Firewall rule optimization method, device, electronic device, medium and program product

By scoring, clustering and sorting firewall rules, and combining related rule information, the precise cleaning of firewall rules is achieved, solving the performance bottlenecks and accumulation of redundant rules caused by the excessive number of firewall rules, and improving network security.

CN115473689BActive Publication Date: 2025-06-20BEIJING SINO BRIDGE TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210977557.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-08-15
Publication Date
2025-06-20
Estimated Expiration
2042-08-15

AI Technical Summary

Technical Problem

With the increase in the number of firewall rules, it leads to the accumulation of performance bottlenecks and redundant rules, and lacks effective methods to organize rules, forming a vicious cycle and affecting network security.

Method used

By obtaining the rule information of the firewall rules and their associated rules, scoring, clustering, sorting and comprehensive scoring, and finally cleaning the firewall rules based on the comprehensive scores to optimize the rule configuration.

Benefits of technology

It realizes accurate cleaning of firewall rules, avoids the error clearance of low hits but important rules, and improves the performance and network security of the firewall.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115473689B_ABST
    Figure CN115473689B_ABST
Patent Text Reader

Abstract

Embodiments of the present disclosure disclose a method, apparatus, electronic device, medium, and program product for optimizing firewall rules. The method includes: obtaining rule information of a firewall rule and its associated rules, scoring the firewall rule based on the rule information of the firewall rule and its associated rules to obtain a score of the firewall rule; clustering multiple firewall rules in a firewall based on the rule details to obtain at least one cluster, where each cluster includes at least one firewall rule; sorting the clusters based on the scores of the firewall rules in each cluster; comprehensively scoring according to the scores of the firewall rules and the sorting of the clusters where they are located to obtain a comprehensive score; and adjusting and cleaning the firewall rules according to the comprehensive scores of the firewall rules. This technical solution can more accurately sort firewall rules, and thus more precisely clean up redundant firewall rules.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present disclosure relate to the field of data security technology, and specifically to a firewall rule optimization method, device, electronic device, medium, and program product. Background Art

[0002] Firewalls mainly use hardware and software to create a protective barrier between the internal and external network environments, thereby blocking unsafe network factors of computers. Firewalls detect the passing data packets in order according to the network security rules configured by them, and prevent illegal data from invading the internal network to achieve security protection. With the development of the Internet, the scale of the network continues to expand, and the data packets are increasing day by day. As a security barrier between the internal and external networks, firewalls play a vital security role.

[0003] With the long-term use of firewalls, the configured firewall rules accumulate more and more. On the one hand, too many firewall rules may lead to performance bottlenecks of the firewall; on the other hand, many rules have not been hit for a long time, but there is no effective way to sort them out. Over time, a vicious circle has been formed. Redundant rules accumulate more and more, but new network security rules are still needed. Therefore, there is an urgent need to optimize the firewall rules. Summary of the invention

[0004] In order to solve the problems in the related art, the embodiments of the present disclosure provide a firewall rule optimization method, device, electronic device, medium and program product.

[0005] In a first aspect, a firewall rule optimization method is provided in an embodiment of the present disclosure.

[0006] Specifically, the firewall rule optimization method includes:

[0007] Obtaining rule information of a firewall rule and its associated rules, wherein the rule information includes a time series of rule hit times, rule importance, and rule details;

[0008] Scoring the firewall rule based on rule information of the firewall rule and its associated rules to obtain a score of the firewall rule;

[0009] Clustering a plurality of firewall rules in the firewall based on the rule details to obtain at least one cluster, each cluster including at least one firewall rule;

[0010] sorting the clusters based on the scores of the firewall rules in the clusters;

[0011] Comprehensively score the firewall rules according to their scores and the ranking of their clusters to get a comprehensive score.

[0012] Clean up the firewall rules according to the comprehensive scores of each firewall rule.

[0013] In a possible implementation, scoring the firewall rules based on the rule information of the firewall rules and their associated rules to obtain the scores of the firewall rules includes:

[0014] Input the rule information of the firewall rules and their associated rules into a preset evaluation model, execute the evaluation model, and obtain the scores corresponding to the firewall rules.

[0015] In a possible implementation, the preset evaluation model includes a time series feature extraction layer and an output layer; inputting the rule information of the firewall rules and their associated rules into the preset evaluation model, executing the evaluation model, and obtaining the scores corresponding to the firewall rules includes:

[0016] Input the time series of the rule hit times of the firewall rules and their associated rules into the time series feature extraction layer to extract the time series features of the firewall rules;

[0017] Based on the rule importance and rule details of the firewall rules, obtain the attribute features of the firewall rules;

[0018] Concatenate the time series features and attribute features of the firewall rules into the firewall rule concatenated features;

[0019] Input the firewall rule concatenated features into the output layer to obtain the scores corresponding to the firewall rules output by the output layer.

[0020] In a possible implementation, concatenating the time series features and attribute features of the firewall rules into the firewall rule concatenated features includes:

[0021] Input the time series features and attribute features of the firewall rules into the weight feature extraction layer to obtain the time series weight features and attribute weight features output by the weight feature extraction layer;

[0022] Concatenate the time series weight features and attribute weight features into the firewall rule concatenated features.

[0023] In a possible implementation, the method further includes:

[0024] For each firewall rule, sort each rule parameter in the firewall rule according to the historical number of matching failures of each rule parameter in the firewall rule;

[0025] When matching the firewall rule, perform the matching in sequence according to the sorting of each rule parameter in the firewall rule.

[0026] In a possible implementation, the method further includes:

[0027] Merging the N firewall rules with the lowest comprehensive scores to obtain the merged firewall rules.

[0028] In a second aspect, an embodiment of the present disclosure provides a firewall rule cleaning device.

[0029] Specifically, the firewall rule cleaning device includes:

[0030] An acquisition module, configured to acquire the rule information of the firewall rules and their associated rules, where the rule information includes the time series of the rule hit times, the rule importance, and the rule details;

[0031] A first scoring module, configured to score the firewall rules based on the rule information of the firewall rules and their associated rules to obtain the scores of the firewall rules;

[0032] A clustering module, configured to cluster multiple firewall rules in the firewall based on the rule details to obtain at least one clustering cluster, and each clustering cluster includes at least one firewall rule;

[0033] A first sorting module, configured to sort the clustering clusters based on the scores of the firewall rules in each clustering cluster;

[0034] A second scoring module, configured to perform a comprehensive scoring according to the scores of the firewall rules and the sorting of their corresponding clustering clusters to obtain comprehensive scores;

[0035] A cleaning module, configured to clean the firewall rules according to the comprehensive scores of the firewall rules.

[0036] In a possible implementation, the first scoring module is configured to:

[0037] Input the rule information of the firewall rules and their associated rules into a preset evaluation model, execute the evaluation model, and obtain the scores corresponding to the firewall rules.

[0038] In a possible implementation, the preset evaluation model includes a time series feature extraction layer and an output layer; the part of the first scoring module that inputs the rule information of the firewall rules and their associated rules into the preset evaluation model, executes the evaluation model, and obtains the scores corresponding to the firewall rules is configured to:

[0039] Input the time series of the rule hit times of the firewall rules and their associated rules into the time series feature extraction layer to extract the time series features of the firewall rules;

[0040] Obtain the attribute characteristics of the firewall rule based on the rule importance and rule details of the firewall rule;

[0041] Concatenate the temporal characteristics and attribute characteristics of the firewall rule into the firewall rule concatenated characteristic;

[0042] Input the firewall rule concatenated characteristic into the output layer to obtain the score corresponding to the firewall rule output by the output layer.

[0043] In a possible implementation manner, the part in the first scoring module that concatenates the temporal characteristics and attribute characteristics of the firewall rule into the firewall rule concatenated characteristic is configured as:

[0044] Input the temporal characteristics and attribute characteristics of the firewall rule into the weight feature extraction layer to obtain the temporal weight feature and attribute weight feature output by the weight feature extraction layer;

[0045] Concatenate the temporal weight feature and attribute weight feature into the firewall rule concatenated characteristic.

[0046] In a possible implementation manner, the device further includes:

[0047] A second sorting module, configured to sort each rule parameter in the firewall rule according to the historical number of failed matches of each rule parameter in the firewall rule for each firewall rule;

[0048] A matching module, configured to perform matching in sequence according to the sorting of each rule parameter in the firewall rule when matching the firewall rule.

[0049] In a possible implementation manner, the device further includes:

[0050] A merging module, configured to merge the N firewall rules with the lowest comprehensive scores to obtain the merged firewall rule.

[0051] In a third aspect, an embodiment of the present disclosure provides an electronic device, including a memory and a processor, where the memory is used to store one or more computer instructions for supporting a firewall rule optimization device to execute the above-mentioned firewall rule optimization method, and the processor is configured to execute the computer instructions stored in the memory. The firewall rule optimization device may further include a communication interface for communicating between the firewall rule optimization device and other devices or communication networks.

[0052] Fourthly, embodiments of the present disclosure provide a computer-readable storage medium for storing computer instructions used by a firewall rule optimization device, which includes computer instructions for executing the above-mentioned firewall rule optimization method involved in the firewall rule optimization device.

[0053] Fifthly, embodiments of the present disclosure provide a computer program product, including a computer program / instructions, wherein when the computer program / instructions are executed by a processor, the steps in the above-mentioned firewall rule optimization method are implemented.

[0054] According to the technical solution provided by the embodiments of the present disclosure, rule information of firewall rules and their associated rules can be obtained, the firewall rules are scored based on the rule information of the firewall rules and their associated rules to obtain the scores of the firewall rules; multiple firewall rules in the firewall are clustered based on the rule details to obtain at least one clustering cluster, and each clustering cluster includes at least one firewall rule; the clustering clusters are sorted based on the scores of the firewall rules in the clustering clusters; a comprehensive score is obtained by comprehensively scoring according to the scores of the firewall rules and the sorting of the clustering clusters where they are located; the firewall rules are adjusted and cleaned according to the comprehensive scores of the firewall rules. In this way, by comprehensively considering information such as the hit times and importance of firewall rules and their associated rules, as well as information such as the hit times and importance of similar rules, the firewall rules are comprehensively scored, and the firewall rules are adjusted and cleaned according to the comprehensive scores of the firewall rules, avoiding the deletion of less important rules with lower hit times and realizing the precise cleaning of firewall rules.

[0055] It should be understood that the above general description and subsequent detailed description are only exemplary and explanatory, and cannot limit the embodiments of the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS

[0056] In combination with the drawings, through the following detailed description of non-limiting embodiments, other features, objects, and advantages of the embodiments of the present disclosure will become more obvious. In the drawings:

[0057] Figure 1A A flowchart showing a firewall rule optimization method according to an embodiment of the present disclosure is shown;

[0058] Figure 1B A schematic diagram showing the evaluation process of an evaluation model according to an embodiment of the present disclosure is shown;

[0059] Figure 1C A flowchart showing a firewall rule optimization method according to an embodiment of the present disclosure is shown;

[0060] Figure 1D A flowchart showing a firewall rule optimization method according to an embodiment of the present disclosure is shown;

[0061] Figure 1E A schematic diagram showing a usage scenario of a firewall rule optimization method according to an embodiment of the present disclosure;

[0062] Figure 2 A block diagram showing the structure of a firewall rule optimization apparatus according to an embodiment of the present disclosure;

[0063] Figure 3 A block diagram showing the structure of an electronic device according to an embodiment of the present disclosure;

[0064] Figure 4 A schematic diagram of the structure of a computer system suitable for implementing the firewall rule optimization method according to an embodiment of the present disclosure. Detailed implementation manners

[0065] Hereinafter, exemplary embodiments of the present disclosure will be described in detail with reference to the accompanying drawings so that those skilled in the art can easily implement them. In addition, for clarity, parts irrelevant to the description of the exemplary embodiments are omitted in the drawings.

[0066] In the present disclosure, it should be understood that terms such as "including" or "having" are intended to indicate the presence of features, numbers, steps, actions, components, parts, or combinations thereof disclosed in this specification, and are not intended to exclude the possibility of the presence or addition of one or more other features, numbers, steps, actions, components, parts, or combinations thereof.

[0067] In addition, it should be noted that, without conflict, the embodiments in the present disclosure and the features in the embodiments can be combined with each other. The present disclosure will be described in detail below with reference to the accompanying drawings and in combination with the embodiments.

[0068] In the present disclosure, the acquisition of user information or user data is an operation authorized, confirmed by the user, or actively selected by the user.

[0069] As mentioned above, a firewall mainly creates a protective barrier between the internal and external network environments through the action of hardware and software, thereby blocking unsafe network factors for computers. According to the configured network security rules, the firewall sequentially detects the passing data packets to prevent illegal data from invading the internal network and achieve security protection. With the development of the Internet, the network scale has been continuously expanding, and the data packets have been increasing. As a security barrier between the internal and external networks, the firewall plays a crucial security role. With the long-term use of the firewall, the configured firewall rules have accumulated more and more. On the one hand, too many firewall rules may lead to performance bottlenecks of the firewall; on the other hand, many rules have not been hit for a long time, but there is no effective method to organize them. Over time, a vicious cycle has formed, and the redundant rules have accumulated more and more. However, new network security rules still need to be added. Therefore, it is urgent to optimize the firewall rules at present.

[0070] Considering the above problems, the present disclosure proposes a firewall rule optimization method, which can comprehensively consider information such as the hit times and importance of firewall rules and their associated rules, as well as information such as the hit times and importance of similar rules to comprehensively score the firewall rules, and adjust and clean the firewall rules according to the comprehensive scores of each firewall rule, avoiding the deletion of less important rules with lower hit times and achieving precise cleaning of firewall rules.

[0071] Figure 1A The flowchart showing the firewall rule optimization method according to an embodiment of the present disclosure is as Figure 1A shown, and the firewall rule optimization method includes the following steps S101 - S106:

[0072] In step S101, obtain the rule information of the firewall rules and their associated rules, where the rule information includes the time series of rule hit times, rule importance, and rule details;

[0073] In step S102, score the firewall rules based on the rule information of the firewall rules and their associated rules to obtain the scores of the firewall rules;

[0074] In step S103, cluster multiple firewall rules in the firewall based on the rule details to obtain at least one cluster, and each cluster includes at least one firewall rule;

[0075] In step S104, sort the clusters based on the scores of the firewall rules in each cluster;

[0076] In step S105, perform a comprehensive score according to the scores of each firewall rule and the sorting of the clusters where they are located to obtain a comprehensive score;

[0077] In step S106, the firewall rules are cleaned according to the comprehensive scores of the firewall rules.

[0078] In an embodiment of the present disclosure, the firewall rule optimization method is applicable to computers, computing devices, electronic devices, servers, server clusters, etc. that can perform firewall rule cleaning.

[0079] In an embodiment of the present disclosure, the rule information of each firewall rule can be obtained periodically. For example, firewall logs can be received through the syslog (system log) protocol, and the rule hit times of each firewall rule can be obtained from the firewall logs. Then, the rule hit times of each firewall rule within each sequence time period can be statistically obtained, such as the rule hit times of each firewall rule within one day before the current moment, the rule hit times of each firewall rule within one week before the current moment, the rule hit times of each firewall rule within one month before the current moment, the rule hit times of each firewall rule within half a year before the current moment, and so on. In this way, the time series of the rule hit times of each firewall rule can be obtained, and this time series of the rule hit times can reflect the hit conditions of each firewall rule in the long term and short term.

[0080] In an embodiment of the present disclosure, the rule importance refers to the importance of the service protected by the firewall rule. For example, the importance of the rule for protecting against virus intrusion is greater than the importance of the rule for performing email filtering, and so on. The importance of each firewall rule can be configured by experts in the field based on experience and firewall application scenarios. The value range of the importance of each firewall rule can be (0, 1].

[0081] In an embodiment of the present disclosure, the rule details of the firewall rule include matching conditions and actions. By way of example, the firewall rule can be to allow PCs in the internal network segment 10.1.1.0 / 24 to access the Internet. The matching condition is that PCs in the internal network segment 10.1.1.0 / 24 access the Internet, and the action is to allow.

[0082] In an embodiment of the present disclosure, the associated rule of a firewall rule refers to the same or corresponding firewall rules on the primary link and the disaster recovery link. If there is no disaster recovery, the disaster recovery link will not be used, and the hit times of the firewall rules on the disaster recovery link will be 0. However, the hit times of the associated rule on the primary link that is the same as this firewall rule are not 0. Therefore, in order to avoid the scores of the firewall rules on the disaster recovery link being too low and the scoring being inaccurate, resulting in the firewall rules on the disaster recovery link being mis-cleaned, it is necessary to comprehensively consider the rule information of the firewall rule and its associated rules.

[0083] In one embodiment of the present disclosure, when scoring a firewall rule, the time series of the number of rule hits of the firewall rule, the rule importance and the rule details, as well as the time series of the number of rule hits of the associated rules of the firewall rule, the rule importance and the rule details can be comprehensively analyzed to score the firewall rule. For example, the more hits there are in the time series of the number of rule hits of the firewall rule, the higher the score is, the higher the importance is, the higher the score is, the higher the hits of the associated rules are, the higher the importance is, the higher the score is.

[0084] In one embodiment of the present disclosure, when ranking firewall rules, not only the hit situation and importance of the firewall rules and their associated rules should be considered, but also the situation of similar firewall rules should be referred to in order to more accurately rank the firewall rules. Therefore, this embodiment can cluster similar firewall rules in these firewall rules into one category based on the rule details of each firewall rule, and obtain multiple clusters, and the firewall rules in each cluster are similar firewall rules of the same category. The average score of the firewall rules in each cluster can be calculated to obtain the score corresponding to the cluster, and the cluster can be ranked according to the score corresponding to the cluster, so as to obtain the cluster ranking.

[0085] In one embodiment of the present disclosure, a comprehensive score may be obtained by comprehensively scoring the scores of the firewall rules and the ranking of the clusters to which they belong. For example, the score of the firewall rule is P, and the ranking of the clusters to which it belongs is N. The comprehensive score may be P*a^N, where N is the ranking of the clusters to which the firewall rule belongs, a^N refers to a to the power of N, and a is an empirical value that may be adjusted according to actual conditions. For example, a may be 0.9.

[0086] In one embodiment of the present disclosure, each firewall rule can be comprehensively ranked from high to low according to the comprehensive score, and the firewall rules are matched according to the comprehensive ranking. The rules with a rule hit count of 0 and a low ranking are disabled or deleted, so that redundant rules are cleared. At the same time, since the importance of the firewall rule and its associated rules, as well as the hit count and importance of similar rules are also referred to to sort the firewall rules, it is also avoided that the rules with a low hit count but more important are cleared, thereby achieving accurate cleaning of the firewall rules.

[0087] In a possible implementation manner, scoring the firewall rule based on the rule information of the firewall rule and the associated rule to obtain the score of the firewall rule includes:

[0088] The rule information of the firewall rule and its associated rules is input into a preset evaluation model, and the evaluation model is executed to obtain the score corresponding to the firewall rule.

[0089] In this embodiment, the evaluation model can be a deep neural network model, which is used to analyze the rule information of the firewall rules and their associated rules to obtain the evaluation result, i.e., the score, of the firewall rules.

[0090] In this embodiment, an evaluation model is used to evaluate and score the firewall rules, and the scoring is more accurate.

[0091] In a possible implementation manner, Figure 1B The schematic diagram of the evaluation process of the evaluation model according to an embodiment of the present disclosure is shown, as Figure 1B shown, the preset evaluation model includes a time series feature extraction layer and an output layer; inputting the rule information of the firewall rules and their associated rules into the preset evaluation model, executing the evaluation model, and obtaining the score corresponding to the firewall rules includes:

[0092] Inputting the time series of the rule hit times of the firewall rules and their associated rules into the time series feature extraction layer to extract the time series features of the firewall rules;

[0093] Based on the rule importance and rule details of the firewall rules, obtaining the attribute features of the firewall rules;

[0094] Concatenating the time series features and attribute features of the firewall rules into the firewall rule concatenated features;

[0095] Inputting the firewall rule concatenated features into the output layer to obtain the score corresponding to the firewall rules output by the output layer.

[0096] In this embodiment, the time series feature extraction layer is used to extract the time series features in the time series of the rule hit times of the firewall rules and their associated rules to obtain the time series features of the firewall rules. The time series feature extraction layer can be an RNN (Recurrent Neural Networks) model. For example, the time series feature extraction layer can include at least one LSTM (Long Short-Term Memory) network and a pooling layer.

[0097] In this embodiment, feature extraction can be performed on the rule importance and rule details of the firewall rules to obtain the attribute features of the firewall rules; then, the time series features and attribute features of the firewall rules are concatenated together to form the firewall rule concatenated features; finally, the firewall rule concatenated features are input into the output layer to obtain the score output by the output layer.

[0098] In this embodiment, a temporal feature extraction layer is used to extract temporal features in the time series of the rule hit times, so that the feature extraction is more accurate, and thus the obtained score is more accurate.

[0099] In a possible implementation, the splicing of the temporal feature and the attribute feature of the firewall rule into the firewall rule splicing feature includes:

[0100] Inputting the temporal feature and the attribute feature of the firewall rule into a weight feature extraction layer to obtain the temporal weight feature and the attribute weight feature output by the weight feature extraction layer;

[0101] Splicing the temporal weight feature and the attribute weight feature into a firewall rule splicing feature.

[0102] In this embodiment, the preset evaluation model further includes a weight feature extraction layer. The input of this weight feature extraction layer is the temporal feature and the attribute feature of the firewall rule, and the output is the temporal feature and the attribute feature with weights, that is, the temporal weight feature and the attribute weight feature. This weight feature extraction layer is used to learn the weights of the temporal feature and the attribute feature, and the obtained weight values are used to represent the importance of the temporal feature and the attribute feature to the score of the firewall rule. This weight feature extraction layer can be a decision tree model, and the output result is the product of the temporal feature and its weight value, that is, the temporal weight feature, and the product of the attribute feature and its weight value, that is, the attribute weight feature.

[0103] In this embodiment, the temporal weight feature and the attribute weight feature can be spliced into a splicing feature, and scoring is performed based on this splicing feature, making full use of the weight features with high importance, so that the scoring is more accurate.

[0104] In a possible implementation, Figure 1C A flowchart showing a firewall rule optimization method according to an embodiment of the present disclosure is as Figure 1C shown. The above firewall rule optimization method may further include the following steps S107 and S108:

[0105] In step S107, for each firewall rule, sort the rule parameters in the firewall rule according to the historical match failure times of the rule parameters in the firewall rule;

[0106] In step S108, when matching the firewall rule, perform the matching in sequence according to the sorting of the rule parameters in the firewall rule.

[0107] In this embodiment, for each firewall rule, when performing matching, the matching is carried out in sequence according to the sorting of each rule parameter. If the matching is successful, the matching of the next rule parameter is continued. If the matching fails, the matching of the next firewall rule is continued. Therefore, in order to improve the hit efficiency of firewall rules, the rule parameters in each firewall rule can be sorted according to the historical number of failed matches of each rule parameter, that is, the rule parameter with the higher number of failed matches is ranked more forward. In this way, when matching firewall rules, the rule parameter with the highest number of failed matches can be preferentially matched. If the matching fails, the matching of the next rule can be quickly carried out. Such sorting can improve the efficiency of failed matches of each firewall rule and quickly enter the matching of the next rule, thereby improving the hit efficiency of firewall rules.

[0108] In a possible implementation manner, Figure 1D shows a flowchart of a firewall rule optimization method according to an embodiment of the present disclosure, as Figure 1D shown, the above firewall rule optimization method may further include the following step S109:

[0109] In step S109, the N firewall rules with the lowest comprehensive scores are merged to obtain the merged firewall rules.

[0110] In this embodiment, for the N firewall rules with the lowest comprehensive scores, since these firewall rules are all unimportant and have low hit rates, in order to reduce the number of rules, thereby reducing the average number of times a data packet matches firewall rules and achieving the purpose of improving firewall filtering efficiency, these rules can be merged. For example, the firewall rules can be merged by combining like terms. Suppose the firewall rule 1 allows PCs in the internal network segment 10.1.1.0 / 24 to access the Internet, and the firewall rule 2 allows PCs in the internal network segment 10.1.1.0 / 25 to access the Internet. Then they can be merged into the following firewall rule: Allow PCs in the internal network segments 10.1.1.0 / 24 and 10.1.1.0 / 25 to access the Internet.

[0111] This embodiment can perform a merging operation on the N firewall rules with the lowest comprehensive scores, merge the firewall rules that can be merged together. In this way, the number of rules can be reduced, thereby reducing the average number of times a data packet matches firewall rules and achieving the purpose of improving firewall filtering efficiency; at the same time, since the merged are the N firewall rules with the lowest comprehensive scores, these merges will not affect the matching of firewall rules with high comprehensive scores.

[0112] Exemplarily, Figure 1E shows a schematic diagram of the usage scenario of the firewall rule optimization method according to an embodiment of the present disclosure, as Figure 1EAs shown in the figure, the firewall device 11 is located between the internal and external networks and performs access control on the internal and external communications. The firewall device 11 can perform optimization operations such as sorting, cleaning, and merging on the firewall rules stored in the firewall device according to the method in the above embodiment. In this way, the network communication data between the internal network and the external network all needs to pass through the firewall device 11. If a host or server in the internal network sends communication data to the external network, the firewall device 11 can match the communication data with the optimized firewall rules. When the match is successful, if the action of the successfully matched firewall rule is allowed, the communication data sent by the host or server in the internal network can pass through the firewall device 11 to reach the external network. If the action in the successfully matched firewall rule is prohibited, the communication data sent by the host or server in the internal network to the external network is rejected from passing through the firewall device 11.

[0113] The following is an embodiment of the device of the present disclosure, which can be used to execute the embodiment of the method of the present disclosure.

[0114] Figure 2 The structural block diagram of a firewall rule optimization device according to an embodiment of the present disclosure is shown. The device can be implemented as part or all of an electronic device through software, hardware, or a combination of both. As Figure 2 shown, the firewall rule optimization device 200 includes:

[0115] An acquisition module 201, configured to acquire the rule information of the firewall rules and their associated rules, where the rule information includes the time series of the rule hit times, the rule importance, and the rule details;

[0116] A first scoring module 202, configured to score the firewall rules based on the rule information of the firewall rules and their associated rules to obtain the scores of the firewall rules;

[0117] A clustering module 203, configured to cluster multiple firewall rules in the firewall based on the rule details to obtain at least one clustering cluster, and each clustering cluster includes at least one firewall rule;

[0118] A first sorting module 204, configured to sort the clustering clusters based on the scores of the firewall rules in the clustering clusters;

[0119] A second scoring module 205, configured to perform a comprehensive scoring according to the scores of the firewall rules and the sorting of their respective clustering clusters to obtain a comprehensive score;

[0120] A cleaning module 206, configured to clean the firewall rules according to the comprehensive scores of the firewall rules.

[0121] In an embodiment of the present disclosure, the firewall rule optimization device is applicable to computers, computing devices, electronic devices, servers, server clusters, etc. that can perform firewall rule cleaning.

[0122] In an embodiment of the present disclosure, the rule information of each firewall rule can be obtained periodically. For example, firewall logs can be received through the syslog (system log) protocol, and the rule hit times of each firewall rule can be obtained from the firewall logs. Then, the rule hit times of each firewall rule within each time sequence can be statistically obtained, such as the rule hit times of each firewall rule within one day before the current moment, the rule hit times of each firewall rule within one week before the current moment, the rule hit times of each firewall rule within one month before the current moment, the rule hit times of each firewall rule within half a year before the current moment, and so on. In this way, the time sequence of the rule hit times of each firewall rule can be obtained, and this time sequence of the rule hit times can reflect the hit situations of each firewall rule in the long term and short term.

[0123] In an embodiment of the present disclosure, the rule importance refers to the importance of the service protected by the firewall rule. For example, the importance of a rule for protecting against virus intrusion is greater than the importance of a rule for performing email filtering, and so on. The importance of each firewall rule can be configured by experts in the field based on experience and firewall application scenarios. The value range of the importance of each firewall rule can be (0, 1].

[0124] In an embodiment of the present disclosure, the rule details of the firewall rule include matching conditions and actions. For example, the firewall rule can be to allow PCs in the internal network segment 10.1.1.0 / 24 to access the Internet. The matching condition is that PCs in the internal network segment 10.1.1.0 / 24 access the Internet, and the action is to allow.

[0125] In an embodiment of the present disclosure, the associated rule of a firewall rule refers to the same or corresponding firewall rules on the primary link and the disaster recovery link. If there is no disaster recovery, the disaster recovery link will not be used, and the hit times of the firewall rule on the disaster recovery link will be 0, while the hit times of the associated rule on the primary link that is the same as the firewall rule are not 0. Therefore, in order to avoid the score of the firewall rule on the disaster recovery link being too low and the scoring being inaccurate, resulting in the firewall rule on the disaster recovery link being mis-cleaned, it is necessary to comprehensively consider the rule information of the firewall rule and its associated rules.

[0126] In one embodiment of the present disclosure, when scoring a firewall rule, the time series of the number of rule hits of the firewall rule, the rule importance and the rule details, as well as the time series of the number of rule hits of the associated rules of the firewall rule, the rule importance and the rule details can be comprehensively analyzed to score the firewall rule. For example, the more hits there are in the time series of the number of rule hits of the firewall rule, the higher the score is, the higher the importance is, the higher the score is, the higher the hits of the associated rules are, the higher the importance is, the higher the score is.

[0127] In one embodiment of the present disclosure, when ranking firewall rules, not only the hit situation and importance of the firewall rules and their associated rules should be considered, but also the situation of similar firewall rules should be referred to in order to more accurately rank the firewall rules. Therefore, this embodiment can cluster similar firewall rules in these firewall rules into one category based on the rule details of each firewall rule, and obtain multiple clusters, and the firewall rules in each cluster are similar firewall rules of the same category. The average score of the firewall rules in each cluster can be calculated to obtain the score corresponding to the cluster, and the cluster can be ranked according to the score corresponding to the cluster, so as to obtain the cluster ranking.

[0128] In one embodiment of the present disclosure, a comprehensive score may be obtained by comprehensively scoring the scores of the firewall rules and the ranking of the clusters to which they belong. For example, the score of the firewall rule is P, and the ranking of the clusters to which it belongs is N. The comprehensive score may be P*a^N, where N is the ranking of the clusters to which the firewall rule belongs, a^N refers to a to the power of N, and a is an empirical value that may be adjusted according to actual conditions. For example, a may be 0.9.

[0129] In one embodiment of the present disclosure, each firewall rule can be comprehensively ranked from high to low according to the comprehensive score, and the firewall rules are matched according to the comprehensive ranking. The rules with a rule hit count of 0 and a low ranking are disabled or deleted, so that redundant rules are cleared. At the same time, since the importance of the firewall rule and its associated rules, as well as the hit count and importance of similar rules are also referred to to sort the firewall rules, it is also avoided that the rules with a low hit count but more important are cleared, thereby achieving accurate cleaning of the firewall rules.

[0130] In a possible implementation, the first scoring module 202 is configured to:

[0131] The rule information of the firewall rule and its associated rules is input into a preset evaluation model, and the evaluation model is executed to obtain the score corresponding to the firewall rule.

[0132] In this embodiment, the evaluation model can be a deep neural network model, which is used to analyze the rule information of the firewall rule and its associated rules to obtain the evaluation result, i.e., the score, of the firewall rule.

[0133] In this embodiment, an evaluation model is used to evaluate and score the firewall rule, and the scoring is more accurate.

[0134] In a possible embodiment, the preset evaluation model includes a time series feature extraction layer and an output layer; the part in the first scoring module 202 that inputs the rule information of the firewall rule and its associated rules into the preset evaluation model, executes the evaluation model, and obtains the score corresponding to the firewall rule is configured as:

[0135] Input the time series of the rule hit times of the firewall rule and its associated rules into the time series feature extraction layer to extract the time series features of the firewall rule.

[0136] Based on the rule importance and rule details of the firewall rule, obtain the attribute features of the firewall rule.

[0137] Concatenate the time series features and attribute features of the firewall rule into the firewall rule concatenated features.

[0138] Input the firewall rule concatenated features into the output layer to obtain the score corresponding to the firewall rule output by the output layer.

[0139] In this embodiment, the time series feature extraction layer is used to extract the time series features in the time series of the rule hit times of the firewall rule and its associated rules to obtain the time series features of the firewall rule. The time series feature extraction layer can be an RNN (Recurrent Neural Networks) model. For example, the time series feature extraction layer can include at least one LSTM (Long Short-Term Memory) network and a pooling layer.

[0140] In this embodiment, feature extraction can be performed on the rule importance and rule details of the firewall rule to obtain the attribute features of the firewall rule; then, the time series features and attribute features of the firewall rule are concatenated together to form the firewall rule concatenated features; finally, the firewall rule concatenated features are input into the output layer to obtain the score output by the output layer.

[0141] In this embodiment, the time series feature extraction layer is used to extract the time series features in the time series of the rule hit times, and the feature extraction is more accurate, so that the obtained score is more accurate.

[0142] In a possible implementation manner, the part in the first scoring module 202 that splices the temporal feature and the attribute feature of the firewall rule into the firewall rule splicing feature is configured as:

[0143] Input the temporal feature and the attribute feature of the firewall rule into the weight feature extraction layer, and obtain the temporal weight feature and the attribute weight feature output by the weight feature extraction layer;

[0144] Splice the temporal weight feature and the attribute weight feature into the firewall rule splicing feature.

[0145] In this implementation manner, the preset evaluation model further includes a weight feature extraction layer. The input of this weight feature extraction layer is the temporal feature and the attribute feature of the firewall rule, and the output is the temporal feature and the attribute feature with weights, that is, the temporal weight feature and the attribute weight feature. This weight feature extraction layer is used to learn the weights of the temporal feature and the attribute feature, and the obtained weight values are used to represent the importance of the temporal feature and the attribute feature to the score of the firewall rule. This weight feature extraction layer can be a decision tree model, and the output result is the product of the temporal feature and its weight value, that is, the temporal weight feature, and the product of the attribute feature and its weight value, that is, the attribute weight feature.

[0146] In this implementation manner, the temporal weight feature and the attribute weight feature can be spliced into a splicing feature, and scoring is performed based on this splicing feature. The weight features with high importance are fully utilized, making the scoring more accurate.

[0147] In a possible implementation manner, the device further includes:

[0148] A second sorting module, configured to sort each rule parameter in the firewall rule according to the historical number of matching failures of each rule parameter in the firewall rule for each firewall rule;

[0149] A matching module, configured to perform matching in sequence according to the sorting of each rule parameter in the firewall rule when matching the firewall rule.

[0150] In this embodiment, for each firewall rule, when performing matching, the matching is carried out in sequence according to the sorting of each rule parameter. If the matching is successful, the matching of the next rule parameter is continued. If the matching fails, the matching of the next firewall rule is continued. Therefore, in order to improve the hit efficiency of firewall rules, the rule parameters in each firewall rule can be sorted according to the historical number of failed matches of each rule parameter, that is, the rule parameter with a higher number of failed matches is ranked more forward. In this way, when matching firewall rules, the rule parameter with the highest number of failed matches can be preferentially matched. If the matching fails, the matching of the next rule can be quickly carried out. Such sorting can improve the matching failure efficiency of each firewall rule, quickly enter the matching of the next rule, and thus improve the hit efficiency of firewall rules.

[0151] In a possible implementation manner, the device further includes:

[0152] A merging module, configured to merge the N firewall rules with the lowest comprehensive scores to obtain the merged firewall rules.

[0153] In this embodiment, for the N firewall rules with the lowest comprehensive scores, since these firewall rules are all unimportant and have a low hit rate, in order to reduce the number of rules, thereby reducing the average number of times a data packet matches the firewall rules and achieving the purpose of improving the firewall filtering efficiency, these rules can be merged. For example, the firewall rules can be merged by combining like terms. Suppose the firewall rule 1 allows PCs in the internal network segment 10.1.1.0 / 24 to access the Internet, and the firewall rule 2 allows PCs in the internal network segment 10.1.1.0 / 25 to access the Internet. Then they can be merged into the following firewall rule: Allow PCs in the internal network segments 10.1.1.0 / 24 and 10.1.1.0 / 25 to access the Internet.

[0154] This embodiment can perform a merging operation on the N firewall rules with the lowest comprehensive scores, merge the firewall rules that can be merged together. This can reduce the number of rules, thereby reducing the average number of times a data packet matches the firewall rules and achieving the purpose of improving the firewall filtering efficiency; at the same time, since the merged are the N firewall rules with the lowest comprehensive scores, these merges will not affect the matching of the firewall rules with high comprehensive scores.

[0155] The present disclosure also discloses an electronic device, Figure 3 Show a structural block diagram of an electronic device according to an embodiment of the present disclosure.

[0156] Such as Figure 3As shown, the electronic device 300 includes a memory 301 and a processor 302. Among them, the memory 301 is used to store one or more computer instructions, and the one or more computer instructions are executed by the processor 302 to implement the above method steps.

[0157] Figure 4 It is a schematic structural diagram of a computer system suitable for implementing the firewall rule optimization method according to an embodiment of the present disclosure.

[0158] As Figure 4 shown, the computer system 400 includes a processing unit 401, which can execute various processes in the above embodiments according to the program stored in the read-only memory (ROM) 402 or the program loaded from the storage section 408 into the random access memory (RAM) 403. In the RAM 403, various programs and data required for the operation of the system 400 are also stored. The processing unit 401, the ROM 402, and the RAM 403 are connected to each other through a bus 404. The input / output (I / O) interface 405 is also connected to the bus 404.

[0159] The following components are connected to the I / O interface 405: an input section 406 including a keyboard, a mouse, etc.; an output section 407 including a cathode ray tube (CRT), a liquid crystal display (LCD), etc. and a speaker, etc.; a storage section 408 including a hard disk, etc.; and a communication section 409 including a network interface card such as a LAN card, a modem, etc. The communication section 409 performs communication processing via a network such as the Internet. A drive 410 is also connected to the I / O interface 405 as needed. A removable medium 411, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 410 as needed, so that the computer program read from it can be installed into the storage section 408 as needed. Among them, the processing unit 401 can be implemented as a processing unit such as a CPU, a GPU, a TPU, an FPGA, an NPU, etc.

[0160] Specifically, according to an embodiment of the present disclosure, the above-described method can be implemented as a computer software program. For example, an embodiment of the present disclosure includes a computer program product, which includes a computer program tangibly contained on a computer-readable medium, and the computer program includes program code for executing the firewall rule optimization method. In such an embodiment, the computer program can be downloaded and installed from the network through the communication section 409, and / or installed from the removable medium 411.

[0161] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present disclosure. In this regard, each block in the flowchart or block diagram may represent a module, a segment of a program, or a part of code that contains one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than that marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, as well as combinations of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system that performs the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.

[0162] The units or modules involved in the embodiments described in the present disclosure can be implemented in software or in hardware. The units or modules described can also be provided in a processor, and the names of these units or modules do not, in some cases, constitute a limitation on the units or modules themselves.

[0163] As another aspect, the embodiments of the present disclosure also provide a computer-readable storage medium, which can be the computer-readable storage medium included in the device in the above-described embodiments; or it can exist separately and be a computer-readable storage medium not assembled into the device. The computer-readable storage medium stores one or more programs, and the one or more programs are used by one or more processors to execute the methods described in the embodiments of the present disclosure.

[0164] The above description is only a preferred embodiment of the present disclosure and an explanation of the technical principles applied. Those skilled in the art should understand that the scope of the invention involved in the embodiments of the present disclosure is not limited to the technical solutions formed by the specific combination of the above technical features, but should also cover other technical solutions formed by any combination of the above technical features or their equivalent features without departing from the inventive concept. For example, technical solutions formed by mutually replacing the above features with technical features having similar functions (but not limited to) disclosed in the embodiments of the present disclosure.

Claims

1. A firewall rule optimization method, characterized in that, Including: Obtain the rule information of the firewall rules and their associated rules, where the rule information includes the time series of rule hit counts, rule importance, and rule details; Score the firewall rules based on the rule information of the firewall rules and their associated rules to obtain the scores of the firewall rules; Cluster multiple firewall rules in the firewall based on the rule details of the firewall rules and their associated rules to obtain at least one cluster, and each cluster includes at least one firewall rule; wherein, the firewall rules in each cluster are similar and belong to the same type of firewall rules; Sort the clusters based on the scores of the firewall rules in each cluster; Perform a comprehensive scoring according to the scores of each firewall rule and the sorting of the cluster where it is located to obtain a comprehensive score; Clean the firewall rules according to the comprehensive scores of each firewall rule; Merge the N firewall rules with the lowest comprehensive scores to obtain the merged firewall rules.

2. The method according to claim 1, characterized in that, The scoring the firewall rules based on the rule information of the firewall rules and their associated rules to obtain the scores of the firewall rules includes: Input the rule information of the firewall rules and their associated rules into a preset evaluation model, execute the evaluation model, and obtain the scores corresponding to the firewall rules.

3. The method according to claim 2, characterized in that, The preset evaluation model includes a time series feature extraction layer and an output layer; the inputting the rule information of the firewall rules and their associated rules into a preset evaluation model, executing the evaluation model, and obtaining the scores corresponding to the firewall rules includes: Input the time series of rule hit counts of the firewall rules and their associated rules into the time series feature extraction layer to extract the time series features of the firewall rules; Obtain the attribute features of the firewall rules based on the rule importance and rule details of the firewall rules; Concatenate the time series features and attribute features of the firewall rules into the firewall rule concatenated features; Input the firewall rule concatenated features into the output layer to obtain the scores corresponding to the firewall rules output by the output layer.

4. The method according to claim 3, characterized in that, The concatenating the time series features and attribute features of the firewall rules into the firewall rule concatenated features includes: Input the time series features and attribute features of the firewall rules into a weight feature extraction layer to obtain the time series weight features and attribute weight features output by the weight feature extraction layer; Concatenate the time series weight features and attribute weight features into the firewall rule concatenated features.

5. The method according to claim 1, characterized in that, The method further includes: For each firewall rule, sort the rule parameters in the firewall rule according to the historical mismatch counts of the rule parameters in the firewall rule; When matching the firewall rule, perform the matching in sequence according to the sorting of the rule parameters in the firewall rule.

6. A firewall rule optimization device, characterized in that, Including: An acquisition module, configured to obtain the rule information of the firewall rules and their associated rules, where the rule information includes the time series of rule hit counts, rule importance, and rule details; A first scoring module, configured to score the firewall rules based on the rule information of the firewall rules and their associated rules to obtain the scores of the firewall rules; A clustering module, configured to cluster multiple firewall rules in a firewall based on the rule details to obtain at least one clustering cluster, where each clustering cluster includes at least one firewall rule; wherein, the firewall rules in each clustering cluster are similar and of the same type of firewall rules; A first sorting module, configured to sort the clustering clusters based on the scores of the firewall rules in the clustering clusters; A second scoring module, configured to perform comprehensive scoring according to the scores of the firewall rules and the sorting of the clustering clusters where they are located to obtain a comprehensive score; A cleaning module, configured to clean the firewall rules according to the comprehensive scores of the firewall rules; A merging module, configured to merge the N firewall rules with the lowest comprehensive scores to obtain the merged firewall rules.

7. An electronic device, including a memory and at least one processor; characterized in that, The memory is used to store one or more computer instructions, wherein the one or more computer instructions are executed by the at least one processor to implement the method steps described in any one of claims 1-5.

8. A computer-readable storage medium, characterized in that, Stored thereon are computer instructions, which when executed by a processor implement the method steps described in any one of claims 1-5.

9. A computer program product, characterized in that,Including a computer program / instructions, which when executed by a processor implement the method steps described in any one of claims 1-5.

Citation Information

Patent Citations

  • Method for combining safety rules and intelligent device

    CN106603524A

  • Network security policy optimization method

    CN111935186A