Security policy configuration method and device

By learning traffic on network security devices and user editing to generate target security policies, the problem of not being able to configure accurate policies when first launched is solved, and refined control of messages is achieved.

CN115277088BActive Publication Date: 2025-09-02NEW H3C SECURITY TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210721943.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-06-24
Publication Date
2025-09-02
Estimated Expiration
2042-06-24

AI Technical Summary

Technical Problem

In networking without firewall devices, accurate security policies cannot be configured when they are first launched, resulting in the inability to finely control packets between different hosts and services.

Method used

After enabling a universal security policy in the network security device, the traffic flowing through the device is learned, the traffic learning record is generated, and the target security policy that meets user needs is configured through user editing and generating instructions.

Benefits of technology

After the network security equipment is first launched, a refined security policy is generated to meet user needs to achieve accurate control of packets.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115277088B_ABST
    Figure CN115277088B_ABST
Patent Text Reader

Abstract

The present application provides a security policy configuration method and device, which are applied to a network security device that is put online for the first time. The method includes: after the network security device enables the configured general security policy, performing traffic learning on the traffic flowing through the network security device to obtain at least one traffic learning record; outputting and displaying the obtained traffic learning record; receiving an editing instruction for a target traffic learning record; performing a corresponding editing operation on the target traffic learning record according to the editing instruction to obtain an edited record; receiving a policy generation instruction for the edited record; generating a target security policy for the edited record according to the policy generation instruction, and configuring the target security policy in the network security device. In this way, when the network security device is used for the first time in a network, a security policy that meets the requirements of the connected network is configured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer communication technology, and in particular to a security policy configuration method and device. Background Art

[0002] A security policy is a prevention and control strategy that controls packet forwarding and performs deep packet inspection (DPI) based on packet attributes. Security policy control of packets is achieved through rules within the security policy. Rules can be used to set filtering conditions for matching packets, actions for processing packets, and deep inspection of packet content. Each rule can be configured with multiple filtering conditions, such as source security zone, destination security zone, source IP address, destination IP address, and service.

[0003] Currently, in a network that has never used a firewall device, when the firewall device is first put online, it is impossible to configure accurate security policies because the network does not know which hosts exist and which services are open. As a result, it is impossible to finely control the messages between different hosts and services.

[0004] Therefore, when using network security devices for the first time on a network, how to configure security policies that meet the needs of the connected network is one of the technical issues worth considering. Summary of the Invention

[0005] In view of this, the present application provides a security policy configuration method and apparatus for configuring a security policy that meets the requirements of the accessed network when a network security device is used for the first time in the network.

[0006] Specifically, this application is implemented through the following technical solutions:

[0007] According to a first aspect of the present application, a security policy configuration method is provided, which is applied to a network security device that is online for the first time, the method comprising:

[0008] After the network security device activates the configured general security policy, performing traffic learning on the traffic flowing through the network security device to obtain at least one traffic learning record;

[0009] Output and display the obtained traffic learning records;

[0010] receiving an editing instruction for a target traffic learning record;

[0011] Performing a corresponding editing operation on the target flow learning record according to the editing instruction to obtain an edited record;

[0012] receiving a policy generation instruction for the edited record;

[0013] According to the policy generation instruction, the edited record is used to generate a target security policy, and the target security policy is configured in the network security device.

[0014] According to a second aspect of the present application, a security policy configuration device is provided, which is provided in a network security device that is online for the first time, the device comprising:

[0015] A learning module, configured to perform flow learning on the flow passing through the network security device after the general security policy configured on the network security device is enabled, to obtain at least one flow learning record;

[0016] The display module is used to output and display the obtained traffic learning records;

[0017] A first receiving module is configured to receive an editing instruction for a target traffic learning record;

[0018] An editing module, configured to perform a corresponding editing operation on the target flow learning record according to the editing instruction to obtain an edited record;

[0019] a second receiving module, configured to receive a policy generation instruction for the edited record;

[0020] a policy generating module, configured to generate a target security policy from the edited record according to the policy generating instruction;

[0021] A configuration module is used to configure the target security policy in the network security device.

[0022] According to a third aspect of the present application, a network security device is provided, comprising a processor and a machine-readable storage medium, wherein the machine-readable storage medium stores a computer program that can be executed by the processor, and the processor is prompted by the computer program to execute the method provided in the first aspect of the embodiment of the present application.

[0023] According to the fourth aspect of the present application, a machine-readable storage medium is provided, which stores a computer program. When called and executed by a processor, the computer program prompts the processor to execute the method provided in the first aspect of the embodiment of the present application.

[0024] Beneficial effects of the embodiments of the present application:

[0025] In the security policy configuration method and apparatus provided by the embodiment of the present application, after the network security device goes online for the first time and enables the configured general security policy, it will perform traffic learning on the traffic flowing through the network security device to obtain at least one traffic learning record; output and display the obtained traffic learning record; receive an editing instruction for the target traffic learning record; perform corresponding editing operations on the target traffic learning record according to the editing instruction to obtain an edited record; receive a policy generation instruction for the edited record; generate a target security policy for the edited record according to the policy generation instruction, and configure the target security policy in the network security device. In this way, the configuration of the security policy is realized after the network security device goes online for the first time, and the security policy configured on the network security device is generated under the guidance of the user, so that the configured security policy can meet the needs of the user and the connected network, thereby achieving refined control of the message. BRIEF DESCRIPTION OF THE DRAWINGS

[0026] Figure 1 This is a flowchart of a security policy configuration method provided by an embodiment of the present application;

[0027] Figure 2 This is a schematic diagram of the structure of a security policy configuration device provided in an embodiment of the present application;

[0028] Figure 3 This is a hardware structure diagram of a network security device that implements a security policy configuration method provided in an embodiment of the present application. DETAILED DESCRIPTION

[0029] Exemplary embodiments are described in detail herein, with examples illustrated in the accompanying drawings. When the following description refers to the drawings, identical numerals in different figures represent identical or similar elements unless otherwise indicated. The embodiments described in the following exemplary embodiments are not intended to represent all embodiments consistent with the present application. Rather, they are merely examples of apparatuses and methods consistent with certain aspects of the present application.

[0030] The terms used in this application are for the purpose of describing specific embodiments only and are not intended to limit this application. The singular forms "a," "the," and "the" used in this application are also intended to include the plural forms unless the context clearly indicates otherwise. It should also be understood that the term "and / or" as used herein refers to and includes any or all possible combinations of one or more of the corresponding listed items.

[0031] It should be understood that although the terms first, second, third, etc. may be used in this application to describe various information, such information should not be limited to these terms. These terms are only used to distinguish information of the same type from each other. For example, without departing from the scope of this application, first information may also be referred to as second information, and similarly, second information may also be referred to as first information. Depending on the context, the word "if" as used herein may be interpreted as "at the time of" or "when" or "in response to determining".

[0032] The security policy configuration method provided in this application is described in detail below.

[0033] See also Figure 1 , Figure 1 This is a flowchart of a security policy configuration method provided by this application. This method can be applied to a network security device that is first put online. The network security device can be, but is not limited to, a firewall or other device. The method may include the following steps:

[0034] S101: After a network security device activates a configured general security policy, traffic learning is performed on the traffic flowing through the network security device to obtain at least one traffic learning record.

[0035] In this step, to ensure that the network security device can perform certain security protection functions when it first accesses the network, and to configure a security policy that adapts to the network being accessed and meets user needs, this embodiment proposes pre-installing a general security policy in the network security device. This general security policy is a relatively broad security policy, such as an all-pass security policy. It should be noted that the execution action of the policy rules of this all-pass security policy can be "allow". In this way, traffic records flowing through the network security device can be learned, namely, the sender of the traffic, such as which services the host accessed, etc.

[0036] On this basis, when the network security device is enabled, traffic will first flow into the network security device before entering the connected network. The network security device will learn and record the traffic flowing through the device, thus generating at least one traffic learning record. It is worth noting that the learned traffic learning record can essentially be understood as a security policy, and the user can then modify the security policy by modifying the traffic learning record.

[0037] Optionally, before executing step S101, a traffic learning function in the network security device is enabled, and then step S101 is executed.

[0038] S102: Output and display the obtained traffic learning records.

[0039] In this step, the user can log in to the network security device based on a terminal device with display function. Based on this, the network security device can output the recorded traffic learning records to the user, for example, display the traffic learning records in the form of a display page. In this way, the user can view the traffic learning records currently learned by the network security device through the terminal device.

[0040] S103: Receive an editing instruction for the target traffic learning record.

[0041] In this step, in order to customize a security policy that meets user needs, the user can trigger an editing instruction for the traffic learning record that needs to be edited, that is, the above-mentioned target traffic learning record.

[0042] S104. Perform corresponding editing operations on the target flow learning record according to the editing instruction to obtain an edited record.

[0043] In this step, after the network security device receives the editing instruction, it can obtain the target editing information typed by the user, and then perform the corresponding editing operation on the target traffic learning record, that is, adjust the target traffic learning record to the above-mentioned target editing information, thereby obtaining the edited record corresponding to the target traffic learning record.

[0044] It should be noted that when the user executes the editing instruction, the editing instruction can be triggered for batch traffic learning records. Accordingly, the security network device can execute the editing and perform editing operations on the traffic learning records in batches, thereby obtaining the edited records corresponding to each target traffic learning record.

[0045] After the edited record is obtained based on the user's editing instruction, the obtained edited record is the edited record that meets the user's needs.

[0046] S105: Receive a policy generation instruction for the edited record.

[0047] In this step, once the user has completed the traffic learning record adjustments, the security policy generation process can be executed. That is, the user can trigger the policy generation instruction for the edited record. For example, the user can select the edited record and click the "Generate Policy" option to trigger the policy generation instruction.

[0048] S106: Generate a target security policy from the edited record according to the policy generation instruction, and configure the target security policy in the network security device.

[0049] In this step, after receiving the policy generation instruction, the network security device can convert the edited record selected by the user into a target security policy, then configure the target security policy on the network security device, and then achieve precise control of the messages flowing through the network security device based on the target security policy. In this way, a security policy that meets user needs and can ensure the security of the connected network can be configured on the network security device, while also achieving fine-grained control of messages in the network connected to the network.

[0050] By implementing the security policy configuration method provided by the present application, after the network security device goes online for the first time and enables the configured general security policy, it will perform traffic learning on the traffic flowing through the network security device to obtain at least one traffic learning record; output and display the obtained traffic learning record; receive an editing instruction for the target traffic learning record; perform corresponding editing operations on the target traffic learning record according to the editing instruction to obtain an edited record; receive a policy generation instruction for the edited record; generate a target security policy for the edited record according to the policy generation instruction, and configure the target security policy in the network security device. In this way, the configuration of the security policy is realized after the network security device goes online for the first time, and the security policy configured on the network security device is generated under the guidance of the user, so that the configured security policy can meet the user's needs and can achieve refined control of the message.

[0051] Optionally, the above-mentioned editing instruction includes a modification instruction; on this basis, step S104 can be executed according to the following process: after receiving the modification instruction, output a modification page for the traffic learning record indicated by the modification instruction; receive the first target information input based on the modification page, and obtain the first edited record.

[0052] Specifically, after the edited record is generated, a page including the edited record and the traffic learning record will be displayed to the user. The page may include a modification button. When the user clicks the modification button, the modification instruction can be triggered. Then, after the network security device receives the modification instruction, it can output a modification page for the traffic learning record indicated by the modification instruction. In this way, the user can type the first target information based on the modification interface to obtain the first edited record corresponding to the traffic learning record.

[0053] It should be noted that each traffic learning record can correspond to a modification button. The user can click the modification button corresponding to the traffic learning record that needs to be modified to trigger the modification instruction for the traffic learning record. In this way, after the network security device receives the modification instruction, it can put the traffic learning record in an editable state and output the modification page including the editable state to the user. The user can then perform the modification operation based on the traffic learning record to obtain the edited record. Alternatively, all traffic learning records correspond to a modification button. When the user selects the modification button, the modification instruction can be triggered. Then, after the network security device receives the modification instruction, it can put all traffic learning records in an editable state and output the modification page including the editable state to the user. In this way, the user can click the traffic learning record that needs to be modified to perform the modification operation. After the modification is completed, the network security device obtains the edited record.

[0054] Optionally, when the traffic learning record includes multiple editable options, when the user triggers a modification instruction, a modification page pops up showing the editable options, and the user can modify the content of the editable options as needed, that is, fill in the first target information; in addition, the modification page also includes OK and Cancel buttons. After the user fills in the first target information, the user can click the OK button, and the network security device will close the modification page, thereby obtaining the edited record corresponding to the traffic learning record. After the modification page is displayed to the user, if the user does not need to modify it, the user can click the Cancel button, and the network security device will close the modification page after receiving the Cancel instruction.

[0055] Optionally, the editable options may include, but are not limited to, at least one of the following: source security zone, target security zone, source IP address, destination IP address, protocol type, and destination port. Accordingly, when the modification page pops up, the user can, for example, modify the source IP address from 10.1.1.3 to 10.1.1.6. Furthermore, the user can modify multiple editable options to obtain an edited record of the traffic learning record.

[0056] Optionally, based on any of the above embodiments, the editing instruction in this embodiment may also include a replacement instruction. On this basis, step S104 may be executed according to the following process: after receiving the replacement instruction, output a replacement page for the traffic learning record indicated by the replacement instruction; receive second target information input based on the replacement page to obtain a second edited record.

[0057] Specifically, the display page including the traffic learning record may further include a replace button, and the name of the replace button may be, but is not limited to, "Replace," "Replace Learning Record," etc. When the user clicks the replace button, a replace instruction is triggered. Thus, upon receiving the replace instruction, the network security device may display a replacement page to the user, and the user may then enter the second target information in the replacement page to obtain a second edited record of the traffic learning record.

[0058] Specifically, when performing the replacement operation, you can replace one by one or in batches. For details, please refer to the aforementioned modification operations, which will not be described in detail here.

[0059] When the traffic learning record includes multiple editable options, when the user triggers the replacement command, a replacement page pops up with the editable options. The user can then perform a replacement operation on the content of the editable options as needed, i.e., fill in the second target information. In addition, the replacement page may also include confirm and cancel buttons. After the user fills in the second target information, the user can click the confirm button, and the network security device will close the replacement page, thereby obtaining the edited record corresponding to the traffic learning record, i.e., the second edited record. After the replacement page is displayed to the user, if the user does not need to make any changes, the user can click the cancel button. After receiving the cancel command, the network security device will close the replacement page.

[0060] Similarly, the above-mentioned editable options may include, but are not limited to, at least one of the following: source security zone, target security zone, source IP address, destination IP address, protocol type, destination port, etc. For example, a single IP address in a traffic learning record can be replaced with a network segment, range segment, etc.

[0061] Optionally, based on any of the above embodiments, the editing instructions in this embodiment may also include aggregation instructions; on this basis, step S104 may also be executed according to the following process: after receiving the aggregation instruction, the records with the same target options in the target traffic learning record are aggregated to obtain edited records, and the target options include at least one of the following: source IP address, destination IP address and service.

[0062] Specifically, the above-mentioned editing instructions may also include aggregation instructions. On this basis, the above-mentioned display page may also provide an aggregation button, which can trigger the aggregation instruction when the user clicks the aggregation button. When the user receives the aggregation instruction, in one possible embodiment, the network security device can automatically aggregate records with the same target option, and the edited record obtained after the merger should retain the values ​​of different options. The resulting edited record can be recorded as the third edited record. For example, taking the source IP address as an example, the traffic learning records with the same source IP address are aggregated, and the contents of other options in the traffic learning record to which the source IP address belongs are retained. In another possible embodiment, in order to meet the user's personalized needs, after receiving the aggregation instruction, the network security device will respond to the aggregation instruction and display an editing page to the user. In this way, the user can select the traffic learning record to be aggregated on the editing page, and then select the OK button on the editing page. The network security device can then perform the aggregation operation on the traffic learning record selected by the user, thereby obtaining the edited record, thereby meeting the user's security policy requirements.

[0063] Optionally, based on any of the above embodiments, the editing instruction in this embodiment may also include a deletion instruction. On this basis, step S104 may also be executed according to the following process: after receiving the deletion instruction, a deletion operation is performed on the target traffic learning record indicated by the deletion instruction to obtain an edited record.

[0064] Specifically, the traffic learning records in this application are for generating security policies. Therefore, some traffic learning records may not be necessary for users. Therefore, the network security device will configure a delete button on the display interface. When the user clicks the delete button, the deletion instruction will be triggered. After the network security device receives the deletion instruction, it can display an editable interface to the user, and then the user performs the deletion operation on the traffic learning record that needs to be deleted, thereby obtaining an edited record, which is recorded as the fourth edited record. In this way, the network security device can delete the traffic learning record to meet the user's needs.

[0065] In addition, the security policy configuration method provided in this embodiment can also provide functions such as clearing statistical data, policy insertion, policy creation, policy copying, policy moving, policy activation, and policy filtering. In view of this, this embodiment provides options such as clearing statistical data, inserting, creating, copying, moving, activating, and policy filtering on the above policy configuration page. When the user clicks any of the above options, the corresponding function can be triggered.

[0066] Optionally, based on any of the above embodiments, the security policy configuration method provided in this embodiment may further perform the following process: receiving a disabling instruction of any security policy; and configuring the security policy to be disabled.

[0067] Specifically, the security policy configuration method provided in this embodiment can also provide a policy disabling function. Based on this, a disabling option can be configured on the policy configuration page. When the user selects a security policy, the disabling option can be clicked to trigger the disabling instruction, and then the network security device can perform the disabling operation for the selected security policy.

[0068] It should be noted that the enabled target security policy is generally placed before the security policy being learned.

[0069] Therefore, by adding a security policy learning function to the network security device, users such as administrators can understand the actual network traffic status of the connected network, and then generate refined target security policies, and then enable the above target security policies on the network security device that is online for the first time, so as to achieve refined control of the traffic of the network connected to the network security device based on the enabled target security policies.

[0070] Based on the same inventive concept, the present application also provides a security policy configuration device corresponding to the above security policy configuration method. The implementation of the security policy configuration device can refer to the above description of the security policy configuration method, which will not be discussed here one by one.

[0071] See also Figure 2 , Figure 2 A security policy configuration device provided by an exemplary embodiment of the present application is provided in a network security device that is online for the first time. The device includes:

[0072] A learning module 201 is configured to perform traffic learning on the traffic flowing through the network security device after the general security policy configured on the network security device is enabled, and obtain at least one traffic learning record;

[0073] Display module 202, used to output and display the obtained traffic learning records;

[0074] A first receiving module 203 is configured to receive an editing instruction for a target traffic learning record;

[0075] An editing module 204 is configured to perform a corresponding editing operation on the target flow learning record according to the editing instruction to obtain an edited record;

[0076] A second receiving module 205 is configured to receive a policy generation instruction for an edited record;

[0077] a policy generating module 206 for generating a target security policy from the edited record according to the policy generating instruction;

[0078] The configuration module 207 is configured to configure the target security policy in the network security device.

[0079] Optionally, based on the above embodiment, the editing instruction in this embodiment includes a modification instruction; on this basis, the above-mentioned editing module 204 is specifically used to output a modification page for the traffic learning record indicated by the modification instruction after receiving the modification instruction; receive the first target information input based on the modification page, and obtain a first edited record.

[0080] Optionally, based on the above embodiment, the editing instruction in this embodiment includes a replacement instruction; on this basis, the above-mentioned editing module 204 is specifically used to output a replacement page for the traffic learning record indicated by the replacement instruction after receiving the replacement instruction; receive the second target information input based on the replacement page, and obtain a second edited record.

[0081] Optionally, based on the above embodiment, the editing instruction in this embodiment includes an aggregation instruction; on this basis, the above-mentioned editing module 204 is specifically used to aggregate the records with the same target options in the target traffic learning record after receiving the aggregation instruction to obtain a third edited record, and the target option includes at least one of the following: source IP address, destination IP address and service.

[0082] Optionally, based on the above embodiment, the editing instruction in this embodiment includes a deletion instruction; on this basis, the above-mentioned editing module 204 is specifically used to perform a deletion operation on the target traffic learning record indicated by the deletion instruction after receiving the deletion instruction, to obtain a fourth edited record.

[0083] Optionally, based on any of the above embodiments, the security policy configuration device provided in this embodiment may further include:

[0084] A third receiving module (not shown in the figure) is used to receive a disabling instruction of any security policy;

[0085] The configuration module 207 is further configured to configure the security policy to be disabled.

[0086] In the security policy configuration device provided by the embodiment of the present application, after the network security device goes online for the first time and enables the configured general security policy, it will perform traffic learning on the traffic flowing through the network security device to obtain at least one traffic learning record; output and display the obtained traffic learning record; receive an editing instruction for the target traffic learning record; perform corresponding editing operations on the target traffic learning record according to the editing instruction to obtain an edited record; receive a policy generation instruction for the edited record; generate a target security policy for the edited record according to the policy generation instruction, and configure the target security policy in the network security device. In this way, the configuration of the security policy is realized after the network security device goes online for the first time, and the security policy configured on the network security device is generated under the guidance of the user, so that the configured security policy can meet the user's needs and can achieve refined control of the message.

[0087] Based on the same inventive concept, the embodiment of the present application provides a network security device, such as Figure 3 As shown, the network security device includes a processor 301 and a machine-readable storage medium 302. The machine-readable storage medium 302 stores a computer program executable by the processor 301. The computer program prompts the processor 301 to execute the security policy configuration method provided in any embodiment of the present application. In addition, the network security device also includes a communication interface 303 and a communication bus 304. The processor 301, the communication interface 303, and the machine-readable storage medium 302 communicate with each other via the communication bus 304.

[0088] The communication bus mentioned above for network security devices can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus. This communication bus can be divided into address buses, data buses, control buses, etc. For ease of illustration, the figure uses only one thick line, but this does not mean that there is only one bus or only one type of bus.

[0089] The communication interface is used for communication between the above network security device and other devices.

[0090] The machine-readable storage medium 302 may be a memory, which may include random access memory (RAM), DDR SRAM (Double Data Rate Synchronous Dynamic Random Access Memory), or non-volatile memory (NVM), such as at least one disk storage. Optionally, the memory may be at least one storage device located remotely from the processor.

[0091] The above-mentioned processor can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, and discrete hardware components.

[0092] As for the network security device and machine-readable storage medium embodiments, since the method contents involved are basically similar to the aforementioned method embodiments, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiments.

[0093] It should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply the existence of any such actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article, or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or device. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of other identical elements in the process, method, article, or device comprising the element.

[0094] The implementation process of the functions and effects of each unit / module in the above-mentioned device is specifically described in the implementation process of the corresponding steps in the above-mentioned method, and will not be repeated here.

[0095] For the device embodiments, since they basically correspond to the method embodiments, the relevant parts can be referred to the partial description of the method embodiments. The device embodiments described above are merely schematic, wherein the units / modules described as separate components may or may not be physically separated, and the components displayed as units / modules may or may not be physical units / modules, that is, they may be located in one place, or they may be distributed over multiple network units / modules. Some or all of the units / modules may be selected according to actual needs to achieve the purpose of the present application scheme. A person of ordinary skill in the art can understand and implement it without paying any creative work.

[0096] The above description is only a preferred embodiment of the present application and is not intended to limit the present application. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present application shall be included in the scope of protection of the present application.

Claims

1. A security policy configuration method, characterized in that: Applied to a network security device that is put online for the first time, the method includes: After the network security device activates the configured general security policy, performing traffic learning on the traffic flowing through the network security device to obtain at least one traffic learning record; Output and display the obtained traffic learning records; receiving an editing instruction for a target traffic learning record, wherein the editing instruction includes a modification instruction, a replacement instruction, an aggregation instruction, and a deletion instruction; Performing a corresponding editing operation on the target flow learning record according to the editing instruction to obtain an edited record; receiving a policy generation instruction for the edited record; According to the policy generation instruction, the edited record is used to generate a target security policy, and the target security policy is configured in the network security device.

2. The method according to claim 1, characterized in that The editing instruction includes a modification instruction; Performing a corresponding editing operation on the target flow learning record according to the editing instruction to obtain an edited record includes: After receiving the modification instruction, outputting a modification page for the traffic learning record indicated by the modification instruction; First target information input based on the modification page is received to obtain a first edited record.

3. The method according to claim 1, characterized in that The editing instruction includes a replacement instruction; Performing a corresponding editing operation on the target flow learning record according to the editing instruction to obtain an edited record includes: After receiving the replacement instruction, outputting a replacement page for the traffic learning record indicated by the replacement instruction; Second target information input based on the replacement page is received to obtain a second edited record.

4. The method according to claim 1, wherein The editing instruction includes an aggregation instruction; Performing a corresponding editing operation on the target flow learning record according to the editing instruction to obtain an edited record includes: After receiving the aggregation instruction, the records with the same target options in the target traffic learning record are aggregated to obtain a third edited record, where the target options include at least one of the following: source IP address, destination IP address, and service.

5. The method according to claim 1, characterized in that The editing instruction includes a deletion instruction; Performing a corresponding editing operation on the target flow learning record according to the editing instruction to obtain an edited record includes: After receiving the deletion instruction, a deletion operation is performed on the target traffic learning record indicated by the deletion instruction to obtain a fourth edited record.

6. The method according to claim 1, characterized in that Also includes: Receive a disable instruction from any security policy; Configure the security policy to disabled.

7. A security policy configuration device, characterized in that: Set in a network security device that is put online for the first time, the device includes: A learning module, configured to perform flow learning on the flow passing through the network security device after the general security policy configured on the network security device is enabled, to obtain at least one flow learning record; The display module is used to output and display the obtained traffic learning records; A first receiving module is configured to receive an editing instruction for a target traffic learning record, wherein the editing instruction includes a modification instruction, a replacement instruction, an aggregation instruction, and a deletion instruction; An editing module, configured to perform a corresponding editing operation on the target flow learning record according to the editing instruction to obtain an edited record; a second receiving module, configured to receive a policy generation instruction for the edited record; a policy generating module, configured to generate a target security policy from the edited record according to the policy generating instruction; A configuration module is used to configure the target security policy in the network security device.

8. The device according to claim 7, characterized in that The editing instruction includes a modification instruction; The editing module is specifically configured to, after receiving the modification instruction, output a modification page for the traffic learning record indicated by the modification instruction; receive first target information input based on the modification page, and obtain a first edited record.

9. The device according to claim 7, characterized in that The editing instruction includes a replacement instruction; The editing module is specifically configured to, after receiving a replacement instruction, output a replacement page for the traffic learning record indicated by the replacement instruction; receive second target information input based on the replacement page, and obtain a second edited record.

10. The device according to claim 7, characterized in that The editing instruction includes an aggregation instruction; The editing module is specifically used to aggregate the records with the same target options in the target traffic learning record after receiving the aggregation instruction to obtain a third edited record, and the target option includes at least one of the following: source IP address, destination IP address and service.

11. The device according to claim 7, characterized in that The editing instruction includes a deletion instruction; The editing module is specifically configured to, after receiving the deletion instruction, perform a deletion operation on the target traffic learning record indicated by the deletion instruction to obtain a fourth edited record.

12. The device according to claim 7, characterized in that Also includes: A third receiving module is used to receive a disabling instruction of any security policy; The configuration module is further configured to configure the security policy to be disabled.

Citation Information

Patent Citations

  • Processing system and processing method of network security policies

    CN106254379A

  • Access control strategy configuration method and device

    CN112511524A