a processor, the memory stores a computer program capable of running on the processor, and the processor realizes the steps in the above method when executing the computer program.

[0053] The embodiment of the application further provides a computer readable storage medium, which stores a computer program, and the computer program is executed by a processor to realize the steps in the above method.

[0054] In the embodiment of the present application, the identification information of the Mth terminal address information is determined by traversing the acquired plurality of terminal address information and combining the preset address array set, the address array set is an integer set obtained by fusing the predicted terminal address information and the predicted strategy address information, M is an integer greater than or equal to 1, the answer structure information corresponding to the Mth terminal address information is determined in the preset answer array set by using the identification information, so as to form the current target data, wherein the answer array set is determined by the order feature in the address array set through the intermediate structure information combined with the corresponding predicted strategy data, the intermediate structure information is the array information representing the application and the action determined by the corresponding predicted strategy data, the remaining terminal address information is continuously traversed in combination with the current target data until the traversal of the plurality of terminal address information is completed, the target data is obtained, and the target data is sent to the terminal corresponding to the plurality of terminal address information. The present scheme fuses the plurality of predicted terminal address information and the plurality of predicted strategy address information together, and utilizes the order operation implementation idea of the address array set and the answer array set, so as to effectively improve the query and distribution efficiency of the mass strategy. BRIEF DESCRIPTION OF DRAWINGS

[0055] Figure 1 An optional flowchart of a data query method provided by the embodiment of the present application is provided.

[0056] Figure 2 An optional flowchart of a data query method provided by the embodiment of the present application is provided.

[0057] Figure 3 An optional flowchart of a data query method provided by the embodiment of the present application is provided.

[0058] Figure 4 An optional flowchart of a data query method provided by the embodiment of the present application is provided.

[0059] Figure 5 An optional effect diagram of a data query method provided by the embodiment of the present application is provided.

[0060] Figure 6 A structure diagram of a data query device provided by the embodiment of the present application is provided.

[0061] Figure 7 A hardware entity diagram of a data query device provided by the embodiment of the present application is provided. DETAILED DESCRIPTION

[0062] In order to make the objects, technical solutions and advantages of the present application clearer, the technical solutions of the present application are further described in detail below in combination with the drawings and embodiments, and the described embodiments should not be regarded as limitations on the present application, and all other embodiments obtained by those skilled in the art without creative efforts fall within the scope of protection of the present application.

[0063] In the following description, "some embodiments" are referred to, which describe a subset of all possible embodiments, but it can be understood that "some embodiments" can be the same subset or different subsets of all possible embodiments, and can be combined with each other without conflict.

[0064] If the similar description of "first / second" appears in the invention document, the following description is added, in the following description, the terms "first\second\third" referred to only distinguish similar objects, and do not represent a specific order of the objects, and it can be understood that "first\second\third" can be interchanged in a specific order or sequence as allowed, so that the embodiments of the present application described herein can be implemented in an order other than that illustrated or described herein.

[0065] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which the present application belongs. The terms used herein are only for the purpose of describing the embodiments of the present application, and are not intended to limit the present application.

[0066] Figure 1 An optional flowchart of the data query method provided by the embodiments of the present application will be described in combination with the steps shown in the figure. Figure 1 The steps shown in the figure will be described.

[0067] S101, the acquired plurality of terminal address information is traversed, and the identification information of the Mth terminal address information is determined in combination with a preset address array set; the address array set is an integer set obtained by fusing the known terminal address information and the known strategy address information.

[0068] In the embodiments of the present application, the server traverses the acquired plurality of terminal address information, and determines the identification information of the Mth terminal address information in combination with a preset address array set. The address array set is an integer set obtained by fusing the known terminal address information and the known strategy address information. M is an integer greater than or equal to 1.

[0069] In the embodiments of the present application, the server can be in communication connection with a plurality of terminals, the plurality of terminals report terminal information within a certain time, and then the server can obtain a plurality of terminal information. The server extracts the address information corresponding to each terminal from the plurality of terminal information, and then obtains a plurality of terminal address information. The server can be a service platform for managing the connected plurality of terminals.

[0070] In the embodiment of the present application, the server can traverse the obtained plurality of terminal address information in a certain order. The server obtains the Mth terminal value by converting the Mth terminal address information. The server determines the Mth order information corresponding to the Mth terminal value in the address array set.

[0071] In the embodiment of the present application, the server obtains a plurality of address values by converting and sorting a plurality of known terminal address information and a plurality of known strategy address information in advance, and then forms an address array set by combining the plurality of address values. The plurality of known terminal address information is reported by a plurality of terminals connected to the server in advance. The plurality of known strategy address information is extracted from a plurality of known strategy data. The plurality of known strategy data is configured by a plurality of user terminals and sent to the server in advance.

[0072] In the embodiment of the present application, each known strategy data includes priority information, known strategy address information, at least one application class information, and at least one action class information corresponding to the at least one application class information. The known strategy address information can further include starting strategy address information and ending strategy address information.

[0073] S102, using the identification information, determining the answer structure information corresponding to the Mth terminal address information in the preset answer array set to form the current target data; wherein the answer array set is determined by combining the intermediate structure information with the corresponding known strategy data according to the order characteristics in the address array set; and the intermediate structure information is array information representing applications and actions determined by the corresponding known strategy data.

[0074] In the embodiment of the present application, the server uses the identification information to determine the answer structure information corresponding to the Mth terminal address information in the preset answer array set to form the current target data; wherein the answer array set is determined by combining the intermediate structure information with the corresponding known strategy data according to the order characteristics in the address array set; and the intermediate structure information is array information representing applications and actions determined by the corresponding known strategy data.

[0075] In the embodiment of the present application, the answer array set includes a plurality of intermediate structure information, and each intermediate structure information corresponds to respective order information. Since the server configures the number of intermediate structure information in the answer array set to be consistent with the number of address values when constructing the answer array set and the address array set, the server can determine a corresponding answer structure information in the answer array set using the Mth order information. The server then combines the answer structure information with the data obtained by traversing the first M-1 terminal address information to obtain the current target data.

[0076] In this embodiment of the invention, the server pre-constructs an answer array set. The server traverses multiple predicted strategy data in ascending order of priority, constructing corresponding structural information for each predicted strategy data and determining the predicted strategy address information to determine the corresponding order information in the address array set. The server compares this order information with the previously determined order information. If the two order information are the same, the server merges the structural information with the previous structural information to determine the intermediate structural information corresponding to the order information. If the two order information are different, the server determines the structural information as the new intermediate structural information. The server then adds the intermediate structural information to the corresponding order container in a pre-constructed empty container set according to this order information. This process continues until all predicted strategy data has been traversed, resulting in the answer array set.

[0077] The structural information corresponding to each predicted strategy data is determined by the server through at least one application class information and its corresponding at least one action class information. This structural information can be a two-row array. The first row represents the bitmap information of at least one application class information in multiple applications, and the second row represents the on / off action bitmap information of at least one application class information.

[0078] For example, this structure information can be a struct structure:

[0079] struct ans{

[0080] long long apps; 1000000000

[0081] long long is_forbidden;1000000000

[0082] }

[0083] Wherein, long long apps; 1000000000 indicates that at least one application class information in the corresponding predictive policy data is the first bitmap in multiple applications, and long long is_forbidden; 1000000000 indicates that at least one application class information in the corresponding predictive policy data is a blocking action.

[0084] S103. Combine the current target data and continue to traverse the remaining terminal address information until the traversal of multiple terminal address information is completed, obtain the target data, and send the target data to the terminals corresponding to the multiple terminal address information.

[0085] In the embodiment of the present application, the server combines the current target data, continues to traverse the remaining terminal address information, until the plurality of terminal address information is traversed, the target data is obtained, and the target data is sent to the terminal corresponding to the plurality of terminal address information.

[0086] Wherein, the target data contains the structure information corresponding to each terminal address information. The structure information represents the switch state of the application corresponding to the terminal.

[0087] In the embodiment of the present application, the target data can be json data. The json data can include a plurality of terminal address information and structure information corresponding to each terminal. The server distributes the structure information through the terminal address information in the json data.

[0088] In some embodiments, referring to Figure 2 , Figure 2 An optional flowchart of the data query method provided by the embodiment of the present application is shown in Figure 1 S101 to S102 shown in the figure can be realized by S201 to S205, which will be described in combination with each step.

[0089] S201, read a host information, find out the corresponding serial number in the address array set according to the IP of the host information.

[0090] In the embodiment of the present application, the server reads a host information, converts the IP contained in the host information to obtain an integer, and finds the corresponding serial number in the Internet Protocol Address (IP) array set (that is, the address array set).

[0091] S202, read the corresponding answer structure information in the answer array according to the found serial number, which contains the policy action of the IP.

[0092] S203, construct the corresponding data.

[0093] In the embodiment of the present application, the server constructs the json data according to the determined answer structure information.

[0094] S204, judge whether all host information is traversed.

[0095] In the embodiment of the present application, the server judges whether all host information is traversed, if not all host information is traversed, continue to traverse, if all host information is traversed, obtain the target data.

[0096] S205, at this time, the target data used by the policy is constructed.

[0097] In the embodiment of the present application, the server constructs the json data corresponding to the plurality of terminal address information and issues the same.

[0098] In the embodiment of the present application, the identification information of the Mth terminal address information is determined by traversing the plurality of acquired terminal address information and combining the preset address array set; the address array set is an integer set obtained by fusing the predicted terminal address information and the predicted strategy address information; M is an integer greater than or equal to 1; the answer structure information corresponding to the Mth terminal address information is determined in the preset answer array set by using the identification information, so as to form the current target data; wherein the answer array set is determined by the order feature in the address array set through the intermediate structure information combined with the corresponding predicted strategy data; the intermediate structure information is array information representing the application and action determined by the corresponding predicted strategy data; the remaining terminal address information is continuously traversed in combination with the current target data until the plurality of terminal address information is traversed, the target data is obtained, and the target data is sent to the terminals corresponding to the plurality of terminal address information. The present scheme fuses the plurality of predicted terminal address information and the plurality of predicted strategy address information together, and utilizes the order operation implementation idea of the address array set and the answer array set, thereby effectively improving the query and issue efficiency of the massive strategy.

[0099] In some embodiments, Figure 1 The S101 is further shown to include S104 to S106 before being implemented, which will be described in combination with each step.

[0100] S104, traversing the plurality of predicted strategy data in a predetermined order, determining the Nth structure information by using the preset application array set and combining the application class and action class information of the Nth predicted strategy data.

[0101] In the embodiment of the present application, the server traverses the plurality of predicted strategy data in a predetermined order, determines the Nth structure information by using the preset application array set and combining the application class and action class information of the Nth predicted strategy data. The application array set represents the sorting set corresponding to the plurality of application class information contained in the plurality of predicted strategy data; N is an integer greater than 1.

[0102] In the embodiment of the present application, the server traverses the plurality of predictive strategy data in order from low to high according to the priority of the plurality of predictive strategy data. The server determines at least one application class information in the Nth predictive strategy data in at least one application order information in the application array set. The server replaces the original value of the corresponding order in the pre-constructed array with a first value to obtain a first array. The server combines the switch state represented by the at least one action class information, and replaces the original value of the corresponding order of the at least one application order information in the array with a second value to obtain a second array. The first value can be the same as or different from the second value. For example, the first value can be 1, and the second value can also be 1 when the corresponding application is in the off action state.

[0103] The pre-constructed array includes a plurality of original values, and the number of the plurality of original arrays is consistent with the number of the plurality of applications.

[0104] S105, determine the Nth predictive strategy address information of the Nth predictive strategy data, and the corresponding Nth order feature information in the address array set.

[0105] In the embodiment of the present application, the server determines the Nth predictive strategy address information of the Nth predictive strategy data, and the corresponding Nth order feature information in the address array set.

[0106] In the embodiment of the present application, the server can convert the Nth predictive strategy address information to obtain a corresponding value, determine the address value corresponding to the value in the address array set, and then determine the Nth order feature information corresponding to the address value.

[0107] For example, the address array set can be a value set of 0, 1, 2, 3, 4, 5, 6, 7, 8, and 9. If the server converts the Nth predictive strategy address information to obtain a corresponding value of 6, then the Nth order feature information can be determined to be the 6th.

[0108] S106, compare the Nth order feature information with the Kth order feature information corresponding to the K intermediate structure information respectively, determine the intermediate structure information according to the comparison result, and list the intermediate structure information in the container of the corresponding order in the intermediate answer array set according to the Nth order feature information, until the traversal of the plurality of predictive strategy data is completed, and the answer array set is obtained.

[0109] In the embodiment of the present application, the server respectively compares the Nth order feature information with the K order feature information corresponding to the K intermediate structure information determined, determines the intermediate structure information according to the comparison result, and lists the intermediate structure information in the container of the corresponding order of the intermediate answer array set according to the Nth order feature information, until the traversal of the plurality of prediction strategy data is completed, and the answer array set is obtained. The intermediate answer array set is a set of empty containers with the same integer number as the address array set. K is an integer greater than or equal to 1 and less than N.

[0110] In the embodiment of the present application, if the server determines that the Nth order feature information is the same as the first order feature information in the K order feature information, the high-priority application bitmap is directly overwritten, the original action state of the application not involved in the high priority is retained, the strategy of the application involved in the high priority is directly overwritten, the Nth structure information and the first intermediate structure information corresponding to the first order feature information are merged, and the intermediate structure information is obtained.

[0111] For example, the Nth order feature information is the 6th. The intermediate answer array set includes 10 empty containers. The server can list the intermediate structure information in the 6th empty container, and then perform the traversal of the next prediction strategy data, until the traversal of the plurality of prediction strategy data is completed, and the answer array set is obtained.

[0112] In the embodiment of the present application, the server traverses the plurality of prediction strategy data according to a predetermined order, determines the Nth structure information by using the preset application array set and combining the application class and action class information of the Nth prediction strategy data. The Nth order feature information of the Nth prediction strategy address information is determined. The server respectively compares the Nth order feature information with the K order feature information corresponding to the K intermediate structure information determined, determines the intermediate structure information according to the comparison result, and lists the intermediate structure information in the container of the corresponding order of the intermediate answer array set according to the Nth order feature information, until the traversal of the plurality of prediction strategy data is completed, and the answer array set is obtained. In the present scheme, the server compares the order feature information of the strategy data with the order feature information of the intermediate structure information determined, reduces the redundant structure information, makes the intermediate structure information in the answer array set more accurate, and improves the accuracy of data query.

[0113] In some embodiments, referring to Figure 3 , Figure 3 An optional flowchart of the data query method provided by the embodiment of the present application is shown, and S104 to S106 can also be implemented by S206 to S212, which will be described in combination with each step.

[0114] S206, starting to traverse from the strategy of low priority.

[0115] In the embodiment of the present application, the server starts traversing from the low-priority prediction policy data.

[0116] S207, read a policy and create an answer structure (one for each policy).

[0117] In the embodiment of the present application, the server creates the structure information of the prediction policy data after reading one piece of prediction policy data.

[0118] S208, obtain the data in the answer structure according to a certain algorithm.

[0119] S208 can be implemented through S2081-S2084.

[0120] S2081, read an application involved in this policy, and find the corresponding serial number according to the application array, for example, the serial number of "unlimited" is "1".

[0121] The server can create the struct structure of each prediction policy data. That is, the struct structure is formed:

[0122] struct ans{

[0123] long long apps;

[0124] long long is_forbidden;

[0125] }

[0126] S2082, the first array can be a 64-bit array, and 1 is marked at the corresponding position according to the previously found serial number.

[0127] The first array is the apps array.

[0128] S2083, the second array is a 64-bit array, and 1 or 0 is marked at the corresponding position according to the previously found serial number and whether the policy is blocked.

[0129] The second array is the is_fobidden array.

[0130] S2084, judge whether the application has been traversed.

[0131] S209, find the corresponding range in the address array set according to the start IP point and the end IP point of this policy, for example, 1.1.1.1-1.1.2.2 is the range of 0-1.

[0132] S210, merging the original content and the newly created answer structure according to a certain algorithm.

[0133] S2101, because the traversal starts from the low priority, the high priority application bitmap directly covers, the high priority application not involved retains the original state, and the high priority application involved directly covers.

[0134] S211, judging whether all the strategies have been traversed.

[0135] In the embodiment of the application, the server judges whether the traversal of all the strategy data is completed.

[0136] S212, obtaining the answer array set.

[0137] In the embodiment of the application, until the traversal of the multiple predictive strategy data is completed, the answer array set is obtained.

[0138] In some embodiments, S104 shown further includes S107 to S110 before being implemented, which will be described in combination with each step.

[0139] S107, obtaining multiple predictive strategy data and multiple predictive terminal data.

[0140] In the embodiment of the application, the server obtains the multiple predictive strategy data and the predictive terminal data. Each predictive terminal data includes a predictive terminal address information. Each predictive strategy data includes a predictive strategy address information.

[0141] In the embodiment of the application, the server is connected with multiple terminals, and the server receives the predictive terminal data sent by the multiple terminals. The users of the multiple terminals configure the respective predictive strategy data, and the multiple terminals send the configured multiple predictive strategy data to the server.

[0142] S108, performing conversion processing on the multiple predictive terminal address information to obtain multiple predictive terminal values, and performing conversion processing on the multiple predictive strategy address information to obtain multiple predictive strategy values.

[0143] In the embodiment of the application, the server performs conversion processing on the multiple predictive terminal address information to obtain multiple predictive terminal values, and performs conversion processing on the multiple predictive strategy address information to obtain multiple predictive strategy values.

[0144] In the embodiment of the present application, the server can convert the multiple pre-known terminal address information into integers in unit32 format to obtain multiple pre-known terminal values. Correspondingly, the server can also convert the multiple pre-known policy address information into integers in unit32 format to obtain multiple pre-known policy values.

[0145] In the embodiment of the present application, the server can convert the multiple pre-known terminal address information into integers in other formats by using other algorithms, which will not be described here.

[0146] S109, sorting and merging the multiple pre-known terminal values and the multiple pre-known policy values to obtain multiple address values to form an address array set.

[0147] In the embodiment of the present application, the server sorts and merges the multiple pre-known terminal values and the multiple pre-known policy values to obtain multiple address values to form an address array set.

[0148] In the embodiment of the present application, the server sorts the multiple pre-known terminal values and the multiple pre-known policy values in ascending order and merges the adjacent values that are the same. Finally, the multiple address values in a certain order are obtained, and then the address array set is obtained.

[0149] S110, extracting multiple application class information contained in the multiple pre-known policy data, converting the multiple application class information corresponding to the preset application identifier to obtain multiple application values, sorting the multiple application values to obtain an application array set.

[0150] In the embodiment of the present application, the server extracts multiple application class information contained in the multiple pre-known policy data, converts the multiple application class information corresponding to the preset application identifier to obtain multiple application values, and sorts the multiple application values to obtain an application array set.

[0151] In the embodiment of the present application, each pre-known policy data includes at least one application class information. Each application class information corresponds to a preset application identifier. Therefore, the server can extract multiple application class information from the multiple pre-known policy data. The server converts multiple application identifiers corresponding to the multiple application class information to obtain multiple application values. The server sorts the multiple application values in ascending order to obtain an application array set.

[0152] The method for converting the multiple application identifiers by the server is the same as the method for converting the multiple pre-known terminal address information and the multiple pre-known policy address information. Each application identifier can be a value.

[0153] In the embodiment of the present application, the server fuses the plurality of pre-known terminal address information and the plurality of pre-known policy address information together to obtain an address array set, determines the final answer array set, and uses the consistent order characteristics of the answer array set and the address array set to improve the efficiency of array query delivery.

[0154] In some embodiments, referring to Figure 4 , Figure 4 An optional flowchart of the data query method provided by the embodiment of the present application is shown in S107-S110, which can be implemented by S213-S216, which will be described in combination with each step.

[0155] S213, read all policies, obtain IP points in the policies and convert them into integers, such as 1.1.1.1-1.1.2.2, read 1.1.1.1 and 1.1.2.2, and add them to the address array set; and sort them in ascending order.

[0156] S214, read all IP points in the host information and convert them into integers, add them to the IP array set, because they are all single IP, so add one for each; and sort them in ascending order.

[0157] For example, the server can convert and sort the IP points in all host information and the IP points in the policies, and the obtained IP points can include: 1.1.1.1; 1.1.2.2; 1.1.2.3; 1.1.2.5.

[0158] S215, read all application identification information and add them to the application array set; and perform simple sorting.

[0159] In the embodiment of the present application, the server can perform simple sorting on all application identification information to obtain the application array set.

[0160] For example, the application array set represents the sorting of a plurality of applications.

[0161] S216, create an array with a structure as an element according to the size of the address array set.

[0162] In the embodiment of the present application, the length of the IP array created by the server is consistent with the length of the answer array. That is, the number of structure information in the answer array is the same as the number of IP points in the IP array.

[0163] In some embodiments, S104 is shown before S111, which will be described in combination with each step.

[0164] S111, sort the plurality of pre-known policy data according to the plurality of priority information included in the plurality of pre-known policy data.

[0165] In the embodiment of the present application, the server sorts the plurality of prediction strategy data according to the plurality of priority information included in the plurality of prediction strategy data.

[0166] In the embodiment of the present application, the server sorts the plurality of prediction strategy data according to the priority information from large to small.

[0167] In some embodiments, S104 shown can also be implemented by S112 to S116, which will be described in combination with each step.

[0168] S112, traversing the plurality of prediction strategy data according to the plurality of priority information from low to high.

[0169] In the embodiment of the present application, the server can traverse the plurality of prediction strategy data according to the plurality of priority information from low to high.

[0170] S113, determining at least one application order information corresponding to at least one application class information contained in the Nth prediction strategy data in the application array set.

[0171] In the embodiment of the present application, the server determines at least one application order information corresponding to at least one application class information contained in the Nth prediction strategy data in the application array set.

[0172] In the embodiment of the present application, the server can compare the Nth application identification information in the Nth prediction strategy data with the plurality of application identification information included in the application array set respectively, determine the application identification information corresponding to the Nth application identification information, and then determine the order information of the application identification information as the at least one application order information.

[0173] In the embodiment of the present application, the server can convert the Nth application identification information in the Nth prediction strategy data to obtain the Nth application value. The server then compares the Nth application value with the plurality of application values included in the application array set respectively, determines the application value corresponding to the Nth application value, and then determines the order information of the application value as the at least one application order information.

[0174] In the embodiment of the present application, the application array set can also include a plurality of application class information completed by sorting. The server compares the at least one application class information with the plurality of application class information respectively, determines the intermediate application class information corresponding to the at least one application class information, and determines the order information of the intermediate application class information as the at least one application order information.

[0175] For example, in combination with Figure 5The application array can be a numerical set of 0-N. The length of the application array is the size of the application member bitmap in the answer array, and the length of the application array is the size of the action (blocking) bitmap.

[0176] In the pre-constructed array, the first numerical value is used to replace the original numerical value corresponding to the order of the at least one application order information, to obtain a first array.

[0177] In the embodiment of the application, the server uses the first numerical value to replace the original numerical value corresponding to the order of the at least one application order information in the pre-constructed array, to obtain a first array. The pre-constructed array contains the same number of original numerical values as the number of application numerical values.

[0178] The original numerical value can be 1 or 0. The original numerical value can also be other numerical values.

[0179] For example, the at least one application order information can be the 6th. The pre-constructed array can be 0000000000. The server uses 1 to replace the 6th original numerical value in 0000000000, to obtain a first array 0000010000.

[0180] In the embodiment of the application, the server uses the second numerical value to replace the original numerical value corresponding to the order of the at least one application order information in the array, to obtain a second array, in combination with the on-off state represented by the at least one action class information.

[0181] In the embodiment of the application, the server uses the second numerical value to replace the original numerical value corresponding to the order of the at least one application order information in the array, to obtain a second array, in combination with the on-off state represented by the at least one action class information.

[0182] In the embodiment of the application, if the on-off state represents blocking, the second numerical value can be 1. The server uses 1 to replace the original numerical value corresponding to the order of the at least one application order information in the array, to obtain a second array. If the on-off state represents blocking, the second numerical value can be 0. The server uses 0 to replace the original numerical value corresponding to the order of the at least one application order information in the array, to obtain a second array.

[0183] For example, in combination with the on-off state represented by the at least one action class information, the second numerical value can be 1. Figure 5The IP points of the four prediction strategy data can be 1.1.1.1, 2.1.1.2, 3.1.1.3 and 221.1.1.221 respectively. The server determines the order information of the four prediction strategy data in the address array set as the 0th, the 1st, the 2nd and the 3rd respectively according to the four IP points. The server can determine the corresponding application bitmap as 10011 and the action bitmap as 10011 according to the application class information and the action class information in the 0th prediction strategy data. The server can determine the corresponding application bitmap as 10000 and the action bitmap as 10011 according to the application class information and the action class information in the 1st prediction strategy data. The server can determine the corresponding application bitmap as 11111 and the action bitmap as 10011 according to the application class information and the action class information in the 2nd prediction strategy data. The server can determine the corresponding application bitmap as 00011 and the action bitmap as 10011 according to the application class information and the action class information in the 3rd prediction strategy data. The application bitmap 10011 indicates that the 1st, the 4th and the 5th application class information in the 0th prediction strategy data are included in the application array set. The action bitmap 10011 indicates that the 1st, the 4th and the 5th application class information in the 0th prediction strategy data are all blocking actions.

[0184] S116, combining the first array and the second array to obtain the Nth structure information.

[0185] In the embodiment of the application, the server combines the first array and the second array to obtain the Nth structure information.

[0186] In the embodiment of the application, the server can configure the first array in the first row and the second array in the second row, and then obtain the struct structure.

[0187] In the embodiment of the application, the server combines the intermediate structure information corresponding to the high-priority strategy data and the intermediate structure information corresponding to the low-priority strategy data, directly covers the high-priority application bitmap during the combining process, retains the original state of the application not involved in the high-priority strategy data, and directly covers the strategy of the application state not involved in the high-priority strategy data, thereby effectively reducing the redundant intermediate structure information and improving the efficiency of data query and delivery.

[0188] In some embodiments, S105 shown can also be implemented through S117 to S120, which will be described in combination with each step.

[0189] S117, converting the starting strategy address information to obtain a starting strategy value and converting the ending strategy address information to obtain an ending strategy value.

[0190] In the embodiment of the present application, the server converts the starting policy address information to obtain a starting policy value, and converts the ending policy address information to obtain an ending policy value.

[0191] The pre-known policy address information includes the starting policy address information and the ending policy address information.

[0192] In the embodiment of the present application, the method for the server to convert the starting policy address information and the ending policy address information to obtain the values can be the same as the method for converting the pre-known policy address information.

[0193] S118, the starting policy value is compared with the plurality of address values respectively to determine a first address value corresponding to the starting policy value, and the ending policy value is compared with the plurality of address values respectively to determine a second address value corresponding to the ending policy value.

[0194] In the embodiment of the present application, the server compares the starting policy value with the plurality of address values respectively to determine a first address value corresponding to the starting policy value, and compares the ending policy value with the plurality of address values respectively to determine a second address value corresponding to the ending policy value.

[0195] S119, the first sequence information of the first address value and the second sequence information of the second address value are determined in the address array set.

[0196] In the embodiment of the present application, the server determines the first sequence information of the first address value and the second sequence information of the second address value in the address array set.

[0197] S120, the Nth sequence feature information is determined by combining the first sequence information and the second sequence information.

[0198] In the embodiment of the present application, the server combines the first sequence information and the second sequence information to determine the Nth sequence feature information.

[0199] In the embodiment of the present application, the server determines the Nth sequence feature information by combining the first sequence information and the second sequence information.

[0200] For example, the first sequence information can be the first one, and the second sequence information can be the third one, so that the server can determine the Nth sequence feature information as the first one to the third one by combining the first sequence information and the second sequence information.

[0201] In the embodiment of the present application, the server determines the Nth sequence feature information through the pre-known policy address information, so that the server determines the target data by using the characteristic that the sequence features of the address array set and the answer array set are the same, thereby improving the efficiency of data query and delivery.

[0202] In some embodiments, S106 shown can also be implemented by S121, which will be described in combination with the steps.

[0203] S121, if the comparison result represents that the Nth order feature information is the same as the first order feature information in the K order feature information, then the Nth structure information and the first intermediate structure information corresponding to the first order feature information are merged according to a predetermined strategy to obtain the intermediate structure information.

[0204] In the embodiment of the application, after the server respectively compares the Nth order feature information with the K order feature information corresponding to the K intermediate structure information determined, it is determined that the Nth order feature information is the same as the first order feature information in the K order feature information, and then the Nth structure information and the first intermediate structure information corresponding to the first order feature information are merged according to a predetermined strategy to obtain the intermediate structure information.

[0205] In the embodiment of the application, the K intermediate structure information determined is a plurality of intermediate structure information determined before the Nth structure information is determined. The K intermediate structure information respectively corresponds to an order feature information.

[0206] In some embodiments, S106 shown can also be implemented by S122, which will be described in combination with the steps.

[0207] S122, if the comparison result represents that the Nth order feature information is different from the K order feature information, then the Nth structure information is determined as the intermediate structure information.

[0208] In the embodiment of the application, after the server respectively compares the Nth order feature information with the K order feature information corresponding to the K intermediate structure information determined, it is determined that the Nth order feature information is different from the K order feature information, and then the Nth structure information is determined as the intermediate structure information.

[0209] In some embodiments, S121 shown can also be implemented by S123 to S125, which will be described in combination with the steps.

[0210] S123, the first value in the first array is used to cover the value in the third array corresponding to the order to obtain the fifth array.

[0211] In the embodiment of the application, the first intermediate structure information includes a third array and a fourth array. The first value in the first array is used to cover the value in the third array corresponding to the order to obtain the fifth array.

[0212] The fifth array is also an application bitmap.

[0213] For example, the first array can be 1000000000. The third array can be 0001000000. The server covers the first 0 in the third array with 1 in the first array which can be 1000000000, and thus obtains the fifth array which can be 1001000000.

[0214] S124, covers the value in the fourth array in the corresponding order with the second value in the second array, and thus obtains the sixth array.

[0215] In the embodiment of the present application, the server covers the value in the fourth array in the corresponding order with the second value in the second array, and thus obtains the sixth array.

[0216] The sixth array is the action bitmap.

[0217] S125, combines the fifth array and the sixth array, and thus obtains the intermediate structure information.

[0218] In the embodiment of the present application, the server combines the fifth array and the sixth array, and thus obtains the intermediate structure information.

[0219] In the embodiment of the present application, the server can determine that the fifth array is the application bitmap, determine that the sixth array is the action bitmap, and thus determine the struct structure.

[0220] In some embodiments, Figure 1 The S101 shown can also be implemented by S126 to S128, which will be described in combination with the steps.

[0221] S126, converts the Mth terminal address information to obtain the Mth terminal value.

[0222] In the embodiment of the present application, the server converts the Mth terminal address information to obtain the Mth terminal value.

[0223] In the embodiment of the present application, the method for converting the Mth terminal address information by the server is the same as the method for converting the address information of the known strategy in the address array set.

[0224] S127, respectively compares the Mth terminal value and the plurality of address values, and determines the third address value corresponding to the Mth terminal value.

[0225] In the embodiment of the present application, the server respectively compares the Mth terminal value and the plurality of address values, and determines the third address value corresponding to the Mth terminal value.

[0226] S128, determines the Mth order information of the third address value in the address array set.

[0227] In the embodiment of the present application, the server determines the Mth order information of the third address value in the address array set. The identification information comprises the Mth order information.

[0228] In some embodiments, Figure 1 The S102 shown can also be implemented by S129 to S131, which will be described in combination with each step.

[0229] S129, among the multiple intermediate structure information in the answer array set, the target intermediate structure information corresponding to the Mth order information is determined as the answer structure information.

[0230] In the embodiment of the present application, the server determines the target intermediate structure information corresponding to the Mth order information among the multiple intermediate structure information in the answer array set as the answer structure information.

[0231] Among them, the answer array set comprises: multiple intermediate structure information.

[0232] S130, among the multiple pre-known terminal address information and the multiple pre-known strategy address information, the target address information corresponding to the third address value is determined.

[0233] In the embodiment of the present application, the server determines the target address information corresponding to the third address value among the multiple pre-known terminal address information and the multiple pre-known strategy address information.

[0234] In the embodiment of the present application, since the multiple address values are determined by the multiple pre-known terminal address information and the multiple pre-known strategy address information, the third address value must correspond to an address information, and then the server can determine the target address information corresponding to the third address value among the multiple pre-known terminal address information and the multiple pre-known strategy address information.

[0235] S131, the answer structure information, the target address information and the previous current target data are combined to obtain the current target data.

[0236] In the embodiment of the present application, the server combines the answer structure information, the target address information and the previous current target data to obtain the current target data. The previous current target data is the data obtained after traversing the first M-1 terminal address information.

[0237] Among them, the current target data can be json data.

[0238] In the embodiment of the present application, the previous current target data can include the determined K intermediate structure information and the corresponding address information.

[0239] In the embodiment of the present application, the server utilizes the characteristic that the order features of the address array set and the answer array set are same, and then utilizes the Mth order information to determine the answer structure information in the answer array set to obtain the target data, thereby improving the efficiency of data query.

[0240] Referring to Figure 6 , Figure 6 The structural schematic diagram of the data query device provided by the embodiment of the present application is shown.

[0241] The embodiment of the present application further provides a data query device 800, which comprises a traversal determination unit 803, a processing unit 804 and a sending unit 805.

[0242] The traversal determination unit 803 is used for traversing the acquired multiple terminal address information, and determining the identification information of the Mth terminal address information in combination with a preset address array set; the address array set is an integer set obtained by fusing the known terminal address information and the known strategy address information; M is an integer greater than or equal to 1;

[0243] The processing unit 804 is used for determining the answer structure information corresponding to the Mth terminal address information in a preset answer array set by utilizing the identification information, so as to form the current target data; wherein the answer array set is determined by the order feature in the address array set in combination with the corresponding known strategy data through intermediate structure information; the intermediate structure information is array information representing the application and the action determined by the corresponding known strategy data;

[0244] The sending unit 805 is used for continuing to traverse the remaining terminal address information in combination with the current target data, until the multiple terminal address information is traversed completely, so as to obtain the target data, and send the target data to the terminals corresponding to the multiple terminal address information.

[0245] In the embodiment of the present application, the traversal determination unit 803 in the data query device 800 is configured to traverse the plurality of predictive strategy data in a predetermined order, determine the Nth structure information by using a preset application array set, in combination with the application class and action class information of the Nth predictive strategy data, wherein the application array set represents a sorting set corresponding to the plurality of application class information contained in the plurality of predictive strategy data, N is an integer greater than 1, the Nth predictive strategy address information of the Nth predictive strategy data is determined, and the Nth order feature information corresponding to the address array set, the Nth order feature information is compared with the K order feature information corresponding to the K intermediate structure information determined respectively, the intermediate structure information is determined according to the comparison result, and the intermediate structure information is listed in the container of the corresponding order of the intermediate answer array set according to the Nth order feature information, until the plurality of predictive strategy data is traversed, and the answer array set is obtained, the intermediate answer array set is a set of empty containers with the same integer number as the address array set, and K is an integer greater than or equal to 1 and less than N.

[0246] In the embodiment of the present application, the data query device 800 is configured to obtain the plurality of predictive strategy data and the plurality of predictive terminal data, each predictive terminal data includes one predictive terminal address information, each predictive strategy data includes one predictive strategy address information, the plurality of predictive terminal address information is processed to obtain the plurality of predictive terminal values, the plurality of predictive strategy address information is processed to obtain the plurality of predictive strategy values, the plurality of predictive terminal values and the plurality of predictive strategy values are sorted and merged to obtain the plurality of address values, so as to form the address array set, the plurality of application class information contained in the plurality of predictive strategy data is extracted, the plurality of application values is obtained by converting the preset application identifier corresponding to the plurality of application class information, and the plurality of application values is sorted to obtain the application array set.

[0247] In the embodiment of the present application, the traversal determining unit 803 in the data query device 800 is configured to sort the plurality of predictive strategy data according to the plurality of priority information included in the plurality of predictive strategy data; wherein each predictive strategy data includes: priority information, predictive strategy address information, at least one application class information, and at least one action class information corresponding to the at least one application class information; the plurality of predictive strategy data is traversed in the order from low to high according to the plurality of priority information; at least one application order information corresponding to the at least one application class information included in the Nth predictive strategy data is determined in the application array set; in the pre-constructed array, the original value of the order corresponding to the at least one application order information is replaced by a first value to obtain a first array; the array includes the same number of original values as the plurality of application values; in the array, the original value of the order corresponding to the at least one application order information is replaced by a second value to obtain a second array, combined with the switch state represented by the at least one action class information; and the first array and the second array are combined to obtain the Nth structure information.

[0248] In the embodiment of the present application, the predictive strategy address information includes: starting strategy address information and ending strategy address information; the traversal determining unit 803 in the data query device 800 is configured to convert the starting strategy address information to obtain a starting strategy value, and convert the ending strategy address information to obtain an ending strategy value; compare the starting strategy value with the plurality of address values respectively to determine a first address value corresponding to the starting strategy value, and compare the ending strategy value with the plurality of address values respectively to determine a second address value corresponding to the ending strategy value; the first order information of the first address value and the second order information of the second address value are determined in the address array set; and the Nth order feature information is determined in combination with the first order information and the second order information.

[0249] In the embodiment of the present application, the traversal determining unit 803 in the data query device 800 is configured to, if the comparison result represents that the Nth order feature information is the same as the first order feature information in the K order feature information, merge the Nth structure information and the first intermediate structure information corresponding to the first order feature information according to a predetermined strategy to obtain the intermediate structure information; and if the comparison result represents that the Nth order feature information is different from the K order feature information, determine the Nth structure information as the intermediate structure information.

[0250] In the embodiment of the present application, the first intermediate structure information comprises a third array and a fourth array; the traversal determining unit 803 in the data query device 800 is configured to cover the values in the third array with the first values in the first array to obtain a fifth array, cover the values in the fourth array with the second values in the second array to obtain a sixth array, and combine the fifth array and the sixth array to obtain the intermediate structure information.

[0251] In the embodiment of the present application, the traversal determining unit 803 in the data query device 800 is configured to convert the Mth terminal address information to obtain an Mth terminal value, compare the Mth terminal value with the plurality of address values respectively to determine a third address value corresponding to the Mth terminal value, determine the Mth order information of the third address value in the address array set, and the identification information comprises the Mth order information.

[0252] In the embodiment of the present application, the processing unit 804 in the data query device 800 is configured to determine, among the plurality of intermediate structure information in the answer array set, the target intermediate structure information corresponding to the Mth order information as the answer structure information, determine, among the plurality of pre-known terminal address information and the plurality of pre-known strategy address information, the target address information corresponding to the third address value, and combine the answer structure information, the target address information and a previous current target data to obtain the current target data, wherein the previous current target data is the data obtained after traversing M-1 terminal address information.

[0253] In the embodiment of the present application, the identification information of the Mth terminal address information is determined by the traversal determination unit 803 traversing the acquired plurality of terminal address information in combination with the preset address array set; the address array set is an integer set obtained by fusing the predicted terminal address information and the predicted strategy address information; M is an integer greater than or equal to 1; the answer structure information corresponding to the Mth terminal address information is determined in the preset answer array set by the processing unit 804 using the identification information, so as to form the current target data; wherein the answer array set is determined by the order feature in the address array set in combination with the corresponding predicted strategy data and the intermediate structure information; the intermediate structure information is array information representing the application and the action determined by the corresponding predicted strategy data; the remaining terminal address information is continuously traversed by the sending unit 805 in combination with the current target data until the traversal of the plurality of terminal address information is completed, the target data is obtained, and the target data is sent to the terminal corresponding to the plurality of terminal address information. The present scheme effectively improves the mass strategy query and delivery efficiency by fusing the plurality of predicted terminal address information and the plurality of predicted strategy address information together, and using the order operation implementation idea of the address array set and the answer array set.

[0254] It should be noted that, in the embodiment of the present application, if the above-mentioned data query method is implemented in the form of a software function module and sold or used as an independent product, it can also be stored in a computer-readable storage medium. Based on this understanding, the technical solutions of the embodiments of the present application can be embodied in the form of a software product, which is stored in a storage medium and includes a plurality of instructions for causing a data query device (which can be a personal computer, etc.) to execute all or part of the methods described in the embodiments of the present application. The aforementioned storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM), a magnetic disk or an optical disk, and various storage media that can store program codes. Thus, the embodiments of the present application are not limited to any specific combination of hardware and software.

[0255] Correspondingly, the embodiment of the present application provides a computer readable storage medium having a computer program stored thereon, wherein the computer program is executed by a processor to implement the steps in the above method.

[0256] Correspondingly, the embodiment of the present application provides a data query device, which includes a memory 902 and a processor 901, wherein the memory 902 stores a computer program executable on the processor 901, and the processor 901 implements the steps in the above method when executing the program.

[0257] It should be noted that the above description of the storage medium and device embodiments is similar to the description of the above method embodiments, and has similar beneficial effects as the method embodiments. For technical details not disclosed in the storage medium and device embodiments of the present application, please refer to the description of the method embodiments of the present application for understanding.

[0258] It should be noted that, Figure 7 A hardware entity diagram of the data query device provided by the embodiment of the present application is shown in Figure 7 The hardware entity of the data query device 900 includes a processor 901 and a memory 902, wherein

[0259] The processor 901 generally controls the overall operation of the data query device 900.

[0260] The memory 902 is configured to store instructions and applications executable by the processor 901, and can also cache data (for example, image data, audio data, voice communication data and video communication data) to be processed by the processor 901 and modules in the data query device 900, which can be implemented by FLASH or Random Access Memory (RAM).

[0261] It should be understood that the "one embodiment" or "an embodiment" mentioned throughout the specification means that the specific features, structures or characteristics related to the embodiment are included in at least one embodiment of the present application. Therefore, "in one embodiment" or "in an embodiment" appearing throughout the specification does not necessarily refer to the same embodiment. In addition, these specific features, structures or characteristics can be combined in one or more embodiments in any suitable manner. It should be understood that in various embodiments of the present application, the size of the sequence number of each process does not mean the order of execution, and the execution order of each process should be determined according to its function and inherent logic, and should not constitute any limitation on the implementation process of the embodiment of the present application. The sequence number of the above embodiment of the present application is only for description, not representing the pros and cons of the embodiment.

[0262] It should be noted that in this paper, the term "include", "contain" or any other variant thereof is intended to cover non-exclusive inclusion, so that the process, method, article or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed, or includes elements inherent to such process, method, article or device. Without more limitations, the element defined by the sentence "including a…" does not exclude the presence of other identical elements in the process, method, article or device including the element.

[0263] In several embodiments provided by the present application, it should be understood that the disclosed apparatus and method can be implemented by other manners. The apparatus embodiments described above are merely illustrative, for example, the division of the units is merely a logical function division, and actual implementation can have another division manner, for example, multiple units or components can be combined, or can be integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the displayed or discussed components can be indirect coupling or communication connection through some interfaces, apparatuses or units, which can be electrical, mechanical or other forms.

[0264] The units described above as separate components can or can not be physically separate, and the components shown as units can or can not be physical units; they can be located in one place or distributed on multiple network units; and part or all of the units can be selected according to actual needs to achieve the purpose of the embodiment.

[0265] In addition, each functional unit in each embodiment of the present application can be integrated into one processing unit, or each unit can be a separate unit, or two or more units can be integrated into one unit; the integrated unit can be realized in the form of hardware or hardware plus software functional unit.

[0266] Those skilled in the art can understand that all or part of the steps of the above-mentioned method embodiments can be completed by program instruction related hardware, and the foregoing program can be stored in a computer readable storage medium, and the program executes the steps including the above-mentioned method embodiments when executed; and the foregoing storage medium includes mobile storage device, read only memory (Read Only Memory, ROM), magnetic disc or optical disc and various storage program codes.

[0267] Alternatively, the integrated unit of the present application, if implemented in the form of a software function module and sold or used as an independent product, can also be stored in a computer readable storage medium. Based on this understanding, the technical solutions of the embodiments of the present application can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a plurality of instructions to make a computer device (which can be a personal computer, a server, or a network device, etc.) execute all or part of the methods described in the embodiments of the present application. The foregoing storage medium includes mobile storage device, ROM, magnetic disc or optical disc and various storage program codes.

[0268] The above merely describes the embodiments of the present application, and the protection scope of the present application is not limited thereto, and any person skilled in the art can easily think of changes or replacements within the technical range disclosed by the present application, which should be covered in the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. A data query method, characterized by, The method comprises the following steps: acquiring a plurality of terminal address information, and determining order information of Mth terminal address information in combination with a preset address array set; the address array set is obtained by fusing known terminal address information and known strategy address information; the known strategy address information is known strategy data sent by a terminal corresponding to the known terminal address information; M is an integer greater than or equal to 1; determining answer structure information corresponding to the Mth terminal address information in the preset answer array set by using the order information, so as to form current target data; wherein the answer array set is determined by intermediate structure information in combination with order characteristics of corresponding known strategy data in the address array set; the intermediate structure information is array information representing an application and an action determined by the corresponding known strategy data; combining the current target data, continuously traversing the remaining terminal address information until the plurality of terminal address information is traversed, obtaining target data, and sending the target data to terminals corresponding to the plurality of terminal address information; the target data is used to represent the on-off state of the corresponding application of the corresponding terminal.

2. The data query method of claim 1, wherein, Before the plurality of terminal address information is acquired and the order information of the Mth terminal address information is determined in combination with the preset address array set, the method further comprises the following steps: traversing a plurality of known strategy data in a predetermined order, determining Nth structure information in combination with application class and action class information of Nth known strategy data by using a preset application array set; the application array set represents a sorting set corresponding to a plurality of application class information contained in the plurality of known strategy data; N is an integer greater than 1; determining Nth known strategy address information of the Nth known strategy data, and corresponding Nth order characteristic information in the address array set; comparing the Nth order characteristic information with Kth order characteristic information corresponding to K intermediate structure information respectively, determining the intermediate structure information according to the comparison result, and listing the intermediate structure information in a container corresponding to the order in an intermediate answer array set according to the Nth order characteristic information, until the plurality of known strategy data is traversed, and the answer array set is obtained; the intermediate answer array set is a set of empty containers with the same number of integers as the address array set; K is an integer greater than or equal to 1 and less than N.

3. The data query method of claim 2, wherein, Before the plurality of known strategy data is traversed in a predetermined order, and the Nth structure information is determined in combination with the application class and the action class information of the Nth known strategy data by using the preset application array set, the method further comprises the following steps: acquiring the plurality of known strategy data and a plurality of known terminal data; each known terminal data comprises a known terminal address information; each known strategy data comprises a known strategy address information; performing conversion processing on a plurality of known terminal address information to obtain a plurality of known terminal values, and performing conversion processing on a plurality of known strategy address information to obtain a plurality of known strategy values; The plurality of pre-knowledge terminal values and the plurality of pre-knowledge strategy values are sorted and combined to obtain a plurality of address values, so as to form the address array set; The plurality of application class information contained in the plurality of pre-knowledge strategy data is extracted, the plurality of application class information is converted according to a preset application identifier to obtain a plurality of application values, and the plurality of application values are sorted to obtain the application array set.

4. The data query method of claim 3, wherein, Before the method determines the Nth structure information according to the predetermined order of traversing the plurality of pre-knowledge strategy data, using the preset application array set, and combining the application class and the action class information of the Nth pre-knowledge strategy data, the method further comprises: The plurality of pre-knowledge strategy data is sorted according to a plurality of priority information included in the plurality of pre-knowledge strategy data; wherein each pre-knowledge strategy data comprises: priority information, pre-knowledge strategy address information, at least one application class information and at least one action class information corresponding to the at least one application class information; The plurality of pre-knowledge strategy data is sorted according to a plurality of priority information included in the plurality of pre-knowledge strategy data; wherein each pre-knowledge strategy data comprises: priority information, pre-knowledge strategy address information, at least one application class information and at least one action class information corresponding to the at least one application class information; The plurality of pre-knowledge strategy data is sorted according to a plurality of priority information included in the plurality of pre-knowledge strategy data; wherein each pre-knowledge strategy data comprises: priority information, pre-knowledge strategy address information, at least one application class information and at least one action class information corresponding to the at least one application class information; The plurality of pre-knowledge strategy data is sorted according to a plurality of priority information included in the plurality of pre-knowledge strategy data; wherein each pre-knowledge strategy data comprises: priority information, pre-knowledge strategy address information, at least one application class information and at least one action class information corresponding to the at least one application class information; The plurality of pre-knowledge strategy data is sorted according to a plurality of priority information included in the plurality of pre-knowledge strategy data; wherein each pre-knowledge strategy data comprises: priority information, pre-knowledge strategy address information, at least one application class information and at least one action class information corresponding to the at least one application class information; The first array and the second array are combined to obtain the Nth structure information. The pre-knowledge strategy address information comprises: starting strategy address information and ending strategy address information; 5. The data query method of claim 4, wherein, The Nth order feature information corresponding to the Nth pre-knowledge strategy address information of the Nth pre-knowledge strategy data in the address array set is determined, comprising: The starting strategy address information is converted to obtain a starting strategy value, and the ending strategy address information is converted to obtain an ending strategy value; The starting strategy value and the plurality of address values are compared respectively to determine a first address value corresponding to the starting strategy value, and the ending strategy value and the plurality of address values are compared respectively to determine a second address value corresponding to the ending strategy value; The first order information of the first address value and the second order information of the second address value in the address array set are determined; The Nth order feature information is determined according to the first order information and the second order information. The intermediate structure information is determined according to the comparison result, comprising one of the following:

6. The data query method of claim 5, wherein, ​ If the comparison result represents that the Nth order feature information is the same as the first order feature information in the K order feature information, the Nth structure information and the first intermediate structure information corresponding to the first order feature information are merged according to a predetermined strategy to obtain the intermediate structure information; If the comparison result represents that the Nth order feature information is different from the K order feature information, the Nth structure information is determined as the intermediate structure information.

7. The data query method of claim 6, wherein, The first intermediate structure information includes a third array and a fourth array; The merging of the Nth structure information and the first intermediate structure information corresponding to the first order feature information according to a predetermined strategy to obtain the intermediate structure information includes: The first value in the first array is used to cover the value in the corresponding order in the third array to obtain a fifth array; The second value in the second array is used to cover the value in the corresponding order in the fourth array to obtain a sixth array; The fifth array and the sixth array are combined to obtain the intermediate structure information.

8. The data query method of claim 3, wherein, The combination of the predetermined address array set to determine the order information of the Mth terminal address information includes: The Mth terminal value is obtained by converting the Mth terminal address information; The Mth terminal value is compared with the plurality of address values respectively to determine the third address value corresponding to the Mth terminal value; The Mth order information of the third address value is determined in the address array set; the order information includes the Mth order information.

9. The data query method of claim 8, wherein, The use of the order information to determine the answer structure information corresponding to the Mth terminal address information in the predetermined answer array set to form the current target data includes: In the plurality of intermediate structure information in the answer array set, the target intermediate structure information corresponding to the Mth order information is determined as the answer structure information; the answer array set includes a plurality of intermediate structure information; In the plurality of predicted terminal address information and the plurality of predicted strategy address information, the target address information corresponding to the third address value is determined; The answer structure information, the target address information, and the previous current target data are combined to obtain the current target data; the previous current target data is the data obtained by traversing the first M-1 terminal address information.

10. A data query apparatus, characterized by comprising: It includes: The traversal determination unit is configured to traverse the plurality of terminal address information obtained, and combine a predetermined address array set to determine the order information of the Mth terminal address information; the address array set is an integer set obtained by fusing predicted terminal address information and predicted strategy address information; the predicted strategy address information is predicted strategy data sent by a terminal corresponding to the predicted terminal address information; M is an integer greater than or equal to 1. A processing sending unit is configured to determine, by using the sequence information, answer structure information corresponding to the Mth terminal address information from a preset answer array set to form current target data; the answer array set is determined by combining intermediate structure information with corresponding prediction strategy data according to sequence characteristics in the address array set; the intermediate structure information is array information representing applications and actions determined by the corresponding prediction strategy data; In combination with the current target data, the remaining terminal address information is continuously iterated until the multiple terminal address information is iterated completely to obtain target data, and the target data is sent to terminals corresponding to the multiple terminal address information; the target data is used to represent the on-off state of the corresponding application of the corresponding terminal.

11. A data query device, characterized by A computer program product includes a memory and a processor, the memory stores a computer program capable of running on the processor, and the processor implements the steps in the method of any one of claims 1 to 9 when executing the computer program.

12. A computer readable storage medium having stored thereon a computer program, characterized in that, The computer program is executed by the processor to implement the steps in the method of any one of claims 1 to 9.

Citation Information

Patent Citations

  • Automatic query method and system for firewall policy

    CN105681327A

  • Query and storage method and device for Internet protocol address and electronic equipment

    CN108228834A

  • Firewall strategy detection method

    CN111049801A